Ben Harel, Illumio | RSA Conference 2023
Illumio head of incident response & managed services Ben Harel discusses the company’s new Incident Response Partner Program which has already minimized the impact of dozens of active ransomware attacks around the world. It takes an average of 277 days to identify and contain a breach and the average cost of a data breach is now $4.35 million, according to IBM. During the recovery process, however, attackers often remain active in the environment, preventing organizations from bringing systems back online. Thankfully, the Incident Response Partner Program prevents reinfection by halting all traffic between infected endpoints and servers, granting immediate network visibility, and quickly restoring operations.
Transcript
This is texturing TV. Welcome. We are here at RCC in San Francisco.
2023 great conference energy is high. A lot of people have come back and really enjoying their time here and great conversations. Great technology industry Trends me cool things are happening and speaking of all of that great people and great Trends.
I'm pleasure to be joined by by Ben Harrell, right? That's right correctly. So I make sure a lot of names I'm going through this week like make sure I do a good job of everybody's name and Ben heads up the incident response and major services for alumia.
Welcome. Yes. Thank you much.
Thank you for having me. Yeah, great to have you tell us a little bit about yourself. I love to hear about your background because you're not new to this kind of work obviously and tell us a little bit about aluminum.
Yeah, just a little bit about me. I'm transplant from Israel where I was born and race. I moved to the states and number quite a number of a few years ago and plan on staying at illumio.
I lead our incident response and our managed Services team, which is a combination of some product work. Of work in the field in data breaches in real time supporting our partners and both the recovery and the forensic piece interesting. Well, you said this phrase to me you're usually coming at the time which is the customers worst day right?
Not a great day for them if they're calling you for help, which means they really need some help. Yeah. So usually the way we operate is we we have a number of partners that we are very very close with I would call morning just business partners in the dfr so reach response in the forensic piece and the recovery piece they partner with us to bring a lumio in to really help bring businesses back online faster.
That's actually our primary purpose in a data breach. What I'm curious what kind of Trends new things. Have you seen we hear a lot about fishing and ransomware and the rise of both of those.
Is it more volume of those kind of things different kinds of approaches that the threat factors are taking to to perform. Those data that they're stealing. What's what's kind of the new things are in this field.
Well, it's I would say it's significantly picking back up. There was a major slowdown during the starts of conflict in Ukraine and Russia. We saw a huge decrease in mainly like ransomware type engagements.
There was a very I would say short trip shift to data exfiltration instead of just purely ransomware and in the past. Three months. It just ramped right back up.
I'd say it's as busy as busy as it's been interesting. What do you think a we saw that increase in data exfiltration, but now back to ransomware. What's the reason?
I think it's not as radioactive as ransomware in the sense that when you you do ransomware to company, you are literally destroying the company's ability to operate make money do anything in a case of data exfiltration technically to cut a lot of cases of companies still operational to a degree people can still meet their quotas, you know, quarters and deliverables. So we saw a small shift, I would say towards that we thought it was gonna get bigger didn't and that's mainly why it doesn't get as much attention from the authorities and such. Yeah, Data Theft often can be a little harder to quantify to yes, but the potential impact of that or damages from it would be if it's exposed.
Yeah versus we can't service our customers. We can't pay our employees that tends to get your attention a little bit quicker absolutely talk a little bit about You know the phone rings the ml shows up the text comes it says we need your your help at company X. What do you typically walk into what what are the situations that are pretty common so we go alongside a recovery partner.
A lot of people don't realize in an engagement that a lot of people don't think about recovery. They have the forensic is always front and center because that's the more we'll call it sexy and exciting part of the working investigative part. Yeah this discovery recovery those actually probably the most expensive thing in a data breach sort of like paying a ransom or something like that.
It keeps a lot more expensive. So what we do primarily is we go in alongside the recovery partner because you'll have usually a dfir you know, investigation and Recovery partner that's also doing part of it. And mainly we we get to call it's all times of the day three in the morning is not out of the question holidays, especially we can yes, and we primarily what we're there to do is if is to let the business restore faster.
I'll give you an example. We were working in a very very large manufacturing. I can't even say like the industry they're in but they're very well.
On the experience the data breach when the data breach started, you know, there's a Delta of time between deploying EDR doing the investigation where you can start recovering operations online if people coming in larger color engagements, you have people coming in in the office with infected laptop. So what alumio does in those data breaches what I do is we create basically Clean sterile environments for different applications for Recovery to come back online so it could be sap it could be an Erp. It could be a production floor at a factory.
It's over the place. So typically has the rate if it's ransomware is Ransom been paid or maybe the decided not to and that's when you're coming in. So you're now you're here's the keys and it's definitely paid I'd say a lot of the times it's there.
A lot of these teams have negotiation teams that do it. It's pretty funny. If you've never experienced it before it kind of goes like you reach out usually through chat to a team and I don't know if you it's like a business it is they're like, we're close.
They're negotiators. Yeah specialize in exact ransomware negotiations. So they'll say like we're you know, it's a holiday and so on so we're not open come back tomorrow at five PM, you know Eastern Standard Time or something like that.
So it's very interesting I imagine. Things you run into is yeah, we might have gotten the keys, but that doesn't mean things weren't corrupted. Somebody might have shut off a machine in the middle of something being, you know being encrypted with with the ransom, especially the case where you know, there's no backups.
So attackers very common. Like we'll go into your backup Appliance. Delete your backup.
So go in the San array delete the snapshots. We'll go into VMware encrypt the vmdk stores where all the server data is stored and so on so Interesting. So at that point if it's been deleted more likely it's not recoverable at that point or is it I we there's some really good people and a space that I have been able to pull off.
I've seen Miracles interesting miracles in the past, but most of the cases it's not recoverable but it is very much an interest of the attacker to make a recoverable with the usually you pay get a decryption tool or in the case of Cameron or the ransomware group. Everybody calls all the groups differently, you know the group basically retired. I think it was like last month for two months ago and release their decryption keys for anybody is still Ransom.
So interesting if you were gonna you always wish you could have talked to the customer before this happened, right? Yes, so be better prepared. If you were going to advise someone on you know, it's not if it's when this is probably gonna happen the number one thing I would advise you the mistake most people make that I want don't want you to make what kind of advice would people um You know.
It depends and I can tell you from like across a lot of different data breaches. We always have the same kind of top five things that are the the technical advisors. Tell them the IR firm Style on the breach coach tell them and it's usually always edrm-dr multi-factor authentication active directory hardening and segmentation.
Those are the kind of the top that we hit every time so pigmentation is often missing. I mean, maybe if you're going down the, you know, zero trust path, but still yeah, and I think also what people don't realize about companies like killing me a segmentation that we do we can do traditional segmentation the sense we lock down every system down to the user down to the process down to the server. That's one way of doing segmentation.
It's been around it's completely valid and I think you know, we do a pretty good but there are other things that people don't traditionally think about things like breach risk reduction. If you look at most companies are running Windows a lot of company almost everybody does Windows has a number of very specific protocols that are very common for spread of malware. It's SMB.
It's a RDP not to get through tactical. It's wmi and these others so one of the things we do is we can actually segment protocols. So not thinking like him but a segment this one box instead.
I'm going to say hey, I'm gonna kill RDP an entire environment instantly in a non-destructive way, and I know it's not breaking anything. But you know, I'll let my couple admins that you know, three PM when they need to connect to the servers or purple Jackson's workstation or something like that. So think about it more as a not a physical even though maybe a virtual system but not a thing that you're locking down but a communication path or mechanism exactly about these things operate together because that's how spread happens exactly.
Um, I'll give you another common one that we see most companies I'd say I'm good 99% That's how Relevant, this is had. There's no legitimate reason for any traffic to go inbound to your laptop your computer. There's nothing on 99% of companies that if you were to block all inbound traffic some so simple that it would even break anything.
So those are some of the things you know, lumio does it's scale very very quickly across hundreds of thousands of workloads. That's one of the reason we use them breach when go and turn this on really fast. We have kind of Playbook we follow There's things like, you know, where else you know about Tor Network and stuff like that.
But you know, you have interplanetary file systems. You see those kind of things popping up and replacing as another Vector for spread or in egress into networks for attacks. Definitely see septors sometime going through tour Network outward, but it's a lot of the malware indicators of compromise remain pretty consistent within a certain engagement.
Obviously, they do that. There are a lot of reasons some of the other things we've seen are Data Business email compromise leading the, you know, data exfiltration. I saw an example a couple days ago of somebody using well, I don't want to say who it is, but basically a third party service that everybody knows and wouldn't think of as a methodox filtrate data like social social media, basically, So that's not a topic any of us are talking about but it's people don't think about it.
But a lot of times when it's some like a trade secret or some specific like or code they could just literally paste it into a social media private post and then copy it out. There's all kinds of stuff. We wonder too.
You know with chat GPT is on the mind on the you know tip of everybody's tongue these days that's another Vector of sharing, you know, IP intellectual internal. Absolutely. They say don't do that you guess what, you know, well every it's the red button you're not supposed to touch everybody wants to touch it because it's cool.
Right and it's exciting and it's something you know, we have a really seen before how good something can be we haven't yet seen a lot of things relate to catch you. Obviously there was that Samsung story that came out where they could look up there information that they shared in there. That's not a good thing what I'm what I'm more worried about that I think and I'm not an alarmist by any stretching imagination.
We do engagements are not going to change regardless of what I'm about to say, but I think things like more dynamic. Malware something that has constantly changing indicators of compromise stuff like that is what I expect to see coming out of things like chat GPT or any those kind of solutions where it's it's not necessarily writing malware live and engagement but I think that's what it has a set of like, these are the five different things I can do and if they have you know, this CDR do this automatically and, you know create something new from scratch that doesn't won't show up on a threat intelligence or for anybody else. Well if we can point large language models at you know.
That was intensive hundreds of thousands of sites. You could do that to malware data and it's got to be some. Yeah, exactly.
So it's gonna be used that way. I'm curious. What what are you looking for at rscc this year?
Were you kind of on what's on your radar screen? I'm kind of checking this out. Hope somebody's doing this or I well obviously most focused on Lumia.
It's good to see how many people and I was walking into our say how just the fleet of humans that were just walking a lot more people here. Yeah looked incredible. There's some very cool things around.
They'll mostly AI machine learning automating, you know Asset Management stuff that I've seen but I'm just kind of looking forward to seeing everybody come out what it looks like interacting with people again, it's it's nice. So new experience. It's funny to have to kind of think about.
Oh, that's right this yeah, not me just comment, right? Yeah best relationships are always done in person in best connections. That's what lead to best outcomes speaking of which it's been a pleasure to talk to you very much Builder relationship with you.
Thanks for being on Tech strong TV here at rsac. Ben hopefully, you'll come back and talk with us again. We love talking about kind of what's happening on the response and the recovery side of things Ben Harrell who's with lumio.
Hope you all have a great show. Thank you for having me. Thank you.
Thank you.





