Global Cost of Ransomware Report with Trevor Dearing
Trevor discusses the key findings of the Global Cost of Ransomware Report. The findings reveal the true cost of downtime with a ransomware attack, how many organizations have adopted AI to fight these attacks, and misplaced confidence in security controls, just to name a few.
Transcript
This is Techstrong tv. Hey everyone. Welcome back here to Techstrong tv.
Our next guest is Mr. Trevor Deering. Trevor is Director of Critical Infrastructure Solutions over to lumio.
Let's welcome him. Trevor, welcome. Thanks for coming on Textron TV today.
How are you man? I'm very well, and thank you, Alan. Thanks for having me on.
My pleasure. So, Trevor, director of Critical Infrastructure Solutions. That's a mouthful.
Tell us a little bit about kinda what your job role is, what your duties are, and then if you don't mind, tell us a little bit about yourself, how you came to be the director of critical uh, infrastructure solutions here. Yeah, so, so I, I've, I guess, worked in cybersecurity now, 37 years, probably in this, in the IT industry, 43 years. Um, right back to sort of installing some of the first firewalls in, in uk working with some of the early AV technologies.
I was an engineer primarily. Mm-hmm. Um, and then I suppose sort of worked my way through, you know, through various roles within the, within the industry.
And one of the, you know, one of the key things that I guess in started to interest me was what was happening in some of our more critical environments. So, you know, electricity, grids, healthcare, all of those sort of things. And I've worked for a number of vendors that everyone knows throughout the years.
Um, and about five years ago, an opportunity to join lumio came up and it just fitted in with, you know, with a lot of the things that I was interested in at the time around, you know, protecting those, those parts of critical infrastructure. Absolutely. And look, you know, I, I think especially during covid, um, the whole idea of our critical infrastructure being vulnerable, and also the whole definition of critical infrastructure, right?
I, I've been in security 25 plus years myself, I tech 30 plus years. It used to be critical infrastructure US was the electrical grid. You mentioned it right here in the us we've got NERC and FERC and all of that.
I've worked with that. And um, you know, certainly public utilities was thought of as critical infrastructure, but we found out during COD, healthcare, our healthcare system is critical infrastructure, our supply chain, right? For things as these days as simple as toilet paper at some level is critical infrastructure, right?
Protecting those supply chains. And, and so to me, the mission has, ooh, mushroomed. And when we talk about, you know, protecting critical infrastructure, where it is, what it is, what it does, and, and what do we have to do to protect it, um, I'm cur we we're gonna jump back into that in a second.
Yeah. 'cause I want to hear how Lumio views, you know, the definition of what's critical infrastructure. But first I guess we should define lumio, right?
Many people out here probably know, but Go ahead. Yeah. So, so limo, gosh, we've been around 12 years now.
Um, yep. And what, you know, what we are fundamentally, you know, trying to do is to, is if there is an attack, is making sure it doesn't become a disaster. And this, you know, this really is again, fits into the whole critical infrastructure.
So, you know, our major customers are banks, government manufacturers, utility companies, et cetera, et cetera. And so, you know, we focus on really the resilience of an organization, how to understand where the risks are, how to contain any attacks that when they happen, basically to, to keep organizations working when there is an attack. So, you know, we, we'll, we'll look at when we, when we dive into the numbers, we'll see how, why that's important.
Absolutely. And, and really, you know, what Illumio is known for in the, in the market is, is kind of, they, they, they achieve this using a lot of kinda like microsegmentation. Yeah.
Right. And being able to, I want to use the term wall off, but segment, you know, so if you do get attacked, and, and a lot of times it's not due, it's when you get attacked, you can limit the, the, the blast radius as they used to stay, right? Yeah.
Correct. Um, so before we jump in, you guys just did your, uh, cost of ransomware report. We're gonna jump onto here in a minute, but what's critical infrastructure to you, Trevor?
It's actually, um, it's actually pretty well sort of defined there within a lot of compliance and regulations around the world. And so it, it, it is what we've mentioned, it's, you know, primarily at the top end, it's power, it's utilities, it's water, it's all of those sort of things. But as you said, it's, it's food, it's transport, it's, um, you know, modern days, it's the internet, um, and mobile phones.
Mm-hmm. And, and, you know, all of those sort of areas, banking, for instance, because nothing happens without those. So, you know, we started to see, uh, regulations all around the world now coming in focusing on, on the, the resilience aspect of critical infrastructure.
So, you know, it's not, it's, it's, it's become a thing I, I guess in its in its own right. Absolutely. Absolutely.
And, and I think it, you know, it's kinda like trying to define DevOps, right? The more you put your finger on it, the more it kind of squishes, you know, away critical infrastructure. Something could be critical to you and not critical to me for whatever reason, right?
I live in a cave and the internet's not important or what have you. Right. But I, I think we agree there.
We all agree there are, there are critical pieces of our lives today, and that's increased as we've become more digital that gonna fall into this. So I mentioned this ransomware report you guys did the global cost of, of ransomware. Um, is this the first year you've done this?
Have you guys been doing this report now for a while? So We actually were, we worked with the Ponemon Institute on this, and it's something that they've done before, but this is the first time that Yeah. That we've, We've, I didn't realize.
Yeah, he's actually right down the road from us. You we're here in Boca original Florida. Poman is also in, in, we not a tech set.
Right. People don't come to Boca Ol Florida for the tech. Yeah.
But for the most part, I wish they did. But anyway, just coincidentally, he, they're nearby here, so Interesting. Yes.
I'm, we're, I think we're familiar. Pokemon has been doing this report a while. So for this year, before we jump into the, uh, findings, when was the surveying done?
When, you know, how fresh is the data here? So the, the, the data basically is, has was released yesterday. So the, the research, the research was done just at the end of the tail end of last year.
Obviously, it's all being analyzed and consolidated and turned into a report, which you can, you know, which you can retrieve. com, there's a banner on the front page, click and download it. So you know it, and it's, it's actually full of roots and quite surprising numbers in on a, on a positive and a negative note, really.
Well, that's, that's the way life is, right? Yeah. Go ahead.
Let's, let's, you know, you, let's, before we jump into surprising even, let's go to key findings. How's that? Yeah.
What, you know, what did, what are the key takeaways our audience should, should do on the take on this? I think, I think one of the, you know, one of the interesting findings was that, that people are actually very confident about their ability to prevent and stop ransomware. So, so compared to three years ago, which was the last time they did it, the, the sort of where people are saying, yep, I've, I've got more confidence.
I don't believe that we're a target for ransomware. I've got more confidence in my supply chain. I believe that we are better at, at, at, um, at stopping ransomware.
All of those numbers have improved. So people are more confident. But then on the flip side, numbers, like we had to shut down for a period, have leapt from 45% to nearly 60%, or, um, our brand was damaged as grown, or we lost significant revenue has grown, or the number of, um, attacks we had has grown.
So, so there's a sort of a, a, a weird dichotomy between those Two. They don't jive. Yeah, yeah, yeah.
The numbers don't really, Or, or unless you're telling, but because I was a victim, I feel like I won't be a victim again. Right. So the lion ate this zebra once.
He's not gonna eat the same zebra twice. You've been in security longer than I have even, and I've been in it a long time. I don't believe it.
I, I, I think, not that I don't believe people said this, but I think this is false confidence in, in what they've got here, right? Um, I think everyone is a target. I think, you know, there are certainly strategic targets when it comes to ransomware.
There's something that you have that is very dear, near and dear to me that I want right? Strategically, but I think for the most part, like a lot of cyber crime, you become a target when the bad guy walks down the hall of the hotel and your door happens to be a little more jiggly than the next door, right? And it's easier to break in.
And so I, I don't, I don't buy that. I think people are misguided if they feel that way. I also think with AI and everything, the phishing attacks that people, that the, the bad guys are using to, to get in and, you know, and plant their malware that leads to the ran, you know, the encryption and the ransom.
I think they're better than ever. Trevor, you've gotta be seeing this too, right? Yep.
Yeah, I mean, it's, there was, I was at a, a conference a couple of days ago and there was a big discussion on deep fake, and some deep fakes are less deep and less obvious than than others. But some are very, very good, and they will only get better over, over time. And to a certain extent, you know, the, the primary attack vector is still phishing.
Yeah. And it's becoming more and more difficult to detect that. But there is, you know, better AI tools are trying to detect DeepFakes and, and that battle will go, you know, will go on or not.
But you know, the reality that we, that we face is that over these, you know, over that 37 years, we've got much better at reducing the probability that an attack is gonna be successful probably by, you know, over 99%. But that still means that at some point something is gonna get through and there's probably not enough focus on what happens when the attack gets in. And there's some, you know, there's some real, real things where they talk about, um, uh, uh, like what was the, you know, what was the primary movement for, uh, for ransomware and what was the, you know, what were the things that caused lateral movement?
And it's, and it's still numbers like RDP, weak passwords, unpatched systems. So, so there's a lot of work just on the basics of security that isn't being done, that's allowing those, um, those attacks to have a, have an impact to cause that shutdown down for a period. So, so I think there's two things in there, one of which is a focus on make sure you do the basic things properly, but also how do you then, you know, again, how do you then contain and control that attack?
And I think we've seen sort of an improvement and a, a sort of a drive towards incident response and, you know, some of that, that sort of technology that's, that's starting to help and a hopefully a shift in culture within organizations to move away from, you know, I must do everything to stop every attack, to how do I make my organization more resilient? So I I do, I agree with you there on the resiliency. I think where we have made progress with ransomware is understanding how do we, how do we again, limit the blast radius?
How do we have copies of our data that are not subject to being, you know, encrypted here, right? Yeah. That there's some sort of wall between them.
It, it is about incident response. This is why, frankly, Lumio with microsegmentation is, is a great ransomware kind of fire. I, I don't wanna use the word firewall 'cause it has a different meaning in security, right?
But it's a, it literally is a block, right? Because it, it can limit what, what data gets attacked here. Um, and that, that is where I think we have made progress.
People understand that with the best of intentions and the best of processes and policies, stuff's gonna happen, right? They're going to, it, it, it, the phish gets through, you know, and it only takes one knucklehead click and something they shouldn't click. And that's, you know, where you go from there.
But how you respond to that attack and how you use a, an illumio and or how you have architected your data, you know, storage to, to insulate if you will, is a good word, I guess is, is key to it. Let's talk any, what other kind of surprising results that kind of stood out to you? I think I, I think the obvious thing of, you know, ransomware is not going away.
So yeah. So, so that beca that became an obvious thing that, you know, whatever, whatever we say there is a shift towards more disruptive attacks as opposed to, you know Yeah. As opposed to sort of traditional sort of things.
And there was some, again, again, there was some interesting research into security controls and, you know, the top ones are MFA and patching and all that sort of stuff. But some of those, the numbers of people that are using those technologies was surprisingly small. So out of, out of the population, only 37% said they're using MFA, which really Yeah.
Is, was actually quite, quite surprising in itself. So, and then, you know, that was the most popular. So I think there's still a lot of, I think what they call security poverty in a lot of organizations where, you know, if you are not a top bank or a, you know, a multinational that's got a big organization that the challenges of, of trying to secure your, your company, if, you know, you may still have a, a multimillion dollar company, but if you've got four security guys and a limited budget, you've still got a problem.
So, so again, there's, there's the whole piece about, you know, making sure you do the basics properly and, you know, put the, you know, put the, the good prevention control measures in before, before going mad on spending too much on some sophisticated AI tools. So, so I think that, you know, some of these, some of these things are still, you know, are still, uh, sort of really interesting in there. Um, and so it gives you that, it gives you that sort of view of the, again, the culture within organizations and, you know, and, and where some of that responsibility lies and, you know, and what the impact then of some of those, you know, some of those attacks are on people.
So, so I think, you know, any of these reports, you sort of look at 'em and go, well, actually it, it's then interesting to do another 10 questions on, on that particular subject. So, so I think it gives you that, you know, when you look at this income in sort of alongside some of the other research, so you look at it against like the World Economic Forum cybersecurity report, and you look at it against some, you know, some of the sort of other reports that are coming on there, there is a picture out there that, that sort of says, there's, you know, all the things that are obvious, there's not enough people that, you know, there's a shortfall in, in, in people you can recruit. The, the things that we've done over the last few years have got more and more expensive, but we're getting less and less return from them.
So there has to be a, there has to be this shift in, in culture and attitude within organizations to stop saying, you know, if we get attacked, the CISO gets fired. We've gotta get to the point where let's all work together to make sure that if we are attacked, we stay in Absolutely. Ag.
Agreed. And that is, so I think that's been a big shift in the security world over the last even maybe seven to 10 years, is the, the, the in, you know, the, the response versus prevention aspect. You know, we're, we're over, over time and outta time here, I'd love to talk to you more about this because Trevor, especially when you're talking about mid-level enterprises, you know, the, the fact is a lot of these people are relying on third parties for their, they're all SaaS.
No one has a server closet anymore where they're running the exchange server, right? Or, or something. They're all using Google or Office 365.
All of those emails have two factor authentication, almost by default, you gotta like shut it off not to use it. So why only 37% is because people think it's a pain, pain in the butt. They, they decide not to use it.
com, I-L-L-U-M-I-O, they could go get it right off the front page. Yeah. Trevor, thanks for coming up here on Techstrong TV today.
I appreciate it. And best of luck, man. You know, it's, it's a hard job, right?
But you know how they, what they say in security is when nothing happens, you've done your job. So, absolutely. Absolutely.
Alright, keep it up. Thanks, Alan. All right.
And, uh, hope you again. Thank you. Bye-bye.
Alrighty. Trevor Dearing, director of Critical Infrastructure Solutions at Illumio here on Tech Drunk tv. We're gonna take a break.
We'll be back with another interview in just a moment.