Cybersecurity and your companyTime and again, cybercriminals have proven to be agile operators, sharpening and transforming their tools in response to world events and trends.
As Kroll’s Paul Jackson put it, “criminal ingenuity is constantly improving and organized crime becoming more organized.”
Kroll, where Jackson serves as Asia Pacific lead for cyber risk practice, is a leading provider of services and digital products related to governance, risk and transparency based in New York.
Jackson cited a case in point: more than 20,000 COVID19-related domains and 2,500 Zoom-related domains were registered in May 2021 alone as criminals pounced on people’s fear of COVID and on vulnerable work-from-home setups.
Along with Kroll managing director James McLeary and senior vice president Jay Gomez, Jackson conducted a session on cybercrime and security for almost 100 Lopez Group employees in August.
Further, Jackson shared a July 2021 report from Intel471 indicating that ransomware attacks, where the owner is blocked from accessing their files or data until they pay a ransom, accounted for as much as 75% of cybersecurity breaches, with Europe (35%), North America (32%) and Asia (13%) as the top three targets.
In terms of breaches reported by sector, professional services and accounting represented 19%, followed by manufacturing (17%); consumer and industrial products (15%); technology, media and telecom (10%); and energy, resources and agriculture (9%).
Hackers target these sectors because they possess critical data that, if hijacked, make them more likely to pay a ransom so as to avoid disrupting their business operations, Jackson said.
Visually impersonating domain name or domain name spoofing, which is used in business email compromise (BEC), is also seeing an uptick during the pandemic. The scam has become so rampant that it accounted for a third of cybercrime losses in 2020.
Even as he reiterated that it is a valuable networking tool, Jackson warned about social engineering scams using LinkedIn, where criminals make up headhunter profiles and lure targets with offers of better-paying jobs; they then email the victim a job description file that infects their computer when they open it.
“If you connect with somebody on LinkedIn, somehow it seems you can trust them. It is very easy to social engineer people into accepting malicious documents. Be careful how you represent your role because bad guys are looking for decision makers,” the cybersecurity expert cautioned.
Incident response
Companies looking to protect themselves need to identify their “crown jewels” or most important assets, determine their risk appetite, do a cyberthreat scenario assessment (“know your enemy in order to protect yourself ”) and, lastly, address these risks by putting the necessary improvements in place.
But if the unthinkable happens and an incident is reported, who do you turn to? What do you do?
Outlining Kroll’s response in BEC or domain name abuse incidents, Jackson referred to an incident where an invoice for a third party was intercepted and the funds transferred to the criminals.
In such a case, the team will look into the email systems and investigate where the compromise could be taking place. This is often a slow and complex process that could be hampered by various roadblocks. One is bulletproof hosting, where criminals set up in locations with little or no law enforcement.
Stressing that “email is a critical gateway to your whole organization,” he recommended for companies to build up their email defenses, conduct threat hunting and ensure they’re not already compromised. It is also important to get the information to the cybersecurity team within 24 or 48 hours.
When it comes to data breach cases, Jackson said “organizations should have a conversation about how they respond to it.”
“To start, you need to see what the attackers had done within the network—where they got in, how they got in and did they move around in the network. This is our core function. We come in and we immediately deploy tools that allow us to have this visibility and will start to tell the story of what actually occurred,” Jackson explained.
Aside from identifying which data could be at risk, the team will also determine what the attackers actually did with the data.
“Did they take it out, just look at it, damage it, encrypt it. More importantly, you need to know if the attackers are still in the network. You cannot do business securely until you are sure attackers are no longer in your network,” he stressed.
The latter part of the process includes, with the help of the company’s leaders, deciding what is reportable to the authorities and when to report.
In the end, companies can know the answers only by testing, running through different scenarios and doing tabletop exercises.
Emergence of the CISO
According to James McLeary, the CISO role emerged only in the last few years. The CISO must be someone who is technologically competent and can promote the security agenda in a way that will resonate with his or her peers. He or she can be a full-time employee or an external expert; given the difficulty of hiring the perfect person for the job, McLeary said it is entirely possible to hire two people—an in-house CISO and an external adviser.
With regard to choosing the right cybersecurity framework, Jackson asserted that it should not be an IT decision as it is something that affects the whole company.
McLeary agreed: “A lot of the success of the security function will hinge upon making sure the framework is the right one and that everyone has bought into it.”
One example is the globally adopted framework National Institute of Standards and Technology Cyber Security Framework (NIST-CSF), which uses a language nontech execs can readily buy into and helps connect the security agenda to the overall business vision and mission and strategies, McLeary said.
“It just really revolves around five key pillars: identify, protect, detect, respond and recover. Business impact is critical—you don’t want to be out of business for days or months on end. You want to recover quickly. So, this is what these frameworks provide you,” Jackson said of NIST.
Security solutions
Since Kroll itself is not a developer of software and hardware manufacturer, it can independently help advise clients pick out the best solutions for their company.
“We see companies buying these very expensive solutions and no idea how to deploy them, or they buy these solutions before they’ve got a governance framework, before they’ve identified what they’re actually protecting,” Jackson said.
At the end of the day, however, tools and technology are only a small part of the solution.
“Having the right people, the right advisers is the greatest part of any effective security practice. It’s all about the people,” Jackson stressed.
Paul Jackson, Asia Pacific lead for cyber risk practice at Kroll
James McLeary, Kroll managing director
Jay Gomez, Kroll senior vice president
Published on Thursday, 20 August 2020 | Hits:1199
Kapamilya love reached more Filipinos as ABS-CBN Foundation Inc.’s (AFI) “Pantawid ng Pag-ibig: Isang Daan, Isang Pamilya” campaign distributed food packs and ligtas bags outside Metro Manila for those greatly
Published on Thursday, 18 June 2020 | Hits:1155
Local government units (LGUs) found it challenging to quickly provide relief to families affected by the quarantine. That is why several mayors in Metro Manila and nearby provinces have expressed
Published on Thursday, 18 June 2020 | Hits:1107
As Filipino families continue to struggle with the loss of jobs, ABS-CBN Foundation Inc. (AFI) moves to the second phase of the “Pantawid ng Pagibig” campaign with the aim of
Published on Tuesday, 19 May 2020 | Hits:1271
The “Pantawid ng Pag-ibig” campaign of ABS-CBN and ABS-CBN Foundation Inc. (AFI) has raised P350 million in cash donations and pledges for the benefit of over 600,000 families in Metro
Published on Thursday, 06 February 2020 | Hits:1192
NO evacuee will be left behind. This is the promise of ABSCBN as it launches the “Tulong-Tulong sa Taal” campaign, which aims to unite the nation in helping Filipinos affected
Published on Friday, 23 June 2017 | Hits:5082
ABS-CBN Foundation Europe CIO joins public and private support for the victims of the massive fire that hit the 24-storey residential London Grenfell Tower in West London on June 14
Published on Friday, 17 February 2017 | Hits:5232
A state of calamity has been declared by the Mayor of Surigao City. Relief and rescue operations are underway for the barangays that have been affected.
Published on Tuesday, 19 May 2020 | Hits:2022
The Rural Workers Association of San Rafael (RWASR) based in Bulusan, Sorsogon, which runs Nasipit Eco-Agri Farm, has a simple message for their fellow Filipinos: “There is no problem we
Published on Thursday, 16 April 2020 | Hits:1752
ABS-CBN helps arm Filipinos with relevant information to stop the spread of disease through its “Ligtas Pilipinas sa COVID-19” campaign on radio, TV and online.
Published on Thursday, 16 April 2020 | Hits:1876
HELP came through for health workers in East Avenue Medical Center after ABS-CBN delivered masks and other protective gear and snacks to show support and Kapamilya love to those leading
Published on Monday, 09 March 2020 | Hits:1608
“Maraming, maraming salamat po sa award na ipinagkaloob ninyo sa amin. Alay namin ito sa kapatid kong si Gina Lopez,” said “G Diaries” host and Bantay Bata 163 executive director
Published on Monday, 09 March 2020 | Hits:1626
She could hardly contain her joy and excitement when she saw her son walking towards her. She welcomed him with tight hugs and happy tears as a loving mother would
Published on Monday, 09 March 2020 | Hits:1579
ABS-CBN Lingkod Kapamilya Foundation Inc. (ALKFI) renamed its building Gina Lopez Building in honor of its late chairperson and founder of ALKFI programs Bantay Bata 163 and Bantay Kalikasan.
Published on Thursday, 06 February 2020 | Hits:1623
ACCORDING to UNICEF, 95 children in the Philippines die every day because of malnutrition. This is one of the reasons Alaska Milk Corporation supports the advocacy of ABS-CBN Lingkod Kapamilya
Published on Monday, 16 December 2019 | Hits:2452
IN 2015, Unicef and the Council for the Welfare of Children conducted the National Baseline Study on Violence Against Children in the Philippines, which indicated that eight out of 10
Published on Friday, 05 January 2018 | Hits:2067
For the Love of Children For the Love of Children These children live everyday making ends meet without losing hope that a better future awaits them. Together, let’s keep their hopes alive
Published on Wednesday, 20 December 2017 | Hits:2376
New World Hotels and Resorts gears up for another exciting edition of Run & Raise in 2018. Now on its fourth year, Run & Raise 4 will be held at