Cybersecurity Conflict Russia and Ukraine – Paul Caiazzo, Avertium
Paul Caiazzo, an advisor to Avertium, explains how the cybersecurity conflict between Russia and Ukraine is impacting the average organization.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Paul chaazo who is a advisor to advertium and we're talking about what's going on with the whole Ukraine Russia cybersecurity. Conflict Paul. Welcome the show.
Yeah happy to be here. Thanks for the time Mike. So early on we were supposed to be by now having the equivalent of a cyber security nuclear winner and it doesn't seem that that's quite what has happened.
But there's definitely a lot of conflict still going on. So why didn't this escalate beyond what we thought it was going to be and where are we now? Well, that's a really good question.
I think actually it's still May so I wouldn't say that we're you know behind the worst potential outcome here, but I think geopolitically if you look at what's happening between Russia and NATO, you know, and the rest of the world there's there's certainly a chilling effect from from the perspective of Russia from a aggressor standpoint on what they may expect in terms of retaliation to spilling Beyond Ukraine's borders. And so I think that's primarily why we're seeing the activity stay with within Russian Ukraine. We have seen however an escalation between those two actors both from Russia taking a more concerted approach towards disrupting Ukraine's military efforts as well as Ukraine taking a defensive stance in bringing some of their own cyber Weaponry to Bear against the Russian aggressors.
So it's been interesting to follow certainly from a cyber professionals perspective as you see kind of then, you know complexion of Modern Warfare playing out on the battlefield and where do you fit in this conversation and Are you hearing from other cybersecurity professionals and your customers about what are they doing to respond if anything? Well, I think there's a several ways to look at that first off. You know, what a Verdian does is provide 24/7 monitoring for threats and incident response when those threats are discovered.
So, you know beyond anything else we must be informed in terms of what adversaries are deploying on the Cyber Battlefield throughout the world. And so we've had to stay in very close touch with respect to what new weapons rushes developed and brought to bear some of those include hermetic wiper ghost wiper a bunch of new ransomware that Russia developed and released earlier in the year specifically against Ukraine. So ensuring our customers feel confident that they're protected against these these new approaches by Russia in the event that they should still over and there's really good reason to be concerned about that specific case.
You don't need to look too far back in time to 2017 to be not pet yet incident, which was actually I think the most damaging cyber security incident in history to date which was also a situation where A brought a offensive capability to Bear against Ukraine, which looked like a ransomware attack that in reality. It was just simply destructive attack that completely crippled, you know, not just Ukraine, but many many organizations around the world. I think Maersk the large Multinational Global Shipping Company lost almost a billion dollars in responding to the not Pitch instant and they certainly weren't the target of it, but they certainly felt the effects as well.
So it's it's always good practice just to be aware of what potential outcomes could be in the event that you know mistakes happen or you know, an attack spills over it's intended target base. is one of the downstream impacts of all this is that there are mere rushed by nation states to advance their state-of-the-art of their attacks, especially in the case of Russia and also in the case of Ukraine and will that therefore then eventually people will study those tactics and start using them by, you know, your average every day cyber criminal and the whole state of the offense of weapons will increase Absolutely. Yes, so it is 100% in arms race.
You see not just the nation states sort of developing new capabilities against one another we certainly do the same thing here in the United States. We have a very well regarded at least from capability standpoint offensive capability within our nation's National Security apparatus. Probably the best in the world.
And so we continuously develop new things our adversaries do the same. So when you see that sort of that capability developing on a global scale, it does fill down into the cyber crime ecosystems probably know we're more than Russia actually simply because Russia cyber crime is not just sort of, you know, taking a blind eye and looked at, you know without much regard but in some cases is actually quite sponsored by you know, government activity and you can see traces of Russia's intelligence apparatus within some of the ransomware as a service ecosystem. So tooling that that is developed for the purposes of Russia's nation's data adversarial capability you UC deployed in cybercrime operations as well.
I think some of that can probably be tied back to sanctions. So if the Russian economy has no legitimate ability to fund itself with international funds why not illegitimate ways of funding itself through things like ransomware that's a little bit of speculation but it doesn't seem like too far a bridge and I would expect similar activity to occur in other sanctions countries. So North Korea, they're widely regarded as one of the most capable cybersecurity adversaries on the planet and their routinely accredited with the theft of cryptocurrencies directly and some of their capabilities that has brought to bear again through some of their apt groups like The Lazarus group.
You definitely see filtering down into cybercrime ecosystems as well Iran's in a similar boat and you see other sanctioned areas the world trying to develop capabilities similar to that so that as well as another one that has an advancing cyber capability, but there's definitely a lot of internal linkage between cyber crime and just nation state activity. Large do a lot of those nation-states trying to make it look like somebody else did it and is that part of the heart challenge of figuring out who did what to whom because everybody's getting pretty good at spoofing each other. Yeah.
That's a really really insightful question. And it's absolutely the case that attribution is is very very difficult. It's really only the domain of the intelligence community in military to really truly attribute to a specific actor.
There are intelligence organizations the private sector that do a lot of work around attribution, but even that they are loathe or slow to accredit Any Given attack to a single nation state or individual threat group because it's dangerous to make those attribution claims to your point. You know, if I were China, let's say and I wanted to create a little bit of you know additional tension in this situation between Russia and the West wouldn't it be potentially interesting strategy to deploy some of my own Chinese capabilities against a western western interests making it look like Was Russia and certainly that's possible to do certainly it's happened before that sort of false flag type of attack is something that we've seen happen in the past and in situations like this where they're you know, again geopolitical tensions are so high it would be in the interest of a group, you know, two, you know, again make it look like one of their competitors on the global scale was actually responsible for attack that they weren't they gain a benefit of you know, the potential reaping the words of whatever attack they directly impacted them also the adjacent benefits from a geopolitical diplomatic standpoint as well, which are Super interesting definitely happens. We also saw the US and its allies launched this Shield program and they were inviting people to participate in there.
Is that working? Are we getting better defenses as a whole or too many organizations kind of still out on their own and that really understanding how much risk they have. Well, I think at large this cyber security industry doesn't do as good a job at sharing information as it could and that's when I think the fundamental problems that are really endemic to the entire, you know issue with with cyber security in general is that you know, each individual organization generally has to learn how to defend themselves against you know, some specific threat on their own where has to develop their own protection mechanism on their own employee themself if information were more broadly shared like what you see happening with, you know, both sisa the cyber security information security agency and also nsa's collect the defense program, the more participation there is in that with some prescribed outcomes.
I think the better because at the end of the day again, if there are, you know, if there's information to be gleaned from an attack that can be the high tide that rises All Ships and and provide better Collective defense for other organizations. I personally believe it's in the nation's National Security interests to promote that Activity, but one thing I've observed is that if you look at the vendor ecosystem, let's take some of the the major Sim or EDR vendors or other preventive control vendors. Some of their competitive Advantage is their content right?
So if they know more then they're you know, potentially more competitive against their, you know, vendor competitors, but that knowledge internet itself could be, you know again of National Security interest. And so if that's if that's how the industry views this information and it's not going to move towards a more open sharing sort of model and I think that will inhibit some of our ability to defend ourselves. I think we need to be better at that both sharing intelligence, you know, like iocs IP address is Hash is domain names things like that.
Actually we've gotten better as an industry sharing information like that. But the undercurrent there is that that intelligence is somewhat less valuable because an IP address, it's very very easy for a nation state actor even a cyber criminal to spin up new infrastructure with new I Dresses new hashes new domains, that's all very easy. What's more difficult for them to change is their behaviors and it takes a more conservative researcher to better understand adversarial behavior.
And then there's not really an existing framework for sharing that information broadly like what you might see within, you know intelligence sharing that relates to IP addresses things like that. So advancements there would be a big benefit to the industry and I think the shield program is a step in the right direction, but it requires more broad participation and really, you know, my opinion more of an open mindset to a through with respect to what kind of information can be shared should be shared needs to be shared when there are critical incidents to happen. Are the bad guys getting better at sharing seems like they share all the time.
Absolutely they are and that's one of the the other big challenges within this industry. So, you know, we're fortunate as an industry and that we've got a bad guy. We've got an adversary that we can you know rally against as we do have common enemies in many cases, but our adversaries are definitely very good at working together.
I think the ransomware is a service ecosystem probably is a great Testament to that where there's a handful of, you know groups that there's a lot of overlap between the participants in each of those groups that might be named that you might have heard of black boss does a recent one our evil or evil Conti the big names. There are operators within each of those groups that kind of float between them. And then there's an affiliate Community.
That's just underneath them. Those Affiliates are not Tethered to one of those answer more organizations. They can work with any of them and many of them do and so when there's that level of sharing of talent amongst these cybercriminal ecosystems, then their outcomes are better from their perspective.
So they Or more successful because they share more Talent they share more research. They share tooling a lot of cases as well with you know, again the tacit underwriting of the government that doesn't seem to care that these groups work together in support of you know, again disrupting Western interests. So you've got collaboration at the Cyber criminal operator level, you've got collaboration with a government that you know, again May benefit from that illicit activity and that sort of collaboration kind of doesn't exist at the same level on the good guys side.
So that's that's a problem that again we definitely have to solve we've seen a lot of quote unquote volunteers that are coming to the aid of Ukraine is probably volunteers coming to the aid of Russia here as well and Is that a good thing? Because you know last time I checked, you know, eventually mercenaries got to go find something else to do after the war is over. So are we kind of creating this primordial soup of something that may bind us in ways we don't imagine in the future.
I think we are I think the I think Ukraine's it Army is playing a little bit of a dangerous game personally and any hack to this that gets involved in a situation like that is, you know, potentially playing with fire and I say that because you know, when you're operating against a nation state nation-states do not have some of the restrictions especially, you know, again, this nation's adversaries those sort of governments don't have the same set of restrictions that you know, we might and so when you look at some of the retaliatory activity that Russia has taken against their dissenters even internally it includes, you know death and so a hacktivist taking action against Russia needs to think very carefully the consequence that they're willing to accept for both themselves and their family in the event that their activity were to be attributable because you know, certainly they do not take kindly Russia does not take kindly for people, you know, kind of getting in their business and this is just a situation where an individual who Frankly has no concept of exactly what they're up against with respect to Russia's not just cyber capability but kinetic capability to take action in real life. They're potentially not taking that into account when they're you know, doing their their thing, you know, that's that's behind the anonymity that the internet provides that anonymity might not be as you know, sort of bulletproof as one might think and I personally be quite careful about bringing offensive capabilities to bearing that's a nation state. I mean the United States it's illegal to do even if you're doing that against, you know, again a nation's our nation's adversary.
It's it's a it's a violation of the you know, computer problem Abuse Act. And so, you know that again has to be considered when anybody's thinking about this sort of thing not even a mentioned sort of the other stuff that you talked about what happens when these operations are over, you know, perhaps there's some skills that we're learned in the process of you know, operating in one of these activist groups, that could be brought to bear for legitimate purposes, you know red teaming Or penetration testing or even just simply better defending on an organization Hands-On skills certainly helps with that. But again the consequences there are very very high and I'm not sure that that risk analysis has been completed by everybody participating there.
It seems like to me at least that the biggest threat here is just collateral damage. A lot of these attacks that get launched between rushing green aren't contained by a physical border. So during organizations need to kind of monitor what's going on here simply because there are new attacks being launched.
They may not be them directly, but they sure can land on there systems. So, you know, how much or how closely should they be paying attention to what's going on here? Yeah, I think there's that aspect of it just the interconnectedness of systems also is something to think about where an attack against, you know, someone that happens.
Let's say a Ukrainian business that happens to have a business relationship with other European counterpart a crippling incident, you know within that Ukrainian business could ultimately become, you know, again an instant for that partnered or Allied organization and I think what we're really speaking to there is just supply chain and we're seeing that at the global level right now anyway, so, you know with with so much activity and Ukraine crippling Ukraine's businesses, especially the agricultural businesses. It's very difficult for the rest of the country to you know, or the rest of the world to continue with Food Supplies in the same way that you might have prior similarly within Russia, you know, Russia gas and oil supply much of Europe with its energy. And so this these incidents these cyber incidents that are attacking some of those organizations, you know perpetrated by Ukraine could be impacting, you know, supply of oil and gas to The role as well, so it's not just necessarily the Cyber impacts of this have to be thought through as it relates to Crossing Borders or crossing organizational boundaries, but it's the real world impact of you know, supply chain restriction supply chain issues that will you know, be felt that are currently being felt and that doesn't just apply to this conflict either that would apply to any relationship any business relationship that one might have if you look at you know, some ransomware instance that have happened in the past we've seen an organization be targeted by romance somewhere be ransomed be crippled in the process and then ultimately their partners that might surround them as part of how they go to market have felt the effect of that as well and I've had negative in a financial impact as well on them that results in litigation.
So, you know again there's there's more to it than just a cyber impacts. There's always going to be a real world, you know, sort of impact that's felt by individuals like you and I in terms of rising costs or in terms of just inability to access goods and that also has significant impacts on the businesses that support Us hmm a lot of times I still see organizations that are trying to fight the fight themselves. They're relying on their internal it or cybersecurity staffs.
Is that feasible in this day and age or is it just a recipe for eventual failure? Because we've entered some new phase where you just really can't go It Alone. So I think it depends upon this the size and maturity the business and also probably what industry they operate within, you know, certainly some of the very large financial institutions that we work with have a high degree of capability internally, but they probably also have a hundred million dollar security budget very few organizations can you know claim that level of investment into cyber security alone?
Not even just technology, right? So if you're a smaller organization and by smaller, I mean anybody but the actual biggest you probably need to have a network of support. That's either providing you a service or helping you make the right choices in terms of how to manage between your organization.
I don't think it's really possible for anyone to go it alone. And even that very large financial institution example that I gave you, you know talking to them specifically about how to solve some, you know, very specific operational issues that they happen to have and so even they most people fun to organizations the world realize that they've got to have outside help same goes for Verb our Nations again intelligence Community. There's a lot of partners that support them from the the private sector and that would go for any other industry as well.
So yes, I would say anyone that has you know anything to lose which everyone does needs to consider whether they're internal staff is sufficiently not just capable not just train but enabled do they have the right budget. Have we give them the right remit do they have the charter to be empowered to actually protect your organization? And if they don't then, you know, some different questions have to be answered with respect to doing to increase funding do we need to bring in you know, better providers or an Outsource partner that might help us solve this that is expert in this because frequently when an organization tries to do some of this stuff themselves internally, they'll have generalists who have a broad IT background, which is great.
You need to have you know, broad perspective in terms of Technology, but maybe lack the specific cyber security expertise or just, you know, see time and And black, you know again some of that unique I guess capability or mindset that comes from having it run incidents having a dealt with incident response and threat hunting. It's a very different sort of scenario than you know, managing an outage and sort of your general it shop takes, you know, like I said experience in Sea time and muscle memory and generally you don't get that without having had gone through the trenches a few times and typically in internally staffed organization like that hasn't done it. All right function you heard in here first might be time this circle those wagons Saint Paul.
Thanks for being on the show. Yeah, my pleasure. Mike glad to be here.
All right back to you guys in the studio.