newsfilter.io
Panel, Conference Presentation

My Organization Has Been Hacked

  • Context & Paradigm Shift:

    • Cybersecurity moved from a niche IT function to a mainstream boardroom concern following the 2013 Target breach, followed by high-profile incidents at Sony, Anthem, and OPM.
    • Consensus reached: Prevention is necessary but insufficient; organizations must prioritize post-breach response readiness.
    • Panelists: Ray Rothrock (Moderator/CEO, Red Seal), Dmitri Alperovitch (Co-founder/CTO, CrowdStrike), Heather Adkins (Director, Info Security & Policy, Google), Siobhan McDermott (SVP, Global Cyber Public Policy, Bank of America), Dan Ennis (Consultant, Former NSA).
  • Immediate Response Protocol (First 24 Hours):

    • Legal Privilege: The first action upon breach detection must be contacting the legal team to establish attorney-client privilege over the investigation.
    • Team Assembly: Activate a pre-established "call tree" containing legal, regulators, PR, and incident response (IR) teams.
    • Surprise Factor: Executives should not be surprised by a breach; if they are, it indicates a lack of prior planning.
    • Information Gathering: Initial findings in investigations are often incomplete or incorrect; decision-makers must be prepared to act under the "fog of war" without waiting for full data.
  • Preparation & Organizational Culture:

    • Tabletop Exercises: Regular drills focusing on non-technical crisis elements (regulators, competitor notification, board communication) are critical for building "organizational muscle memory."
    • Transparency Culture: Open internal communication mobilizes employees as a "free detection capability"; burying breaches creates worse long-term damage (e.g., the "reluctant CEO" case where a breach was ignored for months).
    • HR Integration: Security teams must maintain close relationships with HR to manage insider threats, specifically regarding terminated employees or those receiving poor performance reviews.
    • Prioritization: Security spending must be prioritized; without a clear plan, organizations cannot articulate why they were exposed or what actions were taken.
    • Sony Case Study: The Sony hack revealed that the theft of employee data (SSNs, health info) caused massive psychological terror among the workforce, distinct from network downtime.
  • Threat Landscape & Adversaries:

    • Adversary Classification: Threats are categorized into three groups:
      • Nation-States: Russia, China, Iran, North Korea (targeting IP, economic stability, or specific political events like the Sony movie).
      • Cyber Criminals: Groups like "Karbonak" that rival nation-state sophistication (e.g., attacks on central banks in developing nations).
      • Hacktivists: Less sophisticated but motivated by reputation damage; can mobilize instantly via social media.
    • Geopolitical Risk: Financial institutions are high-priority targets for North Korea to fund illicit government activities; cyber attacks are viewed as a tool for de-escalation before kinetic conflict.
    • Insider Threats: Identified as the #1 priority threat; estimated to affect up to 3% of a workforce annually, often inadvertently (e.g., data exfiltration by departing employees).
    • Third-Party Risk: Attacks often traverse the supply chain (e.g., hacking a university to reach the Pentagon, or a payroll vendor to access a law firm).
  • Business Impact & Economics:

    • Valuation Impact: Breaches directly affect deal valuations (e.g., Verizon saving $2 billion on its acquisition of Yahoo due to disclosed breaches).
    • Long-term Competitiveness: State-sponsored IP theft can erode a company's market position years later, even if stock prices do not immediately dip.
    • Regulatory Fines: The EU GDPR (effective May 2018) imposes fines up to 4% of global revenue for inadequate breach response or data protection.
    • Insurance Market:
      • The cyber insurance market is projected to reach $14 billion by 2022.
      • Current policies cover IR, legal fees, and out-of-pocket losses but do not replace network infrastructure.
      • Risk exists of a "next bubble" if systemic attacks compromise multiple insured entities simultaneously.
      • Investors increasingly view cybersecurity diligence as a pricing factor for stocks.
  • Collaboration & Industry Standards:

    • Financial Services Collaboration: The eight largest US banks formed the Financial Services Analysis and Response Center (FSARC) to share threat intelligence, recognizing that a breach in one bank impacts the entire sector.
    • Public-Private Partnership: Models involving government agencies (e.g., Treasury, NSA) sharing data with private sector firms (e.g., Deutsche Bank, US banks) are essential for global defense.
    • Global Interdependence: Critical infrastructure attacks transcend borders; nations must coordinate norms (G7/G20 discussions) to prevent global financial network collapse.
  • Future Outlook & Technology:

    • Artificial Intelligence: AI will be a double-edged sword; while it enables defense automation and pattern recognition in massive datasets, adversaries will use it for automated attacks and data aggregation.
    • Long-term Vision: By 2050–2060, systems may be fully self-defending; currently, human judgment remains the critical competitive advantage in identifying sophisticated errors.
    • International Norms: Establishing cyber "rules of the road" is difficult compared to nuclear non-proliferation due to the low barrier to entry for non-state actors and the vast number of threat vectors.
  • Illustrative Case Studies:

    • Nigerian Scams Evolved: Attackers now conduct months of network reconnaissance to identify executive travel schedules, then use compromised CEO accounts to authorize multimillion-dollar wire transfers (e.g., $30M to Hong Kong) while the executive is unreachable.
    • Social Engineering: A security vendor successfully extracted detailed company secrets from a foreign national employee by impersonating security staff at 3:00 AM, highlighting the efficacy of psychological manipulation over technical intrusion.
    • Forgotten Infrastructure: Network discovery tools frequently uncover "ghost" servers or data centers that remain active and unsecured despite physical building renovations or management changes.