Panel, Conference Presentation
My Organization Has Been Hacked
Milken InstituteRay Rothrock, Heather Adkins, Dmitri Alperovitch, Daniel Ennis, Siobhan MacDermott, Dan Ennis
Context & Paradigm Shift:
- Cybersecurity moved from a niche IT function to a mainstream boardroom concern following the 2013 Target breach, followed by high-profile incidents at Sony, Anthem, and OPM.
- Consensus reached: Prevention is necessary but insufficient; organizations must prioritize post-breach response readiness.
- Panelists: Ray Rothrock (Moderator/CEO, Red Seal), Dmitri Alperovitch (Co-founder/CTO, CrowdStrike), Heather Adkins (Director, Info Security & Policy, Google), Siobhan McDermott (SVP, Global Cyber Public Policy, Bank of America), Dan Ennis (Consultant, Former NSA).
Immediate Response Protocol (First 24 Hours):
- Legal Privilege: The first action upon breach detection must be contacting the legal team to establish attorney-client privilege over the investigation.
- Team Assembly: Activate a pre-established "call tree" containing legal, regulators, PR, and incident response (IR) teams.
- Surprise Factor: Executives should not be surprised by a breach; if they are, it indicates a lack of prior planning.
- Information Gathering: Initial findings in investigations are often incomplete or incorrect; decision-makers must be prepared to act under the "fog of war" without waiting for full data.
Preparation & Organizational Culture:
- Tabletop Exercises: Regular drills focusing on non-technical crisis elements (regulators, competitor notification, board communication) are critical for building "organizational muscle memory."
- Transparency Culture: Open internal communication mobilizes employees as a "free detection capability"; burying breaches creates worse long-term damage (e.g., the "reluctant CEO" case where a breach was ignored for months).
- HR Integration: Security teams must maintain close relationships with HR to manage insider threats, specifically regarding terminated employees or those receiving poor performance reviews.
- Prioritization: Security spending must be prioritized; without a clear plan, organizations cannot articulate why they were exposed or what actions were taken.
- Sony Case Study: The Sony hack revealed that the theft of employee data (SSNs, health info) caused massive psychological terror among the workforce, distinct from network downtime.
Threat Landscape & Adversaries:
- Adversary Classification: Threats are categorized into three groups:
- Nation-States: Russia, China, Iran, North Korea (targeting IP, economic stability, or specific political events like the Sony movie).
- Cyber Criminals: Groups like "Karbonak" that rival nation-state sophistication (e.g., attacks on central banks in developing nations).
- Hacktivists: Less sophisticated but motivated by reputation damage; can mobilize instantly via social media.
- Geopolitical Risk: Financial institutions are high-priority targets for North Korea to fund illicit government activities; cyber attacks are viewed as a tool for de-escalation before kinetic conflict.
- Insider Threats: Identified as the #1 priority threat; estimated to affect up to 3% of a workforce annually, often inadvertently (e.g., data exfiltration by departing employees).
- Third-Party Risk: Attacks often traverse the supply chain (e.g., hacking a university to reach the Pentagon, or a payroll vendor to access a law firm).
- Adversary Classification: Threats are categorized into three groups:
Business Impact & Economics:
- Valuation Impact: Breaches directly affect deal valuations (e.g., Verizon saving $2 billion on its acquisition of Yahoo due to disclosed breaches).
- Long-term Competitiveness: State-sponsored IP theft can erode a company's market position years later, even if stock prices do not immediately dip.
- Regulatory Fines: The EU GDPR (effective May 2018) imposes fines up to 4% of global revenue for inadequate breach response or data protection.
- Insurance Market:
- The cyber insurance market is projected to reach $14 billion by 2022.
- Current policies cover IR, legal fees, and out-of-pocket losses but do not replace network infrastructure.
- Risk exists of a "next bubble" if systemic attacks compromise multiple insured entities simultaneously.
- Investors increasingly view cybersecurity diligence as a pricing factor for stocks.
Collaboration & Industry Standards:
- Financial Services Collaboration: The eight largest US banks formed the Financial Services Analysis and Response Center (FSARC) to share threat intelligence, recognizing that a breach in one bank impacts the entire sector.
- Public-Private Partnership: Models involving government agencies (e.g., Treasury, NSA) sharing data with private sector firms (e.g., Deutsche Bank, US banks) are essential for global defense.
- Global Interdependence: Critical infrastructure attacks transcend borders; nations must coordinate norms (G7/G20 discussions) to prevent global financial network collapse.
Future Outlook & Technology:
- Artificial Intelligence: AI will be a double-edged sword; while it enables defense automation and pattern recognition in massive datasets, adversaries will use it for automated attacks and data aggregation.
- Long-term Vision: By 2050–2060, systems may be fully self-defending; currently, human judgment remains the critical competitive advantage in identifying sophisticated errors.
- International Norms: Establishing cyber "rules of the road" is difficult compared to nuclear non-proliferation due to the low barrier to entry for non-state actors and the vast number of threat vectors.
Illustrative Case Studies:
- Nigerian Scams Evolved: Attackers now conduct months of network reconnaissance to identify executive travel schedules, then use compromised CEO accounts to authorize multimillion-dollar wire transfers (e.g., $30M to Hong Kong) while the executive is unreachable.
- Social Engineering: A security vendor successfully extracted detailed company secrets from a foreign national employee by impersonating security staff at 3:00 AM, highlighting the efficacy of psychological manipulation over technical intrusion.
- Forgotten Infrastructure: Network discovery tools frequently uncover "ghost" servers or data centers that remain active and unsecured despite physical building renovations or management changes.