Live data from Hacker News

MGM losing up to $8.4M a day due to cyberattack, analyist says

reviewjournal.com

91–100 of 111 posts

Re: MGM losing up to $8.4M a day due to cyberattack, analyist says

#91

Earlier quoted context omitted.

Presumably the insurance requires a security audit (yearly?) in order to get in the first place? As long as the auditors OK'd it then the insurance should pay out. Unless they can show that MGM intentionally lied in the information they gave the auditors -- which will surely now be gone through with a fine-toothed comb. (See that HN thread from a couple of days ago wondering if they were personally liable for fraud f…

The audits you get for something like SOC2 are quite weak, I'm very curious to learn if the insurance team's audit is more thorough (if they perform one).

Exactly, often quite weak and might not even include an appropriate scope that covers cyber security/information security controls

Re: MGM losing up to $8.4M a day due to cyberattack, analyist says

#92
post #44

MGM is smart for not paying. You can't let the scammers dictate what a casino does, MGM is already in the business of scamming people. They'll build their whole system from the ground up and be incredibly resistant to future attacks.

I believe they did pay?

Re: MGM losing up to $8.4M a day due to cyberattack, analyist says

#93

Earlier quoted context omitted.

There are multiple things that are done here. Suppose you had great, immutable backups. They still have many things that can ruin your business 1. Restoring networks, servers, third party services with knowledge that anything you restore could be compromised as well. Keys 2. The attackers will then threaten to dump all of your private information. It is more than just restoring data, it is restoring and resetting you…

> And most places have backups, but they don't practice entire restores Or worse, they only practice part of it. Only once in my career have I seen a "restore.txt" that didn't start with something along the lines of "connect to $server". Ok, that assumes a LOT is already in place. Where is the "restore.txt" that goes over how to get $network up so that I can resolve the IP(s) for the server I need to restore? I can't…

to go one step further, then there are all the companies that have done a proper recovery plan, and even tested it.

several years ago.

hopefully there were no externally managed dependencies, as those can change.

hopefully the documentation was entirely written down, not just 80%, with that last 20% having retired, been laid off, or died since then.

how many companies are left at that point?

Re: MGM losing up to $8.4M a day due to cyberattack, analyist says

#94
post #14
post #11

I'm curious if MGM fully understood their cyber risks. Many companies underestimate threats until something like this happens. After seeing MGM, if other hotels beef up security too (very likely), will overall costs for consumers go up?

Security is a SG&A line item, I am sure they are far more fixated on physical security due to their business vertical and had a gap. There will be many cyber companies chomping at the bit to get a piece of the inevitable (I made this number up) 100m MGM will spend on Cybersecurity over the next 5 years. They won't make the same mistake twice and will build a comprehensive cybersecurity program, and it will succeed. U…

Ha, that is funny. I have literally never met a CISO who shares your confidence. Not a single one of the companies chomping at the bit can protect MGM against a multi-million dollar ransomware attack. Companies get hacked because commercial cybersecurity by the big names is useless against the modern, prevailing threat landscape of organized crime. The sum total of their ability is stopping unskilled children, and even then only sometimes.

Just ask any CISO if they would bet their job on surviving a $1M unrestricted red team exercise with a year-long timeframe. They would all be scared shitless by the thought. I bet if you asked the CISO of MGM three days before the attack: "How much would it cost to hack MGM and cripple operations?" they would answer like every other CISO I have heard answer that question and say something on the order of $100K. They know it does not work; they are there to be sacrificed and just hope it does not happen on their watch.

Re: MGM losing up to $8.4M a day due to cyberattack, analyist says

#95

Earlier quoted context omitted.

Accounts don't think revenue and income are synomymous: income is revenue minus expenses. Now if you were to say that profit and income are synonymous, that I might be okay with.

Revenue minus expenses is " net income". "income" is ambiguous.

OK. I believe it.

Re: MGM losing up to $8.4M a day due to cyberattack, analyist says

#96
post #94
post #14

Earlier quoted context omitted.

Security is a SG&A line item, I am sure they are far more fixated on physical security due to their business vertical and had a gap. There will be many cyber companies chomping at the bit to get a piece of the inevitable (I made this number up) 100m MGM will spend on Cybersecurity over the next 5 years. They won't make the same mistake twice and will build a comprehensive cybersecurity program, and it will succeed. U…

Ha, that is funny. I have literally never met a CISO who shares your confidence. Not a single one of the companies chomping at the bit can protect MGM against a multi-million dollar ransomware attack. Companies get hacked because commercial cybersecurity by the big names is useless against the modern, prevailing threat landscape of organized crime. The sum total of their ability is stopping unskilled children, and ev…

You're mistaking compliance with a competent security program.

Re: MGM losing up to $8.4M a day due to cyberattack, analyist says

#97

Earlier quoted context omitted.

You say this as if "addictive" and "harmful" are boolean concepts. These concepts have a wide spectrum in reality. People die every day from addictions to all kinds of socially acceptable products and services, whether it be the dopamine rush from an unhealthy or dangerous activity, a buzz from their favorite beverage, or the sugar rush from an unhealthy snack.

I encourage you to walk through some casinos and take stock of what you see. The scales of enrichment and addiction are nowhere near the balance of candy and soda.

The most harmful things inside of a casino are the bar, the buffet, and the cigarettes.

> I encourage you to walk through some casinos and take stock of what you see.

I have spent a lot of time at casinos with family members who love eating, drinking, smoking, and gambling. Know what I've seen? I've seen that gambling is the only one of the four that hasn't killed at least one of my family members.

Re: MGM losing up to $8.4M a day due to cyberattack, analyist says

#98
post #96
post #94

Earlier quoted context omitted.

Ha, that is funny. I have literally never met a CISO who shares your confidence. Not a single one of the companies chomping at the bit can protect MGM against a multi-million dollar ransomware attack. Companies get hacked because commercial cybersecurity by the big names is useless against the modern, prevailing threat landscape of organized crime. The sum total of their ability is stopping unskilled children, and ev…

You're mistaking compliance with a competent security program.

I am not. Name one competent security program certified and verified to stop total compromise by a $30M unrestricted red team exercise which is the ransom amount demanded by the attackers on Caesars just a few weeks prior.

Keep in mind that amounts to around 100 person-years of dedicated hacking labor. I get a team of 50 and 2 years to achieve total compromise. I get to burn 5-10 zero click RCE zero-days. The idea that any of the commercial cybersecurity companies or any commercial IT organization could design a system that could resist such an attack is laughable. This is not a question of resources, it is one of ability.

I agree, compliance is not an above-average security program. But an security program that is merely above-average is woefully underprepared for the modern threat landscape. You need a security program 100x better than “best practices” to stand a meaningful chance and you are not finding that amongst the charlatans in the big cybersecurity players.

Re: MGM losing up to $8.4M a day due to cyberattack, analyist says

#99
post #63

This is a good example of the kind of case study I will point to when someone starts to get cranky with my unyielding principle of putting the entire business inside a single SQL database. When you have geo replicas and point-in-time restoration capabilities which can synchronously bring 100% of the business back from the dead in a matter of seconds/minutes... How many $8.4m days before a complete rewrite of all syst…

>putting the entire business inside a single SQL database.

I too have a theory that you could get away with this and come out ahead of the industry. The problem is no CEO has the balls to try it in FinTech or any other heavily regulated industry.

Re: MGM losing up to $8.4M a day due to cyberattack, analyist says

#100
post #86

Earlier quoted context omitted.

> Urgent to whom? We live in a multipolar world now. What does that have to do with it? We should expect more of international institutions in a multipolar world. It's urgent to anyone that has had to deal with ransomware gangs. It's urgent for countries suffering from violent cartels. It's urgent for Canada, which just accused India of assassinating one of its citizens on Canadian soil. And so on.

> What does that have to do with it? We should expect more of international institutions in a multipolar world. The whole reason why the world went from unipolar to multipolar is because the existing international organizations failed. What you're missing is these international organizations are political instruments used to obstruct and hinder Russia and China's development. The people in those countries don't share…

> The whole reason why the world went from unipolar to multipolar is because the existing international organizations failed.

They "failed" because they were gutted by a covert, powerful and violent "right-wing" alliance (imperialists, capitalists, white supremacists, all who felt tremendously victimized by recent global events incl. rise of communism). They were not about to throw away centuries of dominance to share international power with "inferior" classes of human.

The UN was rather effective in its initial decades.

Do you really think Hammarskjold, Kennedies, African(-American) leaders getting assassinated en masse in the 1960s was a spate of random coincidence? They were all united in opposing this covert alliance.

But the world is different now, the Global South is decisively emerging from under the imperial boot and multipolarity has a real chance.

Post reply on HN