Security

Pentasecurity Presents Core Security Principles to Counter AI Attacks in the Financial Sector

TECHWORLD ·

Penta Security’s three principles of Cyber Defense [Photo: Penta Security]

✦ AI Summary

Pentasecurity on the 8th distributed a security guide for responding to a series of personal data breaches in the financial sector.

The guide presented three principles — securing visibility, multi-layered defense, and Zero Damage Design — and directions for responding to attacks using AI.

Jung Tae-jun, head of planning, said attacks using AI could expand the speed and scale of existing attacks, and stressed the complete application of basic security controls and swift checks and measures.

Recent personal data breaches have been occurring one after another in South Korea's financial sector. The industry said the backdrop is the full-scale onset of repeated attacks that abuse AI tools, and stressed that response measures are needed for such attacks.

In response, Pentasecurity on the 8th distributed a security guide for responding to a series of breaches in the financial sector. The guide presents three core security principles — securing visibility, multi-layered defense, and Zero Damage Design — and explains how to respond to attacks that use AI.

Among them, securing visibility means detecting attack traffic entering web services and responding quickly. To this end, organizations should periodically check whether protections have been applied and whether attack-detection records exist for major web services, with the goal of identifying signs of abnormal access and automated attacks.

To respond to breaches, two security principles need to be checked. One is the concept of multi-layered defense, which applies additional authentication beyond passwords to business services. This is intended to block access at the next stage even if one authentication step is breached. Accordingly, organizations should check whether there are business services to which additional authentication has not been applied and whether there are accounts exempt from authentication.

The other is the concept of Zero Damage Design, a method centered on protecting the data itself so that, even if a breach occurs, personal and sensitive information does not lead to actual damage. To this end, organizations should check the scope of encryption for critical data and the system for separating and managing encryption keys.

Jung Tae-jun, head of planning at Pentasecurity, said attacks using AI could quickly expand the speed and scale of existing attacks. He said that in a situation where breaches are spreading rapidly, the key to reducing actual damage lies in the complete application of basic security controls. He also stressed the importance of immediately checking security status and swiftly applying necessary measures.

Pentasecurity on the 6th prepared and distributed to customers and partners a configuration guide for its own solutions to counter attacks suspected of using AI agents. The guide includes major settings related to access control for automation tools and Bot, as well as measures for detecting and blocking abnormal attack traffic, and is designed to provide customers and partners with major settings and response measures to prepare for automated access and abnormal traffic.

Source: TECHWORLD · Kim Hye-jin
Original: https://www.epnc.co.kr/news/articleView.html?idxno=407945

References

This article was produced with the help of an automated content generation algorithm.


Source: TECHWORLD

View original

This article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.