Government Takedown of Ransomeware Rings – What CISO’s Need to Know – CISO Talk EP 44
Recent collaborative actions by U.S. and international law enforcement against ransomware rings such as LockBit, BlackCat, and Ragnar Locker serve as a critical wake-up call for CISOs and security leaders. These operations highlight ransomware’s sophistication and pervasive nature, emphasizing the need for robust incident response measures that may involve law enforcement. In this special edition of CISO Talk, hosts Mitch Ashley and JJ Minella are joined by Caroline Wong (Cobalt) to discuss how to understand the evolving threat landscape, foster international collaboration and implement comprehensive security strategies.
Transcript
Hi, everyone. Welcome. We're so glad that you've joined us today.
You are here for a special edition of CSO Talk, which is a video series, uh, kind of panel interview conversational, uh, video series. We have on Techstrong TV and CSO talk's. Been happening, I think probably close to two and a half, maybe even more years.
And we have different folks doing this myself and him and Alan Shimmel kinda started it. And we're always talking about what are the topics that are relevant and top of mind for CISOs and which of course we're always talking about attacks and different types, but also, you know, the technologies and Zero trust and all the approaches that are on, uh, on our plans and what we might be doing in those areas. So this is a interactive conversation.
Um, the three of us who'll introduce our panelists here in just a moment, my co-host and panel. Um, but we encourage you to jump in and, uh, join the conversation and chat. And by that I mean throw in your comments, your reactions, and, Hmm, hadn't thought about that or, I like what, uh, Caroline said, or, Hey, you know, I really, where's the resource I can find out about more?
Or if, you know, here's a question, a scenario that I'm thinking about that I'd love some, you some thinking from the, the folks, uh, talking today. So I'm joined by Jennifer, JJ Minilla welcome co-host. It's always good to, uh, be working with you again, longtime friend, colleague, et cetera, et cetera.
And, and, uh, and of course also another longtime friend, uh, and colleague, uh, Caroline Wong. It's great to have you both with really kinda the three of us hosting this conversation. So, uh, let's, let's, uh, by way of introductions, have you introduce yourself, Caroline, and then JJ will do the same and kind of kick us off on the topic.
Sounds great. Uh, Mitch and JJ and everyone who's joining us, I'm so delighted to be here today with you. My name's Caroline Wong, I'm the Chief Strategy Officer at Cobalt.
We are an offensive security company. I began my security career in 2005, leading security teams at eBay and Zynga. Um, in between now and then, uh, I wrote a book called Security Metrics, A Beginner's Guide.
I host a podcast called Humans of InfoSec. Uh, and I'm really proud to, uh, share that. Uh, at COBAL to every year we publish a research report on the state of pen testing.
Uh, so right now we're working on state of pen testing 2024. Excellent. Feel free to post links to the report or your books.
Uh, I failed to mention your book are both, uh, published authors, so quite accomplished, so appreciate that. Mine Was a coloring book, so that doesn't count. Kidding.
And that would, that would be more my book, I think. Hi, EV Hi everybody. Uh, co-host of CSO talk here with Mitch.
I'm Jennifer JJ Manila, um, also founder and principal advisor with Vision Security, um, and s faculty. And I'm really excited to be here. I mean, Caroline, it's so great to see you and have you, and of course, Mitch and I have to say hi to Mira.
I'm also in C North Carolina, and I saw Trina in North Carolina. It's so awesome to see, um, so many of you guys joining from all over the place. Um, so today we wanted to kind of do a little umbrella view.
Uh, and I hate to say zoom out, I'm so tired of like zooming out and clicking in as, as cliches for how we talk about things. But let you know, things have changing, have been changing in the whole world of ransomware. And it's kind of like the boiling frog where it's this slow thing happening and stuff has changed enough now that we need to talk about it.
And so we're kind of getting around to, you know, are we talking about the same old, same old, uh, story with ransomware? I think it's evolved. We've, we've gone from like destructive codes to regular ransomware to extortion, to double and triple extortion models, and now ransomware as a service.
And, um, the relationship with, with how those organizations are working and those threat actors are, are working has, um, been changing. And then now more recently we have these government takedowns of some of these networks. Um, so it's a really great conversation.
Um, Mitch, and I'm really interested, especially Caroline, given you know, your background and what you've been doing to, to hear what you have to say about some of this Jump right in, Caroline. So I have kind of a fun question. Uh, it's for Mitch, it's for jj, it's for anyone who wants to jump in in the chat.
When was the very first ransomware attack? I think it was, let's see, 1972 when my friend Freddy held my lunch money hostage. The First one I'm aware of, I don't, I I don't know what the first Gigi you might know.
You know, I feel like I should because I did just give a presentation for, for a clients like customer, uh, I mean security awareness thing. And it had the whole history of attacks in it. Um, but I don't know Caroline, and I feel like even if I thought I knew I was gonna be wrong, You know, it's one of those crazy things.
It is the year 2024. You know, I think we all started talking a lot about ransomware in 2020. The first ever ransomware attack happened in 19 89, 1, 9, 8, 9.
Wow. It directed users to mail $189 to a PO address in Panama. So when we talk about this slowly boiling frog, you know, that frog was in a pot of cold water a very long time ago.
And, and it, and it's fascinating how it's evolved and it's become a mainstream topic. Um, you know, with the increase of, you know, everything in society being so dependent on technology, technology being so vulnerable to security problems, um, and now it's just this enormous thing that has tremendous impact on people all over the world. It's, it is really launched of one of the forefront issues to the business, right?
Obviously because of the impact operationally, but also financially, of course. And, you know, the ransomware has evolved from I've encrypted all your stuff, you know, contact me if you want. The key may pay me to, I'm gonna, I've got data and I'll release it if you don't pay me.
Or I may, I may just do any of those things. If you don't pay me, I'll come after you kind of thing. You know, the, the, the payola money right now stop by every week at the restaurant.
And, uh, yeah, we'll, we'll, we'll protect you again this week. Nice restaurant you got here. Be ashamed if something happened to it.
Right? And, and with the, there was an article in February, I think is in the Washington Post that I saw it initially about the federal government working inter internationally to take out some really big ransomware rings, you know, folks that were doing really visible stuff around, uh, lock bid and Black Hat and Wrangler and a number of things. And there's been more since, but it almost felt like, you know, a, a drug bust, like taking down a drug, a major drug ring, uh, distribution ring, almost the same thing, working internationally, capturing these folks and, you know, putting 'em in jail or, or for prosecution, et cetera.
And what it made me think of is that's not something that CISO has had to deal with is, okay, do we have to cooperate with the federal agencies on that? If we've been a victim of it in the past? Um, if we go to the feds and there are times when you need to, is that okay now we may be enthralled in some longer activity that they have and we get to testify or whatever.
I mean, it, it is, you know, we haven't, at least I haven't been, been a part of needing to testify in any drug rings lately. So, um, you know, if we had to do that as a, as a, uh, ransomware activity, I, I don't, that wouldn't be on my radar as a ciso. At least it wouldn't have been a while ago.
I dunno. Am I crazy or does that seem like an issue to you all too? You know, I think it's, I think it's totally appropriate for a CISO to establish proactive relationships with law enforcement wherever they're located.
Uh, you know, certainly years ago, uh, for me, when I was on the eBay information security team, you know, our team, uh, had kind of frequent discussions with the FBI. Um, and I think that, you know, there's really, this whole ransomware topic is so multi-dimensional. You know, I think of it as ransomware being a symptom and the root cause being insecure systems, a lack of updates, a lack of patching, a lack of multifactor authentication backups that are not necessarily in place or tested to, to be sure that they're working.
You know, and I have a, I have a lot of, um, sympathy, uh, for CISOs in their teams who don't necessarily have these things in place. You know, I think about, uh, you know, in several months all of our organizations will be preparing for 2025. We're gonna go through a budget exercise, uh, and every executive's gonna stand up and say, I need money for more engineers.
I need money for more salespeople. I need money for more marketing campaigns. You know, if the CISO stands up and says, I need money to ensure our backups are working.
It's just not very fun and not very sexy. And that is one of the reasons why it's hard to get these things funded. And yet, if you don't have backups in place, what do you do when you are the victim of a ransomware situation?
You know, one of the, uh, links that we've got in our handouts is the ransomware True Cost Report by Cybereason for 2024. You know, of the folks that they talked to for this report, 84% of these folks paid the ransom. Why did they do that?
Because they didn't wanna lose business because it seemed like the fastest, easiest way to do something, because it was a holiday and they were short-staffed, because in some cases, it's literally a matter of life and death. And in some cases, there aren't backup files. You know, backing up your files is one of those basic one-on-one fundamental things.
Why doesn't it get done? 'cause there's just limited time and resources to do everything that you need to do. As a ciso, It's also just very complicated.
I mean, it's so easy, and this is, you know, I, I love and hate my job sometimes, but coming out of like, you know, infrastructure, architecture, and then taking on more of a security role over the years, you know, in 25 years or so of doing this, you know, it's easy to put on a control framework or something from, you know, the security or CISO's office that says, do this. Right? Do your backups, do the testing, do even just something as basic as like running firmware updates in infrastructure, um, regardless of where that infrastructure is living and what it is, is completely ridiculously complex.
Sometimes it's hours or days. Sometimes you, you fix one thing and you break five others and you have to request maintenance when it's like, it, it's not the one line that says to do this from the operational standpoint might be days, weeks, or months of work. And it's just overly complicated.
I think our products have gotten overly complicated just across the board from a technology standpoint. I think the security tooling has gotten overly complicated in the wrong ways. Not complicated on, um, with, you know, like the, the different inputs that it's able to ingest, but the, the way you need to set it up and how you need to, to manually connect things in, um, it, it's just, we can't scale like that.
I put a, by the way, I put a reference, a link to the report that Caroline was talking about, the true cost of ransomware. There, there is one, one of the things that dealing with, you know, such frequent attacks and just blocking them and, you know, securing, making things more secure. It's also about incident response, right?
And I remember not too long ago, maybe a year or two, a year ago, it was, it kind of crossed the threshold about maybe, maybe response is more important than prevention. You need both. But if you don't have the response part, you, you are going to be compromised the, it's not if it's when or how many times.
Right? And that response part of it is extremely important. Um, I would imagine, Caroline, in your work and pen testing assessment and all that kind of things that you do, is that something you get to look at with customers?
I know, I know JJ does as part of her CISO whispering that she does as, uh, that I like to call her. Any, any thoughts on that, on the response part of this? Yeah, so in particular, you know, one of the, one of the offerings that's become a lot more common, uh, amongst Cobalt customers over the last six or so months, is something that we call digital risk assessment, in which we're using open source intelligence techniques in order to identify leaked company information.
You know, sometimes we'll get calls from companies and they'll say, we think we're breached. Where's the data? Help us find out the extent of the leak.
Tell us where our stuff is and what's out there so that we can find it. Um, and that has become something that is very interesting to folks. You know, I think that throughout 2023, even beginning in 2022, and I'm still seeing some of this in 2024, although I'm optimistic for how the market hopefully is beginning to change.
You know, we saw lots of layoffs in security, lots of budget constraints. And what that means is whenever a CISO's gotta figure out how to allocate people and money and time across defensive measures, proactive measures, responsive measures, it's, it's just a different equation, uh, depending on how much money you've got. Uh, cobalt went and we published a report called the off sec Shift Report, offensive Security.
Uh, and we actually found that as a result of some of the layoffs and the budget cuts, what we observe organizations doing is shifting towards offensive security measures so that they can basically demonstrate and emulate what can an attacker do, and therefore be able to focus what defenses need to be put in place. Uh, so that's one of the things, uh, we observing my dog is very excited about this topic. That's a, we always needed the, uh, guard dog helping us too.
That's one of those layers of defense for sure. Okay. CISO whisperer wanna hear, what kind of conversations are you having about the response part of this equation?
Well, you know, and Steve just put a, a note in here in the, the chatter q and A that I completely agree with this kind of circles back to the comment you made a second ago or a minute ago about, um, you know, having to keep up with contacts in law enforcement. And that's that. I really do think most organizations, and so, you know, not to belabor this, but there are, there's not just haves and have nots, there's nos and no, not organizations.
Like there's some, there's a lot of organizations of very large size that are not using controls frameworks, um, that don't have a ciso. Some of them do have like somebody responsible for security, but still don't follow really any structure. Um, and, and, you know, so getting people to like, go through the motions of having these tabletop exercises, having an incident response plan, and then testing like right testing's kind of at the end of all of that.
Um, those are the conversations I think people are having because we're, we have this defi deficiency in backlog, not, not just like technical debt, but I think we also have kind of this knowledge debt where some of, of our peer, our peer professionals and our peer organizations are kind of running and they're doing the cool stuff up here. And we're, we're kind of all back here made to feel like we're supposed to be doing that thing up there, but we haven't done the foundational work to even just understand what we have. Um, I mean, just starting with inventory, right?
Some of the conversations we're having is like, let's figure out what you have, let's figure out then how to protect that and how to do instant response. And so there's this whole chain of leading up to that. But I definitely think that, you know, even in the absence of having, you know, don't let perfection be the, the enemy of progress or whatever the saying is, like, do so something.
And if something is, you know, getting some help or educating yourself on how to prepare for incident response, the first call you make to an IR firm or a forensics firm or a law firm or anybody should not be during an event. And I think the same thing with law enforcement. I think they, you don't want to start reaching out to them in the middle of an event.
You want to have a relationship established. And so you kind of want to have these soft relationships in place in a full circle around the business operations. Extremely good point.
We, we had a really great conversation back, I think it was ex episode 35 with Steven Renold Reynolds was with, uh, baker McKenzie, and he was the, we titled it, who you gonna call? Kind of the Ghostbusters theme, right? Who do you call when you have an incident?
And, uh, and, and Steven told us many, many things, one of which was don't, um, don't turn off your computers in the middle of it. 'cause you may break a, a, an encryption that's in process, never recover your data. But the other is, so many times, most of the times he's getting called without that relationship.
And so you're starting from scratch and they've gotta do just sort of a triage and figure out where you're at and what you're dealing with, and let's help you kind of stabilize what you need to do next versus we know you we're, we're aware of your business and, and how you work and some things that you do. And here we can pick up right off and execute on a plan. We help you put together whatever it might be.
I'll put the link to that episode in there, um, super fast and is one of the, one of the most interesting conversations we've had with someone who does incident kind kinds of response. Um, you know, let, let's kind of swing the conversation to what are the things, uh, we had a question around zero trust, you know, what are the things we can and should be doing in addition to an incident response and being prepared. There we go.
There's the, uh, the guard cat. What's, what's, what's guard cat's name Guard, cat's name is OIE Short for Odysseus. We're, we are a household with a lot of four-legged creatures.
Okay. We've got two cats and four enormous dogs. It's a, it's a pretty good life.
Be careful those sirens on that island Otis that way, but okay. Um, Yeah, zero trust, right? I think, I think, you know, really appreciate Steve, you know, your activity in our chat today and, and, and really encourage folks to also get in your questions, add your comments.
You know, I think with regards to zero trust, with regards to an inventory, as JJ was saying, do something don't like perfect to be the enemy of the good. You know, some of these established organizations with all sorts of legacy dependencies, all sorts of tech debt, like it is, it is actually not even reasonable to think we're gonna do zero trust a hundred percent perfectly. We're gonna do backups a hundred percent perfectly.
No, absolutely not. It's just not even possible. Honestly, I think that in many cases, to even get the 80% would be considered a wild success because of some of the complexity of this.
You know, what I recommend to folks is really to try and narrow down your scope, figure out what matters and focus there and other stuff is okay, you know, and for the stuff that really matters, uh, I wrote in the q and a in response to Steve, you know, in addition to things like backups, which are totally hard to do because of all of these practical and logistical reasons, you know, once you've got your inventory as JJ is recommending to us, make sure your stuff is up to date. A lot of the software vendors and manufacturers actually address security vulnerabilities. But you're not gonna get the advantage of that unless your patch is installed.
Um, additionally, you know, Microsoft has come under a lot of fire for not having M-S-A-M-F-A, excuse me, multifactor authentication on some of their executive accounts where, you know, my understanding is that, uh, you know, they're getting breached. 'cause folks are, guess what? Password spraying and compromising executive emails, uh, that's something that none of us want to happen.
And for, as for as long as we've been dealing with ransomware, we've also known that for important accounts, you do your very best to use multifactor authentication. Do you have to use multifactor authentication on, again, 100% is a fantasy, let go of the fantasy. If you can get to 80, phenomenal.
But please make sure your executives are using multifactor authentication for their email accounts. Just get it on the right 80. Yes.
And that is why I hate things like percent complete metrics because mm-Hmm. That, that's like project management tracking and KPIs, not security strategy. KPI mm-Hmm.
I don't care how, what your percent of users have MFA, are they the right users in the right apps that are MFA protected? Really good point. Really good point.
Talk about zero trust. I mean, you've been working with a lot of companies for, you know, this has been on our radar and there's no to Steven's question that he sent to us. There's no, uh, I'm gonna buy me one of those and install it tomorrow and we'll have us as zero trust, whatever that is.
You know, it's a, it is a strategy, it's an approach, it's a framework, it's a whatever. And, and I remember in, in early conversations is just figuring out what does it mean? How to, how would we do that?
And trying to work with your technology suppliers. What, how, how would you describe kind of the state of Zero trust today? And is it, is it effectively helping us with the ransomware challenge and other kinds of attacks?
I I, it, ugh, the state is, it's, it's in various stages, but I think, so the Zero Trust is a concept. I think it's very well developed, um, conceptually, like we understand conceptually what it should be. The adoption of it though, and the implementation of it has been more of a struggle because, so, well, there's just a lot of confusion.
A lot of vendors have just decided to slap that zero trust sticker on every damn thing they put out the door and just charge you 18% more for it tomorrow. Um, so it's causing a lot of confusion. Um, it, it, it is a real thing.
It's not a silver bullet. Um, but I do think it's probably the best opportunity we've had in a long time to increase security while decreasing complexity and cost and also increasing the, the user experience. Or another way to put that decreasing user friction.
So we can do it, we can be more secure, cheaper, easier, while making the users happier, um, with one type of strategy. Now, the challenge is picking apart what zero trust actually means for each use case and an implementation. Because, you know, zero trust, when we talk about micro-segmentation and workloads and data center is different than zero trust.
When we talk about land-based segmentation, which is different than we talk about VPN replacement solutions. Um, so, you know, sometimes one vendor might work in more than one space, but we, we all kind of throw microsegmentation around, but that's five different product sets. You know, privilege access management falls under, um, you know, zero trust solution.
So it, it's, there's a, it's a broad ecosystem because it's not just a product. Um, I do, but I do think that we can start, you know, and it's easy if you have even a, a gut check of what you think your biggest risk and exposure is. So if it's, you know, you have legacy VPN VPNs and easy, an easy target privileged access management remote access into, instead of letting people use, you know, go to my whatevers, um, and, and kind of pop up stuff here and there, or god forbid, remote desktop without some security controls around it.
Um, this is a great way to really not just check compliance boxes, but drastically increase security and make it so much easier because these, these zero trust tools that are purpose-built for these use cases let you be more granular in policies with without, without the crazy work, right? Like as a network architect and engineer, we're not talking about having to go in and like manually deal with access control lists across the infrastructure that's just absolutely unreasonable. So these products are designed to remove human error, streamline that, and I think if you pick the right product for the right use case, it does a good job.
I'm gonna start off with a point on which I differ from jj. Good, good. I think that the most interesting group discussions are ones where folks have differing points of view.
Uh, and what I've observed is that in some cases, zero trust does not mean ease for the user. Uh, there's an organization, uh, that I'm aware of that, you know, one of the things they were trying to figure out is getting all the employees behind Okta, you know, a single sign on, uh, in order to get to all of their different, uh, corporate applications on the internal network. Uh, and you know, there's this question that the organization faced, which is how often do you make them put in that password and the multifactor authentication?
Because you can imagine an employee, you know, they're trying to get to their HR system, they're trying to get to their, you know, Salesforce, they're trying to get to their whatever, you know, and every time they're like, oh, I gotta go, you know, find my phone and check the authentication code and remember my super long password. And it's a perfect example of zero trust, right? Zero Trust says, just because yesterday I confirmed that you are indeed Mitch Ashley, you come in and you tell me you're Mitch Ashley today, I'm gonna make you prove it.
Um, and so, you know, I think that there are some trade offs. Um, another thought that I have on Zero Trust is that, um, wait, Wait, hang on, hang on. Yes, please, please, yeah, take the next thought.
'cause I don't wanna lose that one. Yeah. I'm gonna counterpoint this or else I'll forget, but that might not be a good implementation of Zero Trust, because in a true zero trust ecosystem, what should be happening are those other integrated trust inferences and signals that are gonna tell that platform something changed and therefore triggered this either re off Revalidation or a step up, right?
If Mitch is still Mitch and he's still connecting on the same system in the same geography that he was yesterday, and that's not, that's not the parameters we need to set. Maybe you get a week or two weeks or a month if nothing changes. Yeah.
And there are no other inputs of, right? 'cause we can look and we can see our Mitch's credentials on, uh, on, on the, on the dark web for sale. So we have, this is where we like zero Trust is different because we should be able to, in this perfect world, take all of these different trust signals and then decide are we worried about Mitch still being Mitch or somebody else using his credentials?
And so that's a perfect example of somebody slapping a zero trust right. Label on something, but not following through with the vision of that integration. And it's hard with the products.
Yeah. It's the tentacles of it, right? Yeah.
You could take it and you need to take it more than just kind of check that off. We've got that now. Yeah.
But I wanna make sure we get to, to your second, your second thought that I interrupted. Yeah, Well said. You know, the other, the other comment that I have is simply the, you know, whenever we're looking to solve any of these problems, there's often a people, a process and a technology component.
And typically the technology component is gonna be a little bit useful, but not the entire thing. You know, when I am in zero trust conversations with folks so often, it actually goes not to sort of the details of the integrations and the signals, which I agree are very important, um, but actually having to do with the design and the architecture. You know, the, the few, the, the less complex any particular architecture is, the more convenient it's going to be in order to secure it.
Um, and, and what a lot of folks I think are facing are these very, very complex systems, um, that have just sort of organically happened over time. Um, you know, and, and, and it's almost like organizations that are newer, that are fresher, that are starting from scratch and have an opportunity to really lay out sort of a beautiful, clean architecture. You know, it's gonna be so much easier for that organization to implement zero Trust from the beginning than an organization that's, you know, 20 or 200 years old.
Yeah, totally agree with that. Good stuff. Speaking of organizations is a great question.
Um, how often do companies use Mitre attack framework? There are others. Um, JJ you wanna start us out on kind of what are some of the one, are some of the things that are already available to us to help us kind of put, I'm, I'm probably gonna punt that one to Caroline because I feel like she's probably more in tune with that.
I have had mixed, um, I have in my limited scope of dealing with that way more questions from the companies that I work with than I do somebody telling me they're using it and how they're using it. Mm-Hmm. Yeah.
Okay. In my experience, MITRE is something that more security mature organizations are aware of and using. I think it's, for the most part, not even on the radar for organizations that are really focusing on getting those 1 0 1 0 1 fundamental basics in place.
Um, and I actually think that Mitre is under leveraged. I think that Mitre can be used by many organizations as a lens to say, well, what are the techniques that we think are gonna be most, most relevant for us? Uh, and therefore, how might we, uh, adjust our controls accordingly?
You know, I actually think Mitre can be a really excellent tool, uh, for prioritization, uh, when it comes to where to focus, what to rank as high risk or as critical or not. Um, so, so those are some of my initial thoughts. Great question, and thank you, Mira.
Yeah. And I'll, I'll, um, so Mitch, I will add to that for Mira that mm-Hmm. Um, and Mitre has different frameworks.
So like they've, they've got the standard enterprise IT stuff. There's also OT frameworks if you go dig around in there that, um, that we've used that are good. So to Caroline's point, you know, I think, you know, saying that the more mature organizations are, are moving in that direction.
I have heard of some, like, pretty interesting use cases. So if you're at the point where you have your, you're doing your 1 0 1 level stuff, two, oh, you know, 2 0 1 level stuff, you've got your controls framework, there is interesting information in there that lets you tune all of the stuff. If you have the controls in place, then you can get way more granular with what you need to be detecting.
Because dementia's point from earlier, you know, we used to go defend, defend, defend, but when we're kind of realized that's sort of a fool's errand at this point, and detection and response are really where we need to prioritize. Not that we just don't care and we let them in, but when we're doing our due diligence on that and, and the defensive side, we need to know when they're in. And I think a lot of the Mitre attack framework is, is, is how to turn the knobs to make that happen in organization.
Interesting. Interesting. org, I don't, I don't have a link for where those frameworks are.
Maybe we can dig, dig a few up and post those in there. I wanna share as many resources as we might have. By the way, both of you feel free to share the links to your books.
Um, JJ has a great one on wireless, uh, security that, uh, it's extremely well done as, as well as Caroline's work. Um, another question we had is how do you approach setting up immutable backup? And this is, well, you know, one of the thoughts I have on this is, you know, you Caroline, I think you mentioned, well, first of all, I gotta test your backup to make sure it works.
I've had that problem before. Um, and also securing backup and multiple, not, not multiple versions, but multiple instance of it. So if this one did get compromised, I've got it in another place that you don't know about.
Um, so kind of a layered approach to thinking about immutable backups, um, since, since you were talking about backups. Caroline, why don't you jump on that topic. Yeah.
You know, the thing about backups is I think that the level of effort differs depending on where you are in the process. So if you're going from no backups to having backups, there's gonna be this whole setup thing. And I actually don't even think that's the hardest part.
I think setting up backups for the first time is not the hardest part. I think making sure they happen as things change is the hard part. And I also think that testing it regularly is the hard part.
Um, and let's, let's kind of, you know, address those two, uh, one at a time. So thing one, assume you've gotten past the point where you've gone from no backups to some backups. You've got something in place and stuff is just gonna change.
And how do you stay on top of that? And that, I think, is, um, gonna be very organizationally specific. You know, I think from a technology perspective, what a lot of the backup technologies are doing these days is, you know, they backup up everything once, you know, and then every day, every week, every month, they're backing up the delta, what did change?
Um, and so I think that there is somewhat of a technology, um, kind of built in, uh, process there. But, but the problem is, you know, if you're backing up thing a 'cause thing A is where all your important stuff is. What if at some point in time, some business or technology executive decides that they're gonna put some really important stuff in thing B and thing B is not connected to the backup system.
You know, this is, this is the bit where, to the extent that the CSO has a seat at the table and can get a preview into what direction the organization is going in, that CSO will be more empowered to ensure that as the business changes, as the technology changes, that the, that the security and IT controls, uh, can shift accordingly. You know? And then the other bit that I think is, is really the hardest part is, and, and frankly, the most important is just testing those backups.
You know, how do you get it so that that is just a little part of someone's job on the regular, you know, how do you get it so that someone, you know, whether they're a full-time employee, maybe it's an outsourced project, every month is just going to check, is this working? You know, the way that I think this actually happens practically is in tabletop exercises. You know, I think folks who are putting together an incident response plan, trying to mature their incident response, uh, function, uh, they'll do a tabletop exercise.
And if, you know, ransomware makes an appearance and that tabletop exercise, that's the point at which they check. Uh, and I do think that, uh, it's a great idea for organizations to conduct tabletop exercises, uh, on a regular basis, you know, depending on the organization from once annually, uh, to once quarterly. You know, I'd, I'd love, I'd love to turn the conversation to some of the evolving threats that are happening around ransomware.
jj, when we were, uh, just logging in, you had mentioned about, just happened recently around health and Human services and United Healthcare, where, uh, an attack actually stopped the flow of money, stop the flow of payments to providers. And for some period of time where now you're causing not just pain to the, that organization, but all the, the ecosystem of networks that they're connected to. And it, the White House got involved, Congress got involved.
I mean, it was several. And even to the point of saying, you know, st start paying, making interim payments, you know, you'll get everything else back up and running. I don't know of another instance like that, but that, that's taking down a whole ecosystem, if you will.
Yeah, I think that's interesting. So that was Black Cat, or, um, I we're calling them ALF V, but I think their intention was for that to be a capital V, which is like an upside down a and it'd be Alpha, but they we're just gonna maybe call them Alpha V and annoy them. Um, I think that's interesting because the whole, yeah, the whole ecosystem, because, you know, for us, this is a threat actor.
They're criminals, it's a nuisance. Um, for them, it is their business model. And for, so what, what happened, suppo supposedly, presumably here, is while the government was sort of taking down, and not just our government, several governments, several places were kind of taking down different ransomware groups, um, and operations Black Cat or, or, or Alf V took $22 million in ransomware payment during that, and then just pieced out and did not pay the affiliate that actually infiltrated the organization.
And so this is an interesting model because what it means immediately for the domino effect of everybody in that ecosystem is we have the ransomware opportunity, okay? So that got paid, but that organization that infiltrated that was the partner and it was supposed to get paid is who got in, which means they probably have other data and they possibly have some persistence. Uh, so if they took other data, now, now we get into extortion opportunity.
And maybe the data that they have wasn't, um, maybe it was the original breached organization's data. Maybe it was partner organization's data. Maybe it was something down the, the chain, right?
So this blast radius just got a lot larger because if they decide they're due their payment, they're not getting it from Alf V or Black Cat, they're, they're probably gonna go explore that somewhere else. So I don't think this story is done with, and I think the other fallout, so that's kind of the immediate thing these CISOs are gonna be dealing with. The other kind of domino effect of this later is, $22 million is a lot of money.
This will substantially change the relationships within this business operation that is ransomware. And because of that, we might see, we might see a different financial model for them moving forward. And I don't know what that's gonna mean for us.
Yeah. com. It, it, it impacted, uh, medical claims for about 90 900,000 physicians, 33,000 pharmacies, 5,500 hospitals, 600 laboratories.
I mean, That's, and Mitch, what, you know, the numbers I heard were like, it impacted one third of Americans in the healthcare system. Wow. Wow.
Yeah. I mean, if it's, it isn't just, are you UnitedHealthcare, you know, coverage, it's impacting, you know, if your Yeah. If your pharmacy is not getting paid and can't operate, you know, whether they're using your claim from UnitedHealthcare or Cigna, it, they're still impacted.
Yeah. Yeah. Every, every part of our lives are so totally integrated with and intertwined with technology that we're effectively all impacted, uh, when these kinds of things happen.
You know, and I think that, uh, one of the interesting things that, uh, I've heard a lot of discussion about recently in kind of CISO circles is, uh, SEC rulings, you know, um, and, you know, it's, you know, there, there's a, there's a perspective. I think that the SEC is kind of like trying to do the right thing. Uh, and using SolarWinds as a bit of an example to say, organizations, your security posture represents meaningful impact to your shareholders.
Uh, and you need to be serious about that kind of responsibility. You know, why is it that a, an organization that a healthcare organization doesn't have sort of basic security controls in place? 'cause it hasn't been prioritized enough to get the funding to do so.
Um, and so it's, uh, it's really, it's really quite, quite fascinating. Um, I wanna highlight, uh, a question that, uh, we've been talking about, um, in the, in the chat. Let me see if I can find it here.
Um, you know, uh, Steve was saying, Hey, there's all sorts of credentials on the dark web, you know, at any point in time, you know, you actually don't know if the person you're communicating with is indeed Jennifer Manila, Mitch Ashley, or, you know, some sort of bad actor who's taken over their account. Uh, and so, you know, I've, I I've, I've, I've written, uh, a response and wanna also just highlight it here verbally. You know, I think we can assume at this point in 2024, that username and password is simply not enough to ensure that, you know, someone is who they say that they are.
You know, MFA is absolutely important. The other thing that I think is so interesting is I think that the three of us, and a lot of the folks here joining us for the round table today know that everyone and every organization is getting attacked all the time. That's just how it is.
You know, but for folks who maybe don't work in tech, folks who maybe don't work in security, you know, that that is still something that feels like an outlier. It feels like an exception, you know? And, and so I think to the extent that, you know, we can communicate to our mother-in-laws and our, you know, 9-year-old children, uh, that actually everyone's trying to scam you all of the time.
You know, and the, and the two particular awareness, uh, things that I, that I recommend are thing number one, you get a request. It's urgent. You know, it's pretending to be Amazon, it's pretending to be your mail carrier.
It's pretending to be your company's HR team, or, or whatever it is. If it's an urgent request and you feel unsure, try to contact them via a different method. They contacted you, they contacted you via Facebook.
See if you can find that person's phone number. Give 'em a call. They contacted you via email.
Uh, see if you can message them, you know, via, via, via some platform. Uh, so those are, those are some thoughts that I have, uh, in response to, um, Steve's, Steve's recent question. Thank you again, Steve, for, for your engagement with us.
And, and Caroline too. I think, you know, you were, you're kind of going down a road, and I wanna pick up the ball and carry it a little bit further because we're talking about, you know, blast radius and who's impacted and, and this kind of ultimately possibly hitting home with a lot of us, just not as technical professionals, but as humans that are living, um, in this community. But I think there's, I think the one, the other conversation to be had is that most of these organizations, when they have a breach or they're paying ransom, they're passing that along to the consumers ultimately.
So, you know, we're we, I think we hit like Covid where we saw a lot of price increases, but if you notice, that didn't come back down. And I think what we're kind of like starting to understand and see is the vast majority of organizations, a lot of SMBs won't make it through a major incident if they've lost, uh, money. But the larger organizations are just gonna start charging you more.
And so ultimately we do all have a stake in this, and it does come back around and impact us one way or another, even if it's indirectly. Yeah, I agree with that. And, um, you know, I think, I think it's such a beautiful point to highlight, which is the reason stuff is insecure is because we built our world to be so interconnected.
And there are, there are so many beautiful benefits and advantages of being so interconnected with each other, of, of each of us being so kind of dependent on the various ecosystems and, and all the things that we interact with every day. Um, and yeah, it does, it does affect all of us. Uh, and it does come down to ultimately who's paying for it, uh, the end consumer.
You know, these are, these are, these are big, uh, financial amounts. Um, so while I think it's fun for us to disagree on some points, I couldn't agree with you more on that one. Mm-Hmm.
You know, hey, I wanna call a shout out to Elizabeth V talk about being interconnected. She's been pretty transparent about how this, uh, UnitedHealthcare attack her, her pharmacy, and we were talking about the payments not rolling down and impacting her pharmacy and all that kind of thing. You know, it, I I, one of you, I think mentioned ultimately this affects us, right?
This affects people, customers, users, our data. Not just our data, but being able to get medicine. Can you imagine if you might've experienced like what Elizabeth did of, of, you know, I can't do that transaction now at my pharmacy.
I have to come back, or I have to go to a different place. Or can I even transfer my, my, uh, prescription or, you know, has that been compromised? What, what is going on?
So yeah, Elizabeth Are, are expensive. Mm-Hmm. You know, and some of them are lifesaving medicine for people.
I mean, it's just, yeah, it, it's unbelievable. And I think we're gonna see an interesting twist coming up. So today, So fourth today, uh, CISA published the, the draft proposal for the Circillo reporting rules, which is, oh God, what is it?
It's the something for it. It's labeled as critical infrastructure. Mm-Hmm.
Um, but it's not actually just critical infrastructure. It's, um, your nor the normal things you would consider to be critical infrastructure, like all of, you know, utilities, schools, government facilities, large public venues, blah, blah, blah, manufacturing, transportation. It's also everybody who provides products, hardware, software or services, including cloud services to those organizations.
So they basically just put into scope every based company that's not a yoga studio or a restaurant. Like, uh, it's, it's unbelievable. Um, so we're talk, you know, I saw, uh, Mitch, your, your post in the chat about the at and t breach, and we've talked about some of the other things.
So under the rule as it's well proposed, the draft rule, um, and we have 60 days to give feedback. So if you have strong feelings about this, I'd encourage you to go download that. I'll, I'll put a link in.
Um, but under those rules, CISA is basically building a national incident database at, in real time as it happens, which is why the turnaround for this reporting is 72 hours for an incident and 24 hours if you pay ransom or any part of a ransom. Um, so they want to kind of be a partner. It's definitely not meant to be punitive.
It's not an an SEC style of thing. And they want all of the data that you have. You've got packet captures, they want packet captures, you've got malware samples, they want malware samples.
You've had in exchanges with the threat actor. They want copies of that in the original format, logs, um, endpoint, a list of the, the products, the versions, the patches, and the configurations. It's, um, it's a lot of information that they're gonna be taking.
And so the Microsoft, thank you so much, Caroline, for putting that. Uh, Caroline, just put that in a chat for you guys. Um, you know, all of these big breaches, what we've seen, like the, the cybersecurity review, your review board's been working on the at and t, like all of this would, would, my understanding is as it's written right now, would fall under that and these organizations would have had to, within 72 hours, engage CISA for assistance.
Do you know how they're planning to use that data? They want to be able to, you know, I'm kind of thinking of it as like a mega database, right? And sim, so they want, I think they wanna do a few things with it.
And actually, if you read the document, they do a really good job explaining the thought processes. Like they've thought this out pretty well. Um, but it is broad reaching.
Um, so I think they want two things. If somebody is in the middle of an incident, they want to participate as much as that organization might need help getting help from whoever they need help from. Um, and I think they also want to know if there are vulnerabilities that could help protect other organizations if there are indicators of compromise that can be shared securely within that ecosystem.
And so, you know, it kind of is meant to, we've got like industry ISACs and we've got, you know, federal this and, and this, or, you know, industry based groups, uh, especially around like utilities, um, or all of critical infrastructure. But this is meant to just sort of be a strata across all of that so that we can all learn and benefit when something happens over here. It's not just all the banks that cluster together.
If CISA has that information, they can, they can disseminate it to the right people anonymously and make sure that a much broader audience is protected. I, I wonder, I I may be going way, way down the road with this. It seems like you might all but also be able to connect the dots or anticipate what the dots, uh, you could connect based on a breach.
Like, here's a Microsoft breach, here's what it was, here's the kind of data, here's where we know it is now. Let's look in our database of other companies we know have had been attacked and breached who might also be susceptible. So I don't know if you can be proactive, but at least understand the full scope of what some of those attacks compromises might be.
I think it's a fascinating shift for so long. CISOs experience breaches, and no one ever talks about it. And in some cases, when the breaches are involved in, you know, different lawsuits, different filings, they're actually not allowed to talk about it.
You know, this is, this is a tremendous shift in the opposite direction. I mean, my experience is that whenever any big breach happens, you know, CISOs talk privately among themselves and they say, yeah, well, you know, I can see how that would've happened. 'cause we're always asking for the right things and we're never getting it.
And, you know, I I, I think there's something really awesome about having a public thing that says, you know what? This bad stuff is happening to everyone everywhere all the time. Um, rather than it just being this hidden away shame filled thing, now there's gonna be a tremendous amount of overhead as we've discussed, right?
It's gonna be tremendous amount of overhead for the organizations to complete the notification appropriately, you know, when organizations receive it in order to anonymize it and all this stuff. But I think the shift from secrecy toward sharing, because everyone's going through all the same stuff across the board, um, I actually does, I, I I think it does have potentially very positive implications. I knew it, AI had to come up.
I was just waiting to say, AI hasn't come up yet. And you, You guys all, I filled your bingo card for you now that was in the middle. Okay, so we, we have seven minutes left.
Um, we don't wanna push it too far and hit the top tower, but okay. Take us down to that path and maybe we'll pick that up on another Seesaw talk here. But go ahead, jj.
Oh, there's not a path. They just mentioned that they're, they're actually going to use AI based analytics to parse that data and make something useful out of it. Um, so they're, they'll use that.
They're also gonna be publishing aggregate reports quarterly for everybody's consumption. I think that's a great use case for AI, to be perfectly honest. Yeah.
You know, at Cobalt or an offensive security provider. Uh, and kind of the most common type of offering we provide is a pen test. And I'll tell you what, pen testers love to hack.
They do not like writing reports. And so we're leveraging in-House private AI in order to support our folks in writing really excellent reports. Uh, and they love it.
It's really fun. Um, you know, other ways that we're seeing folks, um, you know, we've got customers coming to us saying, do a pen test for us on this chat bot do a pen test for us on this, uh, LLM. Um, I'm actually working on a course, uh, that I think will be published near the end of this calendar year, uh, via LinkedIn learning about application security and artificial intelligence, uh, which turns out to be like kind of this really fun, kind of meta at some points kind of talk, because of course, AI systems are themselves applications which are vulnerable to security.
Um, and so I just kind of take this multidimensional look at it. What are the risks? What are the advantages?
What can we expect to see changing? Um, I think it's a really exciting topic, uh, and would love to, would love to join an AI talk one of these days with, with you folks. That would be awesome.
Let me plug, um, Caroline mentioned it, but if you guys have the, um, the premium LinkedIn, you have access into the LinkedIn learning, and she's got several courses there. So definitely go check that out. Thank you.
I wanna mention you Have great energy. Like who wouldn't want to listen to you to learn? I'm gonna go watch them too.
Um, I, I totally agree for both of you, both of you, absolutely. Um, I wanna ask, we would love to have folks feedback on our conversation today, this topic, maybe things we're not talking about that we should have. Um, there's a great, uh, number of handouts.
Cody's pointing out Cody's behind the scenes. He's the, he's the, uh, the wizard behind the green curtain there. And, uh, but there are a ton of handouts and we put mentioned a lot of links and things like that that's available there.
And, uh, we will, Cody, if it's okay, we'll send a, an email, both of the recording and also, um, of those links to those handouts, um, in an email. So everybody that will get that, both who is it who attended and also who registered, but may not be here. So I think it's been a great success, thanks to the two of you.
And, uh, it's, it's just so much fun to be part of it, it with you. And, uh, I know my many, many thanks to both of you, wherever you are on your screen. So my aunt and my co-host and, uh, great friend Jennifer, jj, and to my friend, and not co-host, but participant panelist, uh, Caroline, it's, we need to do this again.
So maybe we think about what we might pick up on for another live round table. Let us know again in your feedback. We hope this has been super valuable for you.
We've covered a lot of territory, but I think we've given a lot of, uh, not just pointers but hopefully useful resources to go after and, and kind of check into later. And, uh, Caroline put her LinkedIn, uh, link in there. Uh, jj you're welcome to do that if you wanna do that for yourself and for, um, uh, for your company, for vision security.
And of course, you know, as Techstrong, I'm CTO and also Principal Analyst with Techstrong Research Security Boulevard is where a lot of the links that I was posting, not just 'cause I only searched there, but happened to be topical for some of our conversations. So I wanna shout out too, too, and I'm not gonna name everybody here, but Elizabeth, amazing. Um, let's see, who else?
Steven, fantastic. Roseanne, et cetera. Mira Mira.
Yes, absolutely. Raymond, another, another key participant today. I'm missing some people here.
I can't scroll fast enough to find everybody. But if you commented and if you asked a question, thank you so much. You know, hopefully you see how much we value Diana, appreciate it.
Uh, value your, uh, Satish you as well value your conversation, your questions, um, 'cause we really do guide it based on you. So it's all of us having this conversation, not just three talking heads, which can be interesting, but it's even more interesting. Yeah, you guys make it so much more fun.
It's, well, we'll have another, uh, CISO talk scheduled, uh, live round table. In the meantime, go to Textron tv and look under the series tab. Or if you just scroll down, you'll see CISO talk series, or JJ and I are talking to amazing people, almost as amazing as Caroline and, uh, having great conversations.
And we hope everyone would be back. Please join us there on those recorded sessions and, uh, and we'd love your feedback, fill out that survey. So, any passing thoughts, parting thoughts before we leave?
Uh, JJ or Caroline? JJ first, It's just a rollercoaster we're on. I'm interested to see where we end up.
I just wanna kind of, uh, bring us back to the connectedness, the interconnectedness of all of this, you know, and at the end of the day, like technology was made by humans. It can be secured by humans. Like we actually as a human race have the ability to do good.
Uh, and I'm really looking forward to a bright future. Absolutely. Well, thank you everybody.
We will see you next time. Check us out on Textron tv under the series tab for CISO talk. It's Mitch Ashley, CTO and uh, analyst with Techron Research.
We'll see you again soon. Thank you for joining today.




