<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Computer Emergency Response Team | IMR</title>
	<atom:link href="https://imrmedia.in/tag/computer-emergency-response-team/feed/" rel="self" type="application/rss+xml" />
	<link>https://imrmedia.in/tag/computer-emergency-response-team/</link>
	<description>Indian Military Review, Defense News, Indian Defence Review</description>
	<lastBuildDate>Mon, 09 Jan 2023 09:54:05 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://imrmedia.in/wp-content/uploads/2020/04/cropped-IMR-Logo-512x512-px-32x32.jpg</url>
	<title>Computer Emergency Response Team | IMR</title>
	<link>https://imrmedia.in/tag/computer-emergency-response-team/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>India saw the highest number of cyberattacks on govt agencies in 2022</title>
		<link>https://imrmedia.in/india-saw-the-highest-number-of-cyberattacks-on-govt-agencies-in-2022/</link>
					<comments>https://imrmedia.in/india-saw-the-highest-number-of-cyberattacks-on-govt-agencies-in-2022/#respond</comments>
		
		<dc:creator><![CDATA[IMR Reporter]]></dc:creator>
		<pubDate>Fri, 30 Dec 2022 08:02:46 +0000</pubDate>
				<category><![CDATA[Daily Defence News]]></category>
		<category><![CDATA[AIIMS]]></category>
		<category><![CDATA[All India Institute of Medical Science]]></category>
		<category><![CDATA[CERT-IN]]></category>
		<category><![CDATA[CloudSek]]></category>
		<category><![CDATA[Computer Emergency Response Team]]></category>
		<category><![CDATA[cyberattacks]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Dragon Force]]></category>
		<category><![CDATA[Hacktivism]]></category>
		<category><![CDATA[Khalifah Cyber Crew]]></category>
		<category><![CDATA[LockBIT ransomware campaign]]></category>
		<category><![CDATA[OpIndia]]></category>
		<category><![CDATA[OpsPatuk]]></category>
		<category><![CDATA[RaaS]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[ransomware-as-a-service]]></category>
		<guid isPermaLink="false">https://imrmedia.in/?p=15133</guid>

					<description><![CDATA[<p>India, US, Indonesia, and China accounted for 45% of total cyberattacks on government agencies worldwide in the second half of 2022, according to a report by cybersecurity firm CloudSek, released on 30 December. The number of attacks on government agencies were up 95% year-on-year, the report claims. India was the most targeted country in 2022 [&#8230;]</p>
<p>The post <a href="https://imrmedia.in/india-saw-the-highest-number-of-cyberattacks-on-govt-agencies-in-2022/">India saw the highest number of cyberattacks on govt agencies in 2022</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">India, US, Indonesia, and China accounted for 45% of total cyberattacks on government agencies worldwide in the second half of 2022, according to a report by cybersecurity firm CloudSek, released on 30 December. The number of attacks on government agencies were up 95% year-on-year, the report claims.</p>



<p class="wp-block-paragraph">India was the most targeted country in 2022 as attacks on government agencies more than doubled. CloudSek attributed this to an increase in activities of Malaysia-based hacktivist group Dragon Force, which ran campaigns such as #OpIndia and #OpsPatuk against India in retaliation to the controversial comments by an Indian politician on Prophet Mohammed.</p>



<p class="wp-block-paragraph">Another hacker group Khalifah Cyber Crew intensified attacks on India in protest against alleged “Muslim discrimination&#8221; by the government, the report said.</p>



<p class="wp-block-paragraph">Hacktivism is a form of cyberattack where the hacker’s motivation is not financial gains but to promote a political agenda or protest against certain policies. Last year, attacks on China also increased due to its aggressive stance towards Taiwan and the Uyghur community.</p>



<p class="wp-block-paragraph">Attacks on government agencies in China declined to 4.5% of all attacks from 13.10% last year. On the other hand, in India, US, and Indonesia, the share of all attacks grew from 6.3% to 13.7%, 7.4% to 9.6%, and 4.6% to 9.3%, respectively,</p>



<p class="wp-block-paragraph">In 2022, hacktivism accounted for 9% of the cyberattacks on the government sector.</p>



<p class="wp-block-paragraph">In addition to hacktivism, government agencies in India are also increasingly being targeted by phishing campaigns, according to the report.</p>



<p class="wp-block-paragraph">CloudSek also found that ransomware groups were very active and accounted for 6% of the attacks on governments. LockBIT, which provides ransomware-as-a-service (RaaS) was the most prominent ransomware operator. Its targets this year include government agencies in the US, Canada, and Italy. In November, a Russian national was arrested in Canada for alleged involvement in LockBIT ransomware campaigns in the US.</p>



<p class="wp-block-paragraph">Last month, India’s top government-run hospital All India Institute of Medical Science (AIIMS) was also hit by a cyberattack causing disruption of online services that lasted over two weeks.</p>



<p class="wp-block-paragraph">India’s nodal cybersecurity agency Computer Emergency Response Team (CERT-In) found in its investigation that five AIIMS’ servers were compromised during the attack and nearly 1.3 terabytes of data was encrypted by hackers.</p>



<p class="wp-block-paragraph">“The ratio of government-sponsored attacks has also multiplied; however, there is no exact figure for this increase since these attacks are mostly untraceable. This growth can be primarily attributed to the advent of RaaS models,&#8221; CloudSek said.</p>



<p class="wp-block-paragraph">Attacks on Russia increased 600% in 2022 in retaliation to its invasion of Ukraine, making it the fifth most targeted country.</p>



<p class="wp-block-paragraph">Cyberattacks on government agencies are not new. Many of these attacks state sponsored and are aimed at stealing sensitive information or cripple critical infrastructure of other countries. Indian entities are often targeted by hacker groups with links to China. Similarly, many of the attacks on US agencies often originate from Russia or North Korea.</p>



<p class="wp-block-paragraph">According to IBM’s ‘Cost of Data Breach Report 2022’, the average cost of data breaches in the government sector has increased from $1.93 million in 2021 to $2.07 million this year.</p>



<p class="wp-block-paragraph">Experts believe that state-sponsored hackers will go after cloud services next year due to growing digital transformation. “Nation states will begin to target cloud service provider (CSP) managed services as companies migrate more of their attack surface to these managed services,&#8221; said Bob Huber, chief security officer at Tenable, a cybersecurity firm.</p>
<p>The post <a href="https://imrmedia.in/india-saw-the-highest-number-of-cyberattacks-on-govt-agencies-in-2022/">India saw the highest number of cyberattacks on govt agencies in 2022</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://imrmedia.in/india-saw-the-highest-number-of-cyberattacks-on-govt-agencies-in-2022/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>2022 was India’s worst year of cyberattacks</title>
		<link>https://imrmedia.in/2022-was-indias-worst-year-of-cyberattacks/</link>
					<comments>https://imrmedia.in/2022-was-indias-worst-year-of-cyberattacks/#respond</comments>
		
		<dc:creator><![CDATA[IMR Reporter]]></dc:creator>
		<pubDate>Fri, 30 Dec 2022 05:26:36 +0000</pubDate>
				<category><![CDATA[Daily Defence News]]></category>
		<category><![CDATA[AIIMS]]></category>
		<category><![CDATA[CERT-IN]]></category>
		<category><![CDATA[Computer Emergency Response Team]]></category>
		<category><![CDATA[cyber warfare]]></category>
		<category><![CDATA[cyberattacks]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Data protection Bill]]></category>
		<category><![CDATA[ransomware attack]]></category>
		<guid isPermaLink="false">https://imrmedia.in/?p=15091</guid>

					<description><![CDATA[<p>The&#160;high-profile ransomware attack on Delhi’s All-India Institute of Medical Sciences (AIIMS) last month drew attention to holes in the country’s cybersecurity infrastructure, but it was hardly an isolated incident.&#160; Industry data shows that 2022 has been the worst year so far for India when it comes to cyberattacks&#160;— a problem that has only grown with [&#8230;]</p>
<p>The post <a href="https://imrmedia.in/2022-was-indias-worst-year-of-cyberattacks/">2022 was India’s worst year of cyberattacks</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">The&nbsp;high-profile ransomware attack on Delhi’s All-India Institute of Medical Sciences (AIIMS) last month drew attention to holes in the country’s cybersecurity infrastructure, but it was hardly an isolated incident.&nbsp;</p>



<p class="wp-block-paragraph">Industry data shows that 2022 has been the worst year so far for India when it comes to cyberattacks&nbsp;— a problem that has only grown with increasing digitalisation. The question now is, what next?&nbsp;</p>



<p class="wp-block-paragraph">According to a&nbsp;study&nbsp;released Tuesday by Indusface, a Tata Capital-funded software-as-a-service (SaaS) security firm, India has become one of the most attacked and breached countries in the world. Among the 829 million cyber-attacks detected and blocked globally by the firm in the fourth quarter of 2022, close to 59 per cent were directed towards India.&nbsp;</p>



<p class="wp-block-paragraph">“Ransomware attacks in India have increased significantly and one of the most distinguishing aspects in 2022 was the involvement of state actors,” Sameer Patil, senior fellow at Observer Research Foundation (ORF), a multi-disciplinary think-tank, told ThePrint.</p>



<p class="wp-block-paragraph">“So, it is not just profit motivation. We saw how police personnel had come out with&nbsp;Chinese links&nbsp;[in AIIMS cyberattack], of how they had a role to play,” he added.&nbsp;</p>



<p class="wp-block-paragraph">Government data, collated by the Ministry of Electronics and Information Technology’s Indian Computer Emergency Response Team (CERT-In), is&nbsp;available&nbsp;only till 2021, but that too shows an increase in cyberattacks in India.</p>



<p class="wp-block-paragraph">In 2019, CERT-In handled close to 3,94,499 incidents in total, in which it suggested remedial measures for organisations and shared notes on “cyber threats and vulnerabilities”. In the same year, CERT-In issued 204 security alerts and 38 advisories.</p>



<p class="wp-block-paragraph">The number of incidents handled by CERT-In surged in 2020 to 11,58,208, a near-tripling over the previous year. This surge continued in 2021, which saw 14,02,809 incidents, a 21 per cent increase.&nbsp;</p>



<p class="wp-block-paragraph">The matters CERT-In looks into include website intrusion and malware propagation, malicious code, phishing, distributed denial-of-service (DDoS) attacks, website defacements, unauthorised network scanning or probing activities, ransomware attacks, data breaches and vulnerable services.</p>



<p class="wp-block-paragraph">In this backdrop, what will the government and companies do differently in the coming year?</p>



<p class="wp-block-paragraph">As the government readies its legislation on cybersecurity, numerous industry-wide surveys and sector experts say that 2023 will see companies spending significant amounts to secure their digital systems from attacks.</p>



<p class="wp-block-paragraph">CERT-In has also laid out a standard operating procedure for data breaches wherein companies and other organisations are supposed to inform the government of any breach within&nbsp;six hours, although this move has received a mixed reaction since compliance may be challenging.</p>



<h3 class="wp-block-heading" id="h-what-will-companies-do-differently">What will companies do differently?</h3>



<p class="wp-block-paragraph">A significant increase in cybersecurity budgets, the advent of a slew of cybersecurity guidelines for companies, and awareness programmes for the public by law enforcement agencies are some of the preventive methods that will be seen more in 2023.</p>



<p class="wp-block-paragraph">According to Sajan Paul, managing director &amp; country manager, India &amp; SAARC, Juniper Networks, there will be a significant increase in cybersecurity budgets in 2023 within organisations, and a more preventive approach will be embraced.</p>



<p class="wp-block-paragraph">“With the ongoing threat of cyberattacks, data security remains a major priority,” he said, citing figures from&nbsp;PwC’s annual Global Digital Trust Insights&nbsp;survey. “Over 82 per cent of business executives in India foresee an increase in their cybersecurity budget in 2023. The survey also reported that 65 per cent of business executives believe cyber criminals will significantly affect their organisation in 2023, more than in 2022,” he explained.</p>



<p class="wp-block-paragraph">He added that a “zero trust” policy will be an “essential security strategy” for India, going forward.&nbsp;</p>



<p class="wp-block-paragraph">“‘Zero trust’ is the essential security strategy in today’s hybrid work environment. Instead of assuming that everything behind the corporate firewall is safe, the ‘zero trust’ model assumes breach and verifies each request as though it originates from an open network,” Paul explained.</p>



<p class="wp-block-paragraph">“Regardless of where the request originates from or what resource it accesses, ‘zero trust’ teaches us to ‘never trust, always verify’. The zero trust network reduces the complexity of securing your assets and makes it much easier to isolate problems,” he added.&nbsp;</p>



<p class="wp-block-paragraph">Even at an individual level, experts have pointed out, there must be an increase in cyber hygiene so that people don’t inadvertently enable breaches to take place.</p>



<p class="wp-block-paragraph">According to ORF’s Patil, lack of awareness about cyber-hygiene in the general populace, remains a challenge. “People don’t know what to click on and what not to in the digital space, and inadvertently become enablers [of breaches],” he said.&nbsp;</p>



<p class="wp-block-paragraph">“Online tools like deepfake have proven themselves useful for recreating videos and content that may spread incorrect information to the public. These may have huge national security implications if not identified immediately,” he added.</p>



<h3 class="wp-block-heading">Data protection Bill and CERT-In rules</h3>



<p class="wp-block-paragraph">India’s IT ministry has come up with the Digital Personal Data Protection Bill, 2022, defining some roles of data fiduciaries and introducing appellate committees that will deal with redressals and grievances. Many have&nbsp;termed it&nbsp;a “step in the right direction” to ensure data security.</p>



<p class="wp-block-paragraph">The draft law, alongside CERT-In rules, has been part of core policy discussions in India. As mentioned earlier, the rules now require companies to report cybersecurity incidents within six hours. While this seems stringent, it might not be practical, some experts believe.&nbsp;</p>



<p class="wp-block-paragraph">According to Akash Karmakar, partner with the Law Offices of Panag &amp; Babu, and who leads its fintech and regulatory advisory practice, the CERT-In rules&nbsp; should have been subject to change as companies may not have the financial bandwidth to recognise breaches.</p>



<p class="wp-block-paragraph">“The CERT-In directions mandating reporting of cyber security incidents [within six hours] was perhaps the most significant development in the cybersecurity domain this year. I’m surprised this has not been challenged since it is onerous to comply with and operationally very difficult to implement. The tightest global equivalent for reporting cybersecurity incidents is 72 hours,” Karmakar told ThePrint.</p>



<p class="wp-block-paragraph">He also highlighted how the way forward could be the prescription of a “cybersecurity insurance”. This, according to him, could “go a long way”.</p>



<p class="wp-block-paragraph">“The other challenge is how monetary loss owing to a cybersecurity incident is remediated. Mandating cybersecurity insurance for certain key risks, akin to a mandated motor vehicle or travel insurance, would go a long way to ensure that impacted entities are in a position to pay out compensation for personal data that is lost,” he said.</p>
<p>The post <a href="https://imrmedia.in/2022-was-indias-worst-year-of-cyberattacks/">2022 was India’s worst year of cyberattacks</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://imrmedia.in/2022-was-indias-worst-year-of-cyberattacks/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
