Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

60
Ukraine Cyberattack a Warning to U.S. Com panies

description

Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPThttp://carmoongroup.com

Transcript of Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

Page 2: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

By Floyd Arthur

Page 3: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

On Dec. 23, 2015, hundreds of thousands of homes and businesses in the Ukraine lost

Page 4: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

electrical power for six hours following what is now being called a well-coordinated,

Page 5: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

well-planned cyberattack. Referring to the attack on the power-grid as the first of its

Page 6: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

kind, SANS Industrial Control Systems described the takedown as a multi-faceted

Page 7: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

effort that involved:

Page 8: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

Cyberattacks

Page 9: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

* remotely switching off breakers to cut the power supply

Page 10: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

* exploiting malware already in the system to prevent utility company employees from detecting the outage

Page 11: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

* flooding phone lines to prevent customers from reporting that the power was out

Page 12: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

The malware also damaged the system server, preventing the affected power

Page 13: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

companies from quickly restoring service and making investigation more difficult.

Page 14: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

Although Ukrainian authorities have yet to release a full report, and questions about

Page 15: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

the malicious code used to implement the cyberattack remain, the cybersecurity

Page 16: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

firm iSIGHT Partners has attributed it to the Russian hacker group Sandworm. In an

Page 17: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

interview with Ars Technica, John Hultquist, head of iSIGHT's cyber espionage

Page 18: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

intelligence division said, "It's the major scenario we've all been concerned about for so long.”

Page 19: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

U.S. Utility Companies Warned of Cyberattack Dangers

Page 20: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

In the wake of the attack, the U.S. power industry’s Electrical Information Sharing

Page 21: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

and Analysis Center issued a warning to power companies that they needed to review

Page 22: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

their cyber-defense systems and “do a better job” of preventing cyberattacks,

Page 23: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

according to a Reuters report. The warning did not identify any critical shortcomings

Page 24: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

in the U.S. power grid, nor did it indicate that the group felt there was an imminent

Page 25: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

danger of a similar incident on U.S. soil. According to EIS spokesperson, Kimberly

Page 26: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

Mielcarek, "There is no credible evidence that the incident could affect North

Page 27: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

American grid operations and no plans to modify existing regulations or guidance based on this incident."

Page 28: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

Increasing Awareness of Cyberattack Threat

Page 29: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

Perhaps the most disturbing aspect of the Ukranian cyberattack was how easy it was.

Page 30: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

According to Robert Lipovsk, senior malware researcher at the Ukrainian software-

Page 31: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

security firm ESET, "The alarming aspect of this attack was that the infection vector”

Page 32: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

[for the malware] was phishing, the practice of using email with a malicious

Page 33: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

attachment to gain access to a computer, “which is quite a trivial way to get in.”

Page 34: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

In fact, cyber-security firms advise that employee carelessness, such as opening email

Page 35: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

attachments from unknown senders of using insecure passwords on private

Page 36: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

computers used at work, is one of the biggest threats to a business’ cybersecurity.

Page 37: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

According to experts who weighed in at a Guardian roundtable last October, another

Page 38: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

is the failure of company leadership to understand the threat. “One of the real

Page 39: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

dangers is that many leaders don’t realise their organisations have become digital,”

Page 40: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

said one participant. They “probably started their careers when their business was

Page 41: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

paper-based, and in their minds that’s how the business still works.”

Page 42: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

Communication and education (at all organizational levels), the group agreed, is the

Page 43: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

key to an effective cyber security program, whether the company is protecting

Page 44: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

customer data or access to a power grid. The group, which included industry leaders

Page 45: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

such as Nigel Harrison, non-executive director of the Cyber Security Challenge UK,

Page 46: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

Andrew Rogoyski, vice-president of cybersecurity services at CGI, and Emma Philpott,

Page 47: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

chief executive at the IASME Consortium, also urged businesses to:

Page 48: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

* Encourage all employees to set strong passwords and change them regularly

Page 49: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

* Update hardware, firmware and software as needed

Page 50: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

* Regularly patch firewalls

Page 51: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

* Change the default password on WiFi routers and gateways

Page 52: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

* Educate leadership and employees about cybersafety

Page 53: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

* Mandate that employees who use their own devices at work install firewalls and antivirus software.

Page 54: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

All across the globe, cybercriminals are becoming more adept at planning and

Page 55: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

implementing cyberattacks, and no business, no matter how small, is immune. A

Page 56: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

strong IT security program and educated employees is the best defense against

Page 57: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

hackers, but having cyber liability insurance to protect your firm is important as well.

Page 58: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

Find out more about this essential form of coverage by contacting one of our business

Page 59: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

insurance experts today. Call us at 516-292-3780 Monday through Friday 9 a.m. to 6

Page 60: Ukraine Cyberattack a Warning to U.S. Companies By Floyd Arthur PPT

p.m., or request a free consultation online now.

Visit www.Carmoongroup.com