Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

131–140 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#131
post #129

Earlier quoted context omitted.

>Dude, if you look at Equifaxes and Solarwinds EBITDA/earnings statements following their respective breaches, you will clearly see that there has been no major impact to their bottom line. I'm looking at Equifax's 2018 statements right now. With Operating Revenue of $3.4 billion and profits of $850 million, they had $400 million of expenses related to the breach. "No major impact" my ass.

If you compare year over year, many of the things they attribute to the breach are actually just IT/overhead costs they were able to shift to a loss. If you look at their EBITDA, everything is essentially static. In the grand scheme of things, it really isn't a huge impact to them. Lets say you are a CEO: If you underspend on technology/security by ~50-100m/year, for 5 or 10 years... then have a bad breach, which cos…

>If you compare year over year, many of the things they attribute to the breach are actually just IT/overhead costs they were able to shift to a loss.

No, it's not. Read the 10-K. It includes pages upon pages of the breach-related expenditures, including hundreds of millions of dollars spent on extra stuff like credit monitoring, legal fees, and professional services costs. That's not "just IT/overhead costs".

Just because a company was planning to spend $400 million anyway doesn't mean that having to spend that $400 million on breach-related expenses is no impact. The budget doesn't just come out of thin air, it gets allocated from other places. Spending $400 million on breach-related expenses means not spending that $400 million on something else like product development, research, marketing, or other company initiatives. The impact is enormous.

>In the grand scheme of things, it really isn't a huge impact to them.

You have no clue how businesses work if you seriously think that an additional, unexpected $400 million in expenses (almost 50% of their yearly net profits) "isn't a huge impact to them". That's really all that has to be said here.

Re: US companies hit by 'colossal' cyber-attack

#134

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

A lot of these companies are actually huge enterprises with dozens if not hundred(s) of cybersecurity consultants and engineers. All of them are CISSPs and GICSPs(I do put my CISSP in the signature when working in those places too though). I go through security reviews all the time with them, they have so many security processes that you get dizzy and on paper everything looks fine. They create security zones with ma…

ISC² has done so much damage to the industry via enabling the fallacy of appeal to false authority it is mind-blowing. The cissp is such a terrible proof of whether someone knows anything, everyone knows it, but for some reason people keep falling for it.

Re: US companies hit by 'colossal' cyber-attack

#135
post #61

Earlier quoted context omitted.

That has been a consideration in the AV software I recommend to friends, family, and professionally as an informal part of my threat assessment model. I viewed it as safer to buy products from anywhere other than someone that has ANY potential at all to go to war with the government of the country I live and work in. I really hope it never happens, but 'cold war' tensions might be waged with little cyber attacks and…

Two more things to consider: - Can you articulate specific reasons to buy anything beyond the default windows defender? - If anyone went to an actual war with the US, would the source of your antivirus software get even close to top 5000 things you care about at that point...

As for default Windows Defender, there isn't really good reporting tools related to it. There are reporting tools for Defender, but those are paid license add-ons.

And yeah there's a decent chance if the US went to war with another country it might not impact the majority of US businesses very directly especially in the short term IRT their IT plans. McDonald's kept selling burgers when we invaded Iraq (multiple times). Ford was still producing vehicles during WWII. There have been lots of military engagements the US has been involved in where things in the mainland US weren't massively affected in day to day operations. Who knows what some potential future war with Russia would look like. Would it be a true head to head war with tanks rolling, fighter jets scrambling, cities bombed? Would it be more skirmishes testing how far the other would really go? Would it just be escalation of supply chain attacks and attacks on infrastructure to weaken the other? Of course this greatly varies based on the specifics on what that potential future war looks like, it would be naïve to think wars will always look like WWII, Korea, Vietnam, Iraq, etc from a US mainland perspective.

Re: US companies hit by 'colossal' cyber-attack

#136

Oddly explosive headline, considering: > It is not clear what specific companies have been affected - a Kaseya representative contacted by the BBC declined to give details. So why "colossal"? > "This is a colossal and devastating supply chain attack," Huntress Labs' senior security researcher John Hammond said in an email to Reuters news agency. The BBC is going with "colossal" in their headline simply because the gu…

Hacker News hit by "oddly explosive" BBC headline.

Re: US companies hit by 'colossal' cyber-attack

#137
post #129

Earlier quoted context omitted.

If you compare year over year, many of the things they attribute to the breach are actually just IT/overhead costs they were able to shift to a loss. If you look at their EBITDA, everything is essentially static. In the grand scheme of things, it really isn't a huge impact to them. Lets say you are a CEO: If you underspend on technology/security by ~50-100m/year, for 5 or 10 years... then have a bad breach, which cos…

>If you compare year over year, many of the things they attribute to the breach are actually just IT/overhead costs they were able to shift to a loss. No, it's not. Read the 10-K. It includes pages upon pages of the breach-related expenditures, including hundreds of millions of dollars spent on extra stuff like credit monitoring, legal fees, and professional services costs. That's not "just IT/overhead costs". Just b…

> You have no clue how businesses work if you seriously think that an additional, unexpected $400 million in expenses (almost 50% of their yearly net profits) "isn't a huge impact to them". That's really all that has to be said here.

You clearly have no clue how it looks inside the board rooms and executive offices of some of these huge companies. This type of stuff is treated the exact same way as if a 400m building burns down.

define: impact

2) have a strong effect on someone or something.

My point still stands... If a company can weather the storm, there is no long term impact. If you look at equifaxes breach, it hasn't depressed their revenue. They haven't had to massively changed how they operate or had to pivot into new businesses. Over the long term, it has had very little effect on the company long term, which is my entire point.

Re: US companies hit by 'colossal' cyber-attack

#138
“ At a summit in Geneva last month, US President Joe Biden said he told Russian President Vladimir Putin he had a responsibility to rein in such cyber-attacks.”

I don’t understand how Putin can stop these attacks unless he is personally responsible for them.

Imagine someone in the US hacking systems in Russia or China. How in the hell Biden would know who did that and stop them?

The naivety of US government is just astonishing. I’m sure Putin just laughs when he hears such accusations.

We can’t stop these attacks by asking people not to exploit the systems. We can only stop then by building more secure systems and improving the processes within organizations.

Re: US companies hit by 'colossal' cyber-attack

#139

“ At a summit in Geneva last month, US President Joe Biden said he told Russian President Vladimir Putin he had a responsibility to rein in such cyber-attacks.” I don’t understand how Putin can stop these attacks unless he is personally responsible for them. Imagine someone in the US hacking systems in Russia or China. How in the hell Biden would know who did that and stop them? The naivety of US government is just a…

It may be worth considering if you are naive in thinking that Putin doesn’t explicitly fund and direct the execution of cyber attacks against the west as a lever in improving Russia’s own relative standing.

Why do you think he wouldn’t do so? American sponsors the same cyberattacks on Iranian and North Korean entities.

Re: US companies hit by 'colossal' cyber-attack

#140
post #137

Earlier quoted context omitted.

>If you compare year over year, many of the things they attribute to the breach are actually just IT/overhead costs they were able to shift to a loss. No, it's not. Read the 10-K. It includes pages upon pages of the breach-related expenditures, including hundreds of millions of dollars spent on extra stuff like credit monitoring, legal fees, and professional services costs. That's not "just IT/overhead costs". Just b…

> You have no clue how businesses work if you seriously think that an additional, unexpected $400 million in expenses (almost 50% of their yearly net profits) "isn't a huge impact to them". That's really all that has to be said here. You clearly have no clue how it looks inside the board rooms and executive offices of some of these huge companies. This type of stuff is treated the exact same way as if a 400m building…

>You clearly have no clue how it looks inside the board rooms and executive offices of some of these huge companies. This type of stuff is treated the exact same way as if a 400m building burns down.

I sit with CISOs daily discussing this stuff. $400m expenditures is enough to scare the shit out of them. A $400m building burning down would have CEOs fired (see: Equifax CEO being fired after breach). I don't know what fantasy land you live in, but you're either delusional or lying.

>If a company can weather the storm, there is no long term impact.

That's not what impact means.

>If you look at equifaxes breach, it hasn't depressed their revenue.

This means nothing. It's possible that with an additional 50% of their yearly net income freed up, they could have massively increased their revenue by spending that on product development or sales efforts. You cannot draw any conclusions simply from the fact that their revenue hasn't decreased.

>Over the long term, it has had very little effect on the company long term, which is my entire point.

On the other hand, it may have had an enormous impact. In a time period where every other company is seeing massively rising profits and stock prices, Equifax has been relatively stagnant. Your point has no standing.

Post reply on HN