A TOP Bahraini expert has called for a global watchdog to monitor the rise in cybersecurity crimes.
Such an entity will help mend the “rift” in information sharing between experts and police, explained Bahrain National Cyber Security Centre (NCSC) senior security analyst Shaikh Khalifa Khalid Al Khalifa.
Currently, while dealing with cybercrime, information is shared on two fronts – experts and police – which often don’t help in efficiently resolving the crimes, he said.
Shaikh Khalifa was speaking during a webinar on ‘Cyber Security: Present and Future’, organised by the American Chamber of Commerce in Bahrain (AmCham).
“I would very much support establishing an international body for fighting cybercrime.
“Right now, cybercrime is being fought on two fronts – on the surface level and through law enforcement.
“That creates a rift because cybersecurity experts have certain information and the police have certain information and sometimes to get the job done, you need information from both.
“Also, you have attackers using proxies to jump from country to country.
“Unless you have all that information, it’s very difficult to trace back any attack to the original source.
“What we have right now is communication channels as opposed to an international body. You have the Interpol, an international body that fights cybercrime on an international level, but I don’t think that fits the description accurately.”
The GDN reported last week that more than six million cyber threats were blocked in Bahrain during the first half of the year by the American-Japanese software company Trend Micro.
Meanwhile, Shaikh Khalifa, who has been in office since the inception of NCSC last October, noted that Microsoft Exchange vulnerabilities were on the top of the list of cybersecurity threats in the country.

Shaikh Khalifa
The vulnerability targets the authentication server of Microsoft Exchange Server 2016 and 2019 which gives access to the list of permissions to the server. This can ultimately help a hacker remotely execute commands on someone else’s computing device.
“The vulnerability gives you direct access to the inside of a network, and it contains valuable information that can be exfiltrated in the emails,” said Shaikh Khalifa.
Plans in the pipeline are awareness programmes and baseline security standards document due to be published next year in Bahrain.
“The Bahrain Development Bank in association with the Central Bank of Bahrain is doing awareness programmes for the banking system and its employees,” said Shaikh Khalifa.
“The baseline security standards document has been drafted; it’s going to be published next year.”
The document – which defines a set of basic security objectives which must be met by any given service or system – would familiarise the user with security-related situations and subsequently will enable him/her developing proactive solutions.
“The document covers a wide range of topics, including third-party security, which many people overlook.
Password
“For instance, if a vendor uses a certain password for your account in your company and that password is stolen, that person will use that vendor’s account in another company, causing a chain reaction.”
US Department of Homeland Security’s Cybersecurity Vulnerability Management, Cybersecurity and Infrastructure Security Agency senior adviser Thomas Millar recommended three “don’ts” as basic cybersecurity practices.
“Don’t use unsupported software, don’t use known default or unchangeable passwords, and don’t use single factor authentication,” he said.
Mr Millar also stressed on three things that a common user should bear in mind – strong authentication, updated software and backup.

Mr Millar
“The best number one thing that you can do to protect your personal devices is to use strong authentication, be it hardware, one-time password tools like a YubiKey, a multi-factor authentication via SMS, or preferably by an app like Microsoft or Google Authenticator.
“Update your software,” he said, saying that the red dot popping up on home screen settings can be “boring” but important.
“When the red dot pops up on settings that is basically kind of like the check engine light going off on your car.”
He said that cloud backups were good for personal devices, but ransomware could be a problem for small and medium businesses.
raji@gdn.com.bh