02:00 PM
Dark Reading
Dark Reading
Products and Releases

Weak DevOps Cryptographic Policies Increase Financial Services Cyber Risk: Venafi

Salt Lake City, UT – May 31, 2017 – Venafi®, the leading provider of machine identity protection, today announced the results of a study on the cryptographic security practices of DevOps teams in the financial services industry. Cryptographic security risks are amplified in DevOps settings, where compromises in development  or test environments can spread to production systems and applications. This is a particular issue for financial services organizations, which have been early adopters of DevOps technology.

According to the study, many financial services organizations have fairly strong cryptographic security policies in their production systems; however, they often fail to enforce the same vital measures in their DevOps environments. In addition, financial services organizations continue to use DevOps certificates once software, apps and updates have gone live. This oversight leaves vulnerabilities in their systems that could easily be prevented.

“Financial services organizations use DevOps technology to deliver new features and improve customer experience in today’s hyper competitive market,” said Kevin Bocek, chief security strategist for Venafi. “However, the competitive advantage DevOps offers can’t come at the expense of security, data privacy and compliance. It’s clear many financial services organizations are still struggling with securing the machine identities that impact everything from mobile banking to high speed trading. Despite DevOps teams indicating they are aware of the risks associated with TLS/SSL keys and certificates—the most frequently used method to establish machine identities—this awareness clearly isn’t being translated into meaningful protection.”

Key study findings:

  • Financial services organizations struggle with enforcing security polices for DevOps environments. Almost a third (30%) of financial services organizations do not consistently enforce the same cryptographic security policies for DevOps projects as they do with production environments. In addition, 7% of respondents were unsure if these polices were enforced across both DevOps and production environments.
  • The majority (80%) of financial services DevOps teams are aware of the volume and severity of cyber attacks as a result of compromised keys and certificates. Two thirds (67%) of these teams are aware of the controls needed to prevent this type of cyber attack.
  • Only half (51%) of financial services organizations replace all DevOps certificates with production certificates once live. When certificates are not changed, there is no way to distinguish between the identities of untested machines that should remain in development and trusted machines that are safe to place in production.
  • On the positive side, financial services organizations generally implement robust cryptographic security practices throughout their operations, with 75% requiring strong keys (2048-bit or stronger) and 60% of organizations requiring different certificate authorities for development and production environments. Encouragingly, only 2% of respondents said their organization does not require key and certificate policies.

As the speed and scale of DevOps development intensifies, particularly in the financial services industry, the need to secure machine identities through encryption  is exploding. Without robust security measures and practices, successful attacks that target DevOps keys and certificates can allow attackers to remain hidden in encrypted traffic and evade detection. According to a recent report from A10 Networks, 41% of cyber attacks used encryption to evade detection.

“As we’ve seen with the SWIFT attacks, financial services organizations are a valuable and popular target for cyber criminals,” said Tim Bedard, director of threat intelligence and analytics for Venafi. “If the keys and certificates used by financial services DevOps teams are not properly protected, cyber criminals will be able to exploit SSL/TLS keys and certificates to create their own encrypted tunnels. Or attackers can use misappropriated SSH keys to pivot inside the network, elevate their own privileged access, install malware or exfiltrate large quantities of sensitive corporate data all while remaining undetected.”

The study was conducted by Dimensional Research in November 2016. Study respondents included 103 IT professionals responsible for cryptographic assets in financial services companies with DevOps programs in the U.S. and Europe.

For more information, please visit: https://www.venafi.com/research/mature-devops-study

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
8 Ways Hackers Monetize Stolen Data
Steve Zurier, Freelance Writer,  4/17/2018
The Role of KPIs in Incident Response
John Moran, Senior Product Manager, DFLabs,  4/18/2018
Register for Dark Reading Newsletters
White Papers
Current Issue
How to Cope with the IT Security Skills Shortage
Most enterprises don't have all the in-house skills they need to meet the rising threat from online attackers. Here are some tips on ways to beat the shortage.
Flash Poll
[Strategic Security Report] Navigating the Threat Intelligence Maze
[Strategic Security Report] Navigating the Threat Intelligence Maze
Most enterprises are using threat intel services, but many are still figuring out how to use the data they're collecting. In this Dark Reading survey we give you a look at what they're doing today - and where they hope to go.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.