Twenty years ago, the main communications worry for IT and security teams was whether anyone was using business phones to call third-world countries off-hours. Modern cloud-based unified communication (UC) and UCaaS systems face very different threats and require enterprise-grade security to secure unified communications.
This week’s Enterprise Connect 2023 conference covered the latest breakthroughs in the collaboration, communication, and call center world. During one session, Sorrell Slaymaker, an analyst with TechVision Research, said that this technology needs high-level protection to remain secure.
Slaymaker highlighted how security fears have shifted over the last couple of decades.
“Securing unified communication means that when multiple entities are communicating, and no third-party can listen in or be aware of what communications are taking place,” said Slaymaker. “End-to-end encryption is not enough. You need to protect the metadata about who is talking to whom including when, for how long, and all contact info.”
An abundance of data, for example, is stored in telecommunication billing systems. Ransomware attackers sometimes use this data to show what they have and what they can expose, if the ransom isn’t paid promptly.
Slaymaker said that security should never be left only to cloud providers. They have humans working for them who can be bought off or who can make errors, he said. Therefore, the enterprise must encrypt and secure its own data.
Securing Unified Communication: The FrameworkThe primary facets of enterprise-grade protection for communications include directory authentication of identities, a zero-trust network, and multi-factor authentication (MFA). In the latter category, he suggested going beyond text to include biometrics or even location-based signatures.
“Radio frequency signals are different all over the world so enable location to be used as a part of MFA,” said Slaymaker.
Some businesses rely only on client-to-server encryption. To prevent eavesdropping, he recommended end-to-end encryption. Every session needs to be encrypted with different keys used for each channel. That way, if one channel is compromised, the others are safeguarded.
Similarly at the device level, institute enterprise management of all devices: All software downloads or subscriptions must be vetted and approved. This prevents spouses or children adding malware, spyware, or insecure gaming software to mobile devices sitting around the home, as well as employees downloading potentially dangerous apps.
The next aspect of a UC security framework is the use of a proxy for each service. This aids in data loss prevention and the tracking of what is going in and out organization. Audio watermarks, too, are helpful in tracing who leaked data from a session.
Security information and event management (SIEM) must be in place. SIEM provides a baseline of who talks to who, what apps interface with what others, and establishes normal traffic patterns for the enterprise. It becomes much easier, then, to spot differences like apps suddenly interacting with strange services or incorrect users, and sending lots of data to unusual places.
Finally, storage. Slaymaker said to store UCaaS data as well as video and audio recordings in a secure and searchable way. This makes it simple to find a specific section of a recording.
“Otherwise, you have to search through meeting minute by minute as opposed to word search to find topics,” he said.
How Secure Is Your UCaaS Platform?With so many communications and collaboration platforms on the market, how do you know which is best for the enterprise in terms of security?
“Cisco WebEx is the only major platform to meet all the criteria for ultra-secure enterprise communications,” said Slaymaker.
He said Microsoft Teams does a good job in securing documents, but in real-time collaboration, voice, and video, there are gaps including lack of end-to-end encryption and strict controls for metadata. It does perform encryption but only from the client to the server, not end to end. Slaymaker pointed out that enterprises can’t yet use their own encryption keys on Teams; they can only use vendor keys.
Zoom, he said, continues to invest in security, privacy, and compliance but has a way to go. Like Teams, gaps remain.
Thus, Slaymaker recommended that those evaluating UCaaS look beyond usability and features to include how the platform deals with data classification and security. Check what infrastructure the platform uses, whether cloud, colocation providers, or on-premises, and what is done with the data. Europe and others have enacted laws about the location of data. If UCaaS is keeping video and audio recordings in Germany, for example, but the metadata comes to the U.S., there is a risk of falling afoul of data privacy rules.
When it comes to system design or product evaluation, he recommended finding the right balance between convenience and security. If there is an imbalance, people will bypass IT and set up personal zoom accounts, which can expose the enterprise to breaches.
“Your solution should work on personal or managed devices anywhere and be intuitive,” said Slaymaker.
Ransomware Incident Response ExampleA hospital billing system was held for ransom. The bad guys encrypted everything including backups. IT initially believed the breach had occurred via a legacy PBX system. Analysis revealed that the first point of exposure had been malware on a PC via phishing. That device was then used to feed malware to the PBX (which hadn’t been patched) and from there, hackers bridged into the server network. Investigation revealed they had been inside for weeks. They noted hundreds of millions of dollars of billings and set a price tag of more than $10 million for the payment.
Slaymaker laid out some best practices that were used in dealing with such an incident: Make sure no one is getting into the response and recovery plans to reveal what the CISO, CEO, and insurance company are doing to mitigate risk. The best approach is to assume everything is compromised and that the bad guys are watching. Slaymaker interfaced with the company via his Webex account and authenticated everyone to verify they were not being listened to.
Internal Threats to Secure Unified CommunicationsSlaymaker ended by outlining some common fallacies concerning security:
Myth: I can see everyone on the call so no one is listening in.
Reality: They might be snooping on your metadata.
Myth: We will pay and they will go away.
Reality: Once a ransom is paid, your reputation in the cybersecurity world goes down and you become prone to more breaches).
Myth: This is an isolated incident.
Reality: The stats say different. Ransomware frequency keeps going up.
Myth: This is purely an outside job.
Reality: Eighty percent of breaches have internal components via a malicious or incentivized employee or contractor, or a PC with malware.
Greg Schulz, an analyst with StorageIO Group, concurs on that last point. He said that the bulk of cybersecurity attention is spent looking for or deflecting external threats. Little time is given to insider-originated attacks or data exfiltration attempts.
“While outward internet facing IT resources, services, apps, and data get all of the headline coverage about security vulnerabilities, it is common for threats to occur from within,” said Schulz. “Everyone – organizations, vendors, partners, solution providers, and the media – are tunnel vision-focused on only internet facing attacks and attack surfaces. Organizations are often vulnerable to incidents that originate from within.”
Comments