Earlier quoted context omitted.
“After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line.” It’s even worse than just weathering a storm. Lax security has been incentivized. The Equifax CEO, Richard Smith, stepped down shortly after th…
Isn't Equifax a government organization? How do they have severance packages?
US companies hit by 'colossal' cyber-attack
151–160 of 514 posts
Re: US companies hit by 'colossal' cyber-attack
#152Re: US companies hit by 'colossal' cyber-attack
#153Earlier quoted context omitted.
Two more things to consider: - Can you articulate specific reasons to buy anything beyond the default windows defender? - If anyone went to an actual war with the US, would the source of your antivirus software get even close to top 5000 things you care about at that point...
As for default Windows Defender, there isn't really good reporting tools related to it. There are reporting tools for Defender, but those are paid license add-ons. And yeah there's a decent chance if the US went to war with another country it might not impact the majority of US businesses very directly especially in the short term IRT their IT plans. McDonald's kept selling burgers when we invaded Iraq (multiple time…
Re: US companies hit by 'colossal' cyber-attack
#154It's amazing that the World Economic Forum was able to predict a global pandemic in 2019 with Event 201 [1] and widespread cyber attacks in 2021 with Cyber Polygon [2]. Their timing for conducting these trainings is impeccable. We'll probably need Internet Passports, with malware scan certificates, to get online safely. Hope you're not an anti-scanner (it's totally secure). Evil Russian hackers will be a convenient s…
Re: US companies hit by 'colossal' cyber-attack
#155After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…
We have 20-30 years of data on cyber attacks and Cybersecurity is not that important - https://ubiquity.acm.org/article.cfm?id=3333611
Larger the dumps get the harder they are to exploit or do serious damage. I can hand you all my orgs data and 200 people who work with it everyday and it will still take you years to figure out what anything means.
Re: US companies hit by 'colossal' cyber-attack
#156Earlier quoted context omitted.
“After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line.” It’s even worse than just weathering a storm. Lax security has been incentivized. The Equifax CEO, Richard Smith, stepped down shortly after th…
Isn't Equifax a government organization? How do they have severance packages?
Re: US companies hit by 'colossal' cyber-attack
#157Earlier quoted context omitted.
Give it time, these are start-ups bootstrapping themselves. They don't have the support infrastructure in place yet to scale to beyond a few hundred companies. As it is, there are going to be a lot of over-worked people at REvil doing crunch time, missing family dinners and their kids' recitals and soccer games managing the logistics of this hack. No worries though, the ransom from this round should serve nicely as a…
I wonder how much of a human element is involved in each individual hack. I would have thought the sticky note, encryption, payment & decryption was all automated.
What's not is managing big sums of money, turning crypto in to a more traditional currency/assets. That side of the operation probably has more people doing leg work than you'd think.
Re: US companies hit by 'colossal' cyber-attack
#158It's amazing that the World Economic Forum was able to predict a global pandemic in 2019 with Event 201 [1] and widespread cyber attacks in 2021 with Cyber Polygon [2]. Their timing for conducting these trainings is impeccable. We'll probably need Internet Passports, with malware scan certificates, to get online safely. Hope you're not an anti-scanner (it's totally secure). Evil Russian hackers will be a convenient s…
Re: US companies hit by 'colossal' cyber-attack
#159Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…
It sucks, because I know my company is quite small but we take security extremely seriously (we have 9 people, 4 are security engineers, and the other 5 have varying degrees of experience in security). I think people might worry that, because of our size, we won't be as secure as a larger company. But the irony is that larger companies are often far less secure than us, because we've done shit right from day 1.
There's just not a lot of ways to prove it. Compliance is meaningless. You could get a pentest report, but it really comes down to who's doing the pentest, and so if your pentest becomes a public doc the incentive is to have them go easy on you - not to mention that lots of reports contain "findings" that are nonsense but a casual reader might misunderstand.
We plan to give talks and blog about how companies at our stage can do things that would make companies 100x our size jealous, because that's kinda the only thing we can do to really explain that it's possible.
I think it's totally criminal that companies ask for RCE on all of your devices and then push out some closed source C++ app that's probably parsing all sorts of random shit, reading poorly authorized commands from some C2, etc.
Re: US companies hit by 'colossal' cyber-attack
#160Earlier quoted context omitted.
> You have no clue how businesses work if you seriously think that an additional, unexpected $400 million in expenses (almost 50% of their yearly net profits) "isn't a huge impact to them". That's really all that has to be said here. You clearly have no clue how it looks inside the board rooms and executive offices of some of these huge companies. This type of stuff is treated the exact same way as if a 400m building…
>You clearly have no clue how it looks inside the board rooms and executive offices of some of these huge companies. This type of stuff is treated the exact same way as if a 400m building burns down. I sit with CISOs daily discussing this stuff. $400m expenditures is enough to scare the shit out of them. A $400m building burning down would have CEOs fired (see: Equifax CEO being fired after breach). I don't know what…