The Cybersecurity Tech Accord is a public commitment among more than 60 global companies to protect and empower civilians online and to improve the security, stability and resilience of cyberspace.

Cybersecurity Tech Accord joins cross-sector efforts to improve security of email communication; defend against most common and dangerous cyberattacks

Yesterday, in an event in Washington DC, the Cybersecurity Tech Accord took a decisive step to enhance the security of email communication, one of the most vulnerable areas in cybersecurity and one of the most targeted by cyber criminals worldwide. Building on existing efforts by like-minded organizations, governments and businesses, we endorsed Domain-based Message Authentication, Reporting & Conformance (DMARC), an email authentication policy and reporting protocol that helps prevent impersonation attacks via email. We did so in partnership with the Global Cyber Alliance (GCA), an international non-profit organization that has made eradicating global cyber risk its mission.

Speakers and attendees at the Building a path to secure cyberspace event in Washington D.C, September 16, 2018.

For the past two years, GCA has focused on the risk of phishing and strongly supported DMARC adoption to empower public and private organizations to defend against malicious emails. The GCA implementation guide has helped many businesses create a DMARC policy to protect their brand. The Cybersecurity Tech Accord signatories will support GCA in promoting the adoption of the DMARC protocol on a broad scale and commit to implementing the solution across our own operations, following through on our promise to protect users and customers from evolving cyber threats. As a first step, the Cybersecurity Tech Accord signatories will, under the GCA’s guidance, implement internal education measures around email security.

Email remains one of the primary communications channels for private individuals, organizations and government institutions and has become a preferred attack method for impersonation and fraud. Data on email threats in the first half of 2018 showed that approximately 6.4 billion emails sent worldwide each day are fake with the United States as the main source, and healthcare and government being the most impacted sectors. The fraudulent practice of phishing emails are the entry weapon of choice for many cyber criminals and have become more sophisticated over time.

DMARC is the first and only widely deployed technology that helps protects customers and the brand. Designed on the basis of real-world experience by some of the world’s largest email senders and receivers, DMARC builds on a system where senders and receivers collaborate to improve mail authentication practices of senders and enable receivers to reject unauthenticated messages. DMARC allows:

Domain owners to

  • Signal that they are using email authentication (SPF, DKIM).
  • Provide an email address to gather feedback about messages using their domain – legitimate or not.
  • A policy to apply to messages that fail authentication (report, quarantine, reject).

Email receivers to

  • Be certain a given sending domain is using email authentication.
  • Consistently evaluate SPF and DKIM along with what the end user sees in their inbox.
  • Determine the domain owner’s preference (report, quarantine or reject) for messages that do not pass authentication checks.
  • Provide the domain owner with feedback about messages using their domain.

However, DMARC adoption has been slower than its founders would have expected. Lately efforts have been undertaken at government and industry level to see this protocol implemented more consistently. In October 2017, the US Department of Homeland Security issued a directive that requires all federal agencies to implement DMARC for every domain they own. The UK government has made concrete steps in this direction already in 2016, when Government Digital Service (GDS), part of the UK’s Cabinet Office required that other governments department adopted DMARC to protect their online services. This is despite the fact that the research from GCA, published today, shows the 1,046 organizations that have used GCA’s DMARC tools saved $19 million dollars since the start of 2018.

The Cybersecurity Tech Accord welcomes these developments but believes that it is vital for DMARC adoption to accelerate across sectors with businesses and governments taking a decisive step to enhance email security. Failing to address this issue exposes internet users everywhere to cyberattacks and the internet more broadly to systemic cybersecurity challenges. That is why we are committed as a group to advancing our email security policies and encourage other businesses to do the same with the objective to have a more secure internet ecosystem.

For comment: cybersecurity definitions

In discussions within the group and with external stakeholders, the Cybersecurity Tech Accord signatories realized that many terms in cybersecurity are not yet settled and may be used to mean different things by different stakeholders. To establish greater clarity and alignment in the terms we use, the group has pulled together this initial list of definitions. There is more work to be done and we welcome feedback and suggestions as to how to improve and iterate on this document. Please send comments to techaccord@apcoworldwide.com

View the cybersecurity definitions for comment

10 steps to securing your online environment: the Cybersecurity Tech Accord celebrates Cybersecurity Awareness month

October marks Cybersecurity Awareness Month, an annual awareness campaign intended to encourage greater safety and protection among all computer users. Launched in 2004 by the National Cyber Security Alliance (NCSA) and the U.S. Department of Homeland Security (DHS), the initiative has expanded to Europe and Latin America, among other regions, as the importance of educating citizens about cyber risks has become recognized. In Europe, events, campaigns and other initiatives will be held under the auspices of the European Union Agency for Network and Information Security (ENISA), as well as on the national level, with a focus on digital skills, education, and emerging technologies. The US will see an equally large line-up of events throughout the month under NCSA’s coordination.

In today’s always-on world, cybersecurity can no longer only be a concern for cybersecurity professionals, but should become a shared responsibility, requiring efforts at all levels of organizations and, more broadly, of society. This means that everyone must hold themselves accountable for adhering to cybersecurity best practices; no individual, business, or government entity can be solely responsible nor fully exempt from helping keep the internet safe and secure. Now more than ever, the smallest actions can have the largest positive impact. The events referenced above recognize this need.

However, it is also important to recognize that it is difficult to know what to do if you are not a cybersecurity professional. To this end the Cybersecurity Tech Accord signatories pulled together ten very concrete and simple steps that individuals globally can take to better protect themselves. These are based on the tips the signatories have shared over the years encouraging users to stay safe online (see for example, Cisco, Microsoft, TrendMicro and Facebook). They include:

1. Always change your default passwords, create strong, unique passwords for each of your accounts, and consider using a password manager to help keep personal information safe;
2. Use two-factor authentication whenever possible in addition to strong passwords to confirm your identity when logging into your accounts;
3. Use a firewall to block unauthorized access to computers and devices;
4. Ensure that you update your operating system, browser, and other software up to date with security patches to minimize threats from viruses and malware;
5. Limit what you do over public Wi-Fi and use software that creates a secure connection over the internet such as a Virtual Private Network (VPN) to safely connect from anywhere;
6. Practice safe surfing and shopping, checking that the site’s address starts with “https”, instead of just “http”;
7. Enable privacy settings and increase the default security settings of the software you use;
8. Be selective when sharing personal information as this could be used by hackers to guess passwords and logins.
9. Do not download pirated softwareas it is not only illegal, but it often includes some type of malware;
10. Back up your data, either to an external hard drive or the cloud, as this is the easiest way to recover from a ransomware attack.

Cybersecurity Awareness Month also creates a unique opportunity to get more involved in the various initiatives across the world that seek to generate greater awareness of cybersecurity. Many of our signatories already participate in those, but we also wanted to highlight two that the group has committed to do collectively:

– The Cybersecurity Tech Accord will host an event in and Washington, D.C. on “building a path to a secure cyberspace” on 16th October. Our objective is to contribute to a lively dialogue with policy makers and civil society on how to improve the security of our online environment. Further information on how to register can be found here.

– We have also joined forces with the Global Forum on Cyber Expertise (GFCE) and launched a series of freely available webinars that will begin in October, with the objective to increase the understanding of key cybersecurity topics to empower users, developers and customers to better protect themselves;
Cyberattacks are expected to increase in frequency and complexity in the years to come. The Cybersecurity Tech Accord signatories agree with the sentiment that the Internet is a shared resource and securing it is a shared responsibility. If everyone takes a collective action to protecting our online environment, the digital society that we live in can become stronger, safer, more resilient and more resistant from future cyberattacks.

Cybersecurity Tech Accord: Webinar Series

 

Topic Owner
Application security best practices Imperva
Best Practices for assessing cyber vulnerabilities and/or cyber risk Tenable
Building an Insider Risk Program Rockwell Automation
Controlling access to your data and services Safetica
Cyberattacks on Infrastructure ESET
Email protection Trend Micro
Encryption 101 Koolspan
How to perform cybersecurity forensics? FireEye
Introduction to cloud computing Microsoft
Introduction to ransomware Trend Micro
IoT security Microsoft
Phishing 101 Trend Micro
Protecting from viruses and other malware Trend Micro
Protecting your hardware HP
Root of Trust and Digital Identity WISeKey
Securing software development process and practices CA Technologies
Should I consider cyber insurance? Cisco
What is a SOC? Panasonic

Check back for more featured webinars hosted by individual Cybersecurity Tech Accord signatories.

Cybersecurity Tech Accord expands rapidly; announces partnership with Global Forum on Cyber Expertise (GFCE)

Today, in a move to enhance efforts to secure the online environment, the Cybersecurity Tech Accord announces a new partnership with the Global Forum on Cyber Expertise (GFCE), a global multi-stakeholder platform that aims to strengthen cyber capacity building and expertise through the exchange of best practices, while upholding the values of an Internet that is free, open and secure.

The partnership represents a pivotal role in bringing together governments, international organizations, civil society, and private companies to exchange best practices and expertise on cybersecurity capacity building. Two signatories of the Cybersecurity Tech Accord – Microsoft and Cisco Systems – already contribute to the GFCE’s work as members. To further this commitment, and as a first concrete step under the GFCE umbrella, the Cybersecurity Tech Accord has launched a series of webinars on cybersecurity technical best practices with the objective of increasing the understanding of key cybersecurity topics for emerging markets.

The online world has become a cornerstone of global society, important to virtually every aspect of our public infrastructure and private lives. The webinar series aims to address the growing need to respond to the cybersecurity skills gap around the world and across different sectors.

Additionally, 17 new companies have signed the Cybersecurity Tech Accord promising to protect users and customers worldwide from evolving threats, bringing the total to 61 companies united in their pledge, Aliter, Anomali, Balasys, Billennium, Cognizant, Cyber Services, Hitachi, Imperva, Integrity Partners, Panasonic, Panda, Predica, Rockwell Automation, Safetica, SecuCloud, Swisscom, and Telelink join an expanding community of like-minded companies to improve cyberspace’s resilience against malicious activities, and reaffirm as a group, their pledge to empower users, developers and customers to better protect themselves. The new signatory companies represent countries from across the globe and span sectors from Artificial Intelligence (AI) to telecommunications and will contribute to the group’s existing and upcoming initiatives around cybersecurity capacity building, cyberthreat defense and vulnerability disclosure. As an immediate step toward greater collaboration across the industry, they will join their signatory community to help address the global cybersecurity capacity gap through joined forces with the GFCE, and participation in the webinar series.

Webinars will be freely accessible, recorded and made available once per month on the Cybersecurity Tech Accord website beginning in October. Microsoft will lead the first webinar on ‘Introduction to Cloud Computing’ followed by the expertise of signatories on various cybersecurity basics, including encryption, browser protection, ransomware, and phishing. In addition, we will also create a series of training materials for cybersecurity, which we hope will serve as useful educational resources to be accessed by any interested parties in the future.

With the expansion of new signatories and new partnership with the GFCE, the Cybersecurity Tech Accord signatories hope that by highlighting effective cybersecurity best practices across the different platforms and technologies we represent, we will be able to start raising cybersecurity to a higher level by reaching a new audience.

While the webinar series marks the first milestone in this new partnership between the GFCE and the Cybersecurity Tech Accord signatories, we hope to further build on it with additional joint initiatives in the near future.

EVENT | Building a path to a secure cyberspace – presented by the Cybersecurity Tech Accord and Global Cyber Alliance

Tuesday, 16 October, 8:30am – 1:00pm (a light lunch will be served)
Microsoft Innovation & Policy Center 901 K Street, 11th Floor, Washington DC 20001

The Cybersecurity Tech Accord and the Global Cyber Alliance are delighted to invite you to their first joint event in Washington, where they will discuss, together with policy-makers, existing and emerging efforts being undertaken at government and industry level to improve the security, stability and resilience of cyberspace. Launched in April 2018, the Cybersecurity Tech Accord is the largest-ever cybersecurity alliance gathering more than 40 companies vowing to protect and empower civilians online from evolving cyberthreats. In their pledge to build a safer online world, they have partnered with like-minded organizations such as the Global Cyber Alliance, which has made eradicating cyber risk its mission. The event will be an opportunity to hear more about their initiatives and reflect on what else needs to be done in the path to a secure cyberspace. Discussion panels and workshops will focus on industry and policy perspectives on the challenges we face now and how we can address them to improve the future by promoting coordinated approaches to cyber defense in the US and around the globe. Topics of discussion will include the economic return on investing in cyber security, email security, and responsible vulnerability handling.

Registration at TechAccordDC@apcoworldwide.com before 12 October 2018.

Agenda:

08:30 – 08:45 Registration & welcome coffee
08:45 – 08:55 Welcome remarks

Philip Reitinger, President and CEO, Global Cyber Alliance

08:55 – 9:20 Introductory address

  • Tom McDermott, Deputy Assistant Secretary for Cyber Policy, US Department of Homeland Security
  • Sujit Raman, Associate Deputy Attorney General, US Department of Justice
9:20 – 10:00 The Cybersecurity Tech Accord: The initiative, the goals, the future

  • James Livingston, VP of Sales & Business Development, WISeKey
  • Alissa Starzak, Public Policy, Cloudflare
10:00 – 12:00 Improving our cybersecurity posture: The work of the Cybersecurity Tech Accord and the Global Cyber Alliance
10:00 – 11:00 Session 1 | Leveraging DMARC to enhance email security

  • Introduction to Domain Message Authentication Reporting & Conformance (DMARC) by Aimee Larsen Kirkpatrick, Global Communications Officer, Global Cyber Alliance
  • DMARC in action – discussion of the approach by Joseph Lorenzo Hall, Chief Technologist, Center for Democracy and Technology and Chris Schrimsher, Senior Premier Field Engineer, Microsoft
11:00 – 12:00 Session 2 | The importance of Coordinated Vulnerability Disclosure (CVD) for addressing vulnerabilities

Simulation exercise led by Angela McKay, Senior Director, Cybersecurity Policy and Strategy, Microsoft, with the participation of Danielle Gillam-Moore, Manager, Government Affairs, Salesforce, and Jen Ellis, VP of Community and Public Affairs, RAPID7

12:00 – 1:00 Lunch

 

The Cybersecurity Tech Accord supports the GFCE’s call for industry-wide adoption of transparent policies for coordinated vulnerability disclosure (CVD)

Today, the Cybersecurity Tech Accord takes a step forward in enhancing cybersecurity best practices by endorsing greater transparency around receiving, handling and communicating about vulnerabilities. In doing so, we echo guidance from the Global Forum on Cyber Expertise (GFCE)’s Global Good Practices on Coordinated Vulnerability Disclosure (CVD).  Launched in 2015 in The Hague, the GFCE is a global platform that aims to strengthen cyber capacity and expertise globally, while upholding the values of an Internet that is free, open, and secure. Today’s endorsement of the GFCE’s CVD good practice for transparency by the Cybersecurity Tech Accord a group of leading technology companies committed to protect and empower civilians online and to improve the security, stability and resilience of cyberspace demonstrates our signatories’ commitment to minimizing the harm to society resulting from the malicious exploitation of vulnerabilities. In addition, on an ongoing basis, we also commit to working with the GFCE to achieve greater alignment between the Global Good Practices Guide and best practices for CVD in use by Cybersecurity Tech Accord companies.

Nearly – if not all – organizations and individuals use software today: it runs in products we use every day such as laptops, mobiles, TVs, cars, or even household appliances, but also enables critical infrastructures and services, from public transportation to hospitals, banks, governments, and electricity/water supplies. Any weaknesses in software can enable an attacker to compromise the integrity of these products and services.  In an interconnected world, our ability to manage the risks that can be associated to their use is therefore essential.

Software vulnerabilities have become more prevalent and must be reduced to strengthen cybersecurity: over 14,500 new vulnerabilities were recorded in 2017, compared with just 6,000 the previous year. As vulnerabilities can be maliciously exploited, it is crucial that the affected vendors are informed when they are found, enabling vendors to resolve the issue without exposing users to undue risk.

While the process of disclosing such vulnerabilities can be straightforward, a vast number of different stakeholders are involved (e.g., manufacturers, vendors, reporters, government agencies, IT security providers), adding significant operational and legal complexities. Moreover, stakeholders may have very different motivations to disclose (or not) vulnerabilities: technology companies would want to preserve the integrity and security of their products and services and, ultimately, their reputations; security firms could profit from sharing such information; researchers may want to use vulnerabilities for academic purposes; and, criminals could exploit them.

CVD can significantly contribute to addressing these issues prior to public release. The Cybersecurity Tech Accord signatories strongly believe in CVD and support the idea that this approach should be endorsed by all companies – not just software companies – that develop technology.  While there have been different approaches to CVD, the GFCE has, in our view, developed the most comprehensive guide for good practices.

This guide was published in 2017, building on the efforts of the Dutch, Hungarian, and Romanian governments and industry representatives to establish proven cooperation mechanisms within the cyber security community to effectively find and fix software vulnerabilities. It outlines a set of good practices for all stakeholders involved.  From an industry perspective, it proposes that manufacturers, vendors, and user organizations should:

  • Use existing standards and guidelines (e.g. ISO/IEC standards, FIRST’s guidelines, ENISA good practice, OIS framework);
  • Implement the required processes to deal with incoming reports, investigate the reported vulnerabilities, and communicate with reporters, being as transparent as practicable about risk-based remediation timelines. This also includes publishing CVD policies on organizations’ websites;
  • Allocate adequate resources to implement CVD policies to ensure that organizations have the necessary expertise. This could include running a pilot and starting with a narrow set of in-scope products/services, using a third-party bug bounty platform, and/or consulting with similarly situated organizations that have CVD policies and processes in place;
  • Ensure continuous communication with all stakeholders, explicitly stating expectations towards reporters and third-party organizations;
  • Agree on timelines on a case-by-case basis, avoiding a ‘one-size-fits-all’ policy and maintaining flexibility in handling various vulnerability discovery cases;
  • And provide a clear explanation of pros and cons to the legal counsel, ensuring they have a good understanding of the national legal framework on CVD and the importance and advantages of CVD for an organization. Legal counsel needs to have the right information to give the best legal advice.

As a first concrete step, the Cybersecurity Tech Accord’s signatories commit to publish their CVD policies, in line with one of the GFCE’s best practices inviting organizations to be as transparent as possible (links below). In addition, we call on more technology companies to adopt CVD policies and hope to announce further actions to encourage this initiative in the coming months.

CVD policies of the Cybersecurity Tech Accord signatories:

ABB | ARM | ATLASSIAN | AVAST | BITDEFENDER | BT | CA TECHNOLOGIES | CARBON BLACK | CISCO | CLOUDFLARE | CYBER ADAPT | DATASTAX | DELL | DOCUSIGN | ESET | FACEBOOK | FASTLY | FIREEYE | F-SECURE | GIGAMON | GITHUB | GITLAB | GUARDTIME | HP INC | HPE | INTUIT | JUNIPER NETWORKS | KOOLSPAN | KPN | LINKEDIN | MEDIAPRO | MICROSOFT | NIELSEN | NOKIA | ORACLE | RSA | SALESFORCE | SAP | STRIPE | TELEFONICA | TENABLE | TRENDMICRO | VMWARE | WISEKEY

 

About the Global Forum on Cyber Expertise (GFCE)

The Global Forum on Cyber Expertise (GFCE) is a global platform for countries, international organizations, and private companies to exchange best practices and expertise on cyber capacity building. The aim is to identify successful policies, practices, and ideas and multiply these on a global level. Together with partners from NGOs, the tech community, and academia GFCE members develop practical initiatives to build cyber capacity.

Governments need to do more, and say more, on vulnerability handling

Modern warfare has moved online and the “fifth domain” of cyberspace is today a battlefield in its own right. But in many ways that is where the similarities to other domains end, as cyberweapons and the techniques used to develop and employ them are meaningfully distinct from the conventional weapons of modern warfare.  To create a cyberweapon, governments and sophisticated threat attackers exploit unintentional weaknesses or “vulnerabilities” found in mass-market hardware and software products or services and apply techniques developed to exploit those weaknesses.  The damaging effects of the resulting cyberweapons – especially when mishandled – can extend far beyond an intended target, potentially impacting millions of innocent users around the world.

In a further departure from conventional weaponry, cyberweapons can be recycled easily and indefinitely by third parties.  After being released “into the wild,” cyberweapons can be, wholly or in part, co-opted for ulterior purposes by nation states and cyber-criminals alike, as demonstrated in the WannaCry attack in May 2017 that downed computer systems in 150 countries.  And once in use by cyber-criminals, the security community continues to fight to eradicate a vulnerability for years, possibly for the entire lifecycle of the product, hardware, or service being exploited.

Governments are beginning to consider the risks associated with discovering or acquiring cybersecurity vulnerabilities and the wide-ranging scope of potential impact if they are exploited for use in a cyberweapon.  While there may be national security benefits from acquiring and retaining such vulnerabilities, these benefits must be weighed against the risks that those same vulnerabilities may be used against a government’s own computing infrastructure, all its citizens, and, potentially, interdependent organizations around the world.  The speed and ease with which cyberweapons can be recycled heighten these risks in ways that are incomparable to other domains of conflict and, at a certain point, become unacceptable.  Minimizing risk in developing these capabilities requires governments have deliberative processes in place that include relevant stakeholders, and the potential damage of such capabilities requires that such processes be made public.

At the end of 2017, the US government took a promising step towards greater transparency in this space, when it revised and, more importantly, publicly released significant portions of its Vulnerability Equities Process (VEP).   The VEP details when and how the US government will choose to disclose cyber vulnerabilities it either uncovers or purchases, and work on this process has spanned three years and two administrations. The 2017 update enhanced the transparency of the process, in part by identifying the respective departments and agencies represented on the vulnerability review committee (a mix of intelligence and civilian agencies), the criteria used for determining whether to disclose a vulnerability, and the mechanism for handling disagreements within the committee.  It also calls for annual reports on the program’s performance.

Yet areas for improvement remain, both in the United States and around the world.  The US government approach does not yet share its calculus for assessing the broader economic impact when it discovers or acquires a vulnerability, including not only how it measures direct impacts to consumers but also economic security issues related to the resilience and reliability of the global technology ecosystem.  The U.S. approach also does not seem to include in its analysis the “long tail” of cleanup when a vulnerability is released into the broader public, nor does it yet take into consideration how to address other forces seeking to leverage vulnerabilities at the State or local level, where law enforcement needs may call for the use of a vulnerability as part of an investigation.

While estimates of how many countries have cyber offensive capabilities vary widely, the lowest begin at forty.  The number of VEPs around the world is even more difficult to ascertain, with the United States being one of the few governments willing to openly discuss its process.  While it is rumored that other countries have put similar frameworks in place and that a few more, predominately European, countries are likely to adopt them soon, this remains an opaque area of government action that requires both transparency and input from the private sector companies that will need to mitigate the effects of those exploits in products around the world. This is especially concerning given the growing interest and willingness among various government departments to “hack” their way to accomplishing national security or law enforcement objectives.

To strike an appropriate balance between risks and benefits, governments should optimize investing in defensive rather than offensive technologies and develop policies that clearly define how they acquire, retain, and use vulnerability information. Central to this approach should be a presumption of private disclosure over the retention of vulnerabilities and principles underpinning this process should do the following:

  • Presume disclosure as the starting point;
  • Clearly consider the impact on the computing ecosystem if the vulnerability is released publicly and the costs associated with cleanup and mitigation;
  • Clearly define the process of making a disclosure decision and identify the stakeholders at the departmental level, ensuring that stakeholders represent not only national security and law enforcement but also economic, consumer, and diplomatic interests;
  • Make public the criteria used in determining whether to disclose a vulnerability or not. In addition to assessing the relevance of the vulnerability to national security, these criteria should also consider threat and impact, impact on international partners, and commercial concerns;
  • Mandate that all government-held vulnerabilities, irrespective of where or how they have been identified, go through an evaluation process leading to a decision to disclose or retain it;
  • Prohibit any vulnerability non-disclosure agreements between governments and contractors, resellers, or security researchers and limit any other exceptions, e.g., for sensitive issues;
  • Prohibit use of contractors or other third parties as a means of circumventing the disclosure process;
  • Ensure any decision to retain a vulnerability is subject to a six-month review;
  • Establish oversight through an independent body within the government with an annual public report on the body’s activities;
  • Expand funding for defensive vulnerability discovery and research;
  • Ensure disclosure procedures are in line with coordinated vulnerability disclosure, an industry best practice; and
  • Ensure that any retained vulnerabilities are secure from theft (or loss).

The signatories of the Tech Accord have always believed that protecting the public interest in cyberspace requires robust collaboration between the government and private sectors.  When the government approach to vulnerabilities favors stockpiling over disclosure, this critical collaboration is weakened, and we risk losing the public’s trust in cyberspace.  For technology companies and for technology developers, to be effective partners in protecting users, they must be active participants in the awareness and mitigation of new vulnerabilities.  In particular, it is incumbent upon developers to be transparent about how they receive vulnerability information, to use it in a timely, risk-based manner, and to communicate with affected customers and users about the existence of vulnerabilities and about the availability of mitigations. Finally, having a coordinated vulnerability disclosure policy in place demonstrates companies’ commitment to acting on vulnerability information received and to contributing concretely to the stability of cyberspace.

Cybersecurity Tech Accord urges ICANN to expedite solutions for WHOIS data

In May 2018, the European Union’s General Data Protection Regulation (GDPR) officially became law. However, dust on its implementation is far from settled, as companies continue to learn how to navigate the new legal landscape and adapt their business practices accordingly. We are also beginning to realize that the legislation might have certain unexpected consequences. Ironically, some of them may serve to undermine the security of Internet users, rather than protect them. One example is the Internet Corporation for Assigned Names and Numbers (ICANN) and its attempt to ensure compliance of its WHOIS system.

For years, cybercriminals have exploited the domain names system to launch coordinated and automated attacks on a global scale. Attackers often use domain names disguised as major brands to install malware on targeted computers and take control of legitimate servers or websites to cause mass disruption or obtain critical information. Over the past two decades, the global WHOIS directory, has been used by millions of individuals, businesses, organizations and governments, who registered domain names to support a transparent online ecosystem that protects users and customers. The resulting database was searchable, which allowed cyberdefenders to determine the owner of a domain name and IP address, and has provided viable means to obtain the information necessary to identify criminal actors, prevent harm, and protect the online ecosystem.

Since May, ICANN has struggled to come to terms with Europe’s new data protection law. Through an attempt to operate under GDPR, ICANN adopted a temporary resolution in May to ensure a common framework for handling registration information by reducing the quantity and ease of access to WHOIS data. Under the temporary specifications, registrars would collect all of the same data points about their customers yet limit how much of that information is made available through public WHOIS searches. This has not only hampered the ability to identify malicious actors online, but also resulted in divergent approaches by registrars and registries, potentially fragmenting the WHOIS system as a whole in the long run.

In late June, a discussion to develop a framework for an accreditation and access model started the draft of Framework Elements for a Unified Access Model for Continued Access to Full WHOIS Data. The Framework proposes a tiered-access model, with prospective users having to apply for accreditation from specific bodies before gaining access to full WHOIS data. This leaves many details including query types undefined with the intent that the ICANN multi-stakeholder community will generate policy to fill the gaps.

Ultimately, the framework falls short on delivering solutions that allow cybersecurity companies to address the increasing number of cyberspace threats. While we welcome the framework as a starting point for the discussion and are delighted that ICANN has turned to the multi-stakeholder community to provide feedback and help develop a sustainable approach in its consultation process, more needs to be done. The Cybersecurity Tech Accord signatories therefore call on ICANN, in the policy position published today,  to expedite the development and implementation of an accreditation model that allows for broad, persistent and frictionless access to WHOIS data for legitimate purposes, such as cybersecurity.

We strongly embrace an individual’s right to privacy outlined under the GDPR, however we also recognize that there is no privacy without strong security. The WHOIS data represents an important tool that our cybersecurity defenders rely upon to help maintain a stable and secure Internet, and we believe access to such data for the purpose of cybersecurity, needs to be maintained. It is therefore critical that a workable accreditation model is developed, and developed quickly.

Cybersecurity Tech Accord endorses the MANRS initiative, joining efforts to eliminate the most common threats to the Internet’s routing system

Today, the Cybersecurity Tech Accord endorses the Mutually Agreed Norms for Routing Security (MANRS), an initiative launched in 2014 by a group of network operators and managed by the Internet Society (ISOC), a non-profit organization promoting the development of an open Internet. The pledge to promote the MANRS initiative and support its ongoing work to help increase the resilience and security of the Internet’s global routing system, is the first public step demonstrating the principles that bind the Cybersecurity Tech Accord signatories.

“This is an important first step for the Cybersecurity Tech Accord. Challenges related to routing security are real and pressing, impacting citizens’ and business interactions online daily. These challenges will only be resolved through the coordinated action and activities of the many divergent parties. The MANRS initiative reflects the values at the core of the Cybersecurity Tech Accord: to identify cybersecurity challenges that we can only address as a collective and act to solve them.” – the Cybersecurity Tech Accord signatories.

The speed and continuity of our communications requires a stable and secure online environment. The reality is that accessing an online website, paying with a credit card, as well as looking for and exchanging information can be delayed at any time by incidents affecting routing infrastructure. In 2017 alone, more than 14,000 routing outages or attacks, such as  hijacking, leaks, or spoofing led to stolen data, lost revenue and reputational damage. One example is the hijacking event from April 2018 affecting the Ethereum cryptocurrency. Connecting to the service (MyEtherWallet), users were faced with an insecure SSL certificate, a broken link in the site’s verification. Clicking through that, they were redirected to a server in Russia, which proceeded to empty their wallet (the attackers appear to have taken $13,000 in Ethereum during two hours before the attack was shut down).

It is therefore clear that much needs to be done to address the very common challenges related to routing security. The MANRS initiative focuses on four actionable measures that can deliver immediate results in the online security environment. They include:

  • Filtering, to help combat the propagation of incorrect routing information. This measure aims to ensure the correctness of operator and customer routing announcements to adjacent networks with prefix and AS-path granularity;
  • Anti-spoofing, a measure by which network operators implement a system that enables source address validation for at least single-homed stub customer networks, their own-end users and infrastructure. The goal is to prevent packets with an incorrect source IP address from entering and leaving the network;
  • Coordination, to ensure that network operators maintain globally accessible up-to-date contact information in common routing databases and coordination with their peers; and
  • Global validation, to enable network operators to publish routing data, so others can validate routing information on a global scale.

The Cybersecurity Tech Accord signatories strongly believe that a more robust and secure global routing infrastructure demands shared responsibility and coordinated actions from the community of security-minded organizations. We see the efforts undertaken so far under the MANRS initiative as a fantastic example of different stakeholders coming together and partnering towards a common objective – a more secure environment, benefiting all of us – from users, to governments and the industry. As such, we believe this effort firmly falls under the 4th principle guiding our efforts – partnering with each other and with likeminded groups to enhance cybersecurity.

Two of our signatories – KPN and Swisscom – already actively participate in the MANRS initiative today, whilst many of our signatories are considering steps to become more involved going forward. As a group, we will promote MANRS itself, as well as raise awareness of the challenges of routing security and encourage actions to address those, in addition to prompting the culture of collective responsibility of the Internet’s global routing system.

Furthermore, we have today established a working group between the Cybersecurity Tech Accord and the MANRS initiative that will investigate how companies beyond network operators and IXPs can contribute to routing security. We hope to announce concrete steps that will help to evolve the initiative and create a framework for technology companies in the coming weeks and months.

About the Internet Society (ISOC)

Founded by Internet pioneers, the Internet Society (ISOC) is a non-profit organization dedicated to ensuring the open development, evolution and use of the Internet. Working through a global community of chapters and members, the Internet Society collaborates with a broad range of groups to promote the technologies that keep the Internet safe and secure, and advocates for policies that enable universal access. The Internet Society is also the organizational home of the Internet Engineering Task Force (IETF).

About the Cybersecurity Tech Accord

The Cybersecurity Tech Accord is a public commitment among 44 global companies to protect and empower civilians online and to improve the security, stability and resilience of cyberspace. Learn more at www.cybertechaccord.org

Eleven new companies join pledge to fight cyberattacks, promise equal protection for customers worldwide

June 20, 2018 — Today, two months after announcing the Cybersecurity Tech Accord, eleven new companies have joined the watershed agreement to defend all customers everywhere from malicious attacks by cybercriminal enterprises and nation-states. The new signatories include Atlassian, Carbon Black, Cyber adAPT, ESET, Gigamon, GitLab, KoolSpan, KPN, MediaPRO, Salesforce, and WISeKey. These companies oversee important aspects of the world’s communications infrastructure including cloud-based customer relationship management, collaboration tools, telecommunications, endpoint security, datacenter security, and encryption.

Read More

Signing pledge to fight cyberattacks, 34 leading companies promise equal protection for customers worldwide

Companies across every layer of internet communication vow to defend against misuse of their technology; promise to protect all customers regardless of nationality, geography or attack motivation.

REDMOND, Wash. — April 17, 2018 — On Tuesday, 34 global technology and security companies signed a Cybersecurity Tech Accord, a watershed agreement among the largest-ever group of companies agreeing to defend all customers everywhere from malicious attacks by cybercriminal enterprises and nation-states. The 34 companies include ABB, Arm, Cisco, Facebook, HP, HPE, Microsoft, Nokia, Oracle, and Trend Micro, and together represent operators of technologies that power the world’s internet communication and information infrastructure.

“The devastating attacks from the past year demonstrate that cybersecurity is not just about what any single company can do but also about what we can all do together.” said Microsoft President Brad Smith. “This tech sector accord will help us take a principled path towards more effective steps to work together and defend customers around the world.”

The companies made commitments in four areas.

Stronger defense
The companies will mount a stronger defense against cyberattacks. As part of this, recognizing that everyone deserves protection, the companies pledged to protect all customers globally regardless of the motivation for attacks online.

No offense
The companies will not help governments launch cyberattacks against innocent citizens and enterprises, and will protect against tampering or exploitation of their products and services through every stage of technology development, design and distribution.

Capacity building
The companies will do more to empower developers and the people and businesses that use their technology, helping them improve their capacity for protecting themselves. This may include joint work on new security practices and new features the companies can deploy in their individual products and services.

Collective action
The companies will build on existing relationships and together establish new formal and informal partnerships with industry, civil society and security researchers to improve technical collaboration, coordinate vulnerability disclosures, share threats and minimize the potential for malicious code to be introduced into cyberspace.

The companies may have adhered to some or all of these principles prior to the accord, or may have adhered without a public commitment but this agreement represents a public shared commitment to collaborate on cybersecurity efforts. The Tech Accord remains open to consideration of new private sector signatories, large or small and regardless of sector, who are trusted, have high cybersecurity standards and will adhere unreservedly to the Accord’s principles.

“The real world consequences of cyber threats have been repeatedly proven. As an industry, we must band together to fight cybercriminals and stop future attacks from causing even more damage,” said Kevin Simzer, Chief Operating Officer, Trend Micro.

The victims of cyberattacks are businesses and organizations of all sizes, with economic losses expected to reach $8 trillion by 2022.* Recent cyberattacks have caused small businesses to shutter their doors, hospitals to delay surgeries and governments to halt services, among other disruptions and safety risks.

The Tech Accord will help to protect the integrity of the one trillion connected devices we expect to see deployed within the next 20 years,” said Carolyn Herzog, General Counsel, Arm. “It aligns the resources, expertise and thinking of some of the world’s most important technology companies to help to build a trusted foundation for technology users who will benefit immensely from a more security connected world.”

Companies that signed the accord plan to hold their first meeting during the security-focused RSA Conference taking place in San Francisco, and will focus on capacity building and collective action. Future actions may include jointly developed guidelines or broadly deployed features, as well as information sharing and partnering to combat specific threats to make the online world a safer place for people and businesses everywhere — and uphold the promise and benefit technology offers society.

 


* Losses are cumulative over five year, 2017 – 2022. James Moar; Juniper Research: The Future of Cybercrime & Security: Enterprise Threats & Mitigation 2017-2022 (April 25, 2017); https://www.juniperresearch.com/researchstore/innovation-disruption/cybercrime-security/enterprise-threats-mitigation