Category: News

Industrial firms must pay more attention to OT cybersecurity, says vendor

American providers of critical infrastructure services still aren’t spending enough to protect their operational technology (OT) systems, says the head of a company that protects industrial internet-connected systems.

Some firms have acted, Robert Lee, CEO of Dragos Inc., told reporters during a webinar Tuesday. But he estimates less than five per cent of the world’s infrastructure has invested in OT visibility.

“We simply haven’t turned on the lights in the house to see what’s happening.”

One electricity provider told him it spends US$100 million a year on IT security, and just US$5 million on OT security, he said.

That’s understandable, he quickly added, because for years, boards and CEOs of firms with internet-connected industrial systems focused cybersecurity on enterprise IT networks, not realizing that didn’t include the OT side.

OT cybersecurity is unique because factory and industrial network communications and protocols can be different than on IT networks, so IT security solutions can’t merely be copied, Lee said.

What worries him is the possibility that more attack frameworks like Pipedream, which Dragos and U.S. cyber authorities discovered in 2022 and is attributed to a foreign government, may soon be within reach of threat actors with fewer resources than a nation-state.

Pipedream, which was found on a U.S. firm’s network, can manipulate a wide variety of programmable logic controllers (PLCs) and other industrial equipment, is highly scalable, reusable, and can cause damage in [almost] any OT system, Lee said.

Once deployed, there’s no way to stop it, he added. Pipedream isn’t like a vulnerability that can be patched.

“What concerns me is other countries are working on very similar capabilities,” said Lee, “and these capabilities will start proliferating to criminals.”

An example is the discovery earlier this year by Microsoft of a China-based group dubbed Volt Typhoon targeting critical infrastructure organizations — including communications providers, utilities, manufacturers, IT firms, and government departments — in Guam and the U.S. mainland.

This week, Reuters said the U.S. struck back at the IT infrastructure supporting Volt Typhoon.

Lee said Dragos has been watching Volt Typhoon for a while. “They consistently chose industrial targets and play the ‘low and slow game,’ where they get in and wait for the malware to be used when they want,” Lee said.

“We consistently see this as a pattern across the world, where adversaries want to have access to the operational technology portion of the critical infrastructure to be able to leverage it at the time and place of their choosing.”

What makes this kind of threat damaging is the fact that OT networks have moved from being customized for each environment to being automated and commoditized. That leaves them open to attacks whose damage can spread from merely one company to an entire industrial sector or geographic region, he said.

“For most companies in the United States that operate industrial infrastructure, the current reality is that growing complexity in automation means we are losing expertise in companies on the [OT] systems as a whole,” Lee said.

“We may just really understand [OT] subsystems. We may need to call in vendors and integrators and contractors and a bunch of other people to understand these systems of systems. What that means is something that can happen — the network can go down, the system can go down, physical destruction can take place, or a plant can go down — and we wouldn’t know why. That ability to do root cause analysis is only possible with a lot of preparation ahead of time.”

There has been recent progress in awareness, Lee admitted, particularly because the U.S. government is working more closely with industry, and publicizing the problem through Presidential executive orders and reports on Pipedream and Volt Typhoon.

“We are seeing win after win when governments do their part to use their unique capabilities and collaborate with the private sector, so we can use our [capabilities],” he said.

“If we can respect the fact OT is different from IT, we can elevate the discussion so executives and policy makers around the world can understand that reality, and how much we’ve under-invested” in identifying and responding to OT threats, he said.

With that understanding, “we can pull [together] a really powerful, really exciting group of asset owners and operators who give a damn about national security and local security” and, with experts in the private sector and government, “make it extremely costly and painful for adversaries to find success. That is what winning looks like, and it is absolutely doable,”

“But quite frankly,” he added, “we have a lot of ground to cover.”

The public has to understand why utilities and manufacturers are spending on OT security, Lee said. “The less [time] we’re debating on if we should do something, and the more [time spent] on executing on what we know right looks like, the better we’ll be.”

Separately, Kaspersky issued threat predictions for this year for the industrial control and OT sectors.

These include:

— ransomware will remain the No. 1 scourge of industrial enterprises in 2024;
— attacks on logistics and transport companies may become targeted not at the IT infrastructure supporting operations, but the vehicles themselves;
— politically motivated hacktivism along geopolitical fault lines will grow sharper teeth and have more destructive consequences;
— widespread use of “offensive cybersecurity” by companies and cybersecurity firms for gathering cyberthreat intelligence will have both positive and negative consequences;
— The ongoing and rapid automation and digitization of logistics and transport will lead to greater intertwining of cyber- and traditional crime, particularly in long-established criminal fields such as the theft of cars, maritime piracy and logistics fraud.

The post Industrial firms must pay more attention to OT cybersecurity, says vendor first appeared on IT World Canada.

Warning: Threat actors getting around some Ivanti mitigations

Cyber authorities in the U.S. and Australia have issued new warnings to IT administrators to take more action to protect Ivanti Connect Secure and Policy Secure Gateways. At the same time, Ivanti revealed that two new vulnerabilities for the devices have been discovered, on top of a pair revealed earlier this month.

The latest vulnerabilities are CVE-2024-21888, a privilege escalation vulnerability affecting Policy Secure, and CVE-2024-21893, a server-side request forgery vulnerability affecting supported versions of Connect Secure and Policy Secure Gateways.

Ivanti today issued a patch for Connect Secure (versions 9.1R14.4, 9.1R17.2, 9.1R18.3, 22.4R2.2 and 22.5R1.1) and ZTA version 22.6R1.3. that covers the new holes. More patches are coming.

“Out of an abundance of caution, we are recommending as a best practice that customers factory reset their appliance before applying the patch, to prevent the threat actor from gaining upgrade persistence in your environment,” Ivanti said this morning.  Customers should expect the reset process to take three to four hours.

The remaining patches for supported versions will still be released on a staggered schedule, Ivanti adds.

Australia’s Cyber Security Centre said this morning it is aware of reports that threat actors have developed workarounds to some mitigation and detection methods, leading to reported ongoing exploitation activity.

The Centre “strongly advises organizations operating vulnerable Ivanti Connect Secure and Ivanti Policy Secure products to conduct investigation and monitoring for potential compromise of systems,” the alert says. IT administrators should monitor authentication, account usage and identity management services, and consider isolating systems from any enterprise resources as much as possible.

The U.S. issued a similar warning on Tuesday.

“Threat actors are continuing to leverage vulnerabilities in Ivanti Connect Secure and Policy Secure Gateways to capture credentials and/or drop webshells that enable further compromise of enterprise networks,” the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said. “Some threat actors have recently developed workarounds to current mitigations and detection methods and have been able to exploit weaknesses, move laterally, and escalate privileges without detection. CISA is aware of instances in which sophisticated threat actors have subverted the external integrity checker tool (ICT), further minimizing traces of their intrusion.”

If an organization has been running Ivanti Connect Secure (9.x and 22.x) and Policy Secure gateways over the last several weeks and/or continues to run these products, CISA recommends continuous threat hunting on any systems connected to — or recently connected to — the Ivanti device. Additionally, it said, organizations should monitor authentication, account usage, and identity management services that could be exposed, and isolate the system(s) from any enterprise resources as much as possible.

After applying patches, when these become available, CISA recommends that organizations continue to hunt their networks to detect any compromise that may have occurred before patches were implemented.

These warnings to take mitigation action come almost three weeks after Ivanti issued its first alert of an authentication bypass vulnerability (CVE-2023-46805) and a command injection vulnerability (CVE-2024-21887) in the devices.

Also today, Mandiant issued an update to its background blog on the vulnerabilities.  Mandiant has identified zero-day exploitation of these vulnerabilities in the wild, beginning as early as Dec. 3, 2023, by a suspected China-nexus espionage threat actor.

Mandiant notes that a threat actor found a way to get around Ivanti’s recommended mitigation, released Jan. 10, for the first pair of vulnerabilities. That bypass led to the deployment of a custom webshell. Mandiant believes the mitigation bypass activity is “highly targeted, limited, and is distinct from the post-advisory mass exploitation activity.” However, using Ivanti’s external integrity checker tool (ICT) successfully detected the presence of the new webshell.

Mandiant notes Ivanti’s external ICT should be used by IT administrators for reviewing logs, because it is more robust and resistant to tampering than the internal version.

The blog also outlines indicators of compromise.

The post Warning: Threat actors getting around some Ivanti mitigations first appeared on IT World Canada.

Cyber Security Today, Jan. 31, 2024 – A new ransomware strain found, and questions about the level of ransomware payments

A new ransomware strain found, and questions about the level of ransomware payments.

Welcome to Cyber Security Today. It’s Wednesday, January 31st, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



A new ransomware strain has been circulating for almost a year. According to a researcher at Netenrich, the group calls itself Alpha. Its data leak site lists six victims. Three firms are in the U.S., two in the U.K. and one is in Israel. The group is relatively new and still in the process of setting up operations. Victims are sent a personal decryption key to log into a messaging portal where they can negotiate a ransom. The gang says victim firms can upload three encrypted files that will be unscrambled as proof the decryptor they buy actually works.

There’s evidence that fewer organizations hit by ransomware are paying up. Coveware, which acts for firms in ransomware negotiations, says the average ransomware payment dropped over 2023. In fact it went down 33 per cent in the fourth quarter compared to what was paid in the third quarter. This may be due to better IT defences and backups, allowing some victims to ignore payment demands — although by the count of other companies 2023 was a record year for successful ransomware attacks. It also may be that more organizations just don’t trust crooks to keep their promises that stolen data will be deleted. We’ll see if the trend continues.

Another report issued this week has conflicting data. The survey of security and IT pros done by Cohesity suggests that despite pleas by governments not to pay ransomware gangs, organizations haven’t discarded the option. More than 90 per cent of respondents believe their company would pay a ransom to recover data and restore business processes. Nine in 10 respondents said their organization paid a ransom in the last two years. Over two-thirds of respondents believe their organization would be willing to pay over US$3 million to recover data.

Almost half of cybersecurity leaders in financial institutions believe their firm has been successfully hacked without being detected. That’s according to a report from Contrast Security. It surveyed infosec leaders in financial institutions to find out the state of cybersecurity in the sector. Among the findings: Lots of attacks by threat actors trying to steal corporate information, lots of attacks involving the destruction of data and lots of attacks on application programming interfaces. The report suggests financial institutions have to up their defensive game.

Artificial intelligence is coming to Android device users. Google’s Bard AI platform will be used to analyze your Google Messages and become a personal assistant. But will this be a privacy problem — particularly because messages will be sent to Google’s cloud for processing. An article on Forbes.com raises interesting questions. There’s a link to it here.

Security teams have to invest more in automation and internal training to combat knowledge gaps, and on improving the visibility of their IT environment. That’s the conclusion of security vendor Exabeam, which commissioned a global survey of IT pros in eight countries. Over 90 per cent of respondents believed they had a good or excellent ability to detect cyber threats. However almost 60 per cent of respondents said they experienced security incidents in the previous 12 months so significant they required extra resources to remediate. Also, respondents think they are only seeing about 66 per cent of their IT environments.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Jan. 31, 2024 – A new ransomware strain found, and questions about the level of ransomware payments first appeared on IT World Canada.

Hashtag Trending Jan.31- Ransomware payments declining? ChatGPT leaking chat histories; UK law may ban Apple from issuing security updates worldwide



 

Hey out there. Someone wrote me yesterday to tell me that they had tried to pass on how to subscribe, but it was difficult to find Hashtag Trending – apparently a lot of similar names. 

Changing the name of the podcast is a big deal, but finding us isn’t. Just go to our page at itworldcanada.com/podcasts.  Look in any of the daily scripts and there are links that take you directly to us on Apple, Google or Spotify.  

Feel free to share a link to any of those pages with your friends who might want to subscribe. One click and they are there. And I hope I’ve said it enough – thank you for recommending us to your friends and colleagues. It’s working.

Ransomware payments may be on the decline. ChatGPT may be leaking information and no-one is quite sure why, Microsoft’s Future of work claims some huge gains in productivity – and some issues with accuracy. And…they are called Robot wranglers and they’re managing mischievous machines. 

All this and more this edition of, hey, robots have rights too version of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.  

According to a new report from ransomware negotiation firm Coveware, there has been a significant decline in the number of ransomware victims who choose to pay hackers. In the last quarter of 2024, only 29 per cent of organizations opted to pay a ransom to retrieve their stolen data and unlock their systems during a cyberattack. This figure marks a stark contrast to the first quarter of 2019, when 85 per cent of affected organizations were paying ransoms.

The average ransom payment in the fourth quarter of 2023 was approximately $568,000, which is a 33 per cent decrease from the third quarter. Coveware attributes this decline to several factors. Enterprises have strengthened their cyber defenses and have more robust data backups, enabling quicker recovery from attacks. Additionally, there’s a growing distrust among companies towards hackers’ promises to delete stolen data after receiving the ransom.

Ransomware has emerged as a top cyber threat for organizations of all sizes over the past five years. Government officials have been actively working to reduce the number of ransomware attacks targeting businesses, governments, and other entities. However, ransomware hackers are known for their adaptability and may simply change their tactics, so let’s not count them out just yet.

Sources include: Axios

A user of ChatGPT, Chase Whiteside, reported an alarming incident where he found chat histories from unrelated users in his account. These chats contained sensitive information, including unpublished research papers and other private data. OpenAI officials have stated that this issue resulted from Whiteside’s ChatGPT account being compromised, with unauthorized logins traced back to Sri Lanka. Whiteside, who logs in from Brooklyn, New York, expressed doubts about his account being compromised, citing the use of a strong, unique password.

OpenAI’s investigation suggests that the incident was not a case of ChatGPT leaking chat histories to unrelated users but rather a consequence of an account takeover. This situation highlights the lack of mechanisms such as two-factor authentication (2FA) or the ability to track IP locations of logins on the ChatGPT platform, which are standard security features on most major platforms.

The original suspicion that ChatGPT was leaking private conversations, including login credentials and personal details of unrelated users, has been refuted by OpenAI’s findings. However, the incident underscores the importance of maintaining robust security measures for online accounts and being cautious about sharing personal details in AI service queries.

This incident, along with similar experiences reported in the past, serves as a reminder of the potential risks associated with using AI services and the importance of safeguarding personal and proprietary data.

Sources include: ArsTechnica

Proposed amendments to the UK’s Investigatory Powers Act (IPA) could potentially ban Apple from issuing security updates worldwide, a move that Apple has labeled as an “unprecedented overreach.” This development raises significant concerns about data security and information privacy, not just for British citizens, but for tech users globally.

The IPA, enacted in 2016, already grants the UK government the power to issue orders to tech companies to build backdoors into their products to break encryption. Apple has been a vocal opponent of this, previously threatening to withdraw iMessage and FaceTime from the UK market rather than compromise end-to-end encryption.

The new amendments to the IPA could allow the UK government to prevent Apple from providing security updates to iOS if they interfere with the operations of UK security services. Apple argues that this could force non-UK companies to undermine the security of all users because of their UK user base. The company also points out that the Home Office proposes that the extraterritorial scope of the IPA should apply globally, regardless of a provider’s physical presence in the UK.

The proposed amendments have now moved to the next stage in the UK’s legislative process, first passing through the House of Commons and then to the House of Lords. The Lords, an unelected body, often provide a more considered response to legislation, potentially influencing the final outcome of these controversial measures.

Apple, backed by various civil liberties groups, has strongly objected to these new powers. They argue that the amendments would transform private companies into extensions of the surveillance state and erode the security of devices and the internet globally.

This situation highlights a significant conflict between government surveillance desires and the privacy and security of global tech users. The outcome of this legislative process could have far-reaching implications for tech companies and users worldwide.

I hear a Tom Petty song here – won’t back down. I’m not sure Apple can.

Sources include: 9TO5 Mac

Microsoft’s recent report titled “New Future of Work” acknowledges that AI can speed up certain tasks, like writing, by 37 per cent, but also notes downsides – a 19 per cent decrease in accuracy in work done by experts from Boston Consulting Group using large language models.

Microsoft claims its Copilot is “mostly neutral” in its effects on quality and touts it as a solution to AI-related problems. A survey of enterprise users with access to Copilot showed that 68 percent believed it improved the quality of their work, although this is based on perception.

However, since the announcement of Copilot Pro, a premium version of the OpenAI-powered LLM bot, there have been complaints about its effectiveness, pricing, and even why it exists. 

The report also mentions that LLMs are most helpful to less experienced workers.  

It also reveals that small semantic differences in writing prompts can lead to vastly different results. That’s why Microsoft’s Copilot Lab  is providing a collection of suggested prompts.

Microsoft’s vision of the future of work, heavily influenced by its AI investment, is facing regulatory scrutiny. The US Federal Trade Commission, the European Commission, and the UK Competition and Markets Authority are investigating whether the Microsoft/OpenAI partnership could lead to an anticompetitive situation.

This EU regulation thing isn’t going away, is it?

Sources include: YouTube and The Register

At a subsidiary of GE Appliances in LaFayette, Georgia, Scott Samples is pioneering a new profession: he’s a ‘robot wrangler.’ This new job has emerged as companies increasingly integrate robots into their operations, only to discover that these automatons sometimes need a bit of human guidance.

One notorious robot, nicknamed Blinky for its flashing lights signaling distress, is known for its mischievous antics. It often disrupts the smooth transfer of items due to its overzealous conveyor belt movements, leading to humorous exasperation among the staff. “Oh s—, not again. It’s him again,” they’d say, attributing a personality to the mechanical troublemaker. Blinky, unsurprisingly, had no comment on these allegations.

Scott Samples, the ‘robot wrangler’ at Roper, a GE Appliances subsidiary, is the go-to guy for robots that stray off course. The facility’s 25 robots, some resembling wheeled pumpkins, are programmed to follow digital maps and use advanced technology to navigate. Yet, they sometimes end up “lost like a child in the park” or awkwardly trying to hide under someone’s desk. When Samples receives a call about a wandering robot, he uses its cameras and sensors to locate and retrieve the wayward machine.

The human workers at the facility have named the robots everything from Herbie to Wonder Woman, generally coexisting peacefully with their automated counterparts. However, occasional standoffs occur when a robot and a human inadvertently play a game of ‘who moves first,’ leading to comical situations. “This thing is following me and will not let me by,” workers would complain to Samples, unaware of the technical reasons behind the robot’s behavior.

Sean Cusack, a robot engineer in Oakland, California, finds that explaining the robots’ roles isn’t too challenging. “People envision robots as these completely intelligent, Terminator-level things,” he said. In reality, they’re often quite silly. 

Jaci Story, working with Starship Technologies in San Francisco, shares a humorous anecdote about the robots’ unexpected quirks. While charging a robot, it suddenly blurted out, “Whoa, whoa, we have rights you know,” leading her to burst into laughter.

As robot wranglers like Samples and Rutenberg navigate this new landscape, they’re not only managing the robots’ technical needs but also fostering a harmonious relationship between man and machine. Their role is crucial in bridging the gap between traditional human labour and the automated future, ensuring that robots are seen as helpers rather than threats.

In this quirky world of robot wrangling, every day brings a new adventure, whether it’s dealing with a mischievous Blinky or reassuring a robot that, yes, “we have rights, you know.”

Sources include: Wall Street Journal

Hashtag Trending goes to air five days a week with a daily news show and every Saturday, we have an interview show called the Weekend Edition.  

We love your comments. Please let us know what you think. You can reach me at jlove@itwc.ca  or leave a comment under the show notes at www.itworldcanada.com/podcasts

I’m your host Jim Love, thanks for listening and have a Wonderful Wednesday.

 

The post Hashtag Trending Jan.31- Ransomware payments declining? ChatGPT leaking chat histories; UK law may ban Apple from issuing security updates worldwide first appeared on IT World Canada.

Canadian government investigating another hack at Global Affairs

The Canadian government is investigating what could be a major data breach at its foreign affairs department.

CBC News says there is an investigation into what it calls a prolonged data security breach on the internal network of Global Affairs Canada.

At least two internal hard drives, as well as emails, calendars and contacts of many staff members were affected, the news service says.

Some staff have been told they can’t work remotely because of the incident.

One government email to staff, seen by the CBC, says data of any staffer who connected remotely by virtual private network between December 30, 2023 and January 24th is at risk.

“Early results indicate there has been a data breach and that there has been unauthorized access to personal information of users, including employees,” Global Affairs said in a statement to IT World Canada.

“The Department is contacting those affected with mitigation measures to ensure that sensitive and personal information is secure. The incident has also been reported to Canada’s Office of the Privacy Commissioner.”

“An unplanned IT outage is currently affecting remote access to Global Affairs Canada (GAC)’s network in the country. The Department’s critical services and external communication channels remain accessible and operational. This partial outage was intentionally activated on January 24, 2024 to address the discovery of malicious cyber activity. Global Affairs Canada is working with IT partners, including Shared Services Canada and the Canadian Centre for Cyber Security (part of the Communications Security Establishment) to restore full connectivity as soon as possible.”

Shared Services Canada is responsible for consolidating and modernizing certain IT services across federal departments, including email, data centre, and network services.

On-site employee connectivity in government buildings is fully functioning, the Global Affairs statement said, allowing for normal computer/network access. “Employees working remotely in Canada have been provided with workarounds to ensure they remain operational. The Government of Canada deals with ongoing and persistent cyber risks and threats every day. Given its profile, Global Affairs Canada takes a proactive approach and employs a variety of security monitoring measures to detect and address potential risks. The Department is closely monitoring the situation and is conducting an investigation into the matter.

“We cannot comment further at the moment on any specific details for operational and security reasons.”

Global Affairs oversees the government’s foreign policy, and operates Canadian embassies and consulates around the world. Its minister is a member of the cabinet’s Global Affairs and Public Security committee, which not only deals with diplomatic and trade issues, but also threats and risks to the safety and security of the country.

Discovery of the incident comes almost exactly two years after Global Affairs revealed it had been compromised in a cyber attack. At that time, the Treasury Board of Canada Secretariat said the attack was detected on January 19, 2022.

According to The Hill Times, a department investigation after the attack concluded it was “very likely” Global Affairs would face another online threat that would have a “very high” impact.

David Shipley, head of New Brunswick’s Beauceron Security and co-chair of the Canadian Chamber of Commerce’s cyber council, said a key indicator of how serious this breach of security controls is will be how long the Global Affairs network is down. “The last time it happened, two years ago, they had a relatively quick recovery. If it’s a prolonged one [outage] then it’s a more significant compromise. That raises some interesting questions: Did they fully get them [the hackers] out [of the network] two years ago?”

The government needs to publicly explain this breach so other organizations can learn from the incident, he added.

The post Canadian government investigating another hack at Global Affairs first appeared on IT World Canada.

Retailers at critical juncture due to severe tech gaps: SOTI study

A new study released today reveals that the retail industry in Canada and elsewhere around the world faces major challenges as a result of consumers experiencing a major “disconnect between their shopping expectations and the in-store reality.”

The study, conducted by Mississauga-based SOTI, a provider of mobile and IoT device management offerings, concludes that while consumers “crave technology to improve their in-store shopping experience, those offered by retailers do not always meet expectations.”

An example of those expectations can be seen in the fact 45 per cent of those polled expect to be able to pick up an item ordered online from a physical store on the same day. Further, “74 per cent of global consumers expect to always knows the status of their orders, highlighting the need for efficient supply chain visibility.”

Based on interviews with 11,000 consumers from nine markets – Canada, the U.S., Mexico, the U.K., Germany, France, Sweden, the Netherlands. and Australia – conducted in September 2023, findings indicated that:

Security is a significant concern in the retail industry. More than three-quarters (76 per cent) of consumers globally express concerns about entering personal details online or through in-store devices, indicating a pervasive lack of trust in the data collection and payment technologies used in retail.
Security concerns extend to fraud, with 35 per cent of global consumers worrying about becoming a victim of financial fraud, and another 35 per cent expressing concerns about identity fraud.
Consumers cite challenges in-store such as lack of staff to assist with issues relating to self-serve machines (51 per cent of users), and as many as 35 per cent of users complain about Wi-Fi connectivity when using an in-store device.

During a press briefing held last week to discuss the findings, Stephanie Lopinski, vice president of global marketing at SOTI, said the company first launched a study into retail trends five years ago.

“During the pandemic, our research showed that customers went online in droves and retailers invested heavily in perfecting online shopping,” she said. “Fast forward to our 2024 report, the data we are seeing is that consumers are heading back in store, but they are noticing the tech available in stores is lacking the personalization they came to see as table stakes online.

“(This) report highlights that new technology is often poorly deployed and not fit for purpose. Consumers are frustrated. Batteries in tablets and in scanners in stores, they are dying. Self-serve checkouts are not easy to use, and consumers often need assistance.”

Lopinski went on to say that findings show, “there are no staff available to even address these device issues, leading to cart abandonment and frustration. Retailers need to focus on managing their devices and optimizing their tech investments to regain consumer satisfaction.”

Shash Anand, senior vice president of product strategy at SOTI, said it is “crucial to recognize that artificial intelligence (AI) plays a significant role in harnessing deeper intelligence from devices. AI-driven diagnostic intelligence and proactive support solutions empower retailers to identify and resolve issues before they impact the consumer experience.

“By integrating location, signal strength, and data speed with critical business information such as inventory levels and delivery status, AI can ensure that in-store hyper-personalization can replicate the seamlessness consumers expect from online shopping.”

Over the next three years, said Anand, the “focus should be on building trust, safeguarding data and providing seamless experiences that bridge the gap between online and in-store shopping.”

Canadian shoppers, like their counterparts around the globe, are now demanding real-time information, efficient product availability, and rapid delivery, in-store and online, a release from SOTI states.

The report indicates that 41 per cent of consumers will look elsewhere if delivery or pick-up of an item is more than two days away, and that 77 per cent expect to always know the status of their orders, highlighting the need for efficient supply chain visibility.

“When reflecting on the overall retail experience, Canadian respondents continue to expect change and see value in technology to enhance their interactions with retailers, but gaps between expectations and reality continue to jeopardize brand loyalty and sales,” said Anand.

“Looking to the future, retailers must focus on the technologies and infrastructure around them and ask how these applications, devices, and technology solutions are being managed, monitored and maintained.”

Intelligence offerings, he said, “can not only help you visualize your retail operations and entire supply chain – in real-time – but also allow you to uncover operational issues immediately by merging both business and device data, creating a holistic view of your operations both in-store and online.”

The post Retailers at critical juncture due to severe tech gaps: SOTI study first appeared on IT World Canada.

Canadian CEOs worried about economic outlook, but expect turnaround with AI: Report

Over the past year, an increasing number of companies have worried that they will not survive amid rapid technological change and growing economic uncertainties unless they reinvent themselves, PwC’s 27th annual global CEO survey found.

The report finds that artificial intelligence could be the key to reinvention, and consequently, to higher profit margins.

PwC interviewed 4,702 chief executives across 105 countries and territories, including 114 in Canada.

Forty-five per cent of CEOs said that their companies might not be viable in the next 10 years. This represents a 39 per cent increase from last year. A third (32 per cent) also suggested their businesses may not be around in a decade.

CEOs are also concerned about inflation, geopolitical conflict, and cybersecurity risks, as well as climate change, but the key area of concern remains the economy, with only 25 per cent of Canadian CEOs believing that the local economic growth will improve this year, compared to 44 per cent of global respondents who expect better times for their country’s economy.

A recent Capterra report also showed that the stalling economic growth rate in Canada would be the top factor influencing business goals.

“We are operating in a continued poly-crisis environment, further complicated by tough economic headwinds. Therefore, it is not surprising that Canadian CEOs are more pessimistic than their global counterparts when it comes to their outlook on economic growth,” said Nicolas Marcoux, CEO, PwC Canada. “While a soft recessionary landing may be anticipated, CEOs find themselves under increasing pressure to reinvent their organizations.”

On the bright side, the vast majority are taking action, mainly driven by the impetus of technological change and AI, the PwC survey indicated.

Many of them have already kicked off their generative AI journeys, with 36 per cent of Canadian respondents (versus 32 per cent globally) saying they’ve adopted the technology in the last 12 months. However, they continue to exercise caution, with most citing cybersecurity as a top risk, followed by misinformation, legal/reputational risks, and bias towards employees or customers.

For those who are optimistic about AI, upskilling, budget constraints and operational inefficiencies remain top barriers, the report highlighted.

Fifty-five per cent of Canadian CEOs, in fact, agreed that generative AI will require significant upskilling of their workforce in the next three years.

Additionally, they revealed that 44 per cent of the time currently spent on a range of work processes was inefficient.

“Reducing inefficiencies is one area where investments in technologies like generative AI can help,” the report reads. “And by engaging with employees to help them feel safe proposing new ways of doing things and giving them an active role in change and reinvention, CEOs can not only uncover opportunities to accelerate priorities like technology adoption, but also find even more solutions to the inefficient processes holding companies back.”

However, while investing in new software is also critical to reinvention initiatives, 56 per cent of Canadian decision makers end up regretting a software investment decision, with a third blaming unforeseen costs, Capterra noted in its 2024 Tech Trends survey.

The survey advises companies to drill down on four challenges before making a software investment decision:

Identifying the right technology
Security concerns
Staff acceptance and training
Compatibility with existing systems

Companies should also create a list of potential product vendors, gather information using diverse sources like software comparison websites, online reviews, and even generative AI tools such as ChatGPT.

PwC, on the other hand, advises Canadian companies to focus on resource allocation to enable reinvention initiatives.  This includes making tough calls about an organization’s assets and focusing on the benefits of looking beyond a company’s walls by embracing strategic partnerships, alliances, and ecosystems.

Canadian CEOs should also acknowledge the scale and the urgency of the challenges they face, and question the viability of their business models as well as the risks they are exposed to.

“CEOs who are more concerned about their organization’s long-term viability are doing more than others to adapt to today’s intense business pressures, which only heightens the need for Canadian executives to look at additional measures to spot emerging risks and hazards,” the PwC report said. “Those who do so will be better able to see the urgency to not just accelerate change and reinvention but also engage their teams and the whole organization in sustaining it.”

The post Canadian CEOs worried about economic outlook, but expect turnaround with AI: Report first appeared on IT World Canada.

Coffee Briefing Jan. 30 – CGI and National Bank of Canada deepen partnership; OpenText’s new cloud editions release; Telus’ new AI report gathers a diversity of perspectives; and more

Coffee Briefings are timely deliveries of the latest ITWC headlines, interviews, and podcasts. Today’s Coffee Briefing is delivered by IT World Canada’s editorial team! 

Missed the last Coffee Briefing? We’ve got you covered.

CGI and National Bank of Canada renew partnership for 10 years

 

CGI and the National Bank of Canada have renewed their partnership for another 10 years, wherein CGI will continue to deliver a wide range of technology services to help the bank enhance its client experience and drive operational excellence.

“CGI is a trusted partner in the financial services sector,” said Julie Levesque, executive vice president technology and operations, National Bank of Canada. “We value CGI’s expertise and commitment to excellence that will play an important role in our ongoing efforts to meet the evolving needs of our clients and stay at the forefront of the financial services industry.”

This renewed agreement extends the 20-plus year partnership between the organizations, with CGI delivering banking insights, expertise, business consulting, project development, systems integration, and wealth and payment solutions.

“This agreement exemplifies the trust National Bank of Canada has in CGI’s capabilities and we look forward to bringing the best of CGI globally to help the Bank accelerate its transformation,” said Michael Godin, CGI senior vice president, Greater Montréal.

Montreal company enables access to Google’s Privacy Sandbox feature

Software-as-a-Service (SaaS) data management platform Optable has launched an Early Access Program for its Privacy Sandbox activation capabilities.

Google made the Privacy Sandbox APIs available last summer, it said, to foster “greater privacy, transparency, choice, and control without undermining the business model of ad-supported websites.”

Optable says its Early Access Program allows advertisers to target audiences while preserving privacy. Publisher networks also benefit from the ability to launch privacy-safe advertising products, engaging user cohorts across owned, operated, and third-party media.

The API is also integrated with Optable’s data management solution, Optable DMP, and its data clean room suite, Optable Collaborate.

“Our customers require solutions that empower them to leverage both authenticated and anonymous user data in innovative, privacy-centric ways for audience-based planning, activation, and measurement,” said Bosko Milekic, chief product officer and co-founder, Optable. “This integration fundamentally strengthens our platform and will redefine what people expect to get out of data management and collaboration platforms in the era of privacy.”

OpenText Cloud Editions 24.1 release contains 3 Aviator upgrades

OpenText recently released Cloud Editions 24.1, which contains what the company described as the “latest OpenText Aviator innovations.”

These include:

OpenText Content Aviator, which is now available on OpenText Extended ECM, integrating conversational search, summarization, and translation within content management. The update allows an organization to leverage generative AI technology to help accelerate content discovery, improving employee efficiency and productivity.

OpenText IT Operations Aviator on its software as a service (SaaS) offering, service management automation X (SMAX), efficiently resolves common IT service requests, thus minimizing the need for support staff and reducing tier-one business costs. Learn more about the early adopter program here.

OpenText Thrust Studio is now available through an early access program. These new tools enable developers to design, build, and deploy applications utilizing OpenText Thrust APIs more seamlessly with enhanced workflows, permissions, and decision models.

“The latest Cloud Editions launch isn’t just about enhancing our offerings or providing a solution,” said Mark Barrenechea, chief executive officer (CEO) and chief technology officer (CTO) at OpenText. “It is about enabling a paradigm shift in how businesses operate, how industries evolve, and how we collectively engage with technology in this era of rapid transformation.

“Leveraging AI for impactful results depends on reliable data – without it, even the most skilled data scientists will struggle.”

90 per cent of Canadians want AI development to be guided by ethical principles: Telus report

Telus has released a new report highlighting Canadians’ support for AI regulation, as well as the importance of including diverse voices in the development of AI.

The report surveyed 5,000 Canadians, including Indigenous Peoples, racialized groups, the LGBTQ2S+ community, and older and new Canadians, as well as people with physical disabilities.

Over 90 per cent of respondents agreed that AI development should be guided by ethical principles, with almost half believing that AI governance should include community consultation to ensure diverse perspectives. 

In fact, 42 per cent of respondents who self-identified as part of a racialized group feel that AI is biased against them and their peers. Sixty-one per cent of respondents identifying as LGBTQ2S+ fear that AI may be used against certain people and communities.

Many respondents also expressed concerns about the risks of job losses and deepfakes, biases in data, copyright infringement, and privacy.

As a result, 78 per cent of respondents believe that AI usage and development should be regulated in Canada. The majority of respondents believe that this regulation should be government-led, with 2 in 3 suggesting that input is needed from professionals in data ethics, the law, and academia.

Telus emphasized the need for active participation and input of all Canadians.

“This report is our rallying cry for organizations to get involved by building useful resources to educate the public on how they are considering ethics and human impacts throughout the development of this incredibly powerful innovation, while being inclusive in decision-making around all aspects of AI’s development,” said Pam Snively, chief data and trust officer at Telus.

Concordia University of Edmonton and Robogarden present new upskilling programs

 

Concordia University of Edmonton (CUE) and online learning platform RoboGarden have announced the availability of new cohorts for their digital workforce career upskilling and transition programs.

CUE’s Machine Learning and AI Development and Full Stack Development bootcamps, powered by RoboGarden, are 100 per cent online and are supported with scheduled instructor and teaching assistant hours. Students get self-paced study hours and content delivery strategies built for engagement and skill acquisition. Career and freelancer income generation preparation content are also delivered throughout the program, and focused on in the final module.

“Concordia University of Edmonton was one of our first Canadian post-secondary institution partners and we are delighted the University continues to collaborate with RoboGarden in the delivery of digital workforce career upskilling and re-skilling programs,” said RoboGarden president and co-founder Mohamed Elhabiby. “We know Concordia University of Edmonton alumni and learning community members are highly suitable to upskill for the Canadian digital workforce; it is good news that RoboGarden-powered lower-cost programs can continue to be offered by the institution they connect with.”

More to explore

Failure to launch: Cybersecurity pros discuss how to solve the resource crisis

As part of IT World Canada’s partnership with the Canadian Cybersecurity Network, we are featuring a replay of a recent panel discussion featuring cybersecurity professionals discussing the issues that we face in gaining and retaining talent.

FTC investigates AI oligopolies; calls on Microsoft, Alphabet, Amazon to disclose investments in startups

Yesterday, following a half day summit hosted by the U.S. Federal Trade Commission (FTC) that convened experts to examine the key players and the litany of consumer protection issues arising from the mushrooming AI market, the agency announced that it is investigating tech goliaths’ investments in artificial intelligence startups.

Why Canadian provinces, territories need to regulate AI

The use of artificial intelligence in Canada’s federal, provincial, territorial and municipal governments has to be regulated as much as its use in the private sector, a conference on AI in the public sector has been told.

Quebec cybersecurity institute gets $1.3 million grant from Google

Google’s philanthropic arm is giving a $1.3 million grant to a Quebec agency for cybersecurity research.

Bell and Québecor spar over MVNO access service agreements

Bell has accused Québecor of refusing to enter into necessary mobile virtual network operator (MVNO) access agreements.

More work needed to blunt public’s AI privacy concerns: Report

Organizations aren’t making much progress in convincing the public their data is being used responsibly in artificial intelligence applications, a new survey suggests.

Channel Bytes January 26, 2024 – Microsoft hires execs to run nuclear program; Aptum tech partnership with Avant; HiddenLayer launches partner program; and more

Staying informed is a constant challenge. There’s so much to do, and so little time. But we have you covered. Grab a coffee and take five while you nibble on these tidbits.

Listen to the latest episode of Hashtag Trending

Hashtag Trending Jan.30- Google’s Bard may be reading your email; Siri to get an AI makeover? The demise of the floppy disk

Listen to the latest episode of Cybersecurity Today

Cyber Security Today, Jan. 29, 2024 – SolarWinds demands fraud allegation be dropped, a Canadian sentenced for ransomware attacks, and more

 

The post Coffee Briefing Jan. 30 – CGI and National Bank of Canada deepen partnership; OpenText’s new cloud editions release; Telus’ new AI report gathers a diversity of perspectives; and more first appeared on IT World Canada.

Government vows to address corporate privacy worries in proposed cybersecurity law

Parliamentary hearings opened Monday into proposed new laws that would give Ottawa authority over the cybersecurity readiness of critical infrastructure providers, with the government quickly signaling that it’s sensitive to complaints about the amount of information companies may have to give bureaucrats.

The committee had set aside an hour for MPs to discuss Bill C-26, which would amend the Telecommunications Act overseeing telecom companies and create the Critical Cyber Systems Protection Act (CCSPA). Both would obligate designated critical infrastructure providers to have cyber security plans and report breaches of security controls to the Communication Security Establishment (CSE), a division of the Defence Department responsible for securing government networks and, through the Canadian Centre for Cyber Security, advising the private sector and government departments on cybersecurity.

Initially, only a few critical infrastructure sectors (banking, telecom, interprovincial pipelines and energy providers) will be covered.

In his opening remarks to MPs, Sami Khoury, head of the Cyber Centre, told Parliament’s public safety committee that “we are aware of privacy concerns raised by some stakeholder groups about the reporting requirements of cyber incidents to CSE.

“CSE and the Cyber Centre have an important responsibility to protect Canadians’ privacy and personal information, and we take it very seriously.”

However, right after Khoury finished his introduction, the Conservatives introduced a motion demanding the committee call government and private sector witnesses to investigate the recent rise of car thefts in the country. Two Conservative speakers on that motion took up 34 minutes before a Liberal motion to adjourn debate on the request was passed by a 6-5 vote.

Committee members then only had about 10 more minutes to ask questions of government department witnesses on C-26 before the committee adjourned for the day.

During that time, Kelly-Anne Gibson, director of CSE’s cyber protection policy division, told MPs that the CSE knows the privacy of personal and cyber threat information that firms have to provide the government if there are cyber breaches or risks is a “key consideration” for the private sector.

“Protection of confidential information underpins this legislation,” she said, “because if companies and operators don’t feel that we are going to protect information then they are not going to share it. So what you see in the legislation are specific provisions to define confidential information, protect it, and there are consequences if we or others don’t protect that confidential information.”

Federal experts have been meeting behind closed doors for years with critical infrastructure providers — who cover every sector in Canada except retail and hospitality — to improve their ability to withstand cyber attacks. However, no legislation compels them to specific action.

International legislation

As cyber attacks against hospitals, banks, utilities and other critical infrastructure providers around the world increase, some governments are starting to regulate cybersecurity in the private sector.

In 2021 — after the Colonial Pipeline ransomware attack — U.S. President Joe Biden signed a National Security Memorandum (NSM) on improving cybersecurity for critical infrastructure control systems, ordering the Department of Homeland Security’s Cybersecurity & Infrastructure Security Agency (CISA) and the Department of Commerce’s National Institute of Standards and Technology (NIST) to develop cybersecurity performance goals for critical infrastructure firms.

Then, in 2022, he signed into law the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), making designated firms report cyber incidents and ransomware payments to CISA. Final disclosure rules have to be set by September 2025.

In 2018, Australia passed the  Security of Critical Infrastructure Act. It creates a Register of Critical Infrastructure Assets, where critical infrastructure firms have to provide the government with their operational and ownership information. Firms also have to report cyber incidents that impact the delivery of essential services to the Australian Cyber Security Centre, and adopt a written risk management program.

Canada’s Bill C-26

Under Bill C-26’s proposed changes to the Telecommunications Act, carriers like Bell, Rogers, and Telus could be ordered by an Order-in-Council — that is, by the federal cabinet — to do anything necessary to secure their systems. That includes, for example, tearing out a compromised server or router known to be susceptible to a zero-day vulnerability.

The CCSPA would require designated operators — like banks and interprovincial utilities — to establish and implement cyber security programs if they haven’t already done so, mitigate supply-chain and third-party risks, report cyber security incidents to the CSE, exchange information with government agencies, and comply with cyber security directives.

Government officials said details of what companies will have to do will be fleshed out in regulations created — with private sector consultations — after the legislation passes. That would include what kinds of cybersecurity programs critical infrastructure must have, how much firms would have to tell the government about their cybersecurity programs, and how they are taking “reasonable steps” to mitigate risks of cyber attacks through third parties like partners and suppliers.

Khoury highlighted the bill’s importance during his opening remarks, noting that Bill C-26 “is a critical next step that provides the government with new tools and authorities to better bolster defences, improve security across federally regulated industry sectors, and protect Canadians and Canada’s critical infrastructure from cyber threats. This legislation would also establish a regulatory framework to strengthen cybersecurity for services and systems that are vital to national security and public safety, and give the government new authority to issue cybersecurity directives to respond to emerging cyber threats.

“At the Cyber Centre, it will facilitate the sharing of information [from designated firms] as necessary to protect critical infrastructure and investigate reported incidents, and provide mitigation advice [to the private sector]. It will also allow regulators to request advice, guidance or services from CSE by providing information about the designated operator’s cybersecurity program and mitigation of risk from the supply chain or use of third-party products and services.”

The post Government vows to address corporate privacy worries in proposed cybersecurity law first appeared on IT World Canada.

Federal government launches new platform to recruit digital talent

The government of Canada has launched the Digital Talent Platform, an online recruitment site for digital and IT professionals.

The platform simplifies the application process for individuals who specialize in digital and IT who are looking to apply for jobs within the government. It will also provide federal institutions with lists of pre-qualified individuals that match their digital talent needs.

“We are pleased to see the Government of Canada recognizes the pivotal role that tech talent plays in the delivery of modernized digital services and are actively working to improve the way it recruits and deploys digital talent across the public service,” commented Michele Lajeunesse, senior vice president of government relations and policy at Technation Canada.

This announcement comes on the heels of a series of enquiries into the government’s IT systems, with members of parliament denouncing the lack of incentives for the country’s digital talent to join government IT, which contains siloed systems and offers lower pay compared to the private sector.

These issues were further brought to light following the resignation of Canada’s chief information officer, Catherine Luelo, who, during and after her tenure, addressed the dire need for attracting digital talent to the government, but also claimed that outside consultants are as critical.

A couple of months before her resignation, she spearheaded the Digital Talent Strategy to tackle the sluggish recruitment process at the government, as well as develop and retain talent.

Yesterday, the president of the Treasury Board, Anita Anand, echoed these objectives at the 2024 Digital Government Leaders Summit.

“Canada’s public service is one of the best in the world — and we must improve the way we attract and retain new talent, especially for digital and IT,” she said. “The GC Digital Talent Platform will improve the way we recruit digital and IT professionals as we work to better deliver services to Canadians in this digital age.”

The new platform, the government says, is part of the Directive on Digital Talent which supports the development and growth of the digital community through data collection and planning for talent sourcing, management, and guidance across the government. The directive was developed in April 2023 with input from the Professional Institute of the Public Service of Canada (PIPSC), Canada’s largest union of scientists and federal workers.

“We favour any effort to leverage the skill sets of government employees and streamline the hiring process – ideally reducing the need to hire contractors while full-time permanent jobs sit vacant,” said Jennifer Carr, president, PIPSC. “This initiative has the potential to deliver on both efficiency and financial prudence, benefiting the government and Canadians alike.”

The post Federal government launches new platform to recruit digital talent first appeared on IT World Canada.