Hornetsecurity’s Andy Syrewicze on Cybersecurity Risks as Microsoft Ends Office 2016 & 2019 Support
Andy Syrewicze, security evangelist for Hornetsecurity, dives into the cybersecurity implications of Microsoft’s plan to end support for Microsoft Office 2016 and Microsoft Office 2019 on Oct. 14th.
Transcript
Hey guys, we're here with Andy Swi, who's chief security evangelist for Hornet Security. And we're talking about the need to upgrade Microsoft Office 2016 and 2019, which are both at the end of life and well, that could be all kinds of fun, interesting things for cybersecurity folks to pay attention to. Andy, welcome the show.
Yeah, thanks for having us. How much of that particular version of offices out there, and I know Microsoft has a vested interest in kind driving people to upgrade, but is this gonna be like a bulk upgrade last minute rush? 'cause a lot of stuff of that is still out there.
There is still a lot of it out there. And I mean, the organizations that are still gonna be running this particular version of office are probably your larger enterprises that maybe for some regulatory reason, maybe they have a compliance framework that they're part of. Like, uh, I don't know, HIPAA or PCI or something that requires them to have, uh, you know, on-premises, uh, infrastructure and file storage.
They can't use Microsoft 365 for some reason. For example, those are gonna be the organizations that are still on these older versions of office. So, um, and it's definitely, like you said, uh, it's a bulk upgrade, right?
It's not just a, uh, hey, we've got two machines in the office that are running Office 2016. It's gonna be more of the case of, okay, we have 200, 2000 machines that are still running this old version of office. So it's definitely not a, uh, you know, quick, I'm gonna do this upgrade next Monday type of thing and be done with it.
That's unfortunately not how it's gonna be. Well, I know that's how we probably would like it to be, but for sure it feels like maybe there's gonna be a mad rush at the end. I mean, is this gonna be an orderly transition or were some companies gonna try to force it?
Well, you know, I imagine most organizations, at least I I would hope at least have one eyeball on this issue. 'cause I mean, we're coming up pretty close to the, uh, the cutoff here. I wanna say it's October 14th, if I remember correctly.
So if you haven't started planning your transition, you should go do that. Like today, start planning it, right? Because it's gonna take some time.
And anytime you deal anything with the end user's experience, right? There's, you know, gonna be some, some contention, right? Because your end users aren't gonna be able to work for a period of time.
And then of course there's always an increase in support cases, you know, for your internal help desk teams after the fact, right? Because end user use are using a completely new version of something that they were formally very comfortable with. And so that always, you know, it's kind of one of the, the hidden support burdens of upgrading, you know, an application suite that is as prevalent as office.
Mm-hmm. Is it your sense that cyber criminals are kinda hanging out in back alleys waiting for this to happen and they'll go target folks who don't get security updates, and how likely are we gonna about to see some major breaches? And, uh, I don't think that's out of the question because cyber criminals absolutely are on the lookout for any software that is approaching end of life because, uh, that's the risk If, you know, I'm an organization that continues to use Office 2016 or Office 2019.
And, and one thing I wanna be clear on here really quick, maybe for those, uh, wa you know, those viewers, those listeners that aren't aware is that when we say Office 2016, office 2019, we're talking that traditional kind of legacy on-premises version of office that has nothing to do with Microsoft 365. And so once that October 14th date hits, there's not gonna be any more security patches. And so if I'm a threat actor, you know, it's probably not that difficult for me to determine, you know, organizations that may have this particular version of office within their ecosystem.
And that just gives me one additional place that I can target with a higher degree of success than, you know, maybe some of my more traditional avenues because I know that you're using now out of date version of office. And again, once there's no security updates, uh, happening, you know, those holes aren't gonna be patched anymore. So, and I, I forget what the statistic is, exam, uh, exactly, but Office is one of those suites that traditionally has quite a few, uh, security bugs, uh, on the regular had that have been patched and Microsoft Patch Tuesdays over the years.
So I don't think it would take very long before we would see some sort of security incident as a result of, you know, an organization running old versions of office. Will there be organizations that are still delivering for fee patches and things that I can use? Or will it just be no patches whatsoever?
Well, Microsoft has never been an organization to turn down money, right? So, uh, you know, it, it's funny working with them over the years. I sometimes, you know, they're kind of nebulous onto whether they're gonna continue to patch an application even in a extra paid capacity after the official end of support.
Usually it turns out that they end up doing it for a substantial fee because money talks, right? And if I'm a, you know, a 5,000 head organization and I wanna pay a Microsoft a hefty fee to continue to support my outdated version of office, they may in fact do that. That said, if Microsoft decides not to do that, which I, I think is possible, at least for Office 2016, because it's been out for almost 10 years now, right?
Uh, there's certainly are, you know, third party like aftermarkets vendors, I guess I would say that have been known to provide patching for outdated versions of software. Now, uh, personally I have not seen any specifically saying that they're going to do that for office 2016 or 2019, but whenever there's a business need in the markets, the market usually provides, right? So it wouldn't surprise me to see that, uh, that happen in the, in the marketplace In a lot of organizations, there's still a split between the IT folks who manage systems and the cybersecurity folks who try to protect them.
Are the cybersecurity folks aware of this issue? Because, you know, it could be that the IT folks are just making decisions and cybersecurity folks gonna wake up one morning and go, excuse me, come again. What happened?
Well, I would imagine most organizations that have dedicated, uh, security folks on staff, they're probably very well aware of this. 'cause as a security expert, you know, if I was working for a a, an organization where I was responsible for their security posture, one of the first things I would do is create an inventory of all the software that's in use in the organization. And in my charts of said software, I'd have a column that here's the end of support date, right?
And there'd be alarm bells going off on my calendar that would, you know, keep me apprised of that. So I have to imagine that they are aware of it. Uh, if they're not, well, yeah, they could potentially be walking into a an issue there, right?
But I think most security professionals are aware of this issue and are hopefully urging their, uh, you know, operations teams and infrastructure teams to, you know, get their house in order before that that date hits. Right? Are there smaller organizations that might be more at risk?
'cause you know, I go visit, say my local dentist sometimes, you know, they're still running stuff from some era of IT that I've long since forgotten about. Oh, for sure. I, I'm sure there are small organizations that are out there, uh, still running old versions of office.
And, uh, you know, I spent, before my tenure here at Hornet Security, I spent 10, 12 years, uh, in the managed service provider space, you know, in the trenches, right? And I mean, I can't tell you how many times I'd walk into a, a new customer or peck even an existing customer, or you'd walk in and, you know, you're replacing a new workstation or something. Come to find out they're using a version of office that's four revisions old or something like that.
They have no idea where the installer is for it, and they have no idea where their license key is. So I, it's absolutely possible that there'll be some SMBs out there and, uh, they're gonna, they're gonna be at risk too, right? Because they, they're less likely to upgrade than your enterprises are.
And they don't have the resources on staff to keep their eye on that ball either, right? They don't have a security person on staff, you know, saying, Hey, we need to update right now. That said, I will say Microsoft has done a good job of kind of nudging the SMB space in the mid-market, specifically towards Microsoft 365.
Um, they have made it, uh, very financially advantageous for those types of organizations to move to M 365 because M 365 includes those security updates. They just perpetually get updates because it's a subscription based service, right? But there will be those organizations that again, are still running old out of date versions of, of Microsoft Office.
Unfortunately, As we kind of ponder all this for a minute, do you think that, um, this is also gonna get tied up with an effort by Microsoft to get people to move from Windows 10 to Windows 11, and this is all part and parcel of that motion as well, because it seems like Microsoft is trying to get everybody on more current systems that, well, A, it makes it easier for them to support, but b, are actually more secure. You know, it's, uh, interesting that you mentioned that because I believe it's in October. There's a magic date for, for Windows 10 coming up in October two, I believe, where that's not officially supported anymore.
And to your question, I think indirectly Microsoft will be trying to resolve this issue through that upgrade to Windows 11. Because when you install Windows 11, it already has some soft hooks, I guess I would say into M 365. It makes it very easy for, uh, end users and especially the small businesses that we've been talking about to adopt M 365.
'cause it's presented to them right there within Windows 11, right? And so I think indirectly that's gonna be Microsoft trying to get people off of old versions of office. But, uh, of course we have the, you know, the LTSC 2021 and 2024 versions of office, that's like your perpetual, uh, you know, local version, uh, modern version of Office 2016 and 2019, which are going end of life.
Those are kind of that special case where I mentioned at the beginning of our, our talk here where if, you know, I'm a, an organization that for some reason Microsoft 365 is not an option for me, those two options, uh, L office, LTSC 2021 and 2024, those are the two places Microsoft would like me to go. Now that said, uh, if you go to 2021, you're only buying yourself about another year because 2021 is gonna go out of support, you know, not too long from now. So 2024 is probably where you wanna end up if you still wanna run that, that perpetual on-premises version of office, right?
Mm-hmm. Do we still have a problem with staying current with software? And I know historically we've all kind of tried to sweat assets and people are running older versions of systems and they're not willing to maybe upgrade as quickly as they might, but it feels like the cybersecurity risk has become much more profound, and is the risk now greater than running the older systems?
Because some people feel like, well, if I upgrade, I'll break my system. I'll have to migrate all my data, and there's just too much work for that. But I wonder if we're overcoming that inertia yet.
You know, I'll preface this answer with the simple statement that if you can keep your software up to date, you should, I mean, full stop. I mean, that's the, the number one thing you can do to, in terms of your software, um, attack surface to keep yourself safe is to keep your software up to date. Right?
Now, realistically, you know, those of us that have been in the industry for a long time, we know that's not always a hundred percent realistic. I'll give you a tangible example. Uh, I, many years ago, I used to support a, uh, a large, uh, manufacturing organization.
And one of their buildings, they had I think three very, very large, uh, CNC machines that were used to cut steel for raw parts. Now, these machines ran some ancient version of the software that was only supported on Windows 95. Now this was 10 years ago, 95 was long outta Windows, 95 was, was long outta support then.
And so what it comes down to as it professionals, as security professionals, it's measuring the risk. I I think a lot of teams don't do a great job of measuring risk for certain situations In that particular example, what's the risk? Okay, we have a vastly outdated version of the operating system here.
Uh, the, you know, the company, the manufacturer can't easily upgrade that software without significant financial impact. 'cause that was gonna be to the tunes of millions of dollars because they had to, they would've had to replace the CNC machines too. And so that's a situation where a software upgrade is not quick and easy.
So in that case, what mitigations can I put into place? And basically we completely isolated those machines from the network to mitigate that risk, right? And so, you know, it, it all comes down to, to risk management assessing that risk.
But like I said, going back to the beginning of my answer here, you should be keeping your stuff up to date as much as humanly possible. And then in this context, is it really worth the trouble at trying to upgrade to a new version of something like office, um, using existing systems that weren't designed to run that. So they don't usually have the memory or the processing capability to create a fabulous experience, or should I just go out and get new systems?
You know, that's one of the million dollar questions when it comes to asset management for IT organizations, right? And, uh, you know, office 2016 and 2019 have been out and in use long enough to where I would think for the most part, uh, many organizations have gone through a, uh, a hardware refresh, uh, somewhere in that timeframe. If they haven't and they've, you know, still running the same machines that they were back when they installed office 2016 years ago, they might be in a situation where it makes sense to, to upgrade the hardware.
Uh, but of course then you're adding additional work to your plate of migrating to, you know, uh, office LTSC 2021 or 2024 or M 365, right? There is that additional, um, chunk of work involved with replacing out the hardware and refreshing it. But I think for most organizations, uh, most of their systems should already be in a place where, you know, they, they should be able to handle the newer versions of office.
That said, those organizations that can upgrade to, uh, Microsoft 365 instead Microsoft 365, can largely be run inside of a web browser. So if, you know, you're an organization that has some older systems out there and there's not a strong reason for you to keep, you know, your office suite on strictly on premises M 365 might be a viable option for you. 'cause really all you need is a web browser, um, word, Excel, PowerPoint Outlook.
Uh, they can all be run simply in a web browser with, uh, minimal resources. So that might be an option as well. Alright, What's your best advice to folks then as they kinda look at all this?
Or conversely, what's that one thing that makes you shake your head and go, folks, we need to be a little bit smarter than that. Yeah, so, you know, it's tough to give any, you know, magic silver bullet answer to something like this because every organization's needs are different, right? And so I guess kind of what I would suggest people do is if Microsoft 365 is an option for you, I would strongly suggest you look at that first, because you're gonna constantly get security updates.
You're gonna get new features as they come out. Uh, you get all the, the benefits of the M 365 suite, not just on the, uh, you know, the, uh, the office suite side of things, but you also get things like SharePoint and OneDrive and Microsoft Teams and all that other great stuff that's involved with 365. However, if you're in an organization that's, you know, like I mentioned earlier, if you have to adhere to compliance regulations that prevent you from using M 365 or I've seen some organizations that also just have a, um, you know, a general, I guess I would say mantra position that they don't wanna use the cloud.
Uh, you know, that's when you're gonna wanna look at, uh, uh, Microsoft Office LTSC, um, 2021 or 2024. Like I said, look at 2024. Uh, you know, for those people that are ultra conservative and wanna be like super, super safe, you, I guess you could look at 2021, but like I said, you're only buying yourself about a year.
So, uh, it makes sense to look at 2024 in that particular case. All right, folks, there's an old saying about being penny wise and a pound foolish. I think it clearly applies here.
Andy, thanks for being on the show. Yeah, For sure. Appreciate it.
And back to you guys in the studio.