THANK YOU FOR SUBSCRIBING


Peter Kolarov, CEOFounded in 2015, Crayonic’s original product, the Crayonic Pen, was developed to help users e-sign documents with ease, while ensuring that their identities were verified and secured with behavioral biometrics. To achieve this, the company issues an identity certificate prior to authentication and tracks handwriting biometrics to recognise the user. Today, Crayonic is beta-testing its new flagship product, the Crayonic KeyVault, which is specially designed to deliver an easy-to-use, password-less, step-up biometric authentication solution. “In most cases, if multi-factor authentication product ensures high security, it compromises on usability, which hinders enterprises from reaping the overall benefits of their deployment,” adds Kolarov.
Keeping this in mind, Kolarov and his team have built KeyVault with a highly flexible and scalable architecture that allows it to run on a wide range of devices and operating systems. At the same time, the solution enables users to add an extra level of authentication beyond the initial static biometrics (fingerprint). This additional authentication is an on-device biometric PIN (either hand-written or spoken) enhancing standard FIDO required user verification.![]()
The Crayonic KeyVault is a decentralised identity wallet that allows users and enterprises to secure their identities, data, and high-value cloud transactions with ease and efficiency
Further discussing the flexibility of the KeyVault offering, Kolarov elaborates, “Our product not only supports all the standards for password-less authentication but also allows integration with legacy systems to aid users that are deeply-rooted in using their existing authentication infrastructure,” states Kolarov. And in cases where a user does not even have a legacy system in place, Crayonic assists them in building a security posture around FIDO protocols and provides integration support to create a final infrastructure using Crayonic Gateway that is 100 percent compatible with its KeyVault solution. Above all, the Crayonic Gateway enables additional use cases for Crayonic KeyVault such as: non-custodial digital identity and cryptocurrency wallet, eSigning documents using X509 certificates and even KeyVault recovery feature for users who have lost or damaged their KeyVaults.
One of the more interesting differentiators of the Crayonic KeyVault is its unique Proof-of-Free-Will concept, which enables the device to recognise instances where a user is authentication under duress or without intent, thereby ensuring effective security at all times for the most sensitive transactions. Concurrently, the company’s emphasis on using FIDO protocols also helps users in leveraging the KeyVault to perform high-value blockchain and cryptocurrency transactions in the Cloud without worrying about security of their private keys.
Looking ahead, the company aims to complete the beta-testing of KeyVault and Gateway and launch it by the end of 2020. To conclude, Kolarov reiterates the ethos of his company, “We want to continue building solutions that deliver high security as well as unparalleled usability and become the go-to solution provider for decentralised authentication and privacy preserving identity storage.”
Company
Crayonic
Management
Peter Kolarov, CEO
Description
Founded in 2015, Crayonic’s original product, the Crayonic Pen, was developed to help users e-sign documents with ease, while ensuring that their identities were verified and secured with behavioral biometrics. To achieve this, the company issues an identity certificate prior to authentication and tracks handwriting biometrics to recognise the user. Today, Crayonic is beta-testing its new flagship product, the Crayonic KeyVault, which is specially designed to deliver an easy-to-use, password-less, step-up biometric authentication solution
CrayonicEvery year, the healthcare industry grapples with substantial financial losses amounting to tens of billions of USD due to data breaches (source), underscoring the widespread influence of digital transformation in healthcare institutions. Despite this, cybersecurity investment and focus within the entire sector remain disproportionately low. Alarmingly, in some hospitals, IT security is entrusted to the most 'technically proficient' doctor rather than a dedicated professional. While managing IT and cybersecurity may not require a “brain surgeon,” the complexity and critical nature of safeguarding digital patient records in environments with dozens of PCs, local networks, and a growing number of interconnected healthcare IoT devices cannot be underestimated. As the scale of IT infrastructure expands, the need for specialized internal or outsourced IT security experts becomes not just a recommendation, but a critical investment. Before delving into the technology and budget allocations necessary to fortify these institutions, it's crucial to understand the multifaceted threats and risks today's hospitals face.
As a hospital CEO, your top priority is ensuring seamless patient care every day, making sure your hospital operates smoothly. Now, picture being jolted awake early Saturday morning by a frantic call from the head nurse. Every patient record is inaccessible, all computers display a threatening ransom message, the state-of-the-art MRI machine is offline, ultrasounds are inoperable, and the chaos extends beyond. This isn't just a bad start to the weekend; it's a calculated assault by a formidable adversary – let's call them HACKS-R-US. Operating without a recognizable brand, HACKS-R-US boasts revenues and an infrastructure rivaling many publicly traded corporations, complete with round-the-clock support and marketing, offering paid cloud solutions such as Phishing-as-a-Service. Unfortunately, your hospital's defenses, given the current cybersecurity measures, stood little chance against the cyber-attack that has now crippled your operations. Let's unpack how this happened and why:
In the days leading up to the crisis, your hospital was marked as a prime target for a ransomware attack through a phishing scheme. The attackers discovered that you were utilizing Microsoft Office 365 without the robust protection of phishing-resistant multifactor authentication. Armed with this knowledge, they crafted a seemingly authentic email tailored to the language and visual style familiar to your staff, using AI to refine the content. The final manual task for the attackers was gathering your employees' names using social media, setting the stage for the next phase of the attack.
Utilizing a Phishing-as-a-Service platform from HACKS-R-US, they launched a widespread campaign against your employees. This platform isn't exclusive to seasoned criminals; even an inexperienced individual, motivated by quick profit, could orchestrate this level of attack. The crafted phishing emails were dispatched en masse from a familiar-looking domain name, deceitfully urging your staff to urgently update their credentials. Predictably, the campaign succeeded, and the attackers harvested a multitude of credentials, providing broad access to employee mailboxes and even to electronic health records of your cloud EHR.
The immediate financial gain for the attackers lay in the patient records, each valued well over 100 Euros on the dark web, with VIP records fetching even higher sums. Yet, the broader aim was more insidious: gaining control of the hospital's domain controller - Active Directory (AD) server. With a bit of patience and tools rented from HACKS-R-US, they eventually breached your domain controller. Complicating matters, your backup system, likely connected to your AD domain with good intentions exposed your backups to the attacker as well. The attackers then deployed the rented ransomware, methodically encrypting your hospital's infrastructure under AD control, starting with your backups. By Saturday morning, not only had all your data been stolen, but it was also encrypted, with the attackers demanding a ransom of 500k Euro in Bitcoin for the decryption key. The only glimmer of hope lies in the existence of offline backups from the previous month. However, this raises a critical question: when did your stretched-thin IT department last conduct a drill to restore the network-connected filesystem or the comprehensive patient record databases? The answer to this could mean the difference between a swift recovery and a prolonged nightmare.
If yours is an average hospital the damages caused by this attack will climb to millions of Euro, including payment for ransom, recovery services, lost revenue, possibly even fines and legal fees (source).
Why was this attack successful, and could it have been prevented?
At its core, the attack's success hinged on the effective use of social engineering, a technique that exploits human psychology and senses rather than technical hacking. This method is particularly potent in high-pressure environments like hospitals, where busy and stressed personnel are more likely to overlook suspicious details.
Educating employees about the nuances of phishing and other social engineering tactics is a vital line of defense. While no single measure is foolproof, awareness significantly reduces the risk of successful attacks. Therefore, allocating resources for comprehensive training should be a non-negotiable part of your 2024 IT budget.
However, education alone isn't nearly enough. The sophistication of phishing attacks means that technical safeguards are even more critical in healthcare environments. Implementing phishing-resistant multifactor authentication (MFA) across all hospital systems is not just a recommendation; it's an absolute necessity. While the top multifactor authentication (MFA) solutions on the market come with a significant price tag, it's important to consider that this attack, much like 80% of all data breaches, began with an attacker simply logging into your network (source). Given this stark reality, skimping on MFA in your budget is a false economy. Good MFA, coupled with an enterprise antivirus SW providing robust filtering of dangerous links and email attachments, forms a formidable barrier against launching an attack on your hospital infrastructure.
Existing measures like backups, firewalls, and VPNs are foundational but require continuous upgrades to match evolving threats. More importantly, the configurations of Read More