Post-quantum cryptography is here — SecureAge is prepared.

Industry Solution

Cybersecurity solutions
for financial services

Managing complex infrastructures in the financial sector is nothing short of a whack-a-mole approach. data classification and discovery are ineffective and without inherently protecting data, it’s simply too easy to get past the guards.

Cybersecurity in the financial sector
today’s state of play

We’re trusted by the financial institutions that you don’t see in the news – and never will.

The modern-day bank heist is Data theft

It’s been said there are three types of financial organisations – those who have been breached and know it; those who have been breached and don’t know it; and those who have yet to be breached. These data breaches can be by a hacker, a criminal group, a nation state, or even a malicious insider.

But, regardless of how it happens, it’s been proven that it will happen. That’s why you need a data security solution that does more than just check a box for compliance.

The (im) practicalities of identifying sensitive Data

Two things are no longer practical – determining what data is most valuable, and mitigating all types of threats. These days, personal information is everywhere, compliance is critical, and even seemingly harmless data could be dangerous in the wrong hands.

The threat landscape has also grown so big that ‘fire-fighting’ is no longer effective. Add in a pandemic, and we’ve reached a tipping point – all data matters and protection needs to be re-evaluated for the constantly changing ‘new normal’.

Organisational evolution has created a complicated IT patchwork

As a result of ongoing mergers and acquisitions, as well as the nature of having a large number of different corporate entities spread across a wide range of jurisdictions, the financial sector tends to have numerous legacy IT systems and complex IT infrastructures.

As a result of these practical realities, IT professionals in the financial industry are forced to be reactive instead of proactive, security loopholes are increasing at an alarming rate, and the real risks are often not addressed with compliance.

Proactive security solutions for the financial sector

Financial institutes may have been around for centuries, but with an influx of personal and unstructured data, and an evolving work environment, the risk of a data breach is higher than ever. You need cybersecurity solutions that are proven, simple, and comprehensive, and we’ve got you covered

The SecureAge Security Suite

The SecureAge Security Suite is designed to protect enterprise data through asymmetric encryption – a failsafe PKI-based technology that protects ALL of your data, ALL of the time and doesn’t require any additional infrastructure.

100% data security and network protection

With the SecureAge Security Suite, the financial sector can tick all four boxes – compliance, data security, network protection, and the one that’s most forgotten – usability.

Complies with all data privacy laws

It’s no secret that the GDPR has had the most impact on the financial services industry than any other sector. It is without a doubt the most important data protection regulation to follow, but there’s also others. Our security solutions adhere to the California Privacy Bill, Sarbanes-Oxley Act, and the Gramm-Leach-Biley Act. The best part is our file-level approach means compliance is a natural output, not a separate time-consuming process.

Protects ALL files at-rest, in-transit, and in-use

The truth is, data is most vulnerable when it’s accessible. That includes when it’s in-transit, and when it’s in-use. Unfortunately, this is where well- known volume-level encryption tools lose their effectiveness as they only provide security for physical hardware. However, protecting one data state is simply not enough to claim data is secure – the banking and finance industry needs a better solution. That’s why the SecureAge Security Suite protects files in all three states.

Eliminate the human-element gaps of cybersecurity training

Amid an ever-evolving compliance landscape, it’s a challenge for the financial services sector to keep employees up-to-date with the latest cybersecurity skills. That’s why SecureData takes away the human-element and secures files at the most basic self-contained unit: the file-level. We know the most vulnerable threats are already inside your network and if the solution is not natural, your employees will create their own (non-secure) methods. Our solutions will help you avoid that.

[Resolved] Escalation of Privilege in SecureAge Security Suite

A privilege escalation vulnerability has been identified and resolved. Users on affected versions should update immediately.

Vulnerability Overview

A privilege escalation vulnerability was identified in SecureAge Security Suite for Windows. A locally logged-in user could exploit this flaw to create, modify, or delete files in privileged system locations — actins that should only be available to administrators. This vulnerability has been fully resolved in the versions listed below. 

Technical details
The vulnerability stems from how SecureAge Security Suite handles symbolic links during normal operation. A local attacker could create specific symbolic links n the system. When the SecureAge software ran, it would follow  those links and perform file operations in privileged Windows path locations . This could allow an unprivileged user to plant, alter, or remove files they would not ordinarily have access to.
Affected & Fixed Versions
Product Vulnerable Version Fixed Version Status

SecureAge Security Suite

7.0.37 and earlier

7.0.38

✓Resolved

SecureAge Security Suite

7.1.10 and earlier

7.1.11

✓Resolved

SecureAge Security Suite

8.0.17 and earlier

8.0.18

✓Resolved

SecureAge Security Suite

8.1.17 and earlier
8.1.18

✓Resolved

Recommended Action

Update to the fixed version or any later release immediately. No workaround is available—patching is the only resolution. If you are unsure which version you are running, open SecureAge Security Suite and check Help>About. Contact our support team if you need assistance with the update process. 

Acknowledgement

SecureAge thanks GovTech Cyber Security Group (CSG) and CSA Cyber Security Engineering Centre (CSEC) for responsibly disclosing this issue through coordinated vulnerability disclosure. 

Advisory Details
Status

✓ Resolved

Severity

High

Product

SecureAge Security Suite

Platform

Windows

Attack Type

Local