Webinar: Insider Threat – User Behavior Analytics

 

One April 25, the National Cybersecurity Institute (NCI) at Excelsior College hosted a webinar on “Insider Threat: User Behavior Analytics”.

As insider threats become more sophisticated, organizations must employ security capabilities that can quickly assess, identify, and analyze user behavior.聽 User Behavior Analytics (UBA) helps enterprises detect insider threats, targeted attacks and financial fraud.聽 UBA gives responsible folk visibility into user behavior, allowing them to devise efficient ways to detect malicious or negligent users, and to fix the problem.聽 The goal of this webinar was to help those involved in protecting data to understand UBA enough to converse about it intelligently.

The webinar聽provided a聽brief look at the insider threat problem from the beginning down to modern times and also discussed how聽User Behavior Analytics can efficiently and effectively address Insider Threats.

The webinar was presented by Derek Smith. Derek is currently IT Program Manager at the IRS. Formerly, he worked for a number of IT companies including Computer Sciences Corporation and Booz Allen Hamilton. Derek spent 18 years as a special agent for various government agencies and the military. He has also taught business and IT courses at several universities for over 20 years. Derek has also recently published his third book聽entitled Conversational User Behavior Analytics. He has served in the US Navy, Air Force and Army for a total of 24 years. He completed an MBA, MS in IT Information Assurance, Masters in IT Project Management, and a B.S in Education.

 

Webinar: Center for Academic Excellence -Knowledge Unit Mapping Series – Part 2

On April 20, the National Cybersecurity Institute (NCI) hosted a webinar on聽鈥淐enter for Academic Excellence 鈥 Knowledge Unit Mapping – Part 2鈥.

Excelsior College is taking the initiative to produce quality members of the workforce in Cybersecurity. As a Center for Academic Excellence in Cyber Defense the college continues to align their course and program outcomes to the standards put forth by the NSA.

The webinar is part of a new series that focuses on Knowledge Unit Mapping. This second webinar focused on Basic Data Analysis, Introductory Programming, and Fundamental Security Design Principles and what Excelsior College is doing to assure learners have the proper skills to be outstanding members of the Cybersecurity workforce.

The webinar was presented by Dr. Andrew Hurd. Dr. Hurd is the Faculty Program Director for Cybersecurity at Excelsior College. He is responsible for curriculum development and degree requirements for the Bachelors and Master degrees in Cybersecurity. Prior to joining Excelsior, Dr. Hurd worked at Hudson Valley CC and SUNY Albany. He holds dual Bachelors of Arts in Computer Science and Mathematics, a Masters in the Science of teaching mathematics, and a PhD in Information Sciences specialized in Information Assurance and Online Learning. Dr. Hurd also won the SUNY Chancellors award for Excellence in Teaching in 2012 while working at HVCC.

 

Urinary Incontinence Research with Associate Degree Nursing Students

Photo of Sharon AronovitchSharon Aronovitch, PhD, RN, CWOCN, 聽conducted a study with associate degree nursing students鈥 to determine if their beliefs, attitudes, knowledge of urinary incontinence (UI) impacted their clinical judgment when caring for a patient who is experiencing UI. 聽Aronovitch is lead faculty program director of the graduate nursing program at Excelsior.

This was a non-experimental study using a convenience sample of associate degree nursing students from a distance-based and traditional associate degree nursing programs. The 501 participants in the study had completed the urinary incontinence component of the respective school鈥檚 curriculum. Each student received an email containing an introduction to the study which included a link to the study instruments, Urinary Incontinence Scales, developed by Joan Shade Henderson and a demographic sheet.

The response rate was low (16.97%, n=85; N=501) with the distance-based associate degree nursing students having a higher participation rate and nine participants did not identify a school affiliation. The participants mean scores 聽for the Beliefs Scale (93.69, SD 12.18, maximum score 138) and the Attitude Scale (91.01, SD 12.01, maximum score of 120) demonstrated a positive impact on the care the associate degree nursing student provided to patients experiencing urinary incontinence. The scores for the Facts Scale (25.61, SD 2.79, maximum of 35) indicated a high recall of UI knowledge and the Actions Scale (41.76, SD 19.64, maximum of 75) demonstrated the critical thinking required to manage UI was only moderate.

Warning Bells Ring: But too Late?

The electrical industry is just one industry that relies on SCADA systems.
The electrical industry is just one industry that relies on SCADA systems.

It seems that someone has finally gotten the message that our critical infrastructure is in danger! A recent article in nbcnews.com, U.S. Infrastructure Can Be Hacked With Google, Simple Passwords, quotes authorities as saying that “…the 2013 hack of the Bowman Avenue Dam in Rye Brook, N.Y., was a “frightening new frontier” of cybercrime that’s “scary to think about.” Since this realization comes nearly three years after the event, one has to wonder what remote cave authorities have been living in all these years.

For some time those with a vested interest in cybersecurity have been sounding the alarm that our critical infrastructures are in grave danger.

Just to recap, our nation’s critical infrastructure consists of sixteen sectors that have been deemed critical by Presidential Policy Directive 21 (PPD-21) for the countries viability. They have been identified as: the Chemical Sector, Commercial Facilities Sector, Communications Sector, Critical Manufacturing Sector, Dams Sector, Defense Industrial Base Sector, Emergency Services Sector, Energy Sector, Financial Services Sector, Food and Agriculture Sector, Government Facilities Sector, Healthcare and Public Health Sector, Information Technology Sector, Nuclear Reactors, Materials, and Waste Sector, Transportation Systems Sector, and the Water and Wastewater Systems Sector.

Those with malicious intent, for better word, hackers, have for years been intent on gaining access to those systems. They are particularly interested in gaining control of the SCADA systems to those critical sectors. SCADA, the Acronym for Supervisory Control And Data Acquisition,聽 a type of聽 industrial control system, is an integration of computer monitoring systems and physical processes. Essentially, if you can hack into the SCADA system of a critical sector, you can physically control the operations of the sector. With a few keystrokes you can open and close switches or valves and generally wreak havoc on a system.

For example, a water utility in Illinois was hacked and a pump was destroyed, centrifuges were damaged at an Iranian nuclear facility, SCADA systems in the Ukrainian power grid were attacked resulting in a blackout in the region, a nuclear plant in the US was attacked in 2003 resulting in a shutdown, the list goes on, but the attack on the dam in Upstate NY currently has grabbed headlines. Chris Francescani, in writing the above mentioned nbcnews.com article quotes FBI computer crime investigator Mike Bazzell as saying “This stuff has been happening undetected for years, and now this is one of the first times that it’s surfaced publicly.”

As intent as hackers are in gaining control of our systems, the good guys, that’s us, must be equally intent on preventing that from happening. Since most critical sectors are privately owned enterprises, this must be a coordinated and cooperative effort by businesses, government agencies and cyber professionals to prevent a major catastrophe from striking our nation. For years cyber experts have been warning about a cyber Pearl Harbor occurring should hackers gain control of our systems. Slowly, steadily it appears they have been doing so. To forestall their efforts, attention and funding is beginning to show up to bolster our defenses. In his latest budget proposal, President Obama has called for a $14 billion increase in cyber security initiatives to help protect our critical infrastructure. Let’s hope it’s enough, and not too late.

Learn more about protecting our .

Sources

Department of Homeland Security (n.d.). Critical Infrastructure Sector. Retrieved from https://www.dhs.gov/critical-infrastructure-sectors

Francescani, C. (2016, April 3). U.S. Infrastructure Can Be Hacked With Google, Simple Passwords. NBC News. Retrieved from http://www.nbcnews.com/news/us-news/u-s-infrastructure-can-be-hacked-google-simple-passwords-n548661

Rashid, F. Y. (2011, November 18). Cyber-Attackers Breach SCADA Network, Destroy Destroy Pump at Water Utility. eWeek. Retrieved from http://www.eweek.com/c/a/Security/CyberAttackers-Breach-SCADA-Network-Destroy-Pump-at-Water-Utility-614710

Reiten, G. (2012, September, 27). Chinese Hackers Blamed for Breach of Telvent鈥檚 SCADA-Related Network. Powermag. Retrieved from http://www.powermag.com/chinese-hackers-blamed-for-breach-of-telvents-scada-related-network/

Shalal, A. (2015, February, 2). Obama seeks $14 billion to boost U.S. cybersecurity defenses. Reuters. Retrieved from http://www.reuters.com/article/us-usa-budget-cybersecurity-idUSKBN0L61WQ20150202

Excelsior College announces new professional and technical writing concentration for students

Excelsior College鈥檚 School of Liberal Arts (SLA) will be launching a new Professional and Technical Writing concentration on April 6.

According to research conducted by , projected technical writing jobs will increase between now and 2022 with more than 50,000 employees and 22,600 job openings in the field.聽 The introduction of the Professional and Technical Writing Concentration to the College curriculum will help students reach their educational goals and encourage some to pursue careers in professional writing.

The Professional and Technical Writing (PTW) concentration offers training on nationally-recognized writing competencies.聽 The PTW concentration targets students who want to enhance their skills for career advancement or add a writing credential to their bachelor of science liberal arts 聽(or any related) degree.聽 Courses in technical, scientific, and medical writing will include practice in professional editing, use of various communication media, and writing for the global marketplace and for new media. Graduates with strong writing skills are poised for employment and advancement in health care, technology, pharmaceutical, government, science, and the military.

鈥淭he market for graduates with a professional or technical writing credential is well-documented, and employer reports indicate the need for all employees to have solid writing skills,鈥 said Joseph Bocchi, program director in the School of Liberal Arts.

鈥淲hile the concentration allows Excelsior students to apply existing writing courses offered by the School of Health Sciences and the School of Business and Technology, SLA has been developing a core of new courses that require hands-on application of skills as learning outcomes,鈥 said Bocchi.聽 鈥淭he concentration offers students the chance to apply their knowledge and experience within an academically rigorous program that provides skills for real-world applications across disciplines.鈥

To learn more about the PTW concentration, visit the Liberal Arts PTW concentration page.

 

###

 

About Excelsior College

Excelsior College is a regionally accredited, nonprofit distance learning institution that focuses on removing obstacles to the educational goals of adult learners. Founded in 1971 and located in Albany, NY, Excelsior is a proven leader in the assessment and validation of student knowledge. It offers more efficient and affordable access to degree completion through multiple avenues: its own online courses and college-level proficiency examinations, and the acceptance in transfer of credit from other colleges and universities as well as recognized corporate and military training programs. Excelsior College is accredited by the Middle States Commission on Higher Education and designated as a Center for Academic Excellence in Cyber Defense Education by the National Security Agency and the US Department of Homeland Security.

What鈥檚 in Your Toolbox?

Vicki Pocorobba, Student Success Coach
Vicki Pocorobba, Student Success Coach

Have you ever had one of those days when you just can鈥檛 seem to get motivated? When you can鈥檛 seem to find time for yourself, your work, family AND schoolwork?聽 I think it鈥檚 safe to say that we鈥檝e all had those days, especially as adult learners with busy lives trying to balance so many things at once.

As a Success Coach, I talk to students every day with the goal of supporting them in developing skills that help them to succeed not only in school, but in life. 聽I鈥檓 curious about how they turn things around when they鈥檙e struggling to motivate. I ask them this for two reasons:

  • to help them pinpoint what works/has worked, so they can re-use that tool in the future, and
  • to learn from them so that I can share these successful strategies with other students.

Many of our students already have an effective toolbox that they utilize on a daily basis.聽聽 Below are a few strategies I have learned from some of our students.聽 Maybe you do something similar, or maybe you can borrow one of these 鈥渢ools鈥 the next time you鈥檙e needing a little something to keep you moving forward:

  • Talk the talk 鈥 expect that you will do well, say it out loud and follow up on your actions 鈥 that way, you are setting yourself up to succeed.
  • Plan for it, expect it, achieve it.
  • Focus and challenge yourself because you are responsible for your own success.
  • Do not procrastinate, set your mind to it and just do it!
  • Listen to a great song that gets you motivated!
  • Choose a positive self-affirmation and post it somewhere so you see if often.
  • Create your own self-fulfilling prophecy – don鈥檛 say 鈥淚 can鈥檛鈥, instead, say 鈥淚 can鈥 and 鈥淚 will鈥

If you have other strategies that work for you, I鈥檇 love to hear about them. 聽Post them in the comments below.

What I Learned at the Royal College of Nursing鈥檚 100 year Celebration

By Bonny Kehm, PhD, RN
Faculty Program Director, BS Nursing Program

Last month I had the honor of attending and presenting at the Royal College of Nursing Education Forum International Conference and Exhibition in England. The conference titled, Partners in practice 鈥搕he global perspective, brought together nurses from all over the world who have a commitment to education. The conference was stimulating and informative and I had an opportunity to meet nurses from all over the globe.

One in particular was the keynote speaker, Dr. Tracy Levett-Jones, professor, School of Nursing and Midwifery, The University of Newcastle, Australia. She spoke about the need to teach nursing students empathy. She also discussed the meaning of empathy, significance, and application in nursing education. Behavioral Empathy, as Levett-Jones presented, is the gold standard and synonymous with compassion. This type of empathy requires a conscious decision and doesn鈥檛 come naturally.

I encourage all nurses to attend and present at conferences as they provide one with not only an opportunity to continue professional development, but with a feeling of being inspired and invigorated about our profession.

*My presentation and attendance to this conference was supported by the Robert E. Kinsinger Institute for Nursing Excellence, Tau Kappa At-Large Chapter – Research Dissemination Scholarship, and FPDSC Professional Research Grant awarded by Excelsior College.

Who to sue?

Recently word that a US casino was suing a cybersecurity company for failure to protect the assets of the casino. Writing for ‘The Hill’ Katie Williams writes: “Affinity Gaming hired Trustwave, a Chicago-based cybersecurity firm, to investigate and remedy a 2014 breach that compromised credit card information for around 300,000 customers”. Traditionally the stakeholder of an organization…in many cases the customers…lawyer up if there has been a breach and the PII of that customer has been stolen by hackers.

ca

In this case, the organization is suing the cybersecurity firm for failure to protect the organization. This should serve as a reminder to everyone who has a vested interest in cybersecurity that security is a serious business and is a shared responsibility by all parties. Individuals need to protect and monitor their PII to ensure that it is being handled properly by those entrusted with it, as well as see to their own personal protection (ie…not spreading your PII all over social media, or keeping your system updated). Organizations need to exhibit due diligence in protecting data entrusted to them and adhering to best practices. They must also be very particular in what organization they contract with if they outsource their cybersecurity. Failure to do so will surely bring about the interest of the FTC. And obviously organizations that contract to protect the assets of a company need to be sure of their people, their knowledge and their ability to deliver the protection they assert they can.

Cybersecurity is a serious business and needs to treated as such. It is also a shared responsibility in which everyone involved with a particular digital system must perform to their utmost potential in the protection of the assets on that system.

Learn more about cyber liability and protecting businesses at the .

Sources

Khandelwal, S. (2016, January 15). Casino Sues Cyber Security Company Over Failure to Stop Hackers. The Hacker News. Retrieved from http://thehackernews.com/2016/01/casino-hacker.html

Law.com (2016, January 19). Casino Sues Cybersecurity Firm for Woefully Inadequate Investigation. Retrieve from http://www.law.com/sites/articles/2016/01/19/casino-sues-cybersecurity-firm-for-woefully-inadequate-investigation/

Williams, K.B. (2016, January 18). Hacked Casino Sues Cybersecurity Firm. The Hill. Retrieved from

Office of Civil Rights HIPAA Privacy, Security, and Breach Notification Program

On March 21st the Office of Civil Rights (OCR) announced the launch of Phase 2 of the HIPAA Audit Program. Phase 2 of the HIPAA Audit Program will review the policies and procedures of the covered entities and their business associates to meet selected standards and implement specifications of the Privacy, Security, and Breach Notification Rules.

cyber & healthcare

These audits will primarily be desk audits, with some on-site audits.OCR will post updated audit protocols for the audits on its website.聽 The audit protocol will reflect the HIPAA Omnibus Rulemaking and can be used as a tool by organizations to conduct internal self-audits as part of their HIPAA compliance activities.

Sequence and scope:

  1. The address verification letters will be sent out
  1. The second step will be the mailing of the Entity Questionnaire
  1. Conduct 200 desk/onsite audits
  1. Desk audits will be completed by the end of CY 2016
  1. Results and lessons learned will be shared publicly and will be used for the framework of the permanent program
  1. Security Assessments and Gap analyses are not the same in the eyes of the OCR.聽 A comprehensive Security Assessment聽 must include all forms of PHI (not just EHR data).
  1. Patient Right of Access will be included in the audit protocol
  1. Audit Protocols will be released in the near future

To learn more about OCR鈥檚 Phase 2 Audit program, please visit their website found in sources.

To learn more about HIPAA check out our wide variety of material from webcasts to blogs, and training opportunities at the .

Sources

U.S. Department of Health & Human Services (n.d.). HIPAA Privacy, Security, and Breach Notification Audit Program. Retrieved from

Kicking Bad Habits

Dilanthi Graham, Student Success Coach
Dilanthi Graham, Student Success Coach

Breaking a bad habit is never easy.聽 Even more difficult is being able to identify those habits which are weighing you down as you try to move forward.聽 There are the usual suspects like procrastination or not paying attention to deadlines.聽 Any behavior or attitude that creates a barrier to your success can potentially be problematic.聽 Many Excelsior College students lead busy lives and do not have a lot of time to reflect on what鈥檚 working and what鈥檚 not.聽 When life gets hectic and with the demands of school, we focus on just getting through it all.聽 How many times have you resorted to telling yourself you would power through your work or studying?聽 Is this doable?聽 Yes.聽 A smart and effective choice?聽 You decide.聽 I encourage you to strategize your way to the end of the tunnel.聽 Start small and transform these habits into skills that will serve you better.聽 Think of it as a short term sacrifice for the ultimate long term reward鈥攜our college degree!

Take a mental snapshot of your life.聽 What small changes can you make today that will make your tomorrow even better?聽 Do you need more sleep?聽 Are you spending too much time on Facebook?聽 Usually one bad habit creates a domino effect, which can have an impact on your effectiveness as a student and in other areas of life, like work and family.聽 Explore your options.聽 There may be a happy medium, where school work comes first and then you can indulge in whatever makes you happy.

Sometimes the smallest change can have the biggest impact.聽 So do what works best for you.聽 If that means kicking bad habits to the curb cold turkey, go for it!

Webinar: Mentoring Women and Minorities in Cybersecurity 鈥 Discovering Your Role

On April 4, the National Cybersecurity Institute (NCI) hosted a webinar on Mentoring Women and Minorities in Cybersecurity.

In today鈥檚 global workforce, technology plays a key role in almost every corner of decision-making. Executives continue to be challenged with the security of information, government regulations to maintain compliance, and staff training to prevent insider threats. Many careers are being built, and strong relational networks are being formed.

The webinar discussed questions like: Where do you fit in this new matrix of skills? How do you access the people that can help you solidify your career path in Cyber Security?

This webinar is part of a new series on Women and Minorities in Cybersecurity.

The webinar was presented by Tasha Phelps. Tasha is nothing short of a seasoned professional in the IT industry. She has over 20 years of professional and academic experience writing, developing and implementing technical solutions for businesses, and governmental agencies. 聽In her 19-year old company, Phelco Technologies, she has been fortunate in serving clients nation-wide, with the support of a team of application developers, graphic designers and project managers. 聽Her strengths exist in being able to understand (and apply) technical security functions for clients. 聽Tasha is able to communicate, very well, to the C-suite of decision makers, by helping them understand the impact of making decisions about technology. 聽She says that the credit of the success in her business should be given to her staff because they are committed to achieving results, rather than just crossing a task off the list. 聽Moving forward, she looks to be of significant thought to government agencies as they consider employing stronger technical defense tools to secure information.

 

Fraudulent LinkedIn Profiles

CEOs and high profile staff are often targets for LinkedIn fraud. The fraudsters develop fake profiles, with fake photos. They sometimes cut and paste from real profiles. The photos may be of a legitimate LinkedIn member, or a stock photo. Some of the fraudulent member profiles are very good, listing real companies, real positions and even endorsements. Symantec, a security company, noted in a December 2015 blog that they have seen an increase in fake profiles.

Social media savvy essential for corporate cybersecurity
Social media savvy essential for corporate cybersecurity

Why a Fraudulent LinkedIn Profile

Hackers are looking for ways to get personal information including your business email address. They want to know who you are connected to, especially within your company and your peers. The fraudsters take the information gleaned from your profile and enhance it with other stolen or public information. They may try to send bogus emails from your compromised account to request wire transfers out of your business accounts. They may try to implement an elaborate scam leveraging your business. They may try to access your company鈥檚 network system using your email account and password hacking.

The Internet offers numerous ways a cyber-criminal can attempt to extort money from you or your business, or leverage personal information to gain access to networks owned by your vendors or customers. The creativity of criminals is amazing. For a fascinating true story, visit this blog by a patent attorney.

Tips on what to look for

  • Consider the likely age in relation to accomplishments, length of experience, type of experience. If she looks under 30 but has 20 years鈥 experience, it may be worth investigating.
  • Photo looks like a stock photo. Does she just not look real for the position? There are not a lot of civil engineers that look like runway models. Is the expression suitable for the industry? This is a business network, not a dating site. Some hackers seem to have a sense of humor and use photos of deceased famous people.
  • Question why the person wants to connect with you. Put your ego aside for a moment and think if there is a reasonable business reason this person reached out to you. If she is out of your geography, not in your industry and didn鈥檛 go to your college, you might want to research this person.

How you can protect yourself

Even the most skeptical person can be victim to high quality fake profiles, but here are some ways to check out those doubtful invitations.

  • Use Google Images to search the web for other occurrences of the photo. If it appears some place strange, or with multiple names, it is probably a borrowed image. for information on how to use Google鈥檚 reverse image search see sources below.
  • Check potential connections via an Internet search. Look at the mentioned employers, schools and associated degrees. One example is a fake profile with an engineering degree from a medial university.
  • Investigate recruiter profiles via an Internet search. Call the recruiting employer and ask to speak with the LinkedIn requester, if her picture is not on the website.
  • If you have an active business Twitter account, is the person following you and if so, what are his tweets like?

Other tips include:

  • Periodically search LinkedIn for people who list your company as an employer. Contact LinkedIn Help for anyone incorrectly listing your company.
  • When you invite someone to connect, take a few seconds to write a personal note. Why you want to connect with him/her, what you have in common, or where you met. Most fraudsters don鈥檛 take the time to personalize their invitations. Chances are good your recipient will appreciate your personal touch.

Learn more about how to protect your small business or nonprofit by attending our specialize training specific to your needs. Details, schedule, and registration can be found here.

Source:

Google. (n.d.). How Reverse Image Search Works. Retrieved from https://support.google.com/websearch/answer/1325808?hl=en

McCabe, M. Jr. (2015, December 28). IPethics & Insights. Retrieved from http://ipethicslaw.com/attorneys-at-grave-risk-for-online-fraud-linkedin-meets-the-nigerian-letter-scam/

Narang, S. (2015, December 2).Fake LinkedIn accounts want to add you to their professional network: Scammers copy information from real LinkedIn profiles. Retrieved from