|
Welcome back to the monthly TCE Strategy newsletter! Wow… January has been one of those months in cybersecurity where there is so much to cover that it can’t all fit in one newsletter. The most important and interesting news stories are below. From doughnut ransomware to pardoning the founder of Silk Road, let’s see how this month’s cybersecurity news can help us make better decisions about what is Secure Enough for us, the companies we work for, and our families.
Krispy Kreme’s cybersecurity had a few holes
It’s not often that a cybersecurity incident makes its way to the Saturday Night Live satire news desk, but this one did (don’t watch the video at work – lots of NSFW jokes). The famous Krispy Kreme doughnut shop suffered a cyberattack bad enough that there were reports of closed stores, cash-only sales, and their on-line ordering system going offline. Exact details of what happened have been sparse, but their mandatory SEC filing states that “the Company is experiencing certain operational disruptions, including with online ordering in parts of the United States” and “the incident has had and is reasonably likely to have a material impact on the Company’s business operations.” The Play ransomware group took responsibility for the attack. That particular group has been active since 2022, and their other victims include Rackspace and the City of Antwerp, Belgium. They often gain their initial foothold by exploiting known vulnerabilities in Internet-facing systems where patches are available but have not been installed..
Takeaway: Ransomware is a preventable crime. Patching devices, especially those that are Internet-facing, is extremely important. More details on how to prevent ransomware attacks are available here.
When cybersecurity and politics collide
There isn’t an easy way to talk about politics without offending half (or more) of the population, but avoiding talking about politics and its direct impact on cybersecurity is dangerous in my opinion. So, we’re going to talk about it.
Collision #1: On January 16th, the previous USA administration issued an executive order on cybersecurity, requiring things such as secure software development practices, phishing-resistant authentication technologies, encryption that can withstand cracking from quantum computing, AI engines that need to go through safety checks before being released to the public, and so on. Some of these requirements are similar to those in the Defense Production Act of 1950. The new administration has revoked the cybersecurity executive order, so that is the end of that. To be honest, the order probably wasn’t going to do much good anyway, as things like laws or executive orders do not change behavior. Three things are required to change behavior: laws, enforcement of those laws, and sufficient penalties for breaking those laws. Without all three, not much is going to get done.
Collision #2: CISA stands for the Cybersecurity and Information Security Agency, which is a US government agency that, among other things, acts as an interface between the public sector and private sector for matters related to cybersecurity. I have had a number of times when information from CISA has been instrumental in determining likely attack vectors of cybercriminals while my team is actively engaged in recovering from a cyberattack. One of the advisory committees under CISA was the CSRB, or Cyber Safety Review Board. The CSRB did not have any legislative ability, but the investigated breaches such as Log4Shell and the Microsoft O365 email hack, and gave recommendations on how to prevent future similar incidents from occurring. As of January 20th, the CSRB is no more, and the entire future of CISA is in question. While CISA does a lot of “Ivory Tower” work with guidelines, frameworks, recommendations, etc. that often don’t translate well into the real world, they also maintain a list of known vulnerabilities that are being actively exploited. They even break down the list to call out vulnerabilities that are being exploited by ransomware gangs, which is extremely useful information to have. I hope that aspect of CISA continues to exist into the future.
In other new-administration news, the founder of the infamous website Silk Road, Ross Ulbricht, was recently pardoned after serving over 11 years in prison. Silk Road was a website that was often used for illegal purchases of things like weapons, drugs, and even alleged murder-for-hire schemes. There was already a significant movement to release him under the grounds that operating a website is an expression of free speech, and even if it isn’t, his sentence (two life sentences + 40 years without parole) was unreasonably long.
Takeaway: It’s going to be a significant period of transition over the next several months, and the thought that there are going to be new rules that make it in a large company’s best interest to make cybersecurity products is very slim. Thankfully, there are many things we can do as individuals to protect ourselves from cybercrime.
Until next month, stay safe!
|