<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CERT-IN | IMR</title>
	<atom:link href="https://imrmedia.in/tag/cert-in/feed/" rel="self" type="application/rss+xml" />
	<link>https://imrmedia.in/tag/cert-in/</link>
	<description>Indian Military Review, Defense News, Indian Defence Review</description>
	<lastBuildDate>Fri, 31 Mar 2023 05:48:34 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://imrmedia.in/wp-content/uploads/2020/04/cropped-IMR-Logo-512x512-px-32x32.jpg</url>
	<title>CERT-IN | IMR</title>
	<link>https://imrmedia.in/tag/cert-in/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Cyber Year in Review</title>
		<link>https://imrmedia.in/cyber-year-in-review/</link>
					<comments>https://imrmedia.in/cyber-year-in-review/#respond</comments>
		
		<dc:creator><![CDATA[IMR Reporter]]></dc:creator>
		<pubDate>Sun, 15 Jan 2023 08:28:00 +0000</pubDate>
				<category><![CDATA[Emerging Technologies]]></category>
		<category><![CDATA[National Security]]></category>
		<category><![CDATA[CERT-IN]]></category>
		<category><![CDATA[Cyber capabilities]]></category>
		<category><![CDATA[cyber offensive]]></category>
		<category><![CDATA[cyber operations]]></category>
		<category><![CDATA[cyber threats]]></category>
		<category><![CDATA[cyber warfare]]></category>
		<category><![CDATA[Cyber-espionage]]></category>
		<category><![CDATA[DDoS attack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Khalifah Cyber Crew]]></category>
		<category><![CDATA[non-state actors]]></category>
		<category><![CDATA[ransomware]]></category>
		<guid isPermaLink="false">https://imrmedia.in/?p=15918</guid>

					<description><![CDATA[<p>What to Expect in 2023? India, US, Indonesia, and China accounted for 45% of total cyberattacks on government agencies worldwide in the second half of 2022, according to a report by cybersecurity firm CloudSek, released on 30 December. The number of attacks on government agencies were up 95% year-on-year, the report claimed. The government itself [&#8230;]</p>
<p>The post <a href="https://imrmedia.in/cyber-year-in-review/">Cyber Year in Review</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading">What to Expect in 2023?</h2>



<p class="wp-block-paragraph">India, US, Indonesia, and China accounted for 45% of total cyberattacks on government agencies worldwide in the second half of 2022, according to a report by cybersecurity firm CloudSek, released on 30 December. The number of attacks on government agencies were up 95% year-on-year, the report claimed.</p>



<p class="wp-block-paragraph">The government itself has acknowledged that 18 million cyberattacks and 200,000 online threats daily in the first quarter of 2022.</p>



<p class="wp-block-paragraph">India was the most targeted country in 2022 as attacks on government agencies more than doubled. CloudSek attributed this to an increase in activities of Malaysia-based hacktivist group Dragon Force, which ran campaigns such as #OpIndia and #OpsPatuk against India in retaliation to the controversial comments by an Indian politician on Prophet Mohammed.</p>



<p class="wp-block-paragraph">Another hacker group Khalifah Cyber Crew intensified attacks on India in protest against alleged “Muslim discrimination&#8221; by the government, the report said.</p>



<p class="wp-block-paragraph">Attacks on government agencies in China declined to 4.5% of all attacks from 13.10% last year. On the other hand, in India, US, and Indonesia, the share of all attacks grew from 6.3% to 13.7%, 7.4% to 9.6%, and 4.6% to 9.3%, respectively.</p>



<h3 class="wp-block-heading">CERT-In Data</h3>



<p class="wp-block-paragraph">Government data, collated by the Ministry of Electronics and Information Technology&#8217;s Indian Computer Emergency Response Team (CERT-In), is available only till 2021, but that too shows an increase in cyberattacks in India.</p>



<p class="wp-block-paragraph">In 2019, CERT-In handled close to 3,94,499 incidents in total, in which it suggested remedial measures for organisations and shared notes on “cyber threats and vulnerabilities”. In the same year, CERT-In issued 204 security alerts and 38 advisories.</p>



<p class="wp-block-paragraph">The number of incidents handled by CERT-In surged in 2020 to 11,58,208, a near-tripling over the previous year. This surge continued in 2021, which saw 14,02,809 incidents, a 21 per cent increase.</p>



<p class="wp-block-paragraph">The matters CERT-In looks into include website intrusion and malware propagation, malicious code, phishing, distributed denial-of-service (DDoS) attacks, website defacements, unauthorised network scanning or probing activities, ransomware attacks, data breaches and vulnerable services.</p>



<h3 class="wp-block-heading">Trends</h3>



<p class="wp-block-paragraph">The Indian Computer Emergency Response Team said: “Threat actors were leveraging tools that are already available in the cyber environment rather than making custom tools and malwares. By this way, they were being able to bypass many security controls.”</p>



<p class="wp-block-paragraph">Threat actors are also able to execute scripts that reboot victim&#8217;s machine into &#8216;safe mode&#8217;, and thus bypass security solutions.</p>



<p class="wp-block-paragraph">In terms of mitigation, the agency recommended victims to immediately disconnect and isolate infected systems from the network. IT also recommended to turn off any wireless internet connectivity and isolate all system backups.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img fetchpriority="high" decoding="async" width="600" height="348" src="https://imrmedia.in/wp-content/uploads/2023/01/Attacks-by-Vertical-in-India.jpg" alt="Attacks by Vertical in India" class="wp-image-15921" srcset="https://imrmedia.in/wp-content/uploads/2023/01/Attacks-by-Vertical-in-India.jpg 600w, https://imrmedia.in/wp-content/uploads/2023/01/Attacks-by-Vertical-in-India-300x174.jpg 300w" sizes="(max-width: 600px) 100vw, 600px" /><figcaption>Attacks by Vertical in India</figcaption></figure></div>



<h3 class="wp-block-heading">Spike in Ransomware Attacks in India</h3>



<p class="wp-block-paragraph">In a first of its kind report, the Indian Computer Emergency Response Team (CERT-In) said that it had observed a 51 percent increase in ransomware incidents in the country in the first half of the business year (H1) in 2022.</p>



<p class="wp-block-paragraph">The information technology sector was the most affected when it came to these attacks, CERT-In said, followed by manufacturing and finance.</p>



<p class="wp-block-paragraph">CERT-In attributed the rise in attacks in India to Djvu, a &#8216;high-risk&#8217; virus that majorly targets citizens. The agency also named Phobos, a ransomware which “strikes smaller companies and individuals that have less capacity to pay relative to larger businesses”, to have played a role in the increase.</p>



<p class="wp-block-paragraph">It also attributed the increase to Hive, a year-old ransomware which has grown into one of the most prevalent ransomware payloads in the ransomware-as-a-service (RaaS) ecosystem, according to Microsoft.</p>



<h3 class="wp-block-heading">&#8220;Ransomware as a Service&#8221;</h3>



<p class="wp-block-paragraph">A ransomware is a type of malicious software designed to block access to a computer system until a sum of money is paid. Ransomware as a service (RaaS) is a subscription-based model that enables affiliates to use already-developed ransomware tools to execute ransomware attacks, said Upguard, a cybersecurity company.</p>



<p class="wp-block-paragraph">In the report CERT-In said, “Ransomware-As-A-Service (RAAS) ecosystem is evolving with sophisticated double and triple extortion tactics and a wide range of ransomware campaigns through affiliates.”</p>



<p class="wp-block-paragraph">“This is leading to higher probability of monetization and further rise in attack campaigns. Post covid accelerated digitalisation and hybrid work culture are also aiding this threat emergence,” it added.</p>



<h3 class="wp-block-heading">Modus Operandi</h3>



<p class="wp-block-paragraph">The agency noted that ransomware gangs were focusing on penetrating known unpatched vulnerabilities of public facing applications for gaining entry into the network.</p>



<p class="wp-block-paragraph">“Compromised credentials of remote access services (VPN/ RDP) are being used by threat actors to gain entry into the network,” it said.</p>



<p class="wp-block-paragraph">Apart from that, CERT-In said phishing campaigns are also another major source of ransomware infections.</p>



<p class="wp-block-paragraph">Zerofox describes a phishing campaign as a scam created by cybercriminals to steal financial resources or sensitive data from victims using manipulative emails or other fraudulent digital assets.</p>



<h3 class="wp-block-heading">State of Affairs</h3>



<p class="wp-block-paragraph">In recent times the three most notorious members of the ransomware family- Ryuk, Purga, and Stop made major headlines in the nation.</p>



<p class="wp-block-paragraph">The Stop ransomware caused about 10.10% of the ransomware attacks followed by Ryuk making about 5.84% attacks along with Purga for deploying 0.80% of ransomware attacks</p>



<p class="wp-block-paragraph">Ryuk seemed to have been the most active threat landscape in the Indian public as well as private sectors. On the other hand, brute-force attacks on RDP and SMBs seemed to have steadily increased in the last five years.</p>



<p class="wp-block-paragraph">According to Forbes, there was one ransomware attack every 10 seconds in 2020.</p>



<p class="wp-block-paragraph">Reportedly, organizations have faced double extortion in 2020 across the globe. Moreover, the cost of ransomware damage is predicted to hit around $20 billion by 2021.</p>



<p class="wp-block-paragraph">Although, this figure may vary later depending upon the cost of attacks and their devastating consequences. To know how brutal ransomware attacks can get, here are the top devastating ransomware attacks that took place in India.</p>



<h3 class="wp-block-heading">Hacktivism</h3>



<p class="wp-block-paragraph">In 2022, hacktivism accounted for 9% of the cyberattacks on the government sector. Hacktivism is a form of cyberattack where the hacker&#8217;s motivation is not financial gains but to promote a political agenda or protest against certain policies. Last year, attacks on China also increased due to its aggressive stance towards Taiwan and the Uyghur community.</p>



<p class="wp-block-paragraph">In addition to hacktivism, government agencies in India are also increasingly being targeted by phishing campaigns, according to the report.</p>



<h3 class="wp-block-heading">Ransomware Attacks</h3>



<p class="wp-block-paragraph">CloudSek also found that ransomware groups were very active and accounted for 6% of the attacks on governments. LockBIT, which provides ransomware-as-a-service (RaaS) was the most prominent ransomware operator. Its targets in 2022 included government agencies in the US, Canada, and Italy. In November, a Russian national was arrested in Canada for alleged involvement in LockBIT ransomware campaigns in the US.</p>



<p class="wp-block-paragraph">In November 2022, India&#8217;s top government-run hospital All India Institute of Medical Science (AIIMS) was also hit by a cyberattack causing disruption of online services that lasted over two weeks. India&#8217;s nodal cybersecurity agency Computer Emergency Response Team (CERT-In) found in its investigation that five AIIMS&#8217; servers were compromised during the attack and nearly 1.3 terabytes of data was encrypted by hackers.</p>



<h3 class="wp-block-heading">What to Expect in 2023</h3>



<p class="wp-block-paragraph">Experts believe that state-sponsored hackers will go after cloud services in 2023 due to growing digital transformation. “Nation states will begin to target cloud service provider (CSP) managed services as companies migrate more of their attack surface to these managed services,&#8221; according to Bob Huber, chief security officer at Tenable, a cybersecurity firm.</p>



<p class="wp-block-paragraph">India&#8217;s had its worst year of cyberattacks, but 2023 will see govt &amp; firms ramp up defences</p>



<p class="wp-block-paragraph">India was a top target for cyberattacks in 2022, shows study by web security firm Indusface. As govt tries to address policy vacuum, companies likely to spend more on cybersecurity.</p>



<p class="wp-block-paragraph">According to a study released Tuesday by Indusface, a Tata Capital-funded software-as-a-service (SaaS) security firm, India has become one of the most attacked and breached countries in the world. Among the 829 million cyber-attacks detected and blocked globally by the firm in the fourth quarter of 2022, close to 59 per cent were directed towards India.</p>



<p class="wp-block-paragraph">In this backdrop, what will the government and companies do differently in the coming year?</p>



<p class="wp-block-paragraph">As the government readies its legislation on cybersecurity, numerous industry-wide surveys and sector experts say that 2023 will see companies spending significant amounts to secure their digital systems from attacks.</p>



<p class="wp-block-paragraph">According to Sajan Paul, managing director &amp; country manager, India &amp; SAARC, Juniper Networks, a “zero trust” policy will be an “essential security strategy” for India, going forward. &#8216;Zero trust&#8217; model assumes breach and verifies each request as though it originates from an open network.</p>



<h3 class="wp-block-heading">Data protection Bill and CERT-In rules</h3>



<p class="wp-block-paragraph">India&#8217;s IT ministry has come up with the Digital Personal Data Protection Bill, 2022, defining some roles of data fiduciaries and introducing appellate committees that will deal with redressals and grievances. Many have termed it a “step in the right direction” to ensure data security.</p>



<p class="wp-block-paragraph">The draft law, alongside CERT-In rules, has been part of core policy discussions in India. The rules now require companies to report cybersecurity incidents within six hours. While this seems stringent, it might not be practical, some experts believe. This was perhaps the most significant development in the cybersecurity domain in 2022.</p>



<h3 class="wp-block-heading">Commentary</h3>



<p class="wp-block-paragraph">Cyberattacks on government agencies are not new. Many of these attacks state sponsored and are aimed at stealing sensitive information or cripple critical infrastructure of other countries. Indian entities are often targeted by hacker groups with links to China. Similarly, many of the attacks on US agencies often originate from Russia or North Korea.</p>



<p class="wp-block-paragraph">According to IBM&#8217;s &#8216;Cost of Data Breach Report 2022&#8217;, the average cost of data breaches in the government sector has increased from $1.93 million in 2021 to $2.07 million this year.</p>



<p class="wp-block-paragraph">Threat actors have modernised their attack methodologies, evolved sophisticated tactics and adopted a wide range of attack campaigns.</p>



<p class="wp-block-paragraph">==</p>



<h2 class="wp-block-heading">Top Six Attacks in 2020-21</h2>



<h3 class="wp-block-heading">Telangana and AP Power</h3>



<p class="wp-block-paragraph">A malicious software attacked the power utility systems of&nbsp; Telangana and Andhra Pradesh in 2020 where all the servers went down until the glitch was rectified. Since the computer systems of Telangana and Andhra Pradesh power utilities were interlinked, the virus attack quickly spread, taking down all the systems.</p>



<h3 class="wp-block-heading">UHBVN Ransomware Attack</h3>



<p class="wp-block-paragraph">Uttar Haryana Bijli Vitran Nigam was hit by a ransomware attack where the hackers gained access to the computer systems of the power company and stole the billing data of customers. The attackers demanded Rs.1 crore or $10 million in return for giving back the data.</p>



<h3 class="wp-block-heading">WannaCry</h3>



<p class="wp-block-paragraph">India was the third worst-hit nation by WannaCry ransomware, affecting more than 2 lakh computer systems. During the first wave of attacks, this ransomware attack had hit banks in India including few enterprises in Tamil Nadu and Gujarat. The ransomware majorly affected the US healthcare system and a well-known French car manufacturing firm.</p>



<h3 class="wp-block-heading">Mirai Botnet Malware Attack</h3>



<p class="wp-block-paragraph">This botnet malware took over the internet, targeting home routers and IoT devices. This malware affected 2.5 million IoT devices including a large number of computer systems in India. This self-propagating malware was capable of using exploitable unpatched vulnerabilities to access networks and systems.</p>



<h3 class="wp-block-heading">Petya</h3>



<p class="wp-block-paragraph">India was one of the top 10 countries to be hit by Petya ransomware. This ransomware attack halted work at one of the terminals of India&#8217;s largest seaport causing computer lockdown and serious consequences for the country&#8217;s exports.</p>



<h3 class="wp-block-heading">BSNL Malware Attack</h3>



<p class="wp-block-paragraph">The state-owned telecom operator BSNL was hit by a major malware attack, impacting nearly 2000 broadband modems! 60,000 modems became dysfunctional after the malware attack hit the Telecom Circle.</p>
<p>The post <a href="https://imrmedia.in/cyber-year-in-review/">Cyber Year in Review</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://imrmedia.in/cyber-year-in-review/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>India saw the highest number of cyberattacks on govt agencies in 2022</title>
		<link>https://imrmedia.in/india-saw-the-highest-number-of-cyberattacks-on-govt-agencies-in-2022/</link>
					<comments>https://imrmedia.in/india-saw-the-highest-number-of-cyberattacks-on-govt-agencies-in-2022/#respond</comments>
		
		<dc:creator><![CDATA[IMR Reporter]]></dc:creator>
		<pubDate>Fri, 30 Dec 2022 08:02:46 +0000</pubDate>
				<category><![CDATA[Daily Defence News]]></category>
		<category><![CDATA[AIIMS]]></category>
		<category><![CDATA[All India Institute of Medical Science]]></category>
		<category><![CDATA[CERT-IN]]></category>
		<category><![CDATA[CloudSek]]></category>
		<category><![CDATA[Computer Emergency Response Team]]></category>
		<category><![CDATA[cyberattacks]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Dragon Force]]></category>
		<category><![CDATA[Hacktivism]]></category>
		<category><![CDATA[Khalifah Cyber Crew]]></category>
		<category><![CDATA[LockBIT ransomware campaign]]></category>
		<category><![CDATA[OpIndia]]></category>
		<category><![CDATA[OpsPatuk]]></category>
		<category><![CDATA[RaaS]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[ransomware-as-a-service]]></category>
		<guid isPermaLink="false">https://imrmedia.in/?p=15133</guid>

					<description><![CDATA[<p>India, US, Indonesia, and China accounted for 45% of total cyberattacks on government agencies worldwide in the second half of 2022, according to a report by cybersecurity firm CloudSek, released on 30 December. The number of attacks on government agencies were up 95% year-on-year, the report claims. India was the most targeted country in 2022 [&#8230;]</p>
<p>The post <a href="https://imrmedia.in/india-saw-the-highest-number-of-cyberattacks-on-govt-agencies-in-2022/">India saw the highest number of cyberattacks on govt agencies in 2022</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">India, US, Indonesia, and China accounted for 45% of total cyberattacks on government agencies worldwide in the second half of 2022, according to a report by cybersecurity firm CloudSek, released on 30 December. The number of attacks on government agencies were up 95% year-on-year, the report claims.</p>



<p class="wp-block-paragraph">India was the most targeted country in 2022 as attacks on government agencies more than doubled. CloudSek attributed this to an increase in activities of Malaysia-based hacktivist group Dragon Force, which ran campaigns such as #OpIndia and #OpsPatuk against India in retaliation to the controversial comments by an Indian politician on Prophet Mohammed.</p>



<p class="wp-block-paragraph">Another hacker group Khalifah Cyber Crew intensified attacks on India in protest against alleged “Muslim discrimination&#8221; by the government, the report said.</p>



<p class="wp-block-paragraph">Hacktivism is a form of cyberattack where the hacker’s motivation is not financial gains but to promote a political agenda or protest against certain policies. Last year, attacks on China also increased due to its aggressive stance towards Taiwan and the Uyghur community.</p>



<p class="wp-block-paragraph">Attacks on government agencies in China declined to 4.5% of all attacks from 13.10% last year. On the other hand, in India, US, and Indonesia, the share of all attacks grew from 6.3% to 13.7%, 7.4% to 9.6%, and 4.6% to 9.3%, respectively,</p>



<p class="wp-block-paragraph">In 2022, hacktivism accounted for 9% of the cyberattacks on the government sector.</p>



<p class="wp-block-paragraph">In addition to hacktivism, government agencies in India are also increasingly being targeted by phishing campaigns, according to the report.</p>



<p class="wp-block-paragraph">CloudSek also found that ransomware groups were very active and accounted for 6% of the attacks on governments. LockBIT, which provides ransomware-as-a-service (RaaS) was the most prominent ransomware operator. Its targets this year include government agencies in the US, Canada, and Italy. In November, a Russian national was arrested in Canada for alleged involvement in LockBIT ransomware campaigns in the US.</p>



<p class="wp-block-paragraph">Last month, India’s top government-run hospital All India Institute of Medical Science (AIIMS) was also hit by a cyberattack causing disruption of online services that lasted over two weeks.</p>



<p class="wp-block-paragraph">India’s nodal cybersecurity agency Computer Emergency Response Team (CERT-In) found in its investigation that five AIIMS’ servers were compromised during the attack and nearly 1.3 terabytes of data was encrypted by hackers.</p>



<p class="wp-block-paragraph">“The ratio of government-sponsored attacks has also multiplied; however, there is no exact figure for this increase since these attacks are mostly untraceable. This growth can be primarily attributed to the advent of RaaS models,&#8221; CloudSek said.</p>



<p class="wp-block-paragraph">Attacks on Russia increased 600% in 2022 in retaliation to its invasion of Ukraine, making it the fifth most targeted country.</p>



<p class="wp-block-paragraph">Cyberattacks on government agencies are not new. Many of these attacks state sponsored and are aimed at stealing sensitive information or cripple critical infrastructure of other countries. Indian entities are often targeted by hacker groups with links to China. Similarly, many of the attacks on US agencies often originate from Russia or North Korea.</p>



<p class="wp-block-paragraph">According to IBM’s ‘Cost of Data Breach Report 2022’, the average cost of data breaches in the government sector has increased from $1.93 million in 2021 to $2.07 million this year.</p>



<p class="wp-block-paragraph">Experts believe that state-sponsored hackers will go after cloud services next year due to growing digital transformation. “Nation states will begin to target cloud service provider (CSP) managed services as companies migrate more of their attack surface to these managed services,&#8221; said Bob Huber, chief security officer at Tenable, a cybersecurity firm.</p>
<p>The post <a href="https://imrmedia.in/india-saw-the-highest-number-of-cyberattacks-on-govt-agencies-in-2022/">India saw the highest number of cyberattacks on govt agencies in 2022</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://imrmedia.in/india-saw-the-highest-number-of-cyberattacks-on-govt-agencies-in-2022/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>2022 was India’s worst year of cyberattacks</title>
		<link>https://imrmedia.in/2022-was-indias-worst-year-of-cyberattacks/</link>
					<comments>https://imrmedia.in/2022-was-indias-worst-year-of-cyberattacks/#respond</comments>
		
		<dc:creator><![CDATA[IMR Reporter]]></dc:creator>
		<pubDate>Fri, 30 Dec 2022 05:26:36 +0000</pubDate>
				<category><![CDATA[Daily Defence News]]></category>
		<category><![CDATA[AIIMS]]></category>
		<category><![CDATA[CERT-IN]]></category>
		<category><![CDATA[Computer Emergency Response Team]]></category>
		<category><![CDATA[cyber warfare]]></category>
		<category><![CDATA[cyberattacks]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Data protection Bill]]></category>
		<category><![CDATA[ransomware attack]]></category>
		<guid isPermaLink="false">https://imrmedia.in/?p=15091</guid>

					<description><![CDATA[<p>The&#160;high-profile ransomware attack on Delhi’s All-India Institute of Medical Sciences (AIIMS) last month drew attention to holes in the country’s cybersecurity infrastructure, but it was hardly an isolated incident.&#160; Industry data shows that 2022 has been the worst year so far for India when it comes to cyberattacks&#160;— a problem that has only grown with [&#8230;]</p>
<p>The post <a href="https://imrmedia.in/2022-was-indias-worst-year-of-cyberattacks/">2022 was India’s worst year of cyberattacks</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">The&nbsp;high-profile ransomware attack on Delhi’s All-India Institute of Medical Sciences (AIIMS) last month drew attention to holes in the country’s cybersecurity infrastructure, but it was hardly an isolated incident.&nbsp;</p>



<p class="wp-block-paragraph">Industry data shows that 2022 has been the worst year so far for India when it comes to cyberattacks&nbsp;— a problem that has only grown with increasing digitalisation. The question now is, what next?&nbsp;</p>



<p class="wp-block-paragraph">According to a&nbsp;study&nbsp;released Tuesday by Indusface, a Tata Capital-funded software-as-a-service (SaaS) security firm, India has become one of the most attacked and breached countries in the world. Among the 829 million cyber-attacks detected and blocked globally by the firm in the fourth quarter of 2022, close to 59 per cent were directed towards India.&nbsp;</p>



<p class="wp-block-paragraph">“Ransomware attacks in India have increased significantly and one of the most distinguishing aspects in 2022 was the involvement of state actors,” Sameer Patil, senior fellow at Observer Research Foundation (ORF), a multi-disciplinary think-tank, told ThePrint.</p>



<p class="wp-block-paragraph">“So, it is not just profit motivation. We saw how police personnel had come out with&nbsp;Chinese links&nbsp;[in AIIMS cyberattack], of how they had a role to play,” he added.&nbsp;</p>



<p class="wp-block-paragraph">Government data, collated by the Ministry of Electronics and Information Technology’s Indian Computer Emergency Response Team (CERT-In), is&nbsp;available&nbsp;only till 2021, but that too shows an increase in cyberattacks in India.</p>



<p class="wp-block-paragraph">In 2019, CERT-In handled close to 3,94,499 incidents in total, in which it suggested remedial measures for organisations and shared notes on “cyber threats and vulnerabilities”. In the same year, CERT-In issued 204 security alerts and 38 advisories.</p>



<p class="wp-block-paragraph">The number of incidents handled by CERT-In surged in 2020 to 11,58,208, a near-tripling over the previous year. This surge continued in 2021, which saw 14,02,809 incidents, a 21 per cent increase.&nbsp;</p>



<p class="wp-block-paragraph">The matters CERT-In looks into include website intrusion and malware propagation, malicious code, phishing, distributed denial-of-service (DDoS) attacks, website defacements, unauthorised network scanning or probing activities, ransomware attacks, data breaches and vulnerable services.</p>



<p class="wp-block-paragraph">In this backdrop, what will the government and companies do differently in the coming year?</p>



<p class="wp-block-paragraph">As the government readies its legislation on cybersecurity, numerous industry-wide surveys and sector experts say that 2023 will see companies spending significant amounts to secure their digital systems from attacks.</p>



<p class="wp-block-paragraph">CERT-In has also laid out a standard operating procedure for data breaches wherein companies and other organisations are supposed to inform the government of any breach within&nbsp;six hours, although this move has received a mixed reaction since compliance may be challenging.</p>



<h3 class="wp-block-heading" id="h-what-will-companies-do-differently">What will companies do differently?</h3>



<p class="wp-block-paragraph">A significant increase in cybersecurity budgets, the advent of a slew of cybersecurity guidelines for companies, and awareness programmes for the public by law enforcement agencies are some of the preventive methods that will be seen more in 2023.</p>



<p class="wp-block-paragraph">According to Sajan Paul, managing director &amp; country manager, India &amp; SAARC, Juniper Networks, there will be a significant increase in cybersecurity budgets in 2023 within organisations, and a more preventive approach will be embraced.</p>



<p class="wp-block-paragraph">“With the ongoing threat of cyberattacks, data security remains a major priority,” he said, citing figures from&nbsp;PwC’s annual Global Digital Trust Insights&nbsp;survey. “Over 82 per cent of business executives in India foresee an increase in their cybersecurity budget in 2023. The survey also reported that 65 per cent of business executives believe cyber criminals will significantly affect their organisation in 2023, more than in 2022,” he explained.</p>



<p class="wp-block-paragraph">He added that a “zero trust” policy will be an “essential security strategy” for India, going forward.&nbsp;</p>



<p class="wp-block-paragraph">“‘Zero trust’ is the essential security strategy in today’s hybrid work environment. Instead of assuming that everything behind the corporate firewall is safe, the ‘zero trust’ model assumes breach and verifies each request as though it originates from an open network,” Paul explained.</p>



<p class="wp-block-paragraph">“Regardless of where the request originates from or what resource it accesses, ‘zero trust’ teaches us to ‘never trust, always verify’. The zero trust network reduces the complexity of securing your assets and makes it much easier to isolate problems,” he added.&nbsp;</p>



<p class="wp-block-paragraph">Even at an individual level, experts have pointed out, there must be an increase in cyber hygiene so that people don’t inadvertently enable breaches to take place.</p>



<p class="wp-block-paragraph">According to ORF’s Patil, lack of awareness about cyber-hygiene in the general populace, remains a challenge. “People don’t know what to click on and what not to in the digital space, and inadvertently become enablers [of breaches],” he said.&nbsp;</p>



<p class="wp-block-paragraph">“Online tools like deepfake have proven themselves useful for recreating videos and content that may spread incorrect information to the public. These may have huge national security implications if not identified immediately,” he added.</p>



<h3 class="wp-block-heading">Data protection Bill and CERT-In rules</h3>



<p class="wp-block-paragraph">India’s IT ministry has come up with the Digital Personal Data Protection Bill, 2022, defining some roles of data fiduciaries and introducing appellate committees that will deal with redressals and grievances. Many have&nbsp;termed it&nbsp;a “step in the right direction” to ensure data security.</p>



<p class="wp-block-paragraph">The draft law, alongside CERT-In rules, has been part of core policy discussions in India. As mentioned earlier, the rules now require companies to report cybersecurity incidents within six hours. While this seems stringent, it might not be practical, some experts believe.&nbsp;</p>



<p class="wp-block-paragraph">According to Akash Karmakar, partner with the Law Offices of Panag &amp; Babu, and who leads its fintech and regulatory advisory practice, the CERT-In rules&nbsp; should have been subject to change as companies may not have the financial bandwidth to recognise breaches.</p>



<p class="wp-block-paragraph">“The CERT-In directions mandating reporting of cyber security incidents [within six hours] was perhaps the most significant development in the cybersecurity domain this year. I’m surprised this has not been challenged since it is onerous to comply with and operationally very difficult to implement. The tightest global equivalent for reporting cybersecurity incidents is 72 hours,” Karmakar told ThePrint.</p>



<p class="wp-block-paragraph">He also highlighted how the way forward could be the prescription of a “cybersecurity insurance”. This, according to him, could “go a long way”.</p>



<p class="wp-block-paragraph">“The other challenge is how monetary loss owing to a cybersecurity incident is remediated. Mandating cybersecurity insurance for certain key risks, akin to a mandated motor vehicle or travel insurance, would go a long way to ensure that impacted entities are in a position to pay out compensation for personal data that is lost,” he said.</p>
<p>The post <a href="https://imrmedia.in/2022-was-indias-worst-year-of-cyberattacks/">2022 was India’s worst year of cyberattacks</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://imrmedia.in/2022-was-indias-worst-year-of-cyberattacks/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>New cybersecurity norms announced by CERT-In</title>
		<link>https://imrmedia.in/new-cybersecurity-norms-announced-by-cert-in/</link>
					<comments>https://imrmedia.in/new-cybersecurity-norms-announced-by-cert-in/#respond</comments>
		
		<dc:creator><![CDATA[IMR Reporter]]></dc:creator>
		<pubDate>Fri, 13 May 2022 06:37:00 +0000</pubDate>
				<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[CERT-IN]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Indian Computer Emergency Response Team]]></category>
		<category><![CDATA[virtual private networks]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">https://imrmedia.in/?p=13341</guid>

					<description><![CDATA[<p>The cybersecurity norms announced by the Indian Computer Emergency Response Team (CERT-In) in April 2022, requiring virtual private networks (VPNs) to preserve a wide range of data on their customers for five years may not apply to enterprise and corporate VPN providers. CERT-In is learnt to be working on releasing more details of the cybersecurity [&#8230;]</p>
<p>The post <a href="https://imrmedia.in/new-cybersecurity-norms-announced-by-cert-in/">New cybersecurity norms announced by CERT-In</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">The cybersecurity norms announced by the Indian Computer Emergency Response Team (CERT-In) in April 2022, requiring virtual private networks (VPNs) to preserve a wide range of data on their customers for five years may not apply to enterprise and corporate VPN providers.</p>



<p class="wp-block-paragraph">CERT-In is learnt to be working on releasing more details of the cybersecurity directive issued in April, which has been opposed by industry stakeholders. According to sources, the agency could clarify that the norms apply only to VPN providers who offer “Internet proxy like services” to “general Internet subscribers”, and not to corporate VPN service providers.</p>



<h3 class="wp-block-heading">What are these norms that CERT-In is clarifying?</h3>



<p class="wp-block-paragraph">The norms, released on April 28, asked VPN service providers along with data centres and cloud service providers, to store information such as names, email IDs, contact numbers, and IP addresses (among other things) of their customers for a period of five years. Entities are also required to report cybersecurity incidents to CERT-In within six hours of becoming or being made aware of them.</p>



<p class="wp-block-paragraph">The norms have triggered concerns over privacy, and CERT-In is expected to clarify that private information of individuals will not be affected by the directions.</p>



<p class="wp-block-paragraph">“These directions do not envisage seeking of information by CERT-In from service providers on a continual basis as a standing arrangement. CERT-In may seek information from service providers in case of cyber security incidents and cyber incidents, on a case-to-case basis, for discharge of its statutory obligations to enhance cyber security in the country,” according to a person aware of the clarifications that CERT-In is in the process of finalising.</p>



<p class="wp-block-paragraph">The agency is also likely to include in its clarifications that the April 28 directive to store such information and share it with CERT-In will “override” any contractual obligation VPN providers may have with their customers of not disclosing such information.</p>



<p class="wp-block-paragraph">Queries sent to the IT Ministry and CERT-In Director General Sanjay Bahl were not immediately answered.</p>



<h3 class="wp-block-heading" id="h-but-why-has-cert-in-felt-the-need-to-issue-a-clarification">But why has CERT-In felt the need to issue a clarification?</h3>



<p class="wp-block-paragraph">Prominent VPN providers, a large part of whose value proposition is ensuring anonymity of their users on the Internet, have questioned the directives, and some providers like NordVPN are even considering pulling their servers from India should the directive be enforced on them.</p>



<p class="wp-block-paragraph">“At the moment, our team is investigating the new directive recently passed by the Indian government and exploring the best course of action. As there are still at least two months left until the law comes into effect, we are currently operating as usual. We are committed to protecting the privacy of our customers, therefore, we may remove our servers from India if no other options are left,” Laura Tyrylyte, head of public relations at Nord Security, said.</p>



<p class="wp-block-paragraph">VPN providers like Surfshark have claimed that their technology does not allow the logging of users’ information. “Surfshark has a strict no-logs policy, which means that we don’t collect or share our customer browsing data or any usage information,” Gytis Malinauskas, head of the legal department at Surfshark, said.</p>



<p class="wp-block-paragraph">“Moreover, we operate only with RAM-only servers, which automatically overwrite user-related data. Thus at this moment, we would not be able to comply with the logging requirements even technically. We are still investigating the new regulations and its implications for us, but the overall aim is to continue providing no-logs services to all of our users,” Malinauskas said.</p>



<h3 class="wp-block-heading">How has the government responded to these concerns?</h3>



<p class="wp-block-paragraph">Speaking to The Indian Express earlier this month, IT Minister Ashwini Vaishnaw had said there was “nothing to worry about” CERT-In’s norms. “There is no privacy concern. Suppose somebody takes a mask and shoots, wouldn’t you ask them to remove that mask? It is like that,” Vaishnaw had said during an interview.</p>



<p class="wp-block-paragraph">Explaining the need for the rules, he had said, “Cybersecurity is something which is continuously evolving. So we have issued very comprehensive guidelines from CERT-In. Ultimately, if there is a threat to you, the police and you would both have to work together.”</p>



<p class="wp-block-paragraph">“The basic concept (of the guidelines) is that the people who are actually running the infrastructure should take all possible steps to make sure that things are in place and if there is any breach, immediately inform us so that we can take action,” Vaishnaw said.</p>
<p>The post <a href="https://imrmedia.in/new-cybersecurity-norms-announced-by-cert-in/">New cybersecurity norms announced by CERT-In</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://imrmedia.in/new-cybersecurity-norms-announced-by-cert-in/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>India is assembling an ace group of cyber sleuths to guard its energy grids</title>
		<link>https://imrmedia.in/india-is-assembling-an-ace-group-of-cyber-sleuths-to-guard-its-energy-grids/</link>
					<comments>https://imrmedia.in/india-is-assembling-an-ace-group-of-cyber-sleuths-to-guard-its-energy-grids/#respond</comments>
		
		<dc:creator><![CDATA[IMR Reporter]]></dc:creator>
		<pubDate>Thu, 17 Mar 2022 07:01:00 +0000</pubDate>
				<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[CERT-IN]]></category>
		<category><![CDATA[CSIRT]]></category>
		<category><![CDATA[CSIRT-Energy]]></category>
		<category><![CDATA[cyber assaults]]></category>
		<category><![CDATA[cyber sleuths]]></category>
		<category><![CDATA[energy infrastructure]]></category>
		<category><![CDATA[malware assault]]></category>
		<category><![CDATA[safety incident response group]]></category>
		<guid isPermaLink="false">https://imrmedia.in/?p=13363</guid>

					<description><![CDATA[<p>The rising risk of cyber assaults on India’s energy grid has prompted the federal government to think about establishing a specialised pc safety incident response group (CSIRT) to thwart any try at crippling the essential energy infrastructure, two authorities officers stated. The group, comprising educated professionals, together with area consultants from the personal sector, might [&#8230;]</p>
<p>The post <a href="https://imrmedia.in/india-is-assembling-an-ace-group-of-cyber-sleuths-to-guard-its-energy-grids/">India is assembling an ace group of cyber sleuths to guard its energy grids</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">The rising risk of cyber assaults on India’s energy grid has prompted the federal government to think about establishing a specialised pc safety incident response group (CSIRT) to thwart any try at crippling the essential energy infrastructure, two authorities officers stated.</p>



<p class="wp-block-paragraph">The group, comprising educated professionals, together with area consultants from the personal sector, might be housed below India’s apex energy sector planning physique, Central Electrical energy Authority (CEA), the individuals cited above stated on situation of anonymity. The officers might be recruited via the Mixed Engineering Companies Examination carried out by the Union Public Service Fee.</p>



<p class="wp-block-paragraph">The transfer comess amid rising geopolitical uncertainties, and China’s makes an attempt to focus on India’s essential infrastructure, reminiscent of the facility grids and transportation methods, via malware assaults.</p>



<p class="wp-block-paragraph">“CSIRT-Energy will carry out features pertaining to cyber safety incidents, reminiscent of creating consciousness, incident monitoring and response, and forensic evaluation. It’s going to act as an prolonged arm of CERT-IN, however shall stay below the executive management of CEA. CSIRT-Energy might be outfitted with required sources, {hardware}, software program and sufficiently educated manpower,” based on a authorities doc, which was reviewed by Mint.</p>



<p class="wp-block-paragraph">The Indian Pc Emergency Response Crew (CERT-In) coordinates efforts on cybersecurity points with the Nationwide Crucial Info Infrastructure Safety Centre (NCIIPC) to supervise India’s cybersecurity operations in essential sectors.</p>



<p class="wp-block-paragraph">The union energy ministry on its half has arrange six CERTs for grid operation, thermal, hydropower, electrical energy distribution, transmission and renewable power. India additionally has a Nationwide Cyber Coordination Centre (NCCC).</p>



<p class="wp-block-paragraph">“Round 40 officers might be drawn to man CSIRT-Energy. Whereas 40% of the employees might be drawn from Central Energy Engineering Service, the stability 40% might be from state-run companies with employed area consultants from markets accounting for the remaining 40% employees,” stated one of many two officers cited above.</p>



<p class="wp-block-paragraph">4 out of India’s 5 regional centres which oversee essential electrical energy load administration features have confronted cyberattacks. Some high-profile cyberattacks on India’s energy sector embody state-run Nuclear Energy Corp. of India Ltd’s Kudankulam Nuclear Energy Plant, THDC Ltd’s Tehri dam, West Bengal State Electrical energy Distribution Co. Ltd and at Rajasthan and Haryana discoms. The NCIIPC has reported a number of vulnerabilities in different state energy utilities.</p>



<p class="wp-block-paragraph">State-run Energy System Operation Corp (Posoco) oversees the grid via the Nationwide Load Dispatch Centre, the 5 Regional Load Despatch Centre and 34 state load despatch centres. The grid is below fixed assault, with at the very least 30 day by day occasions, as reported by Mint earlier. Most originate from China, Singapore, Russia and the Commonwealth of Impartial States (CIS) international locations.</p>



<p class="wp-block-paragraph">Queries emailed to a union energy ministry spokesperson on late Monday evening remained unanswered until press time.</p>



<p class="wp-block-paragraph">Crimson Echo, a hacker group affiliated with the Chinese language authorities, repeatedly focused the management rooms that handle essential energy grids early in 2021. The marketing campaign may have triggered widespread blackouts. Nonetheless, Chinese language hackers failed to interrupt into the methods, and no knowledge breach was detected, based on an earlier assertion by the facility ministry.</p>
<p>The post <a href="https://imrmedia.in/india-is-assembling-an-ace-group-of-cyber-sleuths-to-guard-its-energy-grids/">India is assembling an ace group of cyber sleuths to guard its energy grids</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://imrmedia.in/india-is-assembling-an-ace-group-of-cyber-sleuths-to-guard-its-energy-grids/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
