Three Lessons From the San Francisco Muni Ransomware Attack

On Black Friday, a hacker hit San Francisco’s light rail agency with a ransomware attack. Fortunately, this story has a happy ending: the attack ended in failure. So why did it raise the hairs on the back of our collective neck? Because we fear that next time a critical infrastructure system is attacked, it could just as easily end in tragedy. But it doesn’t have to if organizations with Industrial Control Systems (ICS)  heed three key lessons from San Francisco’s ordeal.

First, let’s look at what happened: On Friday, Nov. 25, a hacker infected the San Francisco Municipal Transportation Agency’s (SMFTA) network with ransomware that encrypted data on 900 office computers, spreading through the system’s Windows operating system. As a precautionary measure, the third party that operates SMFTA’s ticketing system shut down payment kiosks to prevent the malware from spreading. Rather than stop service, SMFTA opened the gates and offered free rides for much of the weekend. The attacker demanded a 100 Bitcoin ransom, or around $73,000, to unlock the affected files. SFMTA refused to pay since it has a backup system. By Monday, most of the agency’s computers and systems were back up and running.

Here are three key lessons other ICS organizations should learn from the event, so they’re prepared to derail similar ransomware attacks as deftly:

  1. Recognize you are increasingly in cybercriminals’ cross hairs. Cyberattacks on ICS systems, which control public and private infrastructure such as electrical grids, oil pipelines and water systems, are on the rise. In 2015, the U.S. Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) responded to 20% more cyber incidents than in 2014. And for the first time since the agency started tracking reported incidents in 2009, the critical manufacturing sector experienced more incidents than the energy sector. Critical manufacturing organizations produce products like turbines, generators, primary metals, commercial ships and rail equipment that are essential to other critical infrastructure sectors.
  1. Keep your IT and OT separate. Thankfully, the San Fran Muni ransomware attack never went beyond SFMTA’s front-office systems. But, increasingly, cyber criminals are penetrating control systems through enterprise networks. An ICS-CERT report noted that while the 2015 penetration of OT systems via IT systems was low at 12 percent of reported incidents, it represented a 33 percent increase from 2014. Experts say the solution is to adopt the Purdue Model, a segmented network architecture with separate zones for enterprise, manufacturing and control systems.
  1. Invest in off-site, real-time backup. SFMTA was able to recover the encrypted data without paying the ransom because it had a good backup system. That wasn’t the case with the Lansing (Michigan) Board of Water & Light. When its corporate network suffered a ransomware attack in April, the municipal utility agency paid $25,000 in ransom to unlock its accounting system, email service and phone lines.

If San Francisco’s example isn’t enough to motivate ICS organizations to take cybersecurity seriously, then Booz Allen Hamilton’s 2016 Industrial CyberSecurity Threat Briefing should do the trick. It includes dozens of cyber threats to ICS organizations.

By Laurie Kumerow, Consultant, Code42

[Cloud Security Alliance Blog]

Telecom Organizations’ Strategy to Generate Revenue from Security Services

In this digital age, with telecom service providers’ revenue per bit falling every year, network operators are clearly being forced to consider expanding their catalogue of services to something beyond basic voice connectivity. Providers need some way to unlock the full value of their investment in the network and to expand into new and profitable applications and services.

For a decade or more, Western European and North American telecommunication companies have focused on capturing growth in the consumer market, as mobile phone usage became nearly universal and telcos sold broadband, TV and other data services to users at home and on the go.

The challenge for many telecom executives is how to identify the opportunity that lies beyond the market that historically fueled their profit pool and reshape their companies and priorities to capitalize on the situation.

To win in the expanding market for business telecom and IT services, telcos will need to prioritize the B2B opportunity and embrace newer capabilities.

Cybersecurity Ventures projects $1 trillion will be spent globally on cyber security from 2017 to 2021. Cybercrime is predicted to cost the world $6 trillion annually by 2021.

Traditionally, operators had security services in B2B such as managed firewalls, intrusion and prevention systems, email security, web gateway, security information and event management, vulnerability and penetration testing solutions, risk assessment and end-point protection.

But the digital business needs something unique that can protect their organizations from cyber-attack and data breaches.

The important areas that operators need to focus on in order to generate revenue are:

  1. Internet of Things
  2. Software-defined networking
  3. Big data and analytics
  4. Cloud
  5. Intelligent breach response management

A dozen cyber security startups have each raised $100 million or more in funding since 2014, according to Dow Jones VentureSource – a database that reports on companies globally that receive venture capital and private equity funding.

Hundreds of billions will be spent on securing PCs, mobile and IoT devices, corporate networks, and the cloud over the next five years.

The time has come for operators to generate revenue from these cyber security offerings, and it is up to the service provider to define strategy in developing the capabilities and targeting the market.

References

  1. http://cybersecurityventures.com/
  2. http://www.csoonline.com/
  3. http://bcg.com

Rasool Kareem Irfan, CISM, CEH, ISO/IEC 27001, Senior Manager – Security Practice, Tata Communications Transformation Services

[ISACA Now Blog]

Three Common Mistakes to Avoid When Interviewing

So you have read my blog about finding your next opportunity, and now you have started to interview. I would like to share three common mistakes I see interviewees make that can cost them the job they are hoping to land:

1. Not doing your homework. Every interview situation is different, but most people would admit that interviewing is stressful. The best way to beat that stress is by being prepared. Being over-prepared is even better! The vast majority of candidates I help prepare to interview focus on only one thing: What questions will they ask me and how do I answer them? That’s a start, but let me give you a few more things to prepare for:

  • Research the people you are meeting with on LinkedIn or Google to identify common professional connections, business interests or hobbies outside of work.
  • This may sound obvious, but research fully what the company does. Do not know them only on the surface. Make sure you know every product, service offering and who their customers are.
  • Show them you have done your homework by reviewing the company’s recent news headlines and reading their last Form 10-K (if publicly traded).
  • Prepare concrete reasons you want to work for them and not their competitors. What sets them apart?

2. Not asking the right questions – or not asking questions at all. In my opinion, the worst thing that can happen is if an interviewer asks, “Do you have any questions for me?” and you say, “No, I think you answered them all!” You are planning to work at this company for years and you cannot think of so many questions there will not be enough time to cover them all? Uh oh …

Be over-prepared, with enough open-ended questions (think: how, what, why) to talk for double the amount of time allocated for the interview. You may have only two hours to prove to them you will be a contributor at their organization for years to come. Show them how interested you are by drilling down into the details of what they are doing and how they do it, and steer the conversation toward how you would make an impact if you were hired.

I often get questions about how to learn more about the benefits package during an interview. My advice is to leave out questions on any non-negotiable items until after you have interviewed. Make them want to hire you first, and then focus on getting the benefits details from HR at a later time.

3. Writing a bad follow-up letter. A poorly written and/or bland follow-up letter is one of the easiest ways to ruin an excellent interview. Auditors need to have strong writing skills, and you cannot afford to send a letter with a single typo, punctuation or grammatical error. Have someone proof your letter before you hit ‘send.’ Also, avoid a generic follow-up letter like, “Hi Mark, Thanks so much for taking the time to meet with me today. I enjoyed learning about your position. I look forward to hearing from you soon.” There is no meat to that, and you are missing an opportunity to make yourself stand out.

Be specific in your follow-up letters. Why did you enjoy meeting them? What specifically about the job interested you? Why do you want to work for their company? What part of your background do you think would benefit them the most after learning more about their position?

Bonus tip: Use the follow-up letter as a chance to clarify an answer you may not have communicated well.

Author’s note: I hope these three tips help you to successfully navigate your next career transition. There is a lot more that we can cover at a later time. Until then, I’d like to hear from you. What is your biggest interview mistake and what did you learn from it? What is the best question you have ever asked as an interviewee or best question you have ever been asked by a candidate?

Brad Owens, Recruiting Director, Duval Search

[ISACA Now Blog]

Three Ways to Make Information Security a Habit During Project Management

With eyeballs rolling, they mumble, “Why do security people insist on stopping our projects?”

As information security (IS) professionals, we have seen this response from project managers (PM), developers, and fill-in-your-favorite-role here, when we have derailed a project due to an unplanned InfoSec issue.

What is an InfoSec Professional to Do?
Police chiefs don’t lock our car doors, nor do CISOs read application teams’ code. Because InfoSec is a lifestyle, not an event, we need a security culture. It takes a village. After reading this post you will have three tips for infusing security habits into a village of project managers.

1. Make it easy. According to BJ Fogg, Ph.D., founder of Persuasive Tech Lab at Stanford University, we are basically lazy. Want to make IS easy (or at least easier) for non-InfoSec professionals? Think like Jeopardy!’s Alex Trebek and get the participants to “ask the question.”

Start with your written InfoSec policies and standards. Summarize one or two into a question and work with your Project Management Office (PMO) to include the questions in a new project checklist to provide guidance.

Examples:

  • Building a mobile app? Refer to “Vulnerability Scan Standard.”;
  • Outsourcing or working with third parties? Refer to “Outsourcing and Third Party Policy.”

2. Make it simple. Did you know that InfoSec training and experiences may yield Continuing Education Units (CEU) for certified project managers? For example, certified Project Management Professionals (PMP®s) may be eligible to earn CEUs if the InfoSec training meets the Project Management Institute’s criteria. Risk management is a knowledge and skills area for the institute, and PMPs need to recertify every three years. If you help PMP®s make that connection, it may mean reduced training costs and time, enhanced careers, and stronger InfoSec advocates; all factors in creating habits and a culture of village security.

3. Make it rewarding. Have a “Village Citizen of the Year” recognize her. Does a PM role model a good InfoSec practice? Take five minutes to recognize the specific behavior (example – uses PMO “New Project” checklist to identify new mobile apps that require vulnerability scans). Fogg identifies “pleasure” (think: positive recognition email to boss) as a core motivator for changing behaviors.

What Next? Start Small. It is as Easy as 1…2…3

  1. Ask your PMO or individual PMs if a Jeopardy! approach would reduce project derailments and make InfoSec adoption easier. Then start with one question for the most frequently overlooked InfoSec standard or policy.
  2. Have an upcoming InfoSec event or activity where InfoSec learning may occur? Include in your invite:  “Did you know that some InfoSec training may serve as CEU for certified or wannabe-certified project managers? Click PMI certifications to learn more.”
  3. Add a five-minute invite to your calendar to “Recognize PM once a month.” Example: To: Boss, cc: PM; “Just wanted to recognize PM for role modeling fill-in-the-blank InfoSec practice or attitude! Our organization, teams, and customers are better because of it. Great job, PM!”

Sources: BJ Fogg, Ph.D.; PMI

Luanne Spiros, CISM, PMP

[ISACA Now Blog]

Cyber Insurance Against Phishing? There’s a Catch

If one of your employees gets duped into transferring money or securities in a phishing scam, don’t expect your cyber insurance policy to cover it. And even your crime policy won’t cover it unless you purchase a specific social engineering endorsement. Many companies have learned the hard way and tried to sue their insurance carriers, with little luck.

Aqua Star, a New York seafood importer, expected to be covered after a spoofed email from a supplier drove an employee to change the supplier’s bank account, causing Aqua Star to wire more than $700,000 to a hacker instead of the supplier. Aqua Star has a crime policy through Travelers, which includes Computer Fraud coverage that applies to loss caused by the fraudulent entry of electronic data into any computer system owned, leased or operated by the insured. But when Aqua Star filed the claim, Travelers pointed out an exclusion if the data was entered by an authorized user. Aqua Star then sued Travelers, but the court agreed with Travelers, ruling that the employee was clearly an authorized user.

A similar phishing scam resulted in Apache Corp., an oil and gas producer, wiring $2.4 million to cybercriminals. It’s insurance company, Great American, denied the payout, so Apache went to district court and won. However, Great American appealed to a higher court, which reversed the decision, saying the bogus email didn’t directly cause the loss.

What commercial cyber insurance policies do cover
Cyber insurance policies cover losses that result from unauthorized data breaches or system failures. But they vary greatly in the details and exceptions. Most will cover forensic investigation fees, monetary losses caused by network downtime, data loss recovery fees, costs to notify affected parties and manage a crisis, legal expenses, and regulatory fines.

When it comes to ransomware, you need to look closely at the policy’s Cyber Extortion coverage. If it offers only third-party coverage, then ransomware isn’t covered.

Crime insurance policies cover losses that result from theft, fraud or deception. But as the Aqua Star and Apache examples illustrate, insurers typically deny coverage for social engineering fraud, claiming that the loss didn’t result from “direct” fraud. Insurers contend that the crime policy applies only if a cybercriminal penetrates the company’s computer system and illegally takes money out of company coffers.

Some crime policies also contain a “voluntary parting” exclusion that specifically bars social engineering claims by barring coverage for losses that arise out of anyone acting with authority who voluntarily gives up title to, or possession of, company property.

Fishing for a solution? Add an endorsement
Many insurance companies offer a social engineering fraud endorsement, like this one from Chubb. It’s offered under a crime policy for a nominal additional premium. The coverage, sometimes referred to as an impersonation fraud or fraudulent instruction endorsement, is typically up to $250,000 per occurrence, with no annual aggregate, but higher limits are available for a higher premium.

The net lesson: a phishing endorsement is an easy fix to a potentially costly oversight.

Jeremy Zoss, Managing Editor, Code42

[Cloud Security Alliance Blog]

English
Exit mobile version