Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Advertising and Sponsorship
    • Profile & Readership
    • Contact Us
    • Latest News
    • Privacy & Cookies Policies
    • Terms of Use
    • Advertising Terms
    • Issue 81
    • Issue 80
    • Issue 79
    • Issue 78
    • Issue 77
    • Issue 76
    • Issue 75
    • Issue 74
    • Issue 73
    • Issue 72
    • Issue 71
    • Issue 70
    • View All
    • About the Awards
    • Awards Timetable
    • Awards Winners
    • Submit Nominations
    • Testimonials
    • Media Room
    • FAQ
    • Asset Management Awards
    • Brand of the Year Awards
    • Business Awards
    • Cash Management Banking Awards
    • Banking Technology Awards
    • CEO Awards
    • Customer Service Awards
    • CSR Awards
    • Deal of the Year Awards
    • Corporate Governance Awards
    • Corporate Banking Awards
    • Digital Transformation Awards
    • Fintech Awards
    • Education & Training Awards
    • ESG & Sustainability Awards
    • ESG Awards
    • Forex Banking Awards
    • Innovation Awards
    • Insurance & Takaful Awards
    • Investment Banking Awards
    • Investor Relations Awards
    • Leadership Awards
    • Islamic Banking Awards
    • Real Estate Awards
    • Project Finance Awards
    • Process & Product Awards
    • Telecommunication Awards
    • HR & Recruitment Awards
    • Trade Finance Awards
    • The Next 100 Global Awards
    • Wealth Management Awards
    • Travel Awards
    • Years of Excellence Awards
    • Publishing Principles
    • Ownership & Funding
    • Corrections Policy
    • Editorial Code of Ethics
    • Diversity & Inclusion Policy
    • Fact Checking Policy
    Original content: Global Banking and Finance Review - https://www.globalbankingandfinance.com

    A global financial intelligence and recognition platform delivering authoritative insights, data-driven analysis, and institutional benchmarking across Banking, Capital Markets, Investment, Technology, and Financial Infrastructure.

    Copyright © 2010-2026 - All Rights Reserved. | Sitemap | Tags

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    1. Home
    2. >Technology
    3. >Why are the Hackers Targeting Certificate Authorities and what can you do about it?
    Technology

    Why Are the Hackers Targeting Certificate Authorities and What Can You Do About It?

    Published by Gbaf News

    Posted on February 14, 2012

    12 min read

    Last updated: January 22, 2026

    Add as preferred source on Google
    An image capturing the UK Parliament's debate on proposed changes to the assisted dying law, reflecting ongoing discussions about terminally ill patients' rights. This legislative shift aims to enhance the process of assisted dying in the UK.
    Illustration of UK Parliament discussing assisted dying law changes - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    As we venture into the brave new world that is 2012, many are looking for where the biggest opportunities for hackers will lie. We all know history has a habit of repeating itself so, with the sweet smell of success still in their nostrils, it is a fair assumption that the black hats will stick to what they’ve proven works. What we need to do is change what we’re doing to stop them. Calum MacLeod, EMEA Director, Venafi, examines 2011’s most disturbing IT security development, how certificate authority (CA) third-party trust providers have become the hacker target of choice. He details how it’s happened and what we have to do to ensure we keep the bad guys out.calum

    Probably the most disturbing data breaches of 2011 saw security companies themselves come under determined and sustained attacks. RSA and DigiNotar all fell victim to hackers, sending shockwaves through the security community. And only weeks into the new year we have had the belated announcement that VeriSign – another trusted third-party certificate authority – has been hacked and data breached.  These organisations know that they are high-value targets and take extraordinary measures to protect themselves, and yet they are still successfully attacked and breached despite these best efforts.

     If companies that pride themselves on providing the most advanced and sophisticated network security solutions can’t protect themselves, how can we they look after us? DigiNotar was so seriously damaged that it went out of business—an unprecedented event in the IT security industry.

    The news that VeriSign was compromised should not be a surprise to anyone. Hackers have been targeting and breaching high-value targets like RSA, Comodo, DigiNotar, and now add to the list, VeriSign. These targets are all trusted third-party providers of certificates, services, or secure tokens—technologies that are extensively used to authenticate and create trusted relationships on the internet and within organizations worldwide. The inescapable conclusion is that these providers will continue to be compromised. The breaches cannot be stopped.  What we have to do is learn how to anticipate these criminal attacks and prevent them.”

    A Lucky Strike?
    The devastating attack on DigiNotar is testament to the insecurity of certificates. In a not too dissimilar fiasco, hackers broke into DigiNotar’s systems and created forged digital certificates in the names of Google and other high-profile targets. The task of cleaning up after this attack was crushingly difficult.
    Security experts maintain that cleaning up fraudulently obtained certificates only deals with known attacks. What about other fraudulent certificates that may have slipped by unnoticed? How can organisations be sure others aren’t issued in the future?

    If a CA is compromised or an encryption algorithm is broken, organisations must be prepared to replace all of their certificates and keys in a matter of hours.
    The problem is this: few organisations have an automated management platform that gives them the power to replace compromised certificates quickly. Instead, replacing known and compromised certificates is largely a manual effort. Organisations are forced to continue operations in a compromised condition—possibly for many months—while they manually replace thousands of compromised certificates. In some cases, continuing operations may not even be an option and entire systems may have to be shut down until the organisations can remediate the problem. And this will only work for certificates they know about in their environments. What about the certificates and keys on the network that know one know about and that are not being tracked, even if only via manual processes. In the meantime, they are vulnerable to further attacks.

    What Must Be Done?
    The first step organisations must take to protect themselves is to encrypt everything—yes, all of it.
    As most companies already encrypt the data they consider most critical, they simply need to expand the protective umbrella of encryption to cover all data, wherever it moves or resides. For instance:

    • Organisations should leverage symmetric keys to encrypt stored data on all systems, including server and end-user platforms and remote storage devices.
    • Organisations should use digital certificates and asymmetric and Secure Shell (SSH) encryption keys to encrypt all data flowing between users and applications, as well as data moving between applications. This latter type of communication has become increasingly important in the last few years as cloud computing has turned up the volume on server-to-server transmissions, authentication and processing.
    • IT security professionals must attend to resources that reside in public clouds, which require the security of encryption as much as—or even more than—do internal systems. Given their clear benefits, cloud services have attracted significant attention from both security professionals and criminal organisations, and will continue to command attention as more valuable data moves in their direction.

    It doesn’t end here. Organisations’ next step is to protect themselves by managing all their encryption assets—particularly encryption keys. Too many make the mistake of relying solely on encryption to protect them, but fail to protect the encryption keys.

    Although people regularly crack encryption algorithms at security conferences to earn the accolades of their peers, rarely do people seek exposure this way in the real world. Still, while encryption generally stymies cracking efforts, what was once sacrosanct is now yesterday’s lunch to hackers (think RSA SecureID tokens).

    When data is protected by securing it with an encryption key, the key becomes the data. Thus it is now the key that must be protected. If the key is not well managed, the risk of data loss or theft increases significantly. Using an analogy from the physical world, increasing the size of the lock on your door or business may make you feel more secure, but if you leave the key to the lock under the mat, it doesn’t matter how large or strong the lock is, it can easily be opened.

    Enterprises need to move past the realisation that no CA is infallible and begin to formulate their own compromise-recovery and business-continuity plans.
    To protect their encryption keys, and therefore limit access to, and ensure the security of, sensitive data and critical company information, organisations must take the initiative to implement the following best practices:

    • Minimise encryption keys’ exposure at all points in their lifecycles—from enrollment (in the case of certificates’ private keys) to deployment to ongoing management.
    • Implement strict controls that provide audit trails for access to encryption keys.
    • Use different passwords to secure different keystores, and rotate these passwords.

    In an environment where future CA compromises—and the inability to trust the certificates CAs issue—are foregone conclusions, organisations must encrypt more data and protect their encryption keys with locked-down security policies. Only through rigorously adhering to best practices, implementing a full encryption policy and automating certificate discovery and renewal can they truly say they have done this.

             www.venafi.com
    Calum MacLeod has over 30 years of expertise in secure networking technologies, and is currently EMEA Director for Venafi a  Digital certificate and encryption key management specialists..
     
    Before joining Venafi he worked for  Tufin and then Cyber-Ark all companies that stop data leakage and hacking! MacLeod has also served as an independent consultant to corporate and government clients on IT security strategy for various European market segments, including the European Commission.
     

    As we venture into the brave new world that is 2012, many are looking for where the biggest opportunities for hackers will lie. We all know history has a habit of repeating itself so, with the sweet smell of success still in their nostrils, it is a fair assumption that the black hats will stick to what they’ve proven works. What we need to do is change what we’re doing to stop them. Calum MacLeod, EMEA Director, Venafi, examines 2011’s most disturbing IT security development, how certificate authority (CA) third-party trust providers have become the hacker target of choice. He details how it’s happened and what we have to do to ensure we keep the bad guys out.calum

    Probably the most disturbing data breaches of 2011 saw security companies themselves come under determined and sustained attacks. RSA and DigiNotar all fell victim to hackers, sending shockwaves through the security community. And only weeks into the new year we have had the belated announcement that VeriSign – another trusted third-party certificate authority – has been hacked and data breached.  These organisations know that they are high-value targets and take extraordinary measures to protect themselves, and yet they are still successfully attacked and breached despite these best efforts.

     If companies that pride themselves on providing the most advanced and sophisticated network security solutions can’t protect themselves, how can we they look after us? DigiNotar was so seriously damaged that it went out of business—an unprecedented event in the IT security industry.

    The news that VeriSign was compromised should not be a surprise to anyone. Hackers have been targeting and breaching high-value targets like RSA, Comodo, DigiNotar, and now add to the list, VeriSign. These targets are all trusted third-party providers of certificates, services, or secure tokens—technologies that are extensively used to authenticate and create trusted relationships on the internet and within organizations worldwide. The inescapable conclusion is that these providers will continue to be compromised. The breaches cannot be stopped.  What we have to do is learn how to anticipate these criminal attacks and prevent them.”

    A Lucky Strike?
    The devastating attack on DigiNotar is testament to the insecurity of certificates. In a not too dissimilar fiasco, hackers broke into DigiNotar’s systems and created forged digital certificates in the names of Google and other high-profile targets. The task of cleaning up after this attack was crushingly difficult.
    Security experts maintain that cleaning up fraudulently obtained certificates only deals with known attacks. What about other fraudulent certificates that may have slipped by unnoticed? How can organisations be sure others aren’t issued in the future?

    If a CA is compromised or an encryption algorithm is broken, organisations must be prepared to replace all of their certificates and keys in a matter of hours.
    The problem is this: few organisations have an automated management platform that gives them the power to replace compromised certificates quickly. Instead, replacing known and compromised certificates is largely a manual effort. Organisations are forced to continue operations in a compromised condition—possibly for many months—while they manually replace thousands of compromised certificates. In some cases, continuing operations may not even be an option and entire systems may have to be shut down until the organisations can remediate the problem. And this will only work for certificates they know about in their environments. What about the certificates and keys on the network that know one know about and that are not being tracked, even if only via manual processes. In the meantime, they are vulnerable to further attacks.

    What Must Be Done?
    The first step organisations must take to protect themselves is to encrypt everything—yes, all of it.
    As most companies already encrypt the data they consider most critical, they simply need to expand the protective umbrella of encryption to cover all data, wherever it moves or resides. For instance:

    • Organisations should leverage symmetric keys to encrypt stored data on all systems, including server and end-user platforms and remote storage devices.
    • Organisations should use digital certificates and asymmetric and Secure Shell (SSH) encryption keys to encrypt all data flowing between users and applications, as well as data moving between applications. This latter type of communication has become increasingly important in the last few years as cloud computing has turned up the volume on server-to-server transmissions, authentication and processing.
    • IT security professionals must attend to resources that reside in public clouds, which require the security of encryption as much as—or even more than—do internal systems. Given their clear benefits, cloud services have attracted significant attention from both security professionals and criminal organisations, and will continue to command attention as more valuable data moves in their direction.

    It doesn’t end here. Organisations’ next step is to protect themselves by managing all their encryption assets—particularly encryption keys. Too many make the mistake of relying solely on encryption to protect them, but fail to protect the encryption keys.

    Although people regularly crack encryption algorithms at security conferences to earn the accolades of their peers, rarely do people seek exposure this way in the real world. Still, while encryption generally stymies cracking efforts, what was once sacrosanct is now yesterday’s lunch to hackers (think RSA SecureID tokens).

    When data is protected by securing it with an encryption key, the key becomes the data. Thus it is now the key that must be protected. If the key is not well managed, the risk of data loss or theft increases significantly. Using an analogy from the physical world, increasing the size of the lock on your door or business may make you feel more secure, but if you leave the key to the lock under the mat, it doesn’t matter how large or strong the lock is, it can easily be opened.

    Enterprises need to move past the realisation that no CA is infallible and begin to formulate their own compromise-recovery and business-continuity plans.
    To protect their encryption keys, and therefore limit access to, and ensure the security of, sensitive data and critical company information, organisations must take the initiative to implement the following best practices:

    • Minimise encryption keys’ exposure at all points in their lifecycles—from enrollment (in the case of certificates’ private keys) to deployment to ongoing management.
    • Implement strict controls that provide audit trails for access to encryption keys.
    • Use different passwords to secure different keystores, and rotate these passwords.

    In an environment where future CA compromises—and the inability to trust the certificates CAs issue—are foregone conclusions, organisations must encrypt more data and protect their encryption keys with locked-down security policies. Only through rigorously adhering to best practices, implementing a full encryption policy and automating certificate discovery and renewal can they truly say they have done this.

             www.venafi.com
    Calum MacLeod has over 30 years of expertise in secure networking technologies, and is currently EMEA Director for Venafi a  Digital certificate and encryption key management specialists..
     
    Before joining Venafi he worked for  Tufin and then Cyber-Ark all companies that stop data leakage and hacking! MacLeod has also served as an independent consultant to corporate and government clients on IT security strategy for various European market segments, including the European Commission.
     

    More from Technology

    Explore more articles in the Technology category

    Image for Innovation Through Partnership: The Role of External Tech Teams
    Innovation Through Partnership: The Role of External Tech Teams
    Image for Nominations Open for Technology Awards 2026
    Nominations Open for Technology Awards 2026
    Image for Nominations Open for Innovation Awards 2026
    Nominations Open for Innovation Awards 2026
    Image for Archie earns industry recognition across G2, Capterra, and SoftwareReviews
    Archie Earns Industry Recognition Across G2, Capterra, and SoftwareReviews
    Image for The Bankaool Transformation: How a Regional Mexican Bank Became a Fintech Disruptor
    The Bankaool Transformation: How a Regional Mexican Bank Became a FinTech Disruptor
    Image for Submit Your Entry Today for Digital Banking Awards 2026
    Submit Your Entry Today for Digital Banking Awards 2026
    Image for Behavioral AI in Financial Services: Moving Beyond Automation Toward Human Understanding
    Behavioral AI in Financial Services: Moving Beyond Automation Toward Human Understanding
    Image for Submit Your Entry for Brand of the Year Awards Technology Bahrain 2026
    Submit Your Entry for Brand of the Year Awards Technology Bahrain 2026
    Image for Entries Now Open for Best Islamic Open Banking Burkina Faso APIs 2026
    Entries Now Open for Best Islamic Open Banking Burkina Faso APIs 2026
    Image for Entrepreneurial Discipline in the AI Economy: Insights from Dmytro Lavryniuk
    Entrepreneurial Discipline in the AI Economy: Insights From Dmytro Lavryniuk
    Image for Entries Now Open for Best New Digital Wallet Innovation Award 2026
    Entries Now Open for Best New Digital Wallet Innovation Award 2026
    Image for Call for Entries: Best Digital Wallet 2026
    Call for Entries: Best Digital Wallet 2026
    View All Technology Posts
    Previous Technology PostMsm Software Suits Tuxedo Money Solutions
    Next Technology PostThe Intrinsic Value of Merchant Payments Infrastructures Will Increase in 2012