Its been more than a year since Capital One Financial said it had suffered a data breach that exposed the personal information of 106 million customers, but the lessons from the episode are as timely as ever.
The $80 million penalty assessed by the Office of the Comptroller of the Currency on Thursday against the McLean, Va., company for its security lapse highlights how serious a regulatory risk data-integrity issues are especially those involving cloud computing.
The hack was allegedly carried out by Paige Thompson, a former software engineer at Amazon Web Services, who broke into Capital One's servers in Amazon's cloud through a misconfigured web application firewall. Thompson was arrested and awaits trial on charges of hacking Capital One and 30 other organizations.
Banks continue to put sensitive data in the cloud, especially as digital services have risen in popularity during the pandemic. The incident and its aftermath offer banks a watchlist of precautions that have become clearer with the passage of time, say academic and information security experts interviewed for this story.
Here are six steps banks can take to strengthen their data defenses.
Thompson gained access to the Capital One data through an insecure web application firewall.
Jim Reavis, co-founder and chief executive of the Cloud Security Alliance, said Capital One used open-source software to build its firewall to the servers.
Open-source software in and of itself is not dangerous, he said. All of corporate America uses open-source software of different types and flavors, he said.
But this firewall had a misconfiguration that the attacker used to conduct a server-side request forgery, which enabled her to obtain privileged identity credentials.
Maintaining security updates on open-source software is as important as it is on proprietary software, Reavis said.
Capital One did not immediately respond to a request for comment Friday, but a day earlier, after the OCC penalty was announced, the company said it takes data security seriously and had controls in place at the time of the breach that helped authorities make an arrrest.
"In the year since the incident, we have invested significant additional resources into further strengthening our cyber defenses, and have made substantial progress in addressing the requirements of these orders," a company spokesperson said in an email to American Banker.
A combination of automation and human review can be used to check and double-check the security of software code, said Steve Rubinow, a computer science faculty member at DePaul University and former chief information officer of the New York Stock Exchange.
In any security space, the weakest link is human because we humans make mistakes, Rubinow said. Even the smartest of us, the most capable of people with the best track records are capable of making mistakes.
Thompson was an insider: She had worked at AWS on the Capital One account.
Reavis said companies need to pay more attention to administrator accounts, sometimes called God access accounts, that give insiders carte blanche access to everything. And they should and apply dual key systems, so administrators cant access elevated privileges on their own.
Companies ought to employ a principle of least privileges so when a credential is stolen, as in this case, they can reduce the harm caused, Reavis said.
Capital One made some mistakes with authentication, Reavis said.
Multifactor authentication is a great way to take a lot of different types of successful attacks and cause them to have no negative consequences, he said.
Capital One does use multifactor authentication a lot, Reavis said. But on back-end systems like this one, its use is uncommon.
That's changing you're seeing more organizations thinking of identity more holistically, Reavis said. They're thinking of identity of devices, identity of applications, identity of data stores, and then extending their identity management and authentication strategies across the board.
Capital One did respond quickly and effectively to the breach, such that the hacker was caught right away and the data was rapidly secured.
In addition to a strong incident response, Capital One notified customers of the breach promptly.
It likely reduced their fine significantly, Reavis said.
Throughout the past year, Capital One has been in a court battle to keep private an investigative report it hired the security firm Mandiant to write about the breach. But recently, a court required Capital One to share the report with the plaintiffs' attorneys in a class action.
An incident analysis or forensics type of report is going to have a lot of sensitive information that might expose additional vulnerabilities and threat vectors, Reavis said. I understand the sensitivity. But organizations need to be very frank about how their systems are configured and tested to make sure they're secure in the first place and be very transparent about how incidents are handled, how the systems are governed.
Mark Bower, senior vice president with the data-security company comforte AG, makes a point regulators have been making for years: Companies cant outsource security to vendors, especially cloud vendors.
The signal is very clear: The often-referenced shared responsibility cloud model means naught when its your data, Bower said. You are responsible and accountable, and will pay the price if gaps are exploited.
Rubinow echoed this point.
There have been a number of companies in the past that have so much respect for Amazon or whoever their cloud provider is that they say, if I just put my computing assets in their cloud, they will secure them for me because they're really smart people and they do it at scale, he said.
I always have to remind those people that they don't secure everything. And at the end of the day, these are your applications. This is your data. You need to be vigilant and safeguard them, because no one's going to care about them as much as you are, and it's still your responsibility.
View post:
Capital One fine is latest wake-up call for banks using the cloud - American Banker
- Roundup Of Cloud Computing Forecasts, 2017 - Forbes [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- RCom arm in tie-up for cloud computing - Moneycontrol.com [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- How Do You Define Cloud Computing? - Data Center Knowledge [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- 5 Cloud Computing Stocks to Buy - TheStreet.com [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Cloud Computing Continues to Influence HPC - insideHPC [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Red Hat's New Products Centered Around Cloud Computing, Containers - Virtualization Review [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Adobe bets big on cloud computing for marketing, creative professionals - Livemint [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Verizon sells cloud services to IBM in 'unique cooperation between ... - Cloud Tech [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- How Cloud Computing Is Turning the Tide on Heart Attacks - Fortune [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Hospital CIOs see benefits of healthcare cloud computing - TechTarget [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Trends In Cloud Computing - Business Solutions Magazine [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- A deeper dive into cloud security as a service: Advantages and issues - Cloud Tech [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- OpenText buys cloud computing firm for US$103 million - TheRecord.com [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- Belfast IT firm celebrates cloud computing success in 57 countries ... - Belfast Telegraph [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- Meet The Cloud Wars Top 10: The World's Most-Powerful Cloud-Computing Vendors - Forbes [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- How to approach cloud computing and cyber security in 2017 - Information Age [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- CFOs have discovered the big stick of cloud computing - InfoWorld [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- Belmont Stakes Odds 2017: Latest Vegas Betting Lines Before Post Positions Draw - Bleacher Report [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Cloudistics Announces New Cloud Computing Program That Enables High Margin Reoccurring Revenue Models for ... - Marketwired (press release) [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- CloudCheckr, cloud computing company expects rapid growth in Rochester - WXXI News [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- IBM Losing Facebook's WhatsApp as Cloud Customer, says CNBC - Barron's [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- What My Father Taught Me About Cloud Computing - Virtualization Review [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Workday Phenomenon Goes Global As Cloud Computing Goes Mainstream - Forbes [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- New Cloud Computing and IT Outsourcing Requirements in the Financial Sector - JD Supra (press release) [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- 3 Things You Should Know About Cloud Computing Right Now - Fortune [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Learning in the Sky: Collaborative Robots Embrace Cloud Computing - Machine Design [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Best Practices To Manage Your Hybrid Cloud - Forbes [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Here's how venture capitalists are thinking about cloud computing companies and technologies - GeekWire [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Amazon is helping veterans find jobs in cloud computing - Marketplace - Marketplace.org [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- New Cloud Computing and IT Outsourcing Requirements in the Financial Sector - Lexology (registration) [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Growing Patent Claim Risks in Cloud Computing - Lexology (registration) [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- The benefits of cloud computing, Rust 1.18, and intelligent tracking prevention in WebKit SD Times news digest ... - SDTimes.com [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Edge Computing Is New Cloud Computing Tech Investors Should Track - GuruFocus.com [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Real Estate Weekly: Digital Realty Becomes A Cloud Computing Giant - Seeking Alpha [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Virtualization admin? Pivot -- pivot now -- to a cloud computing career - TechTarget [Last Updated On: June 10th, 2017] [Originally Added On: June 10th, 2017]
- Why isn't Cloud Computing in the 2017 Belmont Stakes? - FanSided [Last Updated On: June 11th, 2017] [Originally Added On: June 11th, 2017]
- Cloud Computing Companies Move Into Medical Diagnosis (GOOG, IBM) - Investopedia [Last Updated On: June 11th, 2017] [Originally Added On: June 11th, 2017]
- China's cloud industry moving to new era with emergence of unicorns - TechNode (blog) [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- Terry Crews Is On Crackdown 3 Trailer, No Cloud Computing For Single Player - EconoTimes [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- The Risks and Perquisites of Cloud Computing - DATAQUEST [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- Alibaba Cloud announces launch of data centres in India and Indonesia - Cloud Tech [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- Indonesia banks have yet to implement cloud computing - Jakarta Post [Last Updated On: June 13th, 2017] [Originally Added On: June 13th, 2017]
- 'Sweden is heaven for cloud computing': Amazon Nordic chief - The ... - The Local Sweden [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- Amazon.com to open second government cloud-computing region ... - The Seattle Times [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- Shadow raises $57 million for its cloud computing service for ... - TechCrunch [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- Amazon Still Leads Cloud Rankings, But Competition Is Coming On Strong - Fortune [Last Updated On: June 16th, 2017] [Originally Added On: June 16th, 2017]
- Alibaba to enter European cloud computing market in mid-2017 | Air ... - Air Cargo World (registration) [Last Updated On: June 17th, 2017] [Originally Added On: June 17th, 2017]
- Alibaba to enter European cloud computing market in mid-2017 - Air Cargo World (registration) [Last Updated On: June 17th, 2017] [Originally Added On: June 17th, 2017]
- Pressing Tech Issue: Enterprise Software Vs. Cloud Computing? - Credit Union Times [Last Updated On: June 17th, 2017] [Originally Added On: June 17th, 2017]
- 7 Tips for Securely Moving Data to the Cloud - Government Technology (blog) [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- Chinese tech giant Alibaba joins key open-source cloud computing foundation - GeekWire [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- Microsoft Could Surpass Amazon in Cloud Computing This Year (AMZN, MSFT) - Investopedia [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- GDS Holdings Limited (GDS) Announces Strategic Partnership with Tencent Cloud - StreetInsider.com [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- Cloud first - Philippine Star [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- Three Considerations for Reducing Risk in Cloud Computing - CIOReview [Last Updated On: June 21st, 2017] [Originally Added On: June 21st, 2017]
- Cloud Computing and Digital Divide 2.0 - CircleID - CircleID [Last Updated On: June 21st, 2017] [Originally Added On: June 21st, 2017]
- Microsoft will ride artificial intelligence, cloud computing to higher ... - CNBC [Last Updated On: June 21st, 2017] [Originally Added On: June 21st, 2017]
- Cloud-Computing Business Lifts Oracle's Profit -- Update - Fox Business [Last Updated On: June 21st, 2017] [Originally Added On: June 21st, 2017]
- Report affirms continued cloud spend for US businesses in 2017 - Cloud Tech [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Catching up with an interconnected federal cloud - GCN.com [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Cloud-Computing Business Lifts Oracle's Profit -- 2nd Update - Fox Business [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Cisco adapts to the rise of cloud computing - The Economist [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Amazon accuses Walmart of bullying in cloud computing clash - BBC News [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Companies plan to spend more on cloud computing services this year, higher prices among drivers: Clutch - Canadian Underwriter [Last Updated On: June 23rd, 2017] [Originally Added On: June 23rd, 2017]
- Survey: businesses ramp up spending on cloud computing DC ... - DC Velocity [Last Updated On: June 24th, 2017] [Originally Added On: June 24th, 2017]
- Morgan Stanley: Cloud computing is at 'an inflection point' but how big will it get? - GeekWire [Last Updated On: June 26th, 2017] [Originally Added On: June 26th, 2017]
- How the cloud has changed education and training - TNW [Last Updated On: June 26th, 2017] [Originally Added On: June 26th, 2017]
- Cloud computing key to 4th industrial revolution - News VietNamNet - VietNamNet Bridge [Last Updated On: June 26th, 2017] [Originally Added On: June 26th, 2017]
- Lady Eli, Cloud Computing Among Workers for Brown - BloodHorse.com (press release) (registration) (blog) [Last Updated On: June 26th, 2017] [Originally Added On: June 26th, 2017]
- Microsoft signs cloud-computing partnership with Box - The Seattle Times [Last Updated On: June 27th, 2017] [Originally Added On: June 27th, 2017]
- Microsoft Signs Cloud Computing Partnership with Box - CIO Today [Last Updated On: June 30th, 2017] [Originally Added On: June 30th, 2017]
- US action on Microsoft email case could devastate cloud computing - Irish Times [Last Updated On: June 30th, 2017] [Originally Added On: June 30th, 2017]
- Cloud computing challenges today: Planning, process and people - TechTarget [Last Updated On: July 2nd, 2017] [Originally Added On: July 2nd, 2017]
- Five podcasts to catch up on the latest trends in cloud computing - TechTarget [Last Updated On: July 2nd, 2017] [Originally Added On: July 2nd, 2017]
- Microsoft reportedly set to lay off thousands as part of massive sales reorganization - GeekWire [Last Updated On: July 3rd, 2017] [Originally Added On: July 3rd, 2017]
- VMware to surge more than 20 percent because the Amazon cloud ... - CNBC [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]
- Google Unveils Custom Hardware Chip for Cloud - Investopedia [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]
- Cloud Computing Confirmed for Travers | TDN | Thoroughbred Daily ... - Thoroughbred Daily News [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]
- Why 2017 Is The Year To Understand Cloud Computing - Nasdaq [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]
- Biz Cloud Computing - Four States Homepage [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]