About Me – Cybersecurity Consultant

Hello! I’m Anub Srivastava, a passionate and experienced Cybersecurity Professional dedicated to guiding organizations in protecting their digital assets, identifying and mitigating risks, and staying resilient against evolving cyber threats. With over 15 years of experience across various roles in IT and cybersecurity, I specialize in both the technical and strategic aspects of cybersecurity, working closely with teams to design, implement, and optimize security solutions tailored to each organization’s unique needs.

My journey began in the IT industry as a Network Engineer, and over the years, I’ve held several key roles, including AnalystNetwork and Security Engineer, Information Security Consultant, and Cybersecurity Engineer. I’ve developed expertise across various cybersecurity domains, including Security Operations, Vulnerability Management, Cyber Threat Intelligence, Risk Management, and Compliance. I have extensive experience working with cybersecurity frameworks that align with industry best practices and regulatory requirements.

Whether you're aiming to strengthen your defenses, ensure compliance with data protection regulations, or respond to a cyber incident, I offer practical, real-world solutions that empower you to safeguard your organization's critical assets and ensure long-term security. Let’s collaborate to build a resilient and secure future for your business.


What is CyberSecurity ?

#Cyberintel.com.au

Cybersecurity is a collection of practices and measures designed to protect systems, networks, and data from digital threats, attacks, and unauthorized access. It involves the implementation of technologies, processes, and strategies to safeguard information and ensure the confidentiality, integrity, and availability of digital assets.

We need cybersecurity to protect our digital systems, data, and networks from a wide range of cyber threats. As more of our personal, business, and government activities move online, the risks of cyberattacks increase. Cybersecurity helps to:

  1. Protect Sensitive Information: It safeguards personal data, financial records, and business secrets from theft, ensuring privacy and preventing identity theft.

  2. Prevent Cyberattacks: Cybersecurity defends against malicious activities such as hacking, ransomware, and phishing attacks that can damage systems and disrupt services.

  3. Ensure Business Continuity: By securing networks and data, cybersecurity helps maintain the integrity and availability of critical systems, ensuring that businesses and organizations can operate smoothly without downtime caused by cyber incidents.

  4. Preserve Trust: Strong cybersecurity measures build trust among customers, clients, and partners, assuring them that their data and transactions are secure.

  5. Comply with Legal and Regulatory Requirements: Many industries are subject to laws and regulations that mandate the protection of sensitive data. Cybersecurity ensures compliance and avoids legal consequences.

  6. Protect Critical Infrastructure: Key sectors such as healthcare, energy, and finance rely on secure digital systems. Cybersecurity is essential for protecting these vital infrastructures from threats that could have wide-reaching impacts.

In summary, cybersecurity is crucial for safeguarding privacy, maintaining operational stability, and reducing the risks posed by cyber threats in an increasingly connected world.

Financial institutions in Australia face a range of cybersecurity compliance

#Cyberintel.com.au

1. APRA CPS 234 – Information Security

  • Overview: The Australian Prudential Regulation Authority (APRA) enforces CPS 234, which mandates that regulated financial institutions must implement a robust and comprehensive information security framework.

  • Key Requirements:

  • Financial institutions must develop, maintain, and implement an information security capability to manage risks that are commensurate with the size, business activities, and risks of the institution.

  • Senior management is accountable for the cybersecurity posture of the institution, ensuring resources and actions are aligned to mitigate cybersecurity risks.

  • Institutions are required to notify APRA of any material cybersecurity incidents (including breaches and attacks) that may affect the financial system's stability or the organization's operations.

  • Regular testing of cybersecurity measures and continual improvement based on risk assessments.

  • Relevance: This is a mandatory regulation for all APRA-regulated entities, including banks, insurers, superannuation funds, and other financial institutions.

2. The Privacy Act 1988 and Australian Privacy Principles (APPs)

  • Overview: The Privacy Act 1988 regulates how personal information is collected, used, and protected by businesses, including financial institutions. The Act’s Australian Privacy Principles (APPs) specifically govern the handling of personal data.

  • Key Requirements:

  • Financial institutions must ensure the secure collection, storage, and transfer of personal information.

  • They must implement reasonable security measures to protect personal data from unauthorized access, disclosure, or loss.

  • The Notifiable Data Breaches (NDB) Scheme requires organizations to notify affected individuals and the Office of the Australian Information Commissioner (OAIC) if a data breach occurs that is likely to result in serious harm to individuals.

  • Relevance: The Privacy Act applies to most financial institutions with an annual turnover of over $3 million, and non-compliance can lead to significant penalties.

3. Security of Critical Infrastructure Act 2021

  • Overview: This legislation aims to enhance the cybersecurity resilience of critical infrastructure, including financial institutions. The Security of Critical Infrastructure (SOCI) Act specifically applies to sectors deemed critical to the national economy and security, such as finance.

  • Key Requirements:

  • Financial institutions that are considered "critical infrastructure" (e.g., large banks) must implement risk management programs to address cybersecurity threats.

  • There are requirements to report significant cyber incidents to the government.

  • Institutions must maintain a minimum level of cybersecurity preparedness and resilience, particularly for systems deemed critical to the economy and national security.

  • Relevance: Financial institutions classified as critical infrastructure must adhere to these regulations, including large banks and entities involved in essential payment systems or infrastructure.

4. Australian Cybersecurity Strategy 2020

  • Overview: The Australian Cybersecurity Strategy 2020 outlines the government’s approach to improving Australia’s cybersecurity resilience, including for financial institutions.

  • Key Requirements:

  • Encourages financial institutions to adopt strong cybersecurity practices.

  • Promotes cooperation between the public and private sectors to combat cyber threats.

  • The strategy emphasizes the importance of resilience for Australian financial markets and payment systems.

  • Relevance: While not a direct regulatory requirement, the strategy provides a framework and incentivizes financial institutions to improve cybersecurity practices.

5. ISO/IEC 27001 – Information Security Management System (ISMS)

  • Overview: ISO/IEC 27001 is an international standard for managing the security of information assets. Many financial institutions implement ISO 27001 as part of their cybersecurity strategy to meet global standards.

  • Key Requirements:

  • Establishing an Information Security Management System (ISMS) that includes policies, controls, risk assessments, and monitoring procedures.

  • Regular audits and continuous improvement of the ISMS to ensure it remains effective.

  • Ensuring that sensitive financial data is securely handled and protected across all systems.

  • Relevance: ISO 27001 certification is not mandatory, but it is a widely recognized best practice and can help financial institutions demonstrate their commitment to robust information security management.

6. Payment Card Industry Data Security Standard (PCI DSS)

  • Overview: PCI DSS is a set of security standards designed to ensure that companies that handle credit card information do so in a secure environment. This standard applies to financial institutions involved in processing, storing, or transmitting payment card data.

  • Key Requirements:

  • Protect cardholder data through encryption, tokenization, and other security controls.

  • Implement access controls to limit who can view or manage cardholder data.

  • Regularly test security systems, including conducting vulnerability assessments and penetration testing.

  • Relevance: PCI DSS is mandatory for all organizations (including financial institutions) that process or handle payment card information.

7. Australian Government Information Security Manual (ISM)

  • Overview: The Information Security Manual (ISM), published by the Australian Cyber Security Centre (ACSC), provides guidelines for securing information and systems within government agencies, contractors, and critical infrastructure.

  • Key Requirements:

  • While originally aimed at government agencies, many financial institutions choose to adopt the ISM’s best practices to align with the security standards expected of public sector entities.

  • The ISM includes specific cybersecurity controls around risk management, access control, monitoring, data protection, and incident response.

  • Relevance: Although it is not legally binding for the private sector, many financial institutions adopt the ISM as part of their risk management strategy and cybersecurity frameworks, especially if they provide services to the government.

8. Financial Services Cybersecurity Framework

  • Overview: Australia’s financial services industry has been subject to increasing cybersecurity guidance from industry bodies and regulators to strengthen overall system resilience.

  • Key Requirements:

  • Financial institutions are encouraged to adhere to cybersecurity principles that align with APRA’s CPS 234, including robust risk management, cybersecurity training, and incident response protocols.

  • Some regulatory bodies, like the Australian Securities and Investments Commission (ASIC), offer additional guidance on how financial institutions should manage cyber risks to maintain market confidence and protect consumers.

  • Relevance: Adherence to industry standards and frameworks is crucial for financial institutions to maintain trust, comply with regulatory expectations, and protect sensitive financial data.

9. Australian Prudential Regulation Authority (APRA) Prudential Standards

  • Overview: In addition to CPS 234, APRA also regulates other aspects of cybersecurity through its prudential standards, including CPS 231 (Outsourcing) and CPS 232 (Business Continuity).

  • Key Requirements:

  • Financial institutions must ensure that third-party service providers (including cloud providers) meet cybersecurity requirements, as defined in CPS 231.

  • CPS 232 outlines the requirement for business continuity planning, which includes preparedness for cyber incidents.

  • Relevance: These standards apply to all APRA-regulated financial institutions and require them to address cybersecurity in the context of outsourcing and operational resilience.

10. Australian Financial Services License (AFSL) Requirements

  • Overview: Financial institutions holding an Australian Financial Services License (AFSL) are required to comply with a range of obligations that include data protection, security, and risk management, which indirectly address cybersecurity.

  • Key Requirements:

  • AFSL holders must implement adequate safeguards to protect client data and prevent cyber incidents that could affect financial transactions or services.

  • Relevance: Compliance with AFSL obligations is mandatory for any financial institution offering financial services in Australia.

Conclusion

Financial institutions in Australia are required to comply with various cybersecurity standards and regulations to safeguard customer data, maintain operational resilience, and ensure the stability of the financial system. The key compliance requirements include APRA CPS 234, ISO 27001, the Privacy Act 1988, PCI DSS, and specific regulations related to critical infrastructure, financial services frameworks, and government security guidelines.

Adhering to these regulations is essential for mitigating risks, maintaining customer trust, and ensuring regulatory compliance. Financial institutions should also continuously monitor the evolving threat landscape and regulatory environment to stay ahead of emerging risks and cybersecurity challenges.

EDR, MDR, and XDR: What They Are and Their Purpose

#Cyberintel.com.au

These terms represent different approaches and tools in cybersecurity aimed at detecting, preventing, and responding to threats. Here’s a breakdown of each:

1. EDR (Endpoint Detection and Response)

Definition:

EDR focuses on monitoring, detecting, and responding to threats at the endpoint level, such as laptops, desktops, and servers. It provides visibility into endpoint activities and uses behavioral analysis to identify threats.

Key Features:

·       Real-time monitoring and data collection from endpoints.

·       Threat detection using behavioral analytics and rules.

·       Incident response tools for investigation and remediation.

·       Integration with broader security ecosystems.

Purpose:

To detect and respond to threats that bypass traditional endpoint protection measures (like antivirus), ensuring individual endpoints are secure against advanced threats.

Use Case:

An organization uses EDR to detect malware on a specific workstation and isolate it from the network to prevent lateral movement.

2. MDR (Managed Detection and Response)

Definition:

MDR is a managed service offering that combines technology (like EDR tools) with human expertise. It provides organizations with 24/7 monitoring, threat hunting, and incident response services.

Key Features:

·       Fully managed threat detection and response services.

·       Human analysis and expert intervention in threat management.

·       Regular reporting and proactive threat hunting.

·       Can integrate with EDR, SIEM (Security Information and Event Management), or other tools.

Purpose:

To provide smaller organizations or those without in-house security expertise access to advanced threat detection and response capabilities without managing it themselves.

Use Case:

A company outsources its cybersecurity operations to an MDR provider, which monitors and responds to threats, ensuring round-the-clock protection.

3. XDR (Extended Detection and Response)

Definition:

XDR extends the concept of EDR by integrating data across multiple security layers (endpoints, networks, emails, servers, and more) to provide a unified approach to detection, investigation, and response.

Key Features:

·       Aggregation and correlation of data from multiple security domains.

·       Automated threat detection and incident response workflows.

·       Enhanced visibility across the entire IT environment.

·       Integration with multiple security tools like firewalls, email gateways, and SIEMs.

Purpose:

To provide a more holistic view of the organization's security posture and detect sophisticated attacks that span multiple layers.

Use Case:

An organization uses XDR to correlate suspicious behavior detected on endpoints, unusual network traffic, and phishing attempts to identify a coordinated attack.


The Essential 8 VS NIST Cybersecurity Framework 

#Cyberintel.com.au

The Essential 8 and the NIST Cybersecurity Framework are both widely recognized cybersecurity frameworks, but they differ in their scope, focus, and application. Below is a comparison that outlines the key differences between the two:

1. Origin and Purpose

  • Essential 8:

  • Origin: Developed by the Australian Cyber Security Centre (ACSC).

  • Purpose: The Essential 8 is a set of eight baseline security controls designed to mitigate the most common and prevalent cyber threats, particularly those targeted at organizations' networks and systems. It is primarily aimed at improving cybersecurity hygiene by reducing risks and preventing attacks like ransomware, phishing, and other cyber intrusions.

  • Target Audience: It is generally targeted at organizations of all sizes, but with a particular focus on those in Australia or those wanting to adopt a practical and straightforward cybersecurity framework.

  • NIST Cybersecurity Framework:

  • Origin: Created by the National Institute of Standards and Technology (NIST) in the U.S., specifically through NIST Special Publication 800-53 and NIST Cybersecurity Framework (CSF).

  • Purpose: The NIST Cybersecurity Framework is a comprehensive, flexible, and risk-based framework designed to help organizations of all sizes and sectors manage cybersecurity risks. It provides guidance on identifying, protecting, detecting, responding to, and recovering from cybersecurity events, while also aligning with risk management and business continuity goals.

  • Target Audience: Primarily aimed at U.S. organizations, but it is widely applicable internationally. It can be adapted for both large and small organizations, across all industries, including government, finance, healthcare, and more.

2. Structure and Components

  • Essential 8:

  • Core Concept: The Essential 8 focuses on 8 key security controls that provide foundational protection against common cyber threats. It is very prescriptive and is designed to be implemented quickly and effectively, especially for organizations with limited resources.

  • Components:

  • Application Whitelisting

  • Patch Applications

  • Configure Microsoft Office Macro Settings

  • User Application Hardening

  • Restrict Administrative Privileges

  • Patch Operating Systems

  • Multi-Factor Authentication (MFA)

  • Daily Backup of Important Data

These eight controls are designed to address the most critical and frequently exploited vulnerabilities and reduce the risk of common attack vectors.

  • NIST Cybersecurity Framework (CSF):

  • Core Concept: The NIST Cybersecurity Framework is more comprehensive and consists of five core functions: Identify, Protect, Detect, Respond, and Recover. Each of these functions is further broken down into categories and subcategories, which are more detailed and flexible compared to the Essential 8. The NIST framework provides high-level guidance and allows organizations to customize its implementation based on their specific needs, risk profile, and maturity level.

  • Components:

  • Identify: Asset management, governance, risk assessment.

  • Protect: Access control, awareness training, data security, maintenance.

  • Detect: Continuous monitoring, detection processes.

  • Respond: Response planning, communications, analysis.

  • Recover: Recovery planning, improvements, communications.

The NIST framework is structured to align with organizational goals, risk management strategies, and legal and regulatory compliance.

3. Scope and Flexibility

  • Essential 8:

  • Scope: The Essential 8 is narrower in scope and focuses primarily on basic cybersecurity controls to mitigate common threats, especially for small and medium-sized organizations that may not have extensive cybersecurity resources.

  • Flexibility: It is less flexible compared to the NIST Cybersecurity Framework. Organizations are expected to implement the full set of controls as per the recommended practices. However, organizations can prioritize certain controls depending on their specific risk environment.

  • NIST Cybersecurity Framework (CSF):

  • Scope: The NIST CSF provides broader guidance on cybersecurity risk management. It encompasses not just technical controls, but also governance, risk assessment, and operational aspects of cybersecurity.

  • Flexibility: The NIST CSF is highly flexible and can be tailored to the organization’s size, complexity, and risk tolerance. Organizations are encouraged to use the framework iteratively and can select the appropriate controls based on their specific needs.

4. Level of Detail

  • Essential 8:

  • The Essential 8 provides specific actions and best practices aimed at mitigating particular risks. It is a straightforward framework that can be adopted without extensive customization. The focus is on practical, actionable steps to prevent common cyber incidents.

  • Example: “Apply patches to operating systems and applications within 48 hours of the release of the patch.”

  • NIST Cybersecurity Framework (CSF):

  • The NIST CSF is more conceptual and strategic. It offers high-level guidance and can be applied in a more adaptive manner depending on the organization's environment. It doesn't prescribe specific technical actions but provides categories and subcategories that organizations can customize.

  • Example: “Implement procedures for the detection of anomalies and events that could indicate a cybersecurity incident.”

5. Implementation and Adoption

  • Essential 8:

  • The Essential 8 is designed to be easier and faster to implement, particularly for organizations that may not have a dedicated, mature cybersecurity function. It is considered a baseline for cybersecurity best practices, with a focus on addressing the most immediate threats.

  • It is often used by organizations looking to rapidly improve their cybersecurity posture with limited resources.

  • NIST Cybersecurity Framework (CSF):

  • The NIST CSF is typically adopted by larger organizations or those with more advanced cybersecurity needs. Its broader scope means that it may take more time and resources to fully implement. The framework is often used as a long-term strategic guide for building a resilient cybersecurity program and is flexible enough to accommodate various organizational contexts, including risk tolerance and regulatory requirements.

6. Industry and Regulatory Focus

  • Essential 8:

  • While the Essential 8 was developed by the ACSC in Australia, it has become widely adopted not only by Australian organizations but also by companies globally that want a practical, prescriptive approach to cybersecurity. It is particularly helpful for industries that face common cyber threats like ransomware and phishing.

  • The Essential 8 is often viewed as a practical baseline that complements other frameworks.

  • NIST Cybersecurity Framework (CSF):

  • The NIST CSF is specifically designed with U.S. organizations in mind but is widely recognized and used internationally. The framework aligns with U.S. government regulations, such as the Federal Information Security Modernization Act (FISMA) and NIST SP 800-53. The NIST CSF is also highly applicable in regulated industries like finance, healthcare, and critical infrastructure, where compliance and risk management are key concerns.