How to be Effective in the Wake of a Cyberattack

How to be Effective in the Wake of a Cyberattack

Helping you be prepared if an attack happens

We now live in an age where cyberattacks are the norm. Large or small, the question is not if you will be attacked, but when?  Once the attack happens, will you be prepared for it? Asking these questions will keep your business operating these days. It has been years and, for experts, insider threats still remain at the top of cybersecurity concerns. Clearly the deadly combination of insider threats and cyberattacks is not going away anytime soon. According to a report released last year by PwC, cyberattacks have only been growing across all industries, by 38 percent, specifically.  Couple insider threats with the rise of ransomware, and you're looking at a dangerous digital world that could bring your real operations to a grinding halt. By now, you may be asking what an “insider” is and – by extension – an insider threat.

Put simply, an insider threat is a security threat that came from within an organization rather than outside. Insiders come in the form of employees, managers, officers and privileged third parties. Insiders cause different types of data breaches which can be categorized into spills, leaks, espionage or outright sabotage. The main reason why insider threat is still a top concern among cybersecurity experts is because it is a people issue, not a technological one. However, there are plenty of technological solutions that can help you prevent insider incidents and data breaches. Before we explore those, let’s see how insiders have impacted companies in 2017 so far.

2017 Context of Insider Threats

Insider threats continue to plague business. For the longest time, insider threats had been focused around malicious insiders. However, in the last two years, studies have shown that the malicious actor in an organization has decreased. Instead, insider incidents have mainly been due to negligent staff. Some of the most recent incidents come from the Washington University School of Medicine, Chipotle and the UK National Health Service (NHS). All of these have been the impact of negligent insiders. Let's explore how they happened.

Washington University School of Medicine

On December 2, 2016, an employee at the Washington University School of Medicine responded to a legitimate-looking email. By responding to the email, the insider granted access to an external actor to all employee email accounts which existed on an unsecured server and held more than 80,000 accounts of patient data. Some key questions to ask yourself about this scenario are: what training did this employee have about cybersecurity? And why did all employee email accounts have access to patient data?

Chipotle

Chitpotle suffered the same type of cyberattack that Home Depot, Target and Arby’s faced. According to two cybersecurity researchers, the data breach was caused by malware embedded in an email attachment titled: ‘payment overdue.’ The body of the email claims a payment was due to them, although no such liability ever existed. The email stated step-by-step what the receiver had to do in order to see more details and fulfill the payment. The employee followed each instruction because the email seemed legitimate. The instructions were to open up a file in Microsoft Office and accept all the warnings. This allowed malware to infect the computer in Chipotle’s Tulsa, Oklahoma, office.

UK National Health Service: WannaCry

The now infamous story of WannaCry at the UK NHS has become a staple example of how dangerous cyberattacks have become. The incident happened because an employee downloaded an attachment from an email which then spread across the network thanks to an exploit in Windows XP systems. The rest is recent history. The NHS case demonstrates how damaging negligent insiders paired with ransomware can be.


Lines of Defense

So far, 2017 has been a scary year for cybersecurity. The cases above demonstrate how easy it is to bypass security when you have negligent insiders. So what can you do as a line of defense against this? To start, many experts agree that security is more than technology alone, and that it needs to work with policy enforcement and employee security awareness. When setting up security, be sure to include systems for identification, monitoring, encryption, restricting, training and extension.

  1. Identification deals with identifying all devices that can access your network or data. Often, security software does an excellent job of protecting your network. However, with mobile devices everywhere, employees are often logging into your network from unsecure devices that can reveal sensitive information to cyber criminals.
  2. Monitoring is one of the most important procedures a company can have in place. Data gathered from device usage, applications, emails and log data can produce comprehensive behavioral insights and provide an analysis of an employee’s productivity. Monitoring is the prerequisite to automated security response. This goes a step beyond just alerting.
  3. Encryption at rest and encryption in transit are very important to protecting your organization’s data. Encryption should apply to any devices that connect in to your network. This helps provide physical security in case laptops or phones are stolen. The data that is encrypted will be protected.
  4. Security Training for your employees is a must in today’s world and one of the strongest ways to deter insider threats. Employee training should help them understand the threats they may be exposed to in the process of their everyday jobs. This means it needs to be tailored to your organization’s specific context. Security training can go one step beyond and discuss the impacts that data has on the overall company.
  5. The principle of least privilege, is a restricting procedure which limits an employee’s access and privileges to only job-related data. This principle helps to deter malicious actors and prevent negligent use of company information.
  6. The final line of defense is extending your security practices with any strategic partners and vendors who have access to your network. This is critical now as the data breach at Target demonstrated. The only thing a cyber criminal needs is someone connected to a network, and it doesn’t always have to be an employee. Engage with all stakeholders who are connected to you for another layer of security.

Best Practices

Below you will find some best practices recommended from the CERT Division at Carnegie Mellon. There is no silver bullet to stop insider threats, however, you can reduce your chances of falling victim to a breach if you start with the following security management practices.

Create an Insider Threat Program

An insider threat program is a company-wide effort that is comprised of a multi-disciplinary team. This team usually includes, at minimum, the IT director and HR director. Each team member should receive specialized insider awareness training. The programs are intended to detect, prevent and respond to insider incidents. Establishing an insider threat program would bring departments together to create a shared understanding of insider threat and form coordinated processes to counter it.

Anticipate Negative Incidents in the Work Environment

Healthy work environments are known to be great for productivity, but did you know it also helps to mitigate insider threat as well? As the leader of your organization, your role here is to establish a foundation of good relations between your employees and their managers. People in your company can become a threat if certain stresses and resentment develop in their lives. Such stresses can include personal financial issues, toxic work environment, or process frustration. Being proactive and checking in on your employees about their work performance, health and well-being will be rewarded with more loyalty in the long-run.

Access Management

When business owners implement new systems for employees to use, they often do not take enough time to implement the principle of least privilege. Threats from within increase as access to everything is left open for employees. Disgruntled employees have free range to sabotage operations before they leave. It is important to conduct periodic reviews to ensure each role has the minimum amount of privilege necessary to perform their job. When there is a negative incident, be very vigilant of attempted breaches and unusual user behavior.

As the actual threat of insider threats continues to be ever present in the lives of business owners and managers, the need for sound security grows. Being caught off-guard can lead to halted operations, brand reputation loss and direct financial loss. You do not want to be in this position, so the best thing to do now is invest in insider threats prevention. Together, with thousands of other businesses out there, you can help be part of a safer cyber environment.

Featured

  • New Report Reveals Top Trends Transforming Access Controller Technology

    Mercury Security, a provider in access control hardware and open platform solutions, has published its Trends in Access Controllers Report, based on a survey of over 450 security professionals across North America and Europe. The findings highlight the controller’s vital role in a physical access control system (PACS), where the device not only enforces access policies but also connects with readers to verify user credentials—ranging from ID badges to biometrics and mobile identities. With 72% of respondents identifying the controller as a critical or important factor in PACS design, the report underscores how the choice of controller platform has become a strategic decision for today’s security leaders. Read Now

  • Overwhelming Majority of CISOs Anticipate Surge in Cyber Attacks Over the Next Three Years

    An overwhelming 98% of chief information security officers (CISOs) expect a surge in cyber attacks over the next three years as organizations face an increasingly complex and artificial intelligence (AI)-driven digital threat landscape. This is according to new research conducted among 300 CISOs, chief information officers (CIOs), and senior IT professionals by CSC1, the leading provider of enterprise-class domain and domain name system (DNS) security. Read Now

  • ASIS International Introduces New ANSI-Approved Investigations Standard

    • Guard Services
  • Cloud Security Alliance Brings AI-Assisted Auditing to Cloud Computing

    The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment, today introduced an innovative addition to its suite of Security, Trust, Assurance and Risk (STAR) Registry assessments with the launch of Valid-AI-ted, an AI-powered, automated validation system. The new tool provides an automated quality check of assurance information of STAR Level 1 self-assessments using state-of-the-art LLM technology. Read Now

  • Report: Nearly 1 in 5 Healthcare Leaders Say Cyberattacks Have Impacted Patient Care

    Omega Systems, a provider of managed IT and security services, today released new research that reveals the growing impact of cybersecurity challenges on leading healthcare organizations and patient safety. According to the 2025 Healthcare IT Landscape Report, 19% of healthcare leaders say a cyberattack has already disrupted patient care, and more than half (52%) believe a fatal cyber-related incident is inevitable within the next five years. Read Now

New Products

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.