February 2023 Newsletter - If you’d like to read this newsletter at the same time as our subscribers, please sign up here.
Who Is Liable for a Cyber Attack? You Won’t Like the Answer
Most business owners assume that they will not be held liable for a cyber attack. Most IT professionals know better. Depending on the nature of the attack and your actions beforehand, you could be out-of-pocket for lost business, ransom payments and restitution for your customers.
An unpleasant aspect of this is making its way through the courts, with potentially wide-ranging implications for businesses. Major insurance companies have gone to a New Jersey appeals court to overturn a ruling demanding they make good on insurance payments for the 2017 “NotPetya” attack against pharmaceutical company Merck. At stake are approximately $1.4 billion in claims.
The same Federal government that is ratcheting up pressure on business owners to improve cyber security opened the door for the insurers’ suit by designating NotPetya as a state-sponsored attack that originated in Russia. Insurers claim in their court filing that this triggers a “war exclusion,” found in many insurance policies, that denies payment for damages resulting from warfare.
Should insurers prevail, the precedent would allow them to deny claims for any attack attributed to a foreign government. Potential targets of those attacks, including financial providers, infrastructure companies, municipal government agencies and utilities should be keeping an eye on this.
For every other business owner, the message is familiar: You are on your own. You cannot rely solely on a cyber insurance policy or what you believe are good security practices. You need professional support from cyber security experts.
I discuss this case and steps you should take now to boost your security in this month’s cover story, Cyber Insurance Companies Go to Court to Block Claims. You will find good, actionable advice here that will help you prepare for coming regulations.
BREAKING:
Reddit Breach Reveals the Best and Worst of Employee Responses to Phishing
Social media site Reddit reported an attack targeting its employees during the first week of February that led to a security breach. A look at what happened, and how Reddit responded, demonstrates some strong employee cyber security awareness.
According to Reddit, the attack was sophisticated. Hackers cloned the Reddit Intranet gateway, then sent emails to employees directing them to use it. One employee fell for the ruse, giving hackers access to some of Reddit’s back-end systems, including “some” contact information for current and former employees. No user data was compromised in the attack, but hackers were able to get employee data they can use in future social-engineering attacks.
This breach was contained because the affected employee realized something was wrong and reported the incident, enabling Reddit’s security team to lock out the hacker and contain the damage. This demonstrates two critical factors in cyber security: You must have employees who are empowered to report their suspicions or admit a mistake, and you must have an action plan to respond to an attack.
In a perfect world, the employee would not fall for the hoax, but the criminals who launch these attacks continually vary their approach and improve their tactics to try and trick employees. Attack prevention is essential, but business owners must put it on an equal footing with reporting and response to respond to evolving threats effectively.
Would you know what to do during an attack? Download our Free Cyber Crime Response Kit.
Stat of the Month
79%
The number of business leaders surveyed who said they make cyber security decisions without considering the threats they actually face.
In their survey of 1,350 business leaders, threat intelligence provider Mandiant found that decision makers are overwhelmed by the amount of threat data they receive, and that most make decisions based on perceived threats they read about in the media, rather than the actual threats their organizations face. Mandiant Vice President of Intelligence Analysis John Hulquist noted that leaders are preoccupied with sophisticated hackers when they should be worrying about ransomware attacks.
Do This Every Time to Stop Fraud
Business email compromise is one of the fastest growing social-engineering scams online. It’s become so successful that criminals have begun launching six-figure attacks against businesses.
The scams work like this: Criminals spoof an email address for a vendor or a client, then place an order or ask for an order to be delivered to a new address. Criminals then collect the goods and you never see payment. In another, more easily detected, version of this scam, criminals impersonate a senior executive and ask for gift cards.
With one simple step, you can prevent this scam 100% of the time: Call the individual to verify. Make this part of your operating procedure for any unexpected order or delivery change, and make sure your employees feel empowered to make those calls.
Go Beyond Generic Deep Web Monitoring
Does your security provider offer Deep Web monitoring? Many will tell you if your email has been found on the Dark Web, but this is not real security intelligence.
With millions of customer records breached in the past decade, you should expect your email to be found on the Dark Web. Lists of emails, addresses and, in many cases, passwords are put up for sale by the terabyte daily. A report telling you that someone is trying to sell your information may sound scary, but it is actually routine.
Real security intelligence, such as Dark Web Monitoring from Protect Now, does two things. First, it provides a report on what information about you and your business is already available online. Second, it alerts you when new data from your business appears, or when online chatter suggests an attack may be planned. This is intelligence you can use to identify breaches, including breaches by your own employees, identify new vulnerabilities and prepare employees for potential phishing attacks.
Our Dark Web Monitoring service uses the same tools and data employed by Fortune 500 companies to protect their businesses. We make it affordable through the collective buying power of multiple subscribers. Contact us today to put this powerful cyber security tool to work protecting your business.
As I noted at the start of this newsletter, you are on your own when it comes to cyber security. That does not mean you are alone. There are hundreds of qualified providers who can help you design secure systems, develop and implement response plans and train your employees to recognize and respond to cyber attacks.
Liability and responsibility are shifting toward business owners, who will soon need to engage private security to protect against the growing onslaught of cyber criminals. The U.S. government will provide some support against the most professional hackers, but it will fall to businesses to defend against low-level threats. That may not be welcome news to hear, as it comes with added responsibility and added expense, but it is reality for the foreseeable future.
Stay safe out there,
Robert & the Protect Now Team
