Online Services

Category: Security

  • Cyber Insurance: Should You Get It?

    You have probably noticed the gradual increase in the number of ads over the past two years selling “cyber insurance,” or insurance that covers a hack. The market for this kind of insurance has been growing.

    According to a 2017 Deloitte report on cyber insurance, the market is currently $1.5 to $3 billion dollars in the United States and will grow to over $20 billion by 2025. In our opinion, that is a conservative estimate which should be higher, based on the growth and size of breaches we have been seeing.

    In a May 2017 survey from the Council of Insurance Agents and Brokers, only 32% of US businesses had some type of cyber insurance. Many of those do not have full coverage.

    As a courtesy to our customers, we are going to briefly discuss the current state of cyber insurance and provide some data and a few anecdotes to help you make a decision on whether to purchase coverage. I have included sources at the end of this post.

    Wordfence and our team do not sell cyber insurance. This is report is informational and as a courtesy to our customers.

    Cyber Insurance Overview

    Cyber insurance is a relatively new market, and it is challenging for both customers and for insurers.

    The challenge for insurers is that they do not have much historical data they can use to price risk. In addition, they face the problem that cyber attacks keep evolving. There also is a risk that insurers will have to pay out for a large number of breaches simultaneously. Insurers may have difficulty understanding what to cover in a highly technical and rapidly evolving field.

    Buyers of insurance, who are mostly non-technical, may have trouble understanding risks and their insurance options. Buyers may also find that the risks associated with a cyber breach cover a wide range of policy types. Policies lack standardization, and most countries lack a body of legal precedent to help predict outcomes when there is a dispute.

    Some of the kinds of loss a company may experience during a cyber breach are:

    • Direct monetary loss through electronic theft.
    • Losses due to extortion from DDoS blackmail or ransomware.
    • Costs of mitigating and investigating the incident.
    • Losses due to downtime.
    • Losses from damage to data and systems, and the costs associated with restoring systems back to normal.
    • Costs of remediation, including the cost to improve security and prevent a similar breach going forward.
    • The cost of customer breach notification, including legal costs and public relations.
    • Expenses of customer compensation, including credit monitoring, service-level agreement penalties, refunds and contractual breaches.
    • Costs of liability associated with the breach, including legal costs.

    Policies to cover such diverse risks are complex, which presents a challenge to insurers who have trouble pricing the risk, and a challenge to consumers who could have trouble understanding the coverage.

    Cyber Insurance Policies Don’t Always Pay

    The past few years have seen several high-profile examples of cyber insurers refusing to pay out, and the issue has usually ended up in court.

    Insurer Does Not Cover BitPay’s Theft of $1.8M in BitCoin

    Bitcoin payment processor BitPay had purchased cyber insurance from Massachusetts Bay Insurance Company (MBIC). In December 2014, they were hacked when an attacker spearphished their Chief Financial Officer.

    The attacker used the hacked email account to spoof emails to the CEO and tricked BitPay into transferring 5000 bitcoins into their wallet. The bitcoins were worth $1,850,000, and they were transferred in three separate transactions over two days.

    MBC did not pay out on BitPay’s cyber insurance policy, so BitPay sued MBC. In court documents, MBC claimed:

    The Policy requires that the loss of money be the direct result of the use of any computer to fraudulently cause a transfer of that property from inside the premises to a person or place outside the premises. “Direct” means without any intervening step i.e. without any intruding or diverting factor. The Computer Fraud Insuring Agreement is only triggered by situations where an unauthorized user hacks into or gains unauthorized access into your computer system and uses that access to fraudulently cause a transfer of Money to an outside person or place. The facts as presented do not support a direct loss since there was not a hacking or unauthorized entry into Bitpay’s computer system fraudulently causing a transfer of Money. Instead, the computer system of David Bailey, Bitpay’s business partner, was compromised resulting in fictitious emails being received by Bitpay. The Policy does not afford coverage for indirect losses caused by a hacking into the computer system of someone other than the insured.

    The dispute was settled in May of last year, two years later. The terms were not disclosed.

    Cyber Breach Costs P.F. Chang’s $1.9 Million in Assessments. Insurer Doesn’t Pay.

    In 2014, Federal Insurance Company, a division of Chubb, sold a policy to P.F. Chang’s parent company that they said was “a flexible insurance solution designed by cyber risk experts to address the full breadth of risks associated with doing business in today’s technology dependent world.”

    In June 2014, hackers stole 60,000 customer credit card numbers from P.F. Chang’s point-of-sale system and posted them on the Internet.

    Federal paid P.F. Chang’s more than $1.7 million for losses associated with the breach. They did not pay out on an additional $1.9 million in fees and assessments imposed by MasterCard.

    P.F. Chang’s sued Federal to recover the assessment charges. They lost – and are currently appealing that ruling.

    Should You Buy Cyber Insurance?

    Cyber insurance is a new product for the insurance industry in a field that is rapidly evolving. It presents unique challenges for buyers and insurers.

    As a small company, your best approach is to avoid a breach in the first place. That means investing in systems that secure your applications and networks, and investing in people and services to support those systems.

    For example, if you use WordPress as a publishing platform, investing in a firewall like Wordfence Premium can dramatically reduce the risk of a breach. You can also have our team perform a security audit on all your WordPress installations to further reduce risk.

    If you are a small business with a low budget, cyber breach insurance may not be for you at this time, because it may simply be too complex or expensive. As the industry matures, products will become more reasonably priced as insurers can price risk better.

    If you are considering cyber insurance, we recommend the following:

    • Use a reputable insurer who has been in the cyber insurance industry for several years. The industry is new, so a history of three to five years may be enough. If your insurer entered the market within the past few months, you may be helping them iron out bugs in their product.
    • Gain a clear understanding of exactly what the insurance policy covers. Check our list of possible costs associated with a breach in this post for reference (above).
    • Chat with your insurer and talk through breach scenarios with them to clearly understand what is covered and what is not. Make sure your insurance contract agrees with the answers you get from your insurer.
    • Check if your insurer has any history of not paying claims. Search Google News.
    • Review your cyber insurance policy every six months. Make sure you still have the coverage you need and that your organization has not rolled out new technology that is not covered.
    • During your semi-annual review, make sure new attack types are covered by your policy.
    • Ensure that you are fully aware of your obligations. Your insurer will require that you implement policies, procedures and technologies to remain covered. If you do not comply with these contractual obligations, you will no longer be covered. Ensure you are in compliance.

    Conclusion and Sources

    While this post is not directly related to WordPress security, I wanted to share our thoughts on cyber insurance because it is an emerging field that our small business customers will want to keep abreast of.

    I used several sources for this post. They were:

    As always, we welcome you to share your thoughts and experiences regarding cyber insurance in the comments below.

    Mark Maunder – Wordfence Founder/CEO

    The post Cyber Insurance: Should You Get It? appeared first on Wordfence.

  • XSS Vulnerability in WooCommerce Product Vendors Plugin

    A reflected cross site scripting vulnerability has been reported in a premium WordPress plugin for WooCommerce known as the ‘Product Vendors‘ plugin. This plugin is used by 28% of all online WooCommerce stores.

    Product Vendors version 2.0.35 is affected by the vulnerability. If you are using this plugin, you need to upgrade immediately to at least version 2.0.36, which includes the fix. The current version of Product Vendors is 2.0.40.

    In the Product Vendors changelog, they do not mention that a vulnerability was fixed. The changelog entry for 2.0.36 simply says:

    2017-07-28 – version 2.0.36
    * Fix – Adjusts how we handle the vendor registration form validation.  

    This ‘form validation’ fix is the fix that removes the cross site scripting (XSS) vulnerability in a sign-up form for new vendors.

    If you are using Wordfence it is unlikely that your site is exploitable because Wordfence includes advanced XSS protection for our free and paid customers.

    The fix for the vulnerability was released on July 28th. Presumably WooCommerce did not mention in their changelog that this was a security fix to try and keep the vulnerability confidential to give their customers time to upgrade.

    The fix has now been out for a month and this vulnerability is being reported to the public. It appeared on Kaspersky’s Threatpost blog 2 hours ago.

    If you are running an older version of the Product Vendors plugin, it is important that you upgrade immediately to avoid having your site exploited. This vulnerability is now public and will be exploited by attackers.

    If you would like to learn more about cross site scripting vulnerabilities and what a ‘reflected’ cross site scripting vulnerability is, you can visit our WordPress security learning center article on cross site scripting. We go into detail explaining the differences between stored and reflected XSS and we even include a guide for developers to help you validate your data and avoid writing cross site scripting vulnerabilities.

    Please share this with the broader WordPress community to help create awareness of the importance of upgrading this plugin as soon as possible.

    The post XSS Vulnerability in WooCommerce Product Vendors Plugin appeared first on Wordfence.

  • Wordfence Launches Short-Circuit Scan Signatures – Up to 6X Performance Increase

    In October 2016, the Wordfence team started chatting about a way to radically boost the speed of scans once we grow beyond a certain number of scan signatures. As a reminder, a scan signature is a pattern that recognizes a certain kind of malware.

    Today Wordfence has 4,523 signatures available for the free community, and we have an additional 226 new signatures that are only available to Wordfence Premium users. These become free once they are 30 days old.

    New Malware Constantly Emerging

    Our team continuously adds from 30 to over 100 new scan signatures each week. The site cleaning team constantly discovers new kinds of malware as they clean hacked websites, and each malware sample is turned into a scan signature and released to Wordfence to help it detect that malware.

    Wordfence is currently at a total of 4,749 scan signatures for our Premium customers (4,523 free + 226 Premium), and within one year, this will grow to somewhere between 6,000 to 10,000 signatures at the current rate we are discovering new malware.

    The constant increase in the amount of malware targeting WordPress is clear, and Wordfence needs to continually grow our scan signatures to keep pace.

    Radical Innovation to Address Growth in WordPress Malware

    In October last year, Matt Rusnak, who heads up QA for Wordfence, and Ryan Britton, who is our senior core developer for Wordfence, started chatting about a new algorithm to radically speed up the Wordfence scan and make it able to handle a much larger number of signatures.

    Matt suggested identifying common patterns across scan signatures, grouping those signatures together and then checking if a file contains the common pattern first before scanning with the signatures in each group.

    In theory, if we had 10,000 signatures, and if we are able to identify groups of 100 scan signatures and create a pre-check for each one, we would need to match only 100 scan signatures for every item we scanned instead of 10,000. Ryan dubbed this “short-circuiting.”

    Earlier this year, we started work on the project. We created the services to support short-circuiting, then tested and launched them on our back-end servers about a month ago. Support was released for short-circuiting within the Wordfence plugin in the past few weeks. And we have been working to create grouped scan signatures with common “short-circuit” patterns.

    Matt Barry, our lead developer who created the Wordfence firewall, worked with Ryan and Matt Rusnak to make this project happen, and they received help from other members of the engineering team.

    A 2X to 6X Speedup With Short-Circuit Scanning

    When we released Wordfence 6.3.17 late last week, you may have noticed an entry in the changelog which said, “Improvement: Prepared code for upcoming scan improvement which will greatly increase scan performance by optimizing malware signatures.

    On Monday this week, we enabled short-circuit scanning on our servers. The speed improvement in Wordfence scans was breathtaking, to say the least.

    We are seeing a 2-to-6-times performance increase across our test sites and customer sites. This is an incredible improvement.

    On one major hosting provider, scans on one of our large test sites went from an average scan time of 8 minutes per scan to 1 minute and 20 seconds for a Wordfence scan to complete.

    Continuous Engineering Innovation in WordPress Security

    This is not the first time we have radically improved scan speed. Last year in September we increased scan speed by refactoring the way we perform many operations in the scan.

    In July of this year, we further improved scan performance for hosting providers by monitoring scan distribution across hosting provider VPS instances and introducing a smoothing algorithm.

    Short-circuiting scan signatures is a powerful new technique the team has created to provide a radical performance improvement on an already fast scan.

    While our many of our competitors don’t even provide a firewall and malware scan in their security products, the Wordfence engineering team is at the forefront of engineering innovation, ensuring that you benefit from a powerful firewall and malware scan combination with lighting-fast performance.

    Congratulations and thank you to Matt Rusnak, Ryan Britton, Matt Barry and Åsa Rosenberg, who all contributed to bringing short-circuit scanning to our customers.

    The post Wordfence Launches Short-Circuit Scan Signatures – Up to 6X Performance Increase appeared first on Wordfence.

  • The Benefits of Wordfence Premium

    On April 21 this year, Wordfence celebrated our fifth year making the world’s best firewall and malware scan for WordPress. The date came and went as we continued to focus on innovating and securing our customers. Today Wordfence has been downloaded over 45 million times and maintains a 4.8 star rating out of 5 stars, from over 3000 reviews on the official WordPress plugin repository.

    Today Wordfence is a team of 16 full-time employees, and our total team size is 30 people, including contractors. Most of our team is US-based, though we have several colleagues around the world in countries like Sweden and the UK.

    Wordfence has become a big project and is now very popular. We protect over 2 million websites, including many of the best known businesses and universities in the world.

    Most of our team’s energy is dedicated to our Premium customers. Our customer service team provides an extremely high level of support for those customers, and our engineering innovation is focused on improving the real-time protection we provide to Premium.

    The community edition of Wordfence is free, and is actually the same software that our Premium customers run. The difference between free and Premium is the data we provide that powers Wordfence and the service you receive from our team.

    Better Data Means Better Protection

    Firewall Rules and Malware Signatures in Real Time for Premium

    Wordfence at its core is a firewall and a malware scanner. But without data, a firewall does not know what to block, and a malware scan does not know what to detect.

    Our team is constantly doing research to uncover the newest threats to WordPress. We discover new threats through investigating hacked WordPress sites, by logging attacks across WordPress sites and analyzing them, and through online research and collaboration with our partners.

    When we find a new kind of attack, we turn that into a firewall rule and release it immediately to our Premium customers. When we discover a new kind of malware, we turn that into a detection signature and release it to our Premium customers.

    This flow of firewall rules and malware signatures happens in real time for our Premium customers, and it is continuous. In contrast, our free customers receive this data with a 30-day delay.

    The (Legendary) Wordfence Premium IP Blacklist

    Last week we published research that shows that well over 50% of all the attacks we block are blocked by the Premium Wordfence IP Blacklist.

    This is what that looks like represented graphically. Each color represents a unique Wordfence firewall rule and how many attacks it blocks per day. The blue represents everything that the Premium IP blacklist blocks.

    The first time I saw the above data, I was pleasantly surprised. Our team has gotten so good at identifying bad IPs and blacklisting them for our Premium customers that we now block more attacks with the blacklist than we do with firewall rules.

    Our IP blacklist is only available to Wordfence Premium customers and is extremely effective at blocking attacks. An additional benefit of the IP blacklist is that it completely blocks known attackers from your site. They can’t even do an initial scan to see your content, what version of WordPress you are running or to probe for other weaknesses.

    Priority Server Processing For Premium Customers

    Wordfence is not just a PHP plugin for WordPress. It comes with back-end services provided by applications that we run on our own physical servers, which are located at multiple data centers. Wordfence Premium customers receive priority processing on our back-end services. We provide a higher degree of reliability for Premium customers on our servers, and we prioritize Premium processing higher than our free customers.

    The Wordfence team constantly releases new versions of the Wordfence plugin, and alongside those releases, they are also releasing new versions of our server code.

    The main reason we provide server-based applications to help Wordfence is to offload much of the processing from your website onto our own machines. For example, we maintain a mirror of every version of every plugin, theme and core file for WordPress ever released. That is well over half a terabyte of data!

    We also maintain our IP blacklists, URL and hostname blacklists and other data to help identify malicious behavior.

    When you perform a scan, our databases do most of the work to determine if a file on your system is malicious. If that happened on your own hosting account, it would take a long time and would consume a large amount of disk space.

    To run Wordfence without our back-end services, you would need over a terabyte of disk space, fast multi-core CPUs, at least 32 Gigabytes of memory and a fast 1-gigabit connection to the network. Most hosting accounts have about 1% of that network speed, and with far less memory, disk and CPU resources.

    Exceptional Customer Service

    Today I was again reminded of one of the most powerful things that our CS (customer service) team do for our customers: they represent you when having conversations with the engineering team. Later this week, we will be announcing a major improvement in Wordfence. When the engineering team unveiled it today, the CS team were all cheering, because they care deeply about you and making sure your problems are solved and that you are protected.

    As a Premium Wordfence customer, you get access to our priority ticketing system. Our team works closely with you to secure your WordPress site.

    The CS team works one-on-one with our customers to solve problems and help you get the best protection from Wordfence for your site. They respond within 24 hours during the week and are very passionate about securing WordPress and securing your website.

    Most of our Wordfence CS team is US-based, and they are all WordPress and Wordfence experts. When you chat with Chloe, Tim, Andie or Asa, they are based in California, Tennessee, Florida and Sweden, respectively – to mention just a few of our amazing team members.

    Free and Premium – We Are Glad to Have You on Board

    Whether you use the free community edition of Wordfence to protect your site or you are one of our valued Premium customers, we are glad to have you as part of the Wordfence family of customers.

    Our team cares deeply about securing your site, and we want you to have the best protection possible. That is why we encourage all our free community users to upgrade to Wordfence Premium. Our current pricing is $99 per year, which works out to just $8.25 per month. It’s an incredible deal.

    Upgrade to Wordfence Premium, today, and get the best protection available for your WordPress website.

    Mark Maunder – Wordfence Founder & CEO

    The post The Benefits of Wordfence Premium appeared first on Wordfence.