Cyberattacks on state, local government up 50%

Many of the cyberattacks on state, local, tribal and territorial governments are not complicated and could be avoided through simple steps such as improved cyber hygiene and two-factor authentication, a new report states.

Since 2017, attacks – which the report defines as targeted instances of intrusion, fraud or damage by malicious cyber actors rather than discovery of insecure databases or accidental online leaks – rose an average of almost 50%, according to the “State and Local Government Security Report” that BlueVoyant, a cybersecurity firm, released Aug. 27. That amount that is likely only a fraction of the true number, the report adds.

The research confirmed the company’s belief that active threat targeting happens across the board. “For every selected county’s online footprint, evidence showed some sign of intentional targeting,” the report states. What’s more, five counties -- or 17% of the 28 studied -- showed signs of potential compromise, indicating that traffic from governments assets was reaching out to malicious networks.

“There’s a collective risk here because there is no standardization,” said Austin Berglas, former FBI special agent in New York and head of ransomware/incident response at BlueVoyant. “You have certain state and locals that are on dot-coms and dot-us or dot-orgs. One would think that these should be on the dot-gov domain because [that] means that you not only check the box as being a certified government site, but you get forced two-factor authentication and you’re always going to have HTTPS.”

Ransomware is the main way municipal assets are attacked. What’s more concerning than the growing number of attacks, however, is the increase in how much bad actors demand in ransom, the report states. Average ransom demands rose from a monthly average of $30,000 to nearly half a million dollars, with total monetary value of ransom demands reaching into the millions.

Even when cities don’t pay, the costs can be staggering. For instance, the 2019 ransomware attack on Baltimore cost the city more than $18 million in damages and remediation.

“The notion of ‘Hey, I’m small. The bad guys aren’t going to be targeting me’ is no longer applicable,” Berglas said. “The bad guys know how valuable” state and local government data is, so they go after  the personally identifiable information in tax records or disrupt entire networks in an extortion attempt. “We’ve personally seen a municipality in the past year get completely compromised, locked up with ransomware and the entire 911 system was locked down.”

Other attack vectors include data breaches and typosquatting, in which threat actors impersonate trusted domains with near-identical website URLs, according to the report. “Such sites are often created as a means of advanced threat infrastructure: pre-positioning for many phishing, spear-phishing and [social media] influence campaigns,” it states.

The coronavirus response and upcoming presidential election have helped put cybersecurity in the limelight.

“We immediately expanded our attack surface immensely,” Berglas said of the pandemic. “If I’m an IT section of a company and I’ve got the responsibility of protecting and maintaining the endpoints -- the laptops, the computers, the phones -- and all of a sudden that just tripled, quadrupled in number and now my company is allowing people to use their own devices, [I need to know how] those devices managed,” he said. “Are there endpoint sensors on those devices to protect them? Are there containers that separate work from personal information? Is there data-loss protection capability on there? All of these questions come into play.”

In terms of election security, what’s at stake is not the potential for changing votes, but rather undermining faith in the process, he added. For instance, when people vote by mail, could votes tallied on a spreadsheet be locked up by a ransomware attack?

State and local governments can take three immediate steps to improve their security postures, Berglas said. The first is to implement password hygiene, or the use of complex passwords that automation would struggle to detect. Second is two-factor authentication, which deters bad actors who don’t want to have to take extra steps to gain access, and the third is a review of remote desktop protocols, including ensuring that ports are closed after employees finish using them.

Agencies can build on their security from there by accounting for sufficient backups, planning for defense-in-depth and following the least-privilege principle, which states that people on the network can access only the information they need to do their jobs. On top of that, Berglas said, agencies need visibility into the entire network so they can monitor it round-the-clock.

“Resiliency takes a front seat here,” he said.

This article first appeared in GCN.com.

Featured

  • Trends Keeping an Eye on Business Decisions

    Today, AI continues to transform the way data is used to make important business decisions. AI and the cloud together are redefining how video surveillance systems are being used to simulate human intelligence by combining data analysis, prediction, and process automation with minimal human intervention. Many organizations are upgrading their surveillance systems to reap the benefits of technologies like AI and cloud applications. Read Now

  • The Future is Happening Outside the Cloud

    For years, the cloud has captivated the physical security industry. And for good reason. Remote access, elastic scalability and simplified maintenance reshaped how we think about deploying and managing systems. But as the number of cameras grows and resolutions push from HD to 4K and beyond, the cloud’s limits are becoming unavoidable. Bandwidth bottlenecks. Latency lags. Rising storage costs. These are not abstract concerns. Read Now

  • The Impact of Convergence Between IT and Physical Security

    For years, the worlds of physical security and information technology (IT) remained separate. While they shared common goals and interests, they often worked in silos. Read Now

  • Unlocking Trustworthy AI: Building Transparency in Security Governance

    In situations where AI supports important security tasks like leading investigations and detecting threats and anomalies, transparency is essential. When an incident occurs, investigators must trace the logic behind each automated response to confirm its validity or spot errors. Demanding interpretable AI turns opaque “black boxes” into accountable partners that enhance, rather than compromise, organizational defense. Read Now

  • Seeking Innovative Solutions

    Denial, Anger, Bargaining, Depression and Acceptance. You may recognize these terms as the “5 Phases” of a grieving process, but they could easily describe the phases one goes through before adopting any new or emerging innovation or technology, especially in a highly risk-averse industry like security. However, the desire for convenience in all aspects of modern life is finally beginning to turn the tide from old school hardware as the go-to towards more user-friendly, yet still secure, door solutions. Read Now

New Products

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities