Cyberattacks on state, local government up 50%

Many of the cyberattacks on state, local, tribal and territorial governments are not complicated and could be avoided through simple steps such as improved cyber hygiene and two-factor authentication, a new report states.

Since 2017, attacks – which the report defines as targeted instances of intrusion, fraud or damage by malicious cyber actors rather than discovery of insecure databases or accidental online leaks – rose an average of almost 50%, according to the “State and Local Government Security Report” that BlueVoyant, a cybersecurity firm, released Aug. 27. That amount that is likely only a fraction of the true number, the report adds.

The research confirmed the company’s belief that active threat targeting happens across the board. “For every selected county’s online footprint, evidence showed some sign of intentional targeting,” the report states. What’s more, five counties -- or 17% of the 28 studied -- showed signs of potential compromise, indicating that traffic from governments assets was reaching out to malicious networks.

“There’s a collective risk here because there is no standardization,” said Austin Berglas, former FBI special agent in New York and head of ransomware/incident response at BlueVoyant. “You have certain state and locals that are on dot-coms and dot-us or dot-orgs. One would think that these should be on the dot-gov domain because [that] means that you not only check the box as being a certified government site, but you get forced two-factor authentication and you’re always going to have HTTPS.”

Ransomware is the main way municipal assets are attacked. What’s more concerning than the growing number of attacks, however, is the increase in how much bad actors demand in ransom, the report states. Average ransom demands rose from a monthly average of $30,000 to nearly half a million dollars, with total monetary value of ransom demands reaching into the millions.

Even when cities don’t pay, the costs can be staggering. For instance, the 2019 ransomware attack on Baltimore cost the city more than $18 million in damages and remediation.

“The notion of ‘Hey, I’m small. The bad guys aren’t going to be targeting me’ is no longer applicable,” Berglas said. “The bad guys know how valuable” state and local government data is, so they go after  the personally identifiable information in tax records or disrupt entire networks in an extortion attempt. “We’ve personally seen a municipality in the past year get completely compromised, locked up with ransomware and the entire 911 system was locked down.”

Other attack vectors include data breaches and typosquatting, in which threat actors impersonate trusted domains with near-identical website URLs, according to the report. “Such sites are often created as a means of advanced threat infrastructure: pre-positioning for many phishing, spear-phishing and [social media] influence campaigns,” it states.

The coronavirus response and upcoming presidential election have helped put cybersecurity in the limelight.

“We immediately expanded our attack surface immensely,” Berglas said of the pandemic. “If I’m an IT section of a company and I’ve got the responsibility of protecting and maintaining the endpoints -- the laptops, the computers, the phones -- and all of a sudden that just tripled, quadrupled in number and now my company is allowing people to use their own devices, [I need to know how] those devices managed,” he said. “Are there endpoint sensors on those devices to protect them? Are there containers that separate work from personal information? Is there data-loss protection capability on there? All of these questions come into play.”

In terms of election security, what’s at stake is not the potential for changing votes, but rather undermining faith in the process, he added. For instance, when people vote by mail, could votes tallied on a spreadsheet be locked up by a ransomware attack?

State and local governments can take three immediate steps to improve their security postures, Berglas said. The first is to implement password hygiene, or the use of complex passwords that automation would struggle to detect. Second is two-factor authentication, which deters bad actors who don’t want to have to take extra steps to gain access, and the third is a review of remote desktop protocols, including ensuring that ports are closed after employees finish using them.

Agencies can build on their security from there by accounting for sufficient backups, planning for defense-in-depth and following the least-privilege principle, which states that people on the network can access only the information they need to do their jobs. On top of that, Berglas said, agencies need visibility into the entire network so they can monitor it round-the-clock.

“Resiliency takes a front seat here,” he said.

This article first appeared in GCN.com.

Featured

  • Maximizing Your Security Budget This Year

    7 Ways You Can Secure a High-Traffic Commercial Security Gate  

    Your commercial security gate is one of your most powerful tools to keep thieves off your property. Without a security gate, your commercial perimeter security plan is all for nothing. Read Now

  • New Report Says Vulnerability Exploitation Boom Threatens Cybersecurity

    Verizon Business recently released the findings of its 17th-annual Data Breach Investigations Report (DBIR), which analyzed a record-high 30,458 security incidents and 10,626 confirmed breaches in 2023—a two-fold increase over 2022. Read Now

  • In The Clouds

    Video data storage in the cloud was a novel concept when Dean Drako founded Eagle Eye Networks back in 2012. While cloud was being used for almost all other business systems at that time, the physical security industry took a cautious and measured approach to cloud adoption. Read Now

  • Surveillance Cameras Provide Peace of Mind for New Florida Homeowners

    Managing a large estate is never easy. Tack on 2 acres of property and keeping track of the comings and goings of family and visitors becomes nearly impossible. Needless to say, the new owner of a $10 million spec home in Florida was eager for a simple way to monitor and manage his 15,000-square-foot residence, 2,800-square-foot clubhouse and expansive outdoor areas. Read Now

Featured Cybersecurity

Webinars

New Products

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities 3

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols. 3

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.” 3