Home Blog Page 84

10 Legal Questions You Should Be Asking About Ransomware

Ransomware, supply chain and ransomware

Data extortion through cyber means is an insidious threat that thousands of companies throughout the world experience firsthand. For many bad actors, it is the attack of choice owing to its ease of execution, low risk of detection, and huge financial upside. According to Coveware Inc., the average ransom payment ($111,605) has increased by 33% from Q4 2019 to Q1 2020. Companies big and small have suffered from ransomware attacks leaving them with an unimaginable business interruption. Ransomware attacks have become so popular amongst cyberattackers that it has become its industry with shrink-wrapped and Ransomware-as-a-Service (RaaS) options made widely available for sale on the dark web. The methods used by ransomware operators to extort money continue to evolve. Some operators use name and shame sites, others simply encrypt the victim’s data holding it hostage till payment is made.

By Tari Schreider, C|CISO, CRISC, MCRP, ITILF, Senior Analyst at Aite Group

This article lists the most frequently asked questions I get from those attending my EC-Council C|CISO Masterclasses or my Ransomware Simulation Exercises.

1. Is it Illegal to Pay a Ransom Under U.S. Law?

The answer can be both yes and no, depending on the situation. For the most part, U.S. law favors those who pay a ransom.  The U.S. does not generally prohibit or punish those paying a ransom for the return of property or people unless it is paid to a country, organization, or person on the U.S. Department of the Treasury’s Office of Foreign Assets Control (“OFAC”) Sanctions List.

The same is not true, however, for the ransomware operators. According to 18 U.S. Code § 1202. Ransom money, the following holds:

  • Whoever receives, possesses, or disposes of any money or other property, or any portion thereof, which has at any time been delivered as ransom or reward in connection with a violation of section 1201 of this title, knowing the same to be money or property, which has been at any time delivered as such ransom or reward, shall be fined under this title or imprisoned not more than ten years, or both.
  • A person who transports, transmits, or transfers in interstate or foreign commerce any proceeds of a kidnapping punishable under State law by imprisonment for more than 1 year, or receives, possesses, conceals, or disposes of any such proceeds after they have crossed a State or the United States boundary, knowing the proceeds to have been unlawfully obtained, shall be imprisoned not more than 10 years, fined under this title, or both.

For those of you that clicked the link “section 1201 of this title,” you have undoubtedly noticed that this law applies to persons, and you would be correct. However, I call your attention to the legal definition of a person. A corporation is a “person” for the purposes of the constitutional guarantees of equal protection under the law.

The U.S. government has prohibited any financial transactions, which include ransom payments to certain governments, organizations, and individuals that are on the U.S. Sanctions Lists. The countries on the sanctions list include the usual suspect havens of ransomware operators, including Iran, North Korea, and Syria. OFAC has also placed sanctions on certain individuals, for example, two Russian citizens responsible for the development and use of the Cryptolocker ransomware, which infected over 120,000 U.S. victims on the list.

The Trading with the Enemy Act of 1917 is an interesting law to consider, especially when you consider the passage: “have materially assisted, sponsored, or provided financial, material, or technological support for, or goods or services in support of, any activity.” Technically, paying a ransom could be conceived as providing material support. This act, in conjunction with a country or individual on the OFAC sanctions list, could cause significant issues for anyone paying a ransom.  The ambiguity of these laws is one reason companies opt to pay ransoms through a third party.

2. Do I Need to be Concerned About any State Ransomware Laws?

Not really! They focus mainly on establishing ransomware as a crime on a property that would apply to ransomware operators. States are always looking for ways to protect their citizens from cyberattacks. Aside from general cybercrime legislation, many states enact specific laws to address emerging cyberthreats they feel have not covered under their current laws. The emergence of ransomware laws is just one example of this. The pervasive nature and widespread destruction exacted on companies made it only a matter of time that laws would be passed to thwart ransomware operators.

On September 27, 2017, California amended Section 523 of their Penal Code with Senate Bill No. 1137. The law specifically names computer crime extortion as a punishable offense. The California law defines ransomware as a “computer contaminant or locks placed or introduced without authorization into a computer, computer system, or computer network that restricts access by an authorized person to the computer, computer system, computer network, or any data therein under circumstances in which the person responsible for the placement or introduction of the ransomware demands payment of money or other consideration to remove the computer contaminant…” Other states with enacted ransomware laws include Connecticut, Michigan, Texas, and Wyoming. Some states, such as New York, are even attempting to enact laws that would make it a crime to use taxpayer money to pay ransom demands. New York Senate Bill S7246 is currently in committee.

3. Has the U.S. Government Passed Anti-Ransomware Laws?

Only marginally. The U.S. Federal government has been slow to act when it comes to passing legislation criminalizing ransomware attacks, their operators’ actions, and the ultimate impact on organizations (victims). I believe this is mostly due to legislators who believe current laws already conclude ransomware as a crime covered under existing statutes. However, a law passed by the U.S. House, H.R. 5074 – DHS Cyber Hunt and Incident Response Teams Act of 2019, was inspired by the reported increasing number of ransomware attacks. Although the Act never mentions the word ransomware, it does authorize the Department of Homeland Security to maintain cyber hunt and incident response teams. The intended purpose is centered around leading a Federal asset protection response to assist Federal and non-Federal organizations alike in responding to cyberattacks. The presumption is that ransomware falls within the Act’s mandate.

4. Will I Violate the Foreign Corrupt Practices Act by Paying a Crypto Ransom?

No. The Foreign Corrupt Practices Act (FCPA) of 1977 is designed to prevent payments to foreign governments assisting in obtaining or retaining business or directing business to any person. A ransomware payment does not meet the threshold of a foreign government bribe. The U.S. Department of Justice and the U.S. Securities and Exchange Commission agree through their guidance on the FCPA that states that sanction extortion will not give rise to FCPA liability because a payment was made in response to true extortionate demands under imminent threat of physical harm.

5. Will a Ransomware Attack Trigger a Data Breach Notification?

In most cases, yes. Ransomware operators are no longer satisfied with just locking you out of your critical files; they want to entice you to pay the ransom by threatening to leak your information. Most data breach laws require that you must be certain no breach occurred, but how can anyone be (absolutely) certain? The answer is you cannot.

Let’s look at the Department of Health and Human Services (HHS)-provided guidance in Fact Sheet: Ransomware and HIPAA that states:

A breach under the HIPAA Rules is defined as, “… the acquisition, access, use, or disclosure of [protected health information] PHI in a manner not permitted under the [HIPAA Privacy Rule] which compromises the security or privacy of the PHI.” See 45 C.F.R. 164.402.6.

The HIPAA Privacy Rule states

“When electronically protected health information (ePHI) is encrypted as the result of a ransomware attack, a breach has occurred because the ePHI encrypted by the ransomware was acquired (i.e., unauthorized individuals have taken possession or control of the information), and thus is a “disclosure” not permitted under the HIPAA Privacy Rule.”

Unless the covered entity or business associate can demonstrate that there is a “… low probability that the PHI has been compromised,” based on the factors outlined in the Breach Notification Rule, a breach of PHI is presumed to have occurred.

6. Can I be Sued After a Ransomware Attack?

This answer is unquestionable, yes! Take the recent lawsuits where Blackbaud Inc. and Epiq Systems Inc. face class action lawsuits over ransomware attacks that affected many of their respective customers. The basis of these lawsuits is the accusation that both companies acted with negligent conduct and failed to protect customer data. Numerous law firms make a practice of filing class-action lawsuits related to cyberattacks.

You will need to ask yourself if your organization complies with a duty to provide reasonable security. When a direct or implied contractual relationship exists, your organization has to protect customer interests and their data.

7. Can my Company Legally Fire Me after a Ransomware Attack?

When a cyberattack occurs, companies seek to affix blame. Companies including Capital One, Equifax, Uber, Target, and others have all fired their senior IT management following a breach of security. With that said, the answer is a resounding yes. But can you file a lawsuit? The answer is yes if you feel it was a wrongful termination. Take the case of Lake City, Florida, which experienced a ransomware attack in 2019. The city realized that it was not prepared to fend off its ransomware attack and ended up paying 42 bitcoins worth $460,000 in ransom. Their IT Director, Brian Hawkins, was blamed for the attack, and his employment was terminated.  Mr. Hawkins has filed a wrongful termination suit against the city, citing his pre-attack insistence that the city’s backup systems were inadequate to recover from a cyberattack. The city has been rebuffing his lawyer’s discovery motions stating it would cost thousands of dollars to provide the emails Mr. Hawkins states are evidence of his due diligence. We will have to wait to see how this plays out in the courts to see who is right. The lesson here is that you will need documentation to prove your recommendations went unheeded and if you find yourself fired over a cyberattack, hire a great lawyer and maintain documentation proving your actions.

8. Can I Sue an Insurance Company for Not Paying a Ransomware Claim?

Yes, you can, and many have. One of the most notable court cases over a denied cyber policy claim is the ongoing Mondelez International v. Zurich American Insurance Company lawsuit, where the insurance company denied a ransomware attack claim in the amount of $100 million stating it was an act of war policy exclusion. The fine print of a cyber or fraud insurance policy has prevented several companies from receiving payment on ransomware damage claims. Some reasons for non-payment include the insurance company determining the ransomware attack was an act of war or that no fraud occurred.

Let us look at one court case where the G&G Oil Company of Indiana found itself the victim of a ransomware attack. The company paid two ransom demands to receive a decryption key to unlock their critical files. Believing the attack was covered under their insurance policy, the company claimed to recover the cost of data recovery as well as the ransom payment. Their insurer, Continental Western Insurance, denied the claim stating that the event was not fraud but an act of theft. Also, G&G Oil’s policy excluded viruses and hacking attacks. Nonetheless, G&G Oil sued, and the court made a summary judgment in favor of the insurer.  So, although you have the right to sue your insurance company, you need to be sure you understand your policy’s exclusions and, if required, purchase a true cyber insurance or data breach policy.

9. Are Ransom Payments Legally Deductible?

They can be if done under the auspice of a tax attorney. The caveat is that the expenses resulting from the ransomware attack must be properly accounted for according to U.S. tax law. One approach would be to claim the related expenses as an ordinary and necessary business expense under 26 U.S. Code 162(a) – Trade or Business Expenses. The nascent nature of ransomware makes the argument that an attack is now part of the cost of doing business on the Internet could very well stand up to Internal Revenue Service (IRS) scrutiny.  The Supreme Court has ruled that for a payment to be “necessary,” it must be “appropriate and helpful” for “the development of the taxpayer’s business.” What could be more necessary than freeing your company from a crippling attack?

Another option is to claim the non-insurance reimbursed costs as a theft event as provided under 26 U.S. Code 165(a) – Losses. A little wrinkle in this is that the IRS states the attack must be illegal under the law of the state where it occurred. If you are in a state with a ransomware law, you are in luck. However, in most states, you can find some legislation to use to justify this ruling. The best advice here is to hire a great corporate tax attorney and deduct your ransomware-related costs.

10. If I Fall Victim to a Ransomware Attack, Am I Legally Required to Disclose?

Yes, depending on the regulations and laws, your organization is governed. A ransomware attack has a legally subtle but important difference compared to typical cybercrimes. With a classic data breach where data is exfiltrated (stolen), the violation of information is never in doubt. In ransomware attacks, data is made inaccessible – so has a theft occurred or privacy violated? If the data is released after payment, has any harm been done? One could argue that as no data was lost and no harm occurred, other than your bruised pride and loss of money – is it a disclosable crime?  Disclosing or not disclosing a cyberattack introduces an ethical dilemma as well. It may be entirely legal not to disclose, but is it the right thing to do? Several years ago, most companies who chose to not disclose would likely not suffer any legal consequences. However, today ransomware operators steal data, threatening to disclose confidential information if the ransom is not paid. In this example, a data breach has occurred.

Public companies have no wiggle room for disclosing a breach. On October 13, 2011, the SEC issued a CF Disclosure Guidance relating to cybersecurity risks and cyber incidents. Hence, beginning in 2021, publicly traded companies must acknowledge any cyberattacks to their respective regulator.  So, the best policy is to do the right thing, disclose the event.

None of what I covered in this article should be construed as providing legal advice, and I advise you to consult with your legal counsel to go through these questions. My goal is to make CISOs the smartest people in the room.

This article first appeared in the December 2020 issue of CISO MAG.


About the Author

Tari SchreiderTari Schreider is a distinguished technologist and nationally known expert in the fields of cybersecurity, risk management, and disaster recovery. He is currently a Senior Analyst with Aite Group covering cybersecurity technologies and practices for Aite Group, LLC. He was formerly Chief Security Architect at Hewlett-Packard Enterprise and National Practice Director for Security and Disaster Recovery at Sprint E|Solutions. Schreider is an instructor for EC-Council where he teaches advanced CISO certification and risk management courses.

Disclaimer

Verification of legal quotations and references in this article has not been done by CISO MAG editors and is the responsibility of the author. Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Corporate Compliance Strategies to Protect Data

cybersecurity compliance

The pandemic has pushed the corporate workforce to remote locations, which has resulted in increased risk to corporate data. As corporations rise to the challenge of responding to this risk, compliance officers, CISOs, and leaders should look to revamp disjointed and siloed approaches to protecting corporate data. The past few years have seen a notable expansion of trade secret laws resulting from a new federal trade secret act in the U.S., the passage of stricter trade secret regimes in Asia, and the harmonization of trade secret protection in Europe with the EU trade secret directive. With these new laws has come a noticeable uptick in trade secret civil and criminal cases. Like traditional compliance risks, theft or loss of information can lead to loss of valuable R&D, business disruption, loss of competitive advantage, reputational damage, and – if an employee improperly uses a third-party’s trade secrets – costly civil or criminal litigation. While ransomware, hacking, and phishing schemes often get the most news coverage, insider theft represents the vast majority of data loss.

By Steve Grimes, Co-leader, and Sheryl Falk, Co-leader, Winston’s Global Privacy & Data Security Practice

The Importance of a Cross-Functional Team Approach 

In our view, a Chief Information Security Officer cannot – on her own – sufficiently mitigate the risks posed by insider threats. The task of building and maintaining a robust information security system to mitigate against internal theft requires cross-functional input, execution, and maintenance. While the critical work of protecting infrastructure and equipment is led by the Info Security team, IT, Human Resources, Legal, and other functional groups have a role to play in successfully protecting the company’s resources. This is especially true as it relates to insider threats, where a company’s own employees or trusted partners steal, lose, or divulge the company’s information.

For example, Human Resources needs to be involved in the training, education, hiring, on-boarding, and off-boarding procedures. R&D and business leaders need to make crucial decisions about designation and access to confidential information. They should also be integrally involved in the design of information security systems and the execution of processes that build the systems. Legal needs to be involved in the drafting and execution of confidentiality agreements, supplier agreements, NDAs, as well as incident management, investigations, and pursuing potential legal remedies if and when theft occurs.

There also needs to be communication between and amongst these groups. For example, Human Resources may work with IT on credential management to disable access for departing employees or alert Legal if an employee with access to valuable information resigns to work for a competitor. IT can advise if company devices are outstanding so that Legal can trigger an investigation, decide to preserve the employee’s devices, or send a letter to the new employer, alerting them of the employee’s ongoing confidentiality obligations. However, in many companies, these functional groups have not historically worked together to develop a cohesive, strategic, and tailored approach to data security. Instead, each group addresses areas of the problem that fall within its silo, leading to inefficient and sometimes counterproductive outcomes. Additionally, some functional groups outside of Legal — such as Human Resources — are not trained on the critical role they play in data security, such as ensuring the prompt collection of a departing employee’s laptop, leading to data leakage theft.

Companies have started to coalesce these different functional groups under a unified leadership structure. The implementations and reporting structures vary, from task forces to steering committees, to “trade secret leadership.” But the goal is the same: to align the functional groups to one unified and smart approach for protecting company assets and preventing employees from using or uploading confidential information belonging to a former employer. This “reverse threat” of a current employee bringing confidential information from a former employer into the business environment is a real risk. That’s because corporations are typically the “deep pocket” on the wrong side of a trade secret theft lawsuit. A cross-functional, unified approach to protecting corporate information will be viewed as a best practice.

Building an Operational Strategy

Companies spend significant amounts of money developing confidential and proprietary data and must implement security measures to protect the data from theft or loss. While many corporations focus on information security to protect against outside cyberattacks, most data theft occurs from insiders. Because employees need access to corporate data to do their jobs, a company must consider which additional data security measures are necessary to allow employees to work. At the same time, there is an obligation to protect trade secret data, including, for example, tracking if confidential or proprietary data leaves the system. This is not just a best practice; it is required. Trade secret regimes worldwide require a company to demonstrate that it took “reasonable measures” to protect their data before they can claim trade secret protection over its information. While “reasonable measures” is not a well-defined term, courts are looking at the overall robustness of an organization’s approach to data security to determine whether a trade secret right has been established.

To address this threat and ensure that reasonable measures are in place, we recommend a cross-functional team to develop an operational strategy. This high-level operational plan allows the team to identify risk and reach consensus on priorities, strategic response, implementation, responsibilities, and accountability. Building consensus around a well-thought-out approach – including identifying data protection strategies designed to protect data from insider threats and allocating resources – is a key step toward effective trade secret protection.

Further, a company’s ability to respond to data theft and minimize what can be catastrophic and costly consequences – depends on the implementation of measures to detect, investigate, and contain any such theft long before it occurs. The operational plan should address data theft response so that a company is well-positioned to respond swiftly and efficiently.

Focusing on Trade Secret Audits

We counsel clients to be proactive in protecting corporate data by conducting a data security audit to identify and protect confidential and trade secret information. The audit should not just focus on the technical aspects of the systems (though technical audits and strategic roadmaps are integral aspects of most information security programs), but also approach protection from a cross-functional, proactive perspective looking at preventing theft, detecting theft, and responding to suspected theft. By assessing the maturity of technical systems and processes and the human side, companies will be able to determine their risk to information theft more accurately and be well-positioned to mitigate that risk in a coordinated approach.

These audits involve identifying the corporate trade secret information, how the data is handled, and who has access to such data. The audits consider a review of the data security provisions in place to restrict and protect data, and a review of policies, processes, and procedures. Audits also include analyzing the enforceability of the company’s standard confidentiality agreements and assessing information security measures, including interviews with key stakeholders.

While the contours of such an audit vary depending on a company’s size, international presence, industry, type of workforce, nature of its trade secrets, and risk tolerance — all companies need to be addressing this risk from the perspective of cross-functional groups.

Here’s a typical scenario. When a key employee is off-boarded, does HR ask probing questions about confidentiality and the employee’s next move? Does HR notify Info Sec when an employee has given notice so that heightened monitoring may be employed? Does R&D fully utilize logs and data access restrictions for higher prioritized information? Do the Legal and InfoSec teams have a protocol for investigating potential misconduct that maximizes evidentiary value while also preserving legal optionality? Have hiring managers been trained about the risks of soliciting competitive information?

The answers to these types of questions, and many others, have a direct bearing on the success or failure of a data security program but may fall within several groups, besides the purview of the CISO.

Furthermore, systems or protocols to improve how the company answers these questions or address data theft require buy-in and implementation by employees outside of the InfoSec team. A company must take a cross-functional approach to data theft to minimize data theft and maximize its ability to respond to (and mitigate the consequence of) a theft that does occur.

As the workforce changes how employees interact with corporate data, companies should bring together the key stakeholders to develop an operational plan to address information security from insider threats and conduct a trade secret audit to protect its valuable data.

Companies that bring teams together and form an operational strategy are more likely to protect data than the best-intentioned silo approach.

This story first appeared in the November 2020 issue of CISO MAG.


About the Authors

Steve GrimesSteve Grimes is co-leader of Winston’s Global Privacy & Data Security Practice. He is a former federal prosecutor, an experienced trial lawyer, and a former Chief Compliance Officer and senior litigation counsel for a global publicly-traded Fortune 500 company. Steve’s practice focuses on compliance and data security counseling, sensitive internal investigations, government interactions, and complex disputes. Steve’s in-house experiences greatly aid his ability to provide tailored and pragmatic service to his clients.

Sheryl FalkSheryl Falk is co-leader of the firm’s Global Privacy and Data Security Practice and is recognized as a leading lawyer in privacy, data security, and trade secrets. She brings significant expertise and strategic thinking to help clients comply with quickly changing privacy laws and protect data, investigate data security incidents, and handle data privacy and trade secret litigation. One of the first attorneys in the U.S. to be certified in computer forensics, Sheryl is a former federal prosecutor and Certified Information Privacy Professional and has been recognized in Legal 500.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

U.S. Introduces Security Bills to Secure Critical Infrastructure

U.S. introduce security bills

Organizations globally continue to suffer cyberthreats from various cybercriminal groups. Most enterprises have increased their cybersecurity budget to boost their security capabilities against evolving threats. It is high time for regulatory bodies and policymakers to implement robust security policies for better protection of critical digital infrastructures globally.

Recently, the U.S. House Committee on Homeland Security passed seven bipartisan security bills to bolster defense capabilities, enhance pipeline security, and defend supply-chain attacks targeting U.S. organizations and critical infrastructure. The latest bills also help state and local governments protect their networks, provide mitigation strategies against critical vulnerabilities, and authorize the Cybersecurity and Infrastructure Security Agency (CISA) to help establish a national cyber exercise program to promote continuous testing of cybersecurity preparedness and resilience to cyberattacks.

The Seven Bipartisan Security Bills include:

  1. The Pipeline Security Act (H.R. 3243), introduced by Congressman Emanuel Cleaver, will enhance the ability of TSA — the principal Federal entity responsible for pipeline security — to guard pipeline systems against cyberattacks, terrorist attacks, and other threats.
  2. The State and Local Cybersecurity Improvement Act (H.R. 3138), introduced by Congresswoman Yvette D. Clarke, seeks to authorize a new $500 million grant program to provide State and local, Tribal, and Territorial governments with dedicated funding to secure their networks from ransomware and other cyberattacks.
  3. The Cybersecurity Vulnerability Remediation Act (H.R. 2980), introduced by Congresswoman Sheila Jackson Lee, will authorize CISA to assist critical infrastructure owners and operators with mitigation strategies against the most critical, known vulnerabilities.
  4. The CISA Cyber Exercise Act (H.R. 3223)establishes a National Cyber Exercise program within CISA to promote more regular testing and systemic assessments of preparedness and resilience to cyberattacks against critical infrastructure. The bill was introduced by Congresswoman Elissa Slotkin.
  5. The DHS Blue Campaign Enhancement Act (H.R. 2795)strengthens the DHS Blue Campaign and enhances the availability of human trafficking prevention training opportunities and the development of such training and materials. The bill was introduced by Congressman Peter Meijer.
  6. The DHS Medical Countermeasures Act (H.R. 3263), introduced by Congresswoman Mariannette Miller-Meeks, establishes a medical countermeasures program to support DHS mission continuity and facilitate the readiness and resilience in the event of a chemical, biological, radiological, nuclear, or explosives attack, naturally occurring disease outbreak, or pandemic.
  7. The Domains Critical to Homeland Security Act (H.R. 3264), introduced by Ranking Member John Katko, authorizes DHS to conduct research and development into supply chain risks for critical domains of the U.S. economy and transmit the results to Congress.

The security bills were introduced in the wake of the Homeland Security Committee’s oversight of recent cyberattacks, including the ransomware attack that disrupted operations of the U.S. largest pipeline service Colonial Pipeline, series of SolarWinds supply chain attacks, and state-sponsored groups targeting critical security vulnerabilities in Microsoft Exchange Servers and Pulse Connect Secure devices.

“The Colonial Pipeline ransomware attack that shut down one of our nation’s largest pipelines and triggered fuel shortages across the northeast has brought new urgency to our work to protect the country’s critical infrastructure. This attack also follows a string of disturbing cyberattacks against government entities and the private sector – from SolarWinds and Pulse Connect Secure to Microsoft Exchange Server and the Oldsmar Water facility,” said Chairman Bennie G. Thompson.

“Since the beginning of this Congress, this Committee has engaged in extensive oversight of these events and how the Federal government partners with others to defend our networks. The legislation we reported today was the result of this oversight. I am pleased that they received broad bipartisan support and hope they are considered on the House floor in short order,” Thompson added.

Colonial Pipeline Reportedly Paid $4.4 Mn in Ransom

Ransomware attack on Colonial Pipeline

The world has taken notice of the ransomware attack on the Colonial Pipeline in the U.S. Given the aftermath of the attack, which caused panic and massive fuel shortages across the East Coast, even countries like Japan have initiated stringent measures to protect their critical as well as private assets. The Biden administration has also signed an Executive Order with the intent of fortifying the country’s cyber defenses that have been targeted extensively in the recent past. However, amid all the chaos, Colonial Pipeline has reportedly confirmed paying a ransom to its attackers for quickly reinstating its paralyzed services.

Paying Ransom, the Last Resort

On May 7, around 5:30 a.m., Colonial Pipeline’s internal team members discovered they were targeted with a sophisticated ransomware attack when one of the control-room operators received a ransom note on the computer. They locked their systems to contain and stop the further spread of the attack to its 260 delivery nodes across 13 states. It took them just over an hour to successfully complete the shutdown procedure, eventually preventing its operational technology (OT) systems from getting infected.

However, damage was done to its IT infrastructure and the Colonial’s team was not sure about the extent, time, and cost of getting back up and running. This led the CEO, Joseph Blount to make a difficult decision – paying up. In an interview with the Wall Street Journal, Blount acknowledged he authorized the ransom payment of 75 Bitcoins, which approximately accounts $4.4 million.

Blount said,

I know that’s a highly controversial decision. I didn’t make it lightly. I will admit that I wasn’t comfortable seeing money go out the door to people like this. But it was the right thing to do for the country.

Whether paying the ransom was the right thing to do or not, as Blount said, it is “highly controversial.” But an official advisory issued late last year by the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC), states that it is “illegal” to pay ransom to any cybercriminals. In the purview of this announcement, Colonial’s ransom payment is rather questionable. Since more than 9,500 gas stations were out of fuel within a matter of few days, with no clear timeline on the restoration of services even after taking expert help from an unnamed firm who has reportedly dealt with the same ransomware gang (DarkSide) in the past, Blount probably agreed upon the inevitable.

As of May 15, Colonial Pipeline’s services had been restored barring a few glitches in the past few days where intermittent disruptions were experienced during its “hardening efforts” of the ongoing restoration process. The company’s Twitter handle clarified that the interruption did not have anything to do with the ransomware attack.

Related News:

Paying Ransom is Now Illegal! U.S. Dept of Treasury Warns

Ransomware Attack Forces Temporary Shutdown of Top U.S. Fuel Pipeline Operator

Suffered Attack, Paid Ransom, Restored Systems: The CNA’s Ransomware Timeline

Ransomware Attacks, Graff ransomware attack

Businesses have been harrowed with the ever-rising question, “To pay or not to pay ransom?” The FBI had urged companies to avoid ransom payments because it only worsens the situation encourages others. The ransom does not fix the vulnerability, and though companies recover their data, cybercriminals make a pocketful out of it. Recently, CNA Financial Corp., one of the largest insurers in the U.S., allegedly paid $40 million to cybercriminals, to recover control of its network systems after being hit by a ransomware attack. While the company did not comment on the ransom, it did state that it reported the security incident to the FBI and the Treasury Department’s Office of Foreign Assets Control.

On March 21, 2021, CNA disclosed that it sustained a sophisticated cyberattack that disrupted some of its systems’ operations.

“We continue to progress our investigation into this incident, in partnership with the third-party forensic experts working to assist CNA. We are pleased that in a short time since the ransomware event, we are now operating in a fully restored state,” CNA said.

Threat Summary

  • On March 21, 2021, CNA detected the ransomware and took immediate action by proactively disconnecting its systems from its network to contain the threat and prevent additional systems from being affected.
  • CNA’s forensic investigation and root cause determination have revealed no indication that this was a targeted attack or that CNA or policyholder data was specifically targeted by the threat actor.
  • Additionally, all attacker activity happened in, or before March 2021.
  • The company is confident that the threat actor has not accessed the CNA environment since the ransomware event.
  • It has no evidence to indicate that external customers were potentially at risk of infection due to the incident.

Is Phoenix Ransomware Group Involved?

While CNA did not reveal the name of the cybercriminal group it paid ransom to, several industry experts stated that threat actor group Phoenix is likely behind the attack. Phoenix ransomware is believed to be linked to the Evil Corp threat group because its code resembles the one used by the Evil Corp threat group.  Phoenix ransomware comes as a legit signed software tricking the victim to execute it and it then encrypts the victim’s data.

Mixed Opinions

CNA clarified that all of its affected systems have now been restored. It added, “CNA is fully restored, and we are operating business as usual. Our IT teams and third-party partners have worked hard to restore business operability.”

However, several industry experts raised concerns over CNA’s failure in detecting the ransomware attack, which led the company to pay a huge ransom to recover its systems.

“Of course, it’s very easy to have a good laugh about a cyber insurance company getting caught with its pants down, hit by ransomware, and paying an EYEWATERING $40 MILLION RANSOM (sorry, but I do think the figure deserves emphasizing), but it could have happened to just about anyone well, maybe not the paying $40 million bit,” said cybersecurity researcher Graham Cluley.

“A stunning failure in management and a benchmark for how low the cybersecurity industry is,” said security researcher Kevin Beaumont.

Tips for Implementing Zero Trust – Taking Trust Away from Security

Zero Trust, cybersecurity

Whether it’s between leaders, managers, and workers, vendors, and customers, or companies and regulators, trust lowers the barriers to cooperation and keeps things moving smoothly.

By Matthew Heap, Head of Solution Architecture, APJ for Rackspace Technology

Still, most businesses – and people – recognize that to be too trusting too soon can be a serious disadvantage. For one emerging network security model, any trust at all is too much.

We’re talking about Zero Trust, an approach to security that’s experienced skyrocketing interest this past year as enterprises have seen their traditional network perimeters stretched perilously thin by mass remote working and expansion to public cloud and SaaS applications.

In simple terms, zero trust means “never trust, always verify.” Zero trust has become a hot topic for executives since remote access rapidly expanded due to COVID-19 and there was an increase in adversaries looking to exploit remote users and computers. Never trusting and always verifying is more rigorous, proactive, and responsive than just building perimeter defenses to keep malicious actors out of networks, multi-cloud workloads, and applications along with remote access from anywhere on any device, perimeter-based trust models are increasingly failing to provide appropriate safeguards.

In 2020, Forrester predicted that the Asia Pacific will finally catch up on Zero Trust adoption. Although Zero Trust adoption in the Asia Pacific has lagged behind its global peers, the acceleration of cloud adoption and an explosion in remote work as well as changing regulations and consumer behaviors make it ripe for change. Forrester anticipates that at least one government in the Asia Pacific will embrace a Zero Trust cybersecurity framework in 2021.

Yet for all its rewards, zero trust implementation is a complicated endeavor. Apart from the technical challenges, success depends on engaging and activating multiple stakeholders from across the business and providing a lot of user hand-holding.

This article will help tech leaders get their bearings with zero trust as they start to think about how they might implement it themselves.

Exploring the technical aspects of zero trust

In practical terms, effective zero trust implementation requires not just technology, but also policy and process. It’s not a switch that IT teams can flip or a product or service that they can buy, but it does require a blend of tooling distinct from that used in traditional perimeter-based security.

Wrapped around these solutions are strict policies defining which users and devices can access which resources; there can be no more free and open access. Defining these policies and enabling their implementation can be a heavy lift. It requires the understanding of application workflows and dependencies, but there are automation and AI-based solutions to ease some of the burden and the benefit to both security and operations is worth the effort. Zero trust security relies on identity and access management, endpoint control, and a mature security monitoring capability.

It is a must to bring people along on the zero-trust journey

It’s important to recognize that implementing zero trust crises crosses team boundaries throughout the organization. It draws in security, network, and identity access management (IAM) teams, along with asset owners and admins, and application owners. This kind of scope means the CIO/CTO will often be the lead, with the CSO/CISO a critical contributor thanks to their perspective on risk management.

Organizations must also invest time in awareness building and socialization of the benefits of zero trust, creating detailed FAQs, and sharing them via company newsletters and intranets with plenty of links to resources. Trust us: education and communication before rollout can save businesses a lot of help desk pain as their policy and process changes start going live.

Start small, start critical – and utilize DevOps

Businesses can get off on the right foot with zero trust by starting small to build a series of incremental but highly visible wins. They may want to start with access control and then move inwards toward more complicated data center implementations.

If IT teams start with a baseline across their environment, they can add to this as they discover and classify workload and data. At the same time, start lining up technology solutions and their configurations. Understand the requirements and select partners to help integrate appropriate technologies to provide for authentication, access control, micro-segmentation, and monitoring.

Prior to enforcement, it is recommended to identify and build company policies and then soft-launching policies in logging mode to help refine the picture of what’s going on in the environment. This offers the opportunity to test processes before launch, to both mitigate the risk of taking down critical systems and to identify patterns and processes that can be automated. From there, adopt rolling implementations to subsets of users – in parallel to business’ existing security systems at first – to iron out processes and build confidence in the user base.

It’s worth mentioning that it’s likely to be very difficult to get all this right without using agile methodologies within the project to deploy DevOps. The early stages are a lot of work with a lot of changing priorities. So use agile methodologies to hasten and pivot where necessary.

Furthermore, operational overheads can quickly mount, owing to the multiple and ongoing changes and updates to infrastructure and policy. DevOps can help here as IT teams work toward automating user and device updates, or application and systems access flows. With infrastructure as code, for example, systems can be created that allow users to self-serve by registering a ticket for a new device, which then pushes out an update to the infrastructure. There are also technologies now that can help deploy DevOps to legacy workloads as well as apps built in a legacy manner.

Zero trust is worth the effort

Moving to a zero-trust security strategy takes several months of hard work and many hours of ongoing monitoring and management. And yet it’s a journey we expect the majority of enterprises will undertake.

The shift we have seen to remote work this past year won’t reverse fully and for some, it may become the norm. So executive-level anxieties will remain over whether users’ endpoints are protected, the mitigation of insider threats, and the risks of lateral movement by intruders should they make it through their perimeter defenses.

It’s not magic; there’s no silver bullet in security. Zero trust is a way to move organizations away from perimeter-based security to a secure access service edge (SASE) as businesses continue their digital transformation.


About the Author

Matthew HeapAs Head of Solutions Architecture for Rackspace Technology across APJ, Matthew Heap is an accomplished and experienced IT leader with over 15 years of experience dedicated to delivering client value.

Certified across all major Public and Private Clouds, Heap has immense experience architecting solutions for AWS, Microsoft Azure, Google Cloud Platform, Alibaba Cloud as well as large Private Hyper-Converged infrastructures. He has been instrumental in developing strategic solutions for enterprise customers to accelerate their journey to the cloud.

In his current role, Heap leads a team of talented solutions architects creating and designing systems to keep mission-critical workloads available across the APJ region.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Android Update! Patches for Four Zero-Day Vulnerabilities Released

Microsoft Azure App, Zero-Day Vulnerability

The risks from cyber criminals exploiting zero-day vulnerabilities have become a continuous threat for organizations, as they could lead to critical data breaches and cyberattacks. Recently, Android discovered four new critical zero-day bugs which were exploited in the wild. However, the company released fixes for the four vulnerabilities – CVE-2021-1905, CVE-2021-1906, CVE-2021-28663, and CVE-2021-28664 in its May 2021 Android Security Bulletin.

The flaws could affect Qualcomm Graphics and Arm Mali GPU Driver modules. If exploited successfully, the vulnerabilities could enable a remote hacker to execute arbitrary code to obtain a privileged process.

Security Researcher at Google’s Project Zero Maddie Stone said, “For 2021, we’ve surpassed the number of 0-days detected in the wild in all of 2020.”

What is a zero-day vulnerability?

A zero-day vulnerability is a flaw in a piece of software that is unknown to the programmer or vendor responsible for the application. Because the vulnerability isn’t known, there is no patch available. And hence, zero-day vulnerabilities pose a higher risk to users and businesses.

Google also recommended certain mitigation measures to reduce the likelihood of security vulnerabilities from becoming exploitable. These include:

  • Exploitation for many issues on Android is made more difficult by enhancements in newer versions of the Android platform. All users are encouraged to update to the latest version of Android where possible.
  • The Android security team actively monitors for abuse through Google Play Protect and warns users about Potentially Harmful Applications. Google Play Protect is enabled by default on devices with Google Mobile Services and is especially important for users who install apps from outside of Google Play.

The latest Android security updates also included security patches for critical vulnerabilities in the System component that could allow an attacker to execute arbitrary malicious code within the context of a privileged process. Google urged all Android users to install the security updates as early as possible.

In its March 2021 Android Security Bulletin, Google addressed 37 vulnerabilities in its Android Operating System, including a critical flaw in the System component.

The State of Android Security

In a recent Google I/O session, the Director of the Android Security Strategy, Eugene Liderman, stated that in the first quarter of 2021, 95% of Android devices were given a security update that was released within 90 days.

Liderman also highlighted that the speed and frequency of Android security updates are now better than before and stated that Google Play Protect helps prevent malicious apps from being published.

Indian Government Gives 7-days to WhatsApp for Privacy Policy Roll Back

WhatsApp and Indian governmentWhatsapp Hack

WhatsApp has recently been in a slew of legal battles in India over its latest privacy policy changes. However, it has now been served a 7-day ultimatum by the Indian government for a complete roll back of all the new privacy policy changes which came into effect on May 15. Failing to do so, the Ministry of Electronics and Information Technology (MeitY) has warned of legal action against all the clauses deemed inappropriate by them.

WhatsApp India Privacy Policy Row

WhatsApp has been previously asked to reconsider its privacy policy changes by the Indian government. In January this year, the Indian government deemed the new privacy policy changes as “discriminatory” because the same policy in the European Union (EU), was made optional to its users owing to the GDPR regulations. Since India still does not have a formal data privacy law in the country (it is currently in the works and will be introduced in the parliament’s coming session), MeitY had requested WhatsApp to withdraw the policy and respect the “right to privacy” and consent of Indian users. However, WhatsApp did not completely dissolve the enforcement of the new privacy policy which was supposed to come into effect on February 8, 2021; instead, it just deferred it by three months to May 15.

In April, the MeitY filed an affidavit in the Delhi high court stating WhatsApp’s privacy policy violated the Information Technology Rules of 2011 on five counts. They were:

  1. It fails to specify the types of sensitive user data being collected.
  2. It fails to notify users of such collection.
  3. It does not let them review or amend the information.
  4. It does not allow the withdrawal of consent later.
  5. It fails to provide any guarantee against non-disclosure to third parties.

In response to the Affidavit, WhatsApp told the Delhi high court that it was conforming with the current Indian IT laws and rules in place and respected users’ privacy for which it has already taken steps such as end-to-end chat data encryption. Additionally, to make its point clearer, it presented another affidavit which names other popular applications in the country like Zomato, Ola, BigBasket, Truecaller, and the government’s own COVID tracking app, Aarogya Setu, which have similar privacy policies.

In response to the petition, Justice Sanjeev Sachdeva had earlier told MeitY that, “It is a private app. Don’t join it. It is a voluntary thing, don’t accept it. Use some other app.” Pointing at other apps like Google Maps, Justice Sachdeva added that even others do it and “you would be surprised as to what all you are consenting to.”

Going by this philosophy of “If you want it, you use it,” a few days back, the company again informed the Delhi high court that it has rolled out the policy on May 15 as decided but it was “not forcing users to accept the new updates in the privacy policy.” It clearly stated that it would not delete the accounts of users who have refrained from accepting the changes for now. However, this does not seem to be enough and the ministry has finally given a countdown of seven days before it initiates legal action as deemed appropriate. There is widespread speculation (on social media and in WhatsApp message forwards) that users who do not accept the new privacy policy may not be able to access all the features of WhatsApp. But this is yet to be confirmed.

Related News:

WhatsApp vs Signal vs Telegram: Which is More Viable and Secure?


Indian Government Asks WhatsApp to Withdraw its “Discriminatory” Policy

ICO Fines Contact Tracing Service Tested.me for Misusing User Data

French Regulator Fined Google

The U.K.’s Information Commissioner’s Office (ICO) has fined a contact tracing service provider Tested.me for misusing users’ personal data.  In an official notice, the data regulator announced that it imposed an £8,000 fine (approximately USD 11,300) under section 55A of the Data Protection Act 1998, after the company ran email marketing campaigns without users’ consent.

Based in St. Albans, Tested.me provides digital contact tracing services to businesses by offering users a QR code to scan on arrival at business premises. Several people provided their personal details to businesses via Tested.me.

What Happened?

The ICO claimed that Tested.me sent over 84,000 unwarranted marketing emails between September and November 2020. According to the ICO, Tested.me violated data protection laws by exploiting users’ personal data without the consent of the people who had provided their information for contact tracing.

The issue came to light when a user reported an email sent by Tested.me regarding a digital health passport to the ICO. “The mail thanked the individual for scanning into a business using TML’s QR code and promoted a related app. The person who received the email said they had not provided consent to be sent it,” ICO said.

In addition to Tested.me investigation, the ICO revealed the rise in the use of QR code technology and asked 16 QR code providers to ensure they were processing people’s personal data securely.

“The checks, which took place over the past six months, found that most of the companies understood the relevant laws and the importance of processing personal data fairly and securely. ICO experts also met with some of them to help improve their practices,” ICO added.

ICO Guidelines to Businesses

The ICO also created guidelines for businesses to follow to ensure users’ data privacy. According to it, organizations in the U.K. should:

  • Adopt a data protection by design approach (DPBD) from the start when they develop new products
  • Make privacy policies clear and simple so that people understand how their information will be handled
  • Not keep any personal data they have collected for more than 21 days — in line with regulations brought in last year for the collection of information for contact tracing
  • Not use the personal data for marketing or any other purpose

The ICO also imposed five steps for businesses to follow when collecting customers’ details. These include:

  1. Ask for only what’s needed
  2. Be transparent with customers
  3. Carefully store the data
  4. Don’t use it for other purposes
  5. Erase it in line with government guidance

“We understand that organizations have lots of new measures to put in place so that they can re-open safely to the public. For many, this includes collecting customers’ and visitors’ personal information for the first time, to support the various contact tracing schemes in the U.K. Whilst asking for contact details has been voluntary so far, new measures have been brought in to oblige certain organizations to ask for this information,” ICO added.

Related Story: Think Before You Scan! Malicious QR Codes in the Wild

3 Takeaways from 2020 for CISOs to Guide This Year’s Strategy

CISOs in remote working

Last year cast a shockingly bright spotlight on cybersecurity with the risks that surfaced due to the rise of remote work. The year was capped off by one of the most significant supply chain hacks. This incident, coupled with the onslaught of ransomware and other cyberattacks in 2020, provides an opportunity for some deep insight into where the focus of cybersecurity efforts needs to be in order to prepare for the future.

By Derek Manky, Chief of Security Insights & Global Threat Alliances, FortiGuard Labs

The supply chain became a bigger target

Supply chains have faced threats since time immemorial, but this time the hack took the threat to a whole new level. As the attack unfolded, a significant amount of information was shared by affected organizations. Monitoring this emerging intelligence closely, enabled the creation of IoCs to detect related activity.

Communications with internet infrastructure associated with SUNBURST detected in 2020, show the attack made victims globally. The “Five Eyes” intelligence alliance exhibited particularly high rates of traffic matching the IoCs. Additional evidence of possible spillover targets underscores the interconnected scope of modern supply chain attacks and the importance of supply chain risk management.

The chief takeaway from all of this is that supply chain security can’t be ignored. CISOs need a supply chain risk management plan to establish policies and procedures for dependencies and exposures. This plan should document key risks throughout the system development life cycle. That includes design, manufacturing, production, distribution, acquisition, installation, operations, maintenance, and decommissioning.

Bad actors are rapt with APT

Though SolarWinds got most of the headlines at the end of last year, many other APT groups continued unabated in their illicit activities in the shadows. For instance, they kept exploiting the pandemic in a variety of ways in the second half of 2020. This included attacks focused on stealing intellectual property, gathering personal information in bulk, and nabbing intelligence aligned with the APT group’s priorities.

The more familiar an organization is with its adversaries and the better it understands their tactics, techniques, and procedures, the better it is able to array effective defenses against them. Persistent adversaries will get in somehow, but successful organizations are able to find and flush them out quickly. Visibility into and focusing on the latest tactics, techniques, and procedures relevant to your organization’s threat profile is a must. Ignorance is their ally, but it’s definitely not yours.

Home is where the heart – and the risk – is

At the risk of sounding like a broken record, the major shift to remote work has had a massive impact on cybersecurity and continues to do so – shining a light on all sorts of potential vulnerabilities and attack vectors. IoT devices gained importance for attackers, in large part because of the blurred divisions between home and corporate offices.

Malicious actors have demonstrated their willingness to subvert the sometimes less-than-enterprise-grade security inherent to many of these devices now that they’re effectively part of the corporate perimeter. That means employees may be accessing corporate resources from a compromised environment—a security model that many organizations are unaccustomed to.

Remote working isn’t going away. Rather, it’s become the standard for a significant portion of the global workforce. It’s unlikely that in-office working will return to pre-pandemic levels. Accordingly, CISOs must move toward deploying viable long-term security strategies for their remote workers.

Takeaways that drive a strategy

 The supply chain is under serious attack, the devices and networks of home offices increase the threat landscape, and advanced persistent threats will persist. These are the key takeaways of 2020 that will inform the security strategy of 2021.

As organizations face attacks on all fronts, that strategy will need to be one of broad awareness and integration. Threat intelligence remains central to understanding these threats and how to defend against evolving threat vectors. Visibility is also essential, especially when a significant number of users are outside the typical network setting. Every device in a home office creates a new network edge that must be monitored and secured.

Organizations can leverage artificial intelligence in automated threat detection to address attacks immediately, not later, and is a modern requirement for mitigating attacks across all edges. They should also keep cybersecurity user awareness training as a priority since cyber hygiene is not just the domain of IT and security teams. Everyone needs effective and ongoing training on best practices for keeping individuals and the organization as a whole secure. In a threat environment that mixes old and new tricks, CISOs must create a strategy that can address them all.


About the Author

Derek MankyAs chief of security insights and global threat alliances at FortiGuard Labs, Derek Manky formulates security strategy with more than 15 years of cybersecurity experience. His ultimate goal is to make a positive impact towards the global war on cybercrime. Manky provides thought leadership to the industry and has presented research and strategy worldwide at premier security conferences. As a cybersecurity expert, his work has included meetings with leading political figures and key policy stakeholders, including law enforcement, who help define the future of cybersecurity. He is actively involved with several global threat intelligence initiatives, including NATO NICP, INTERPOL Expert Working Group, the Cyber Threat Alliance (CTA) working committee, and FIRST, all in an effort to shape the future of actionable threat intelligence and proactive security strategy.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.