newsfilter.io
Panel, Conference Presentation

My Organization Has Been Hacked

  • Ray Rothrock identifies the 2013 Target hack as a turning point elevating cybersecurity to a boardroom priority and forecasts that North Korea may launch cyber attacks to demonstrate capability before any kinetic conflict, while noting that long-term intellectual property theft by China could reduce US company competitiveness within five years.
  • Dimitri Alperovitch predicts CrowdStrike will prevent approximately 300 breaches weekly across 176 countries and anticipates that sophisticated attacks have recently targeted major central banks in developing nations, with North Korea attempting to fund its government through illicit financial transfers.
  • Dimitri Alperovitch states that adversaries fall into three categories—nation-states, cyber criminals, and hacktivists—and warns that Nigerian scam groups are advancing to perform extensive reconnaissance on financial authority while waiting for executives to be unreachable to execute social engineering.
  • Siobhan McDermott expects that C-suite executives face increasing pressure to have cybersecurity plans in place and notes that the eight large US banks founded the Financial Services Resiliency and Analysis Center (FSARC) to share threat intelligence, a model expanding to power, utilities, and cross-border interlinkages.
  • Siobhan McDermott predicts that adversaries are increasingly focused on data integrity and manipulation rather than just exfiltration and identifies insider threat as the top priority, with up to 3% of staff potentially engaging in inadvertent or malicious insider activity annually.
  • Dan Ennis anticipates that many organizations spend on cybersecurity without prioritization, leading to an inability to articulate exposure, and predicts that auditors will focus on whether an organization had and followed a plan while noting that insider attacks are a frequent vector.
  • Dan Ennis expects that proof of value network models will uncover forgotten connections in 100% of cases and warns that companies often fail to remediate identified issues due to competing priorities and complexity.
  • Heather Adkins predicts the GDPR will take effect in May 2018 with fines up to 4% of global revenue and anticipates the cybersecurity insurance market will reach approximately $14 billion by 2022.
  • Heather Adkins warns that a single entity compromising multiple large companies like Yahoo, Google, and Microsoft could trigger the next insurance bubble and notes that nuclear analogies for cyber are complicated by the low barrier to entry and a large marketplace.
  • Heather Adkins predicts that AI will be integrated into platforms by 2050 for autonomous defense and offense, leveraging data aggregation to find patterns beyond human capability, though humans will remain the competitive advantage in error detection.
  • Dimitri Alperovitch asserts that prevention alone is insufficient and that organizations must prepare for crises immediately after a breach, anticipating that most cyber cases will end in court requiring immediate legal privilege establishment.
  • Siobhan McDermott expects that the first action during a breach will likely be contacting lawyers and PR teams to control the narrative, noting that the first call depends on how the compromise was discovered.
  • Siobhan McDermott anticipates that financial services institutions are primary targets because destabilizing them creates havoc elsewhere and predicts that adversaries use value chains to compromise smaller third parties to reach larger entities.
  • Dan Ennis predicts that communication campaigns can discourage insider actions by fostering inclusion and openness, contrasting this with cultures that hide breaches, which often suffer significant compromises.
  • Siobhan McDermott expects that the Bank of America organization measures every employee on security responsibility and predicts that CEOs demanding silence until issues become catastrophic will inevitably be caught by surprise.
  • An insurance speaker predicts a "three-strikes-you're-out" rule for employees who repeatedly fail phishing training, while Siobhan McDermott expects a critical relationship between security and HR to identify potential problem employees.
  • Heather Adkins predicts that social engineering can deceive 10% of any population, including highly educated groups like Google employees, regardless of training, and that a company's culture regarding hacking depends on its existing openness.
  • Dimitri Alperovitch anticipates that executives must make decisions based on incomplete data during crises because regulators, press, and lawyers do not wait, and that CISOs are often compelled by general counsel to consult them during investigations to secure privilege.
  • Siobhan McDermott expects that traditional cyber functions must meet with general counsel and business leaders early to facilitate communication and anticipates that organizations may lack answers at the start of an investigation.
  • Dan Ennis anticipates that having a prioritized plan helps organizations respond to and explain situations to stockholders and predicts that failing to practice response plans leads to unforeseen issues.
  • Dimitri Alperovitch expects that the Sony hack caused massive psychological impact on employees due to personal data theft and anticipates that the biggest mistake post-breach is being unprepared for the resulting crisis.
  • Heather Adkins expects that companies with a culture of hiding breaches suffer from bad culture and significant breaches, while those with open conversations utilize employees as a free detection capability.
  • Heather Adkins anticipates that companies must constantly assess their business environment and work with legal firms to identify transient risks from client activities.
  • Dimitri Alperovitch predicts that hacktivist attacks are less predictable and can occur instantly compared to nation-state or criminal attacks.
  • Siobhan McDermott expects that the G7 and G20 are moving toward cyber norms regarding financial network resiliency.
  • Siobhan McDermott anticipates that the insider threat is the top priority and is increasing over time, with many cases being inadvertent, such as employees taking research data.
  • Heather Adkins anticipates that while nuclear analogies are used, international agreements on cyber weapons are difficult due to the low entry barrier and huge marketplace.
  • Siobhan McDermott predicts that CEOs who demand not to hear issues until they are catastrophic will get caught by surprise.
  • Dan Ennis predicts that nation-states view a country's economic capability, including intellectual property, as a legitimate target.
  • Siobhan McDermott expects that financial services institutions are a primary target because destabilizing them creates havoc everywhere else.
  • Siobhan McDermott anticipates that adversaries are increasingly focused on the integrity and manipulation of data, not just exfiltration.
  • Siobhan McDermott predicts that many organizations are compromised as part of a value chain to get to something else via third-party risk.
  • Heather Adkins expects that the list of nation-states targeting Gmail includes all of them, while others target infrastructure.
  • Heather Adkins anticipates that companies need to constantly assess where they are doing business and work with legal firms to identify transient risks from clients' activities.
  • Ray Rothrock predicts that in the event of a kinetic conflict with North Korea, cyber attacks may occur first to show capability and inflict pain before escalation.
  • Ray Rothrock expects that financial institutions in the United States will worry about potential destructive attacks or large thefts by North Koreans.
  • Ray Rothrock anticipates that the long-term impact of China stealing intellectual property may not dent stock prices today but will make companies less competitive in five years.
  • Heather Adkins predicts that the GDPR will go into effect in May of 2018 in Europe, potentially imposing fines of up to 4% of global revenue.
  • Heather Adkins anticipates that the cybersecurity insurance market will be estimated at around 14 billion by 2022.
  • Heather Adkins expects that the next bubble in the insurance business may occur if a single entity compromises multiple large companies like Yahoo, Google, and Microsoft simultaneously.
  • Dan Ennis expects that breaches are already largely priced into stock prices by investment communities looking for due diligence.
  • Siobhan McDermott predicts that the eight large banks in the United States have founded the Financial Services Resiliency and Analysis Center (FSARC) to share information on common threats.
  • Siobhan McDermott anticipates that the FSARC model started in financial services is now broadening out to other industries like power and utilities.
  • Siobhan McDermott expects that other countries are looking to create similar cross-border interlinkages for cyber security.
  • Dan Ennis predicts that the global interconnectedness of the financial sector requires collaboration across borders because boundaries no longer apply to digital attacks.
  • Heather Adkins anticipates that competition among tech giants does not prevent information sharing behind the scenes when protecting users.
  • Dimitri Alperovitch expects that the Nigerian scam groups are advancing to perform extensive reconnaissance on financial authority within organizations.
  • Dimitri Alperovitch anticipates that adversaries will wait for executives to be unreachable (e.g., on vacation) to execute social engineering attempts like the CEO email scam.
  • Dimitri Alperovitch predicts that adversaries can extract significant amounts of information from employees simply by impersonating security teams.
  • Dan Ennis predicts that the vector of attack for the Joint Chiefs of Staff network was a university, highlighting the risk of the supply chain.
  • Dan Ennis anticipates that buying companies or partnering requires concern for the security of the target's or partner's network, as their problem becomes your problem.
  • Heather Adkins predicts that compromise chains can go very deep, extending from a large multinational to small 20-30 person law firms and their payroll vendors.
  • Siobhan McDermott anticipates that a firm being breached can sometimes be caused by another firm that is also a client of the consulting firm.
  • Dan Ennis expects that 100% of the time, proof of value network models find connections that people forgot about or didn't know existed.
  • Dan Ennis predicts that companies often fail to take action on problems they are told to fix due to priorities and complexity.
  • Siobhan McDermott expects that the insider threat is the top priority on her list of people who are going to hack.
  • Siobhan McDermott predicts that the insider threat priority is increasing over time.
  • Siobhan McDermott anticipates that insider cases are often inadvertent or not malicious, such as employees taking research data thinking they own it.
  • Siobhan McDermott predicts that up to 3% of staff may engage in some kind of insider activity, whether inadvertent or malicious, resulting in a case count that should match this percentage annually.
  • Heather Adkins anticipates that while nuclear analogies are used for cyber, the low bar to entry and huge marketplace make international agreements on cyber weapons difficult.
  • Heather Adkins expects that Russia and China are using cyber as a form of power and foreign policy.
  • Heather Adkins anticipates that G7 and G20 discussions are moving towards cyber norms regarding financial network resiliency.
  • Heather Adkins predicts that by 2050, AI will be built into platforms so computers can defend themselves and attack each other without human help.
  • Heather Adkins expects that the power of AI in cybersecurity lies in the ability to aggregate massive amounts of data to find patterns beyond human capability.
  • Heather Adkins anticipates that bad guys are also using AI to collect data from breaches to find value and leverage it against others.
  • Heather Adkins predicts that the human will remain the competitive advantage in finding errors at the end of the day despite AI capabilities.
  • Ray Rothrock predicts that the 2013 Target hack marked a turning point where cybersecurity shifted from a niche IT issue to a mainstream boardroom concern.
  • Ray Rothrock expects that prevention alone will no longer be sufficient for organizations, asserting it is necessary but not enough.
  • Dimitri Alperovitch predicts that CrowdStrike will stop about 300 breaches every single week across 176 countries.
  • Dimitri Alperovitch states that organizations are currently engaged in probably 50 or so instant response engagements.
  • Dimitri Alperovitch expects that the biggest mistake organizations make after a breach is being fundamentally unprepared to deal with the resulting crisis.
  • Dimitri Alperovitch anticipates that most cyber cases will eventually end up in court, requiring organizations to establish legal privilege immediately.
  • Dimitri Alperovitch predicts that tabletop exercises are essential for understanding how to handle regulators, educate executives, and notify competitors or vendors.
  • Heather Adkins expects that every company on the face of the planet has something that somebody wants to steal.
  • Heather Adkins anticipates that if a company is surprised by a hack, it indicates they have never thought about the problem before.
  • Heather Adkins predicts that organizations need to practice their response plans monthly, even if only for ten minutes, to build organizational muscle memory.
  • Siobhan McDermott expects that the first call to make depends on how the compromise was discovered, noting a different response if found in the Wall Street Journal versus a CISO alert.
  • Siobhan McDermott anticipates that C-suite executives and boards face increasing pressure to have a cybersecurity plan in place.
  • Siobhan McDermott predicts that the first action an organization takes will likely be calling its lawyers and PR team to establish privilege and control the narrative.
  • Siobhan McDermott expects that organizations may not have all the answers at the beginning of an investigation, which is a critical factor in public commentary.
  • Dan Ennis predicts that many organizations spend money on cyber without doing it in a prioritized way, leading to an inability to articulate why they were exposed.
  • Dan Ennis anticipates that if an organization has a plan with priorities, they will be better able to respond to and explain the situation to the C-suite or stockholders.
  • Dan Ennis expects that the most critical question from auditors or investigators will be whether an organization had a plan and followed it.
  • Dan Ennis predicts that organizations that do not practice their plans will face aberrant issues that they did not plan for or realize.
  • Dimitri Alperovitch expects that the Sony hack resulted in a massive psychological impact on the employee base due to the theft of personal data like salary and social security numbers.
  • Dimitri Alperovitch predicts that executives must make decisions based on incomplete and sometimes incorrect data during a crisis because the press, lawyers, and regulators will not wait.
  • Dimitri Alperovitch anticipates that CISOs often need to be compelled by general counsel to call them even while they are still investigating, due to the need for legal privilege.
  • Heather Adkins expects that a company's culture regarding hacking is dependent on its existing culture of openness.
  • Heather Adkins predicts that employees mobilized through open conversations act as a free detection capability because they will see attacks before technology does.
  • Heather Adkins anticipates that companies with a culture of hiding breaches, like the reluctant CEO case, suffer from bad culture and significant breaches.
  • Siobhan McDermott expects that cyber security permeates the Bank of America organization, with every employee being responsible and measured on it.
  • Siobhan McDermott predicts that CEOs who demand not to hear about issues until they are catastrophic will inevitably get caught by surprise as small issues escalate.
  • Siobhan McDermott anticipates that traditional cyber functions need to meet their general counsel and other business leaders early, before a breach occurs, to facilitate communication.
  • Dan Ennis predicts that insider attacks are a frequent vector and that PR campaigns should focus on making people feel included to discourage insider actions.
  • Dan Ennis anticipates that communication campaigns regarding insider threats can create a sense of openness that discourages people from attacking.
  • An insurance company speaker predicts that they are changing policy to dismiss people who fail phishing training repeatedly, citing a "three-strikes-you're-out" rule.
  • Siobhan McDermott expects a relationship between security staff and the HR department is critical to identifying possible problem employees who might act out.
  • Heather Adkins predicts that social engineering can trick 10% of any population, even highly educated ones like Google employees, regardless of training.
  • Dimitri Alperovitch expects that adversaries can be categorized into three buckets: nation-states, cyber criminals, and hacktivists.
  • Dimitri Alperovitch predicts that in the last 18 months, sophisticated attacks have targeted major central banks in the developing world.
  • Dimitri Alperovitch anticipates that North Korea has been attempting to fund its government through illicit financial transfers.
  • Dimitri Alperovitch expects that hacktivist attacks are less predictable than nation-state or criminal attacks and can pop up instantly.
  • Dan Ennis predicts that nation-states view a country's economic capability, including intellectual property and innovation, as a legitimate target.
  • Siobhan McDermott expects that financial services institutions are a primary target because destabilizing them creates havoc everywhere else.
  • Siobhan McDermott anticipates that adversaries are increasingly focused on the integrity and manipulation of data, not just exfiltration.
  • Siobhan McDermott predicts that many organizations are compromised as part of a value chain to get to something else via third-party risk.
  • Heather Adkins expects that the list of nation-states targeting Gmail includes all of them, while others target infrastructure.
  • Heather Adkins anticipates that companies need to constantly assess where they are doing business and work with legal firms to identify transient risks from clients' activities.
  • Ray Rothrock predicts that in the event of a kinetic conflict with North Korea, cyber attacks may occur first to show capability and inflict pain before escalation.
  • Ray Rothrock expects that financial institutions in the United States will worry about potential destructive attacks or large thefts by North Koreans.
  • Ray Rothrock anticipates that the long-term impact of China stealing intellectual property may not dent stock prices today but will make companies less competitive in five years.
  • Heather Adkins predicts that the GDPR will go into effect in May of 2018 in Europe, potentially imposing fines of up to 4% of global revenue.
  • Heather Adkins anticipates that the cybersecurity insurance market will be estimated at around 14 billion by 2022.
  • Heather Adkins expects that the next bubble in the insurance business may occur if a single entity compromises multiple large companies like Yahoo, Google, and Microsoft simultaneously.
  • Dan Ennis expects that breaches are already largely priced into stock prices by investment communities looking for due diligence.
  • Siobhan McDermott predicts that the eight large banks in the United States have founded the Financial Services Resiliency and Analysis Center (FSARC) to share information on common threats.
  • Siobhan McDermott anticipates that the FSARC model started in financial services is now broadening out to other industries like power and utilities.
  • Siobhan McDermott expects that other countries are looking to create similar cross-border interlinkages for cyber security.
  • Dan Ennis predicts that the global interconnectedness of the financial sector requires collaboration across borders because boundaries no longer apply to digital attacks.
  • Heather Adkins anticipates that competition among tech giants does not prevent information sharing behind the scenes when protecting users.
  • Dimitri Alperovitch expects that the Nigerian scam groups are advancing to perform extensive reconnaissance on financial authority within organizations.
  • Dimitri Alperovitch anticipates that adversaries will wait for executives to be unreachable (e