Impact of Ransomware Attacks on Businesses – Allen Jenkins, InterVision
Allen Jenkins, CISO and vice president of cybersecurity consulting at InterVision, explains why cybersecurity teams are underestimating the impact ransomware attacks are having on businesses no matter how quickly they recover
Transcript
This is Textron TV. Hey guys. Thanks in the throw.
We're here with Alan Jenkins who see so and vice president for intervision. They are a cyber security consulting firm and we're going to be talking about ransomware and the recovery there of Alan. Welcome the show.
Hi Mike, how are you? I'm well, but maybe not as well as some other folks are these days depending on whether or not they've been victimized? from your perspective we seem to have a mechanism for at least recovering from ransomware where we get the systems back online, but it doesn't seem like we really understand the total cost of these attacks.
So what's your sense of where are we in terms of our understanding and maturity of these ransomware attacks and how to deal with them? That's a really good question Mike. I think one of the challenges that we've seen is is sort of itemizing out what all the different components are that go into the cost and the impact to business is really challenging to do so, if you look at the cost you a different entity.
So a manufacturing entity has a different cost because perhaps the ability to manufacture stops. So the ability to calculate well what's lost during that period is very different than perhaps like a retail outlet where maybe they can continue to sell but they have to go to like a paper process or whatnot. So just that simple, you know, what what does the business do that's impacted affects it then you've got all the variables that a lot of people don't consider like the the cost of legal representation the the cost of yeah marketing and communication strategies, right?
So how do you have to reach out to your customers that you're affected and and them know so all the sort of side components a lot of people think about just it what happens if we can't function but then you have all these other costs that are super variable depending on on how people have structured their cyber program. If that's the case are people miscalculating what the total cost of investment is in a platform to deal with this versus the total cost of the business or what's at risk and then as such a lot of decisions, maybe you're being made where they're not fully cognizant of what's really going to happen here in terms of the impact of the business. I think you're seeing very clearly there that there is a disconnect and we see that often times a lot of what I do is consult with with organizations and talk to them about their cyber program.
And what we try to do is paint the picture that this isn't just a technology problem. This is a business impacting problem and oftentimes that's news to some of the sea levels that we talk to you because they really didn't think of it that way. And so that's one of the first hurdles is changing that sort of topic to say this is really a risk management issue versus just a technology problem and then putting it in the specific container.
Well, how could this impact your business and then you can start to do some math? The challenges that again is probably different for every organization there a lot of organizations. Do you know cost of reach estimations but a lot of it sort of formulaic.
I don't know that it's a specific for each entity and that's that's part of the challenge as well. One is the current state of the art for ransomware protection these days because initially it was kind of like well, you're gonna have a backup system and that will be great. But you know, and hopefully you'll have a pristine copy of the data, but hopefully the technology and the solutions have evolved somewhat since then.
Well, yeah, we so we saw a lot of that early on where the answer was the backup but you know, the threat actors are pretty smart as well. So they knew that if you if you had a good backup. Well that was your get out of jail free card.
So you were less incentive to pay the ransom if that were the case. So they immediately started to find ways to find those backups and encrypt them. So there's been a lot of movement the last year or two around how to take those backups and better secure them so that they can't be affected but also there's been a lot a lot done in the industry over the last two or three years as well to help with early warning system.
So if you think about it almost like a an alarm system for your house, so it's not necessarily that these guys can't get in. But if we can find out that they're in fast so that we can contain the blast radius if you will so that the impact may affect one user to users versus affecting the entire organization. That's Come a long ways the combination of things though that early warning system along with the capability to back up and knowing that the backups are good is really a part of the magic, right?
So not having one Silver Bullet but having distinct what we used to call defense and depth or layers of technology or layers of solutions to help with things like early warning and Recovery. Back in the day. The biggest problem with recovery was nobody actually tested anything and when I did go to recover the data was corrupted and sometimes now the malware is already corrupted the data in the backup in the first place, but how good are we getting managing the backup process because it used to be the lowest person on the it totem pole was in charge of this and has this whole conversation been elevated.
It has been elevated but it's still a bit of a problem. So depending on the maturity of the organization there again, some organizations. Look at this as a strategic issue that they're trying to deal with some are really trying to sweep it over to the side and say, you know, we're still going to do things the old way.
We're not going to be impacted which is very short-sighted and those organizations. Then you have some of what you just mentioned. You still have some of the the lowest guy on the totem pole is running the back up.
They're checking the option in the backup tool that says verify the backup which means they never truly go and test the recovery processes the other end of the spectrum our organizations that are looking at this and and our more mature and are deploying Technologies, but also deploying processes to say not only are we using newer better Technologies, but we're all so testing those Technologies and we're testing the ability to recover data on a regular basis and when they find shortfalls in their capability to recover They take steps to improve that. What is the relationship between security and it folks these days because a lot of the times it's an IT operations person who's in charge of the backup. And now the security folks are getting more involved.
But sometimes we see it folks running security operations and other times we see security folks maybe taking over back up in recovery. What's your sense and what's going on out there? Yeah, I'm not saying so much of security taking over back up in recovery.
Although that's an interesting concept. Probably the thing that we see the most is not having a dedicated security team again on the on this side. If I go back to the analogy before the highly mature organizations, do you have that and that's a great great for them to have and having that separation between it operations, which really has a different Focus right?
They're focus is on providing Technologies to run the business versus a security practitioner who has a very different point of view. But we don't see that in the less mature organizations the less mature organizations the same person who is setting up your it account in active directory or Azure or AWS is the same person who's also in charge of fixing the printer when it doesn't function and they're also in charge of security and yeah, that's that's a daunting task. It really is so knowing all the different things and knowing them well and being able to focus as a challenge and maybe you know, maybe breaking your question path here, but one of the things that we also see a problem with is not Staffing adequately, so if you have one security person, well what happens if they're sick or what happens if they go on vacation or can they ever go get trained on a new security thing if they're the one person so that's a big thing that we see a lot of times as well.
A lot of organizations been on insurance rather than bolstering their defenses. Do you think that now that that's come full circle the insurance company seem to be getting tougher so was Insurance helping to drive investment in cybersecurity versus avoiding it in the past. Both I think we early on we saw a lot of that avoidance of yeah maturation of the program because you could lean back on insurance and say well if something bad happens then insurance will take care of it Insurance wised up pretty quickly to that and and you know, in fact year ago people would get there, you know their questionnaire if you will to get their insurance policy and maybe two three four questions right now insurance companies have had a hard time over the last three or four years.
They've had to pay out on a lot of these types of claims. So they've matured and so they're asking much more involved questions about how mature security program is for an organization so they can shelter themselves and so doing they're forcing customers and people out there in the world to to build more secure Networks. One of the challenges with that though is I think there still can be a little bit of a checkbox mentality where there if there's not validation that when when I answer the question and send it back to my insurance folks.
Who validates that I really answer that or that I really understood what the question was. So we still see some gaps there but it is improving. As we go along what is that?
One thing that you see organizations doing today? That just makes you shake your head and go. Yeah guys.
We need to move well beyond this, but we're still doing this same thing over and over again. Wow, there's a lot of things. That's a really good question Mike.
I guess one of the keys for us and I think I use this line with someone someone just yesterday is is for me I look at at what I do with a lot of people as really hygiene based. So, you know, I'm talking to people about doing the fundamentals and yeah, I like in it to you know, why do you need to brush your teeth? Right?
Well you brush your teeth so that you don't have a bad problem and have to get a root canal. If I mean liken that to security, well you have to do these basic cyber things so that you don't have a really bad cyber event. So some of those foundational things are things like we see with like the CIS controls the center for Internet Security publishes basic controls that they recommend if you do these things and this has been called out and things like the Verizon data breach investigation report that say if you followed the standards published by that people like CIS, you'd be must much less apt to either be affected or if you were the the impact would be less.
The challenge is a lot of people still skip those hygiene things just like people skip you know brushing their teeth or flossing. So one of those that we see that is often not not really well tended to is an inventory of assets and people think well, why is that a cyber thing? Well the challenges, how can I truly protect?
The environment if I don't know what I have. Right. So you get good case in point is a lot of the the Silver Bullet answer for a lot of people is things like EDR endpoint detection and and response and it's a great tool.
But if I don't know all of the workstations and all of the servers, how do I know where to put the EDR tool? So it's just fundamental and simple but it's not so you having to go and find all of those assets and put them in a tool and manage those so that when Mike loses his device or when you know, when Mike needs a new device we know about that and can track it. It's something that a lot of people just don't do or they don't do it very well.
All right, folks. I heard it here the bad guys. They're gonna be bad.
That's what they do. It's up to us to kind of do the fundamentals to make sure that whatever they're doing isn't at least too easy. Hey Alan.
Thanks for being on the show. Thank you very much. Back to you guys in the studio.