Hi folks,
This week was super exciting for me. I got to join two exercises in "analogue" incident response (think fires and chemical leaks, not hacks). It's amazing to see how many things line up with the digital version that I am more familiar with. Especially how much effort goes into communication and documentation.
One unfortunate thing that stood out though, was how often infosec came up as a blocker. Some folks even brought their personal laptops as backups because the too restrictive security policies get in the way of actually saving lives.
Yes, shadow IT is everywhere, but often for good reason. It reminded me of a wonderful quote: "make rivers not walls". Try and make the right path easy to follow, instead of saying no all the time. Something to ponder.
Enjoy the read!
The SEC plans to charge SolarWinds CISO Timothy Brown with fraud, for his role in allegedly lying to investors by "overstating SolarWinds' cybersecurity practices and understating or failing to disclose known risks."
This, together with the previous occurrence where Uber CISO Joe Sullivan was sentenced for his handling of Uber's data breach, seems to mark a clear changing of the times to where CISO's can be personally held accountable for painting the picture of their security posture a little too bright.
Microsoft's security posture hasn't been getting a lot of great press this year, I suppose this is their plan to counter that. Their "Secure Future Initiative" is a pledge to improve the built-in security of its products and platforms.
From the article: "It will have three pillars, focused on AI-based cyber defenses (ofc), advances in fundamental software engineering, and advocacy for stronger application of international norms to protect civilians from cyber threats."
This is the third Counter Ransomware Initiative (CRI) gathering, bringing together 48 countries, the European Union and Interpol. Some items on the agenda were:
- Set up an initiative to incorporate AI and blockchain analysis into the ransomware fight.
- Set up a new information sharing platform for member countries.
- Create a shared blacklist of crypto wallets used by ransomware groups.
- Commit to assisting other members with incident response if government or lifeline sectors are hit with ransomware.
- Provide a shared statement that member countries will no longer pay ransomware demands.
It sure sounds ambitious, especially that last one. And I'm a bit sceptical. There are a lot of articles on what the gathering -will- do, but since the event already happened at the time of writing, I'm looking for articles that say what actually happened but can't find much. Except for this Whitehouse statement that is still sort of vague on the non-payment policy. I'm curious to see if it will actually become law in the member countries.
It's always a fascinating read when articles go into detail on a threat actor. We don't see quite often that they are native English speaking, for example. They also have a very wide range of attack vectors, including social engineering, duplicating voice patterns, and even actually threatening violence.
One thing that surprised me is that they've been seen using corporate data pipelines in Azure Data Factory to extract data while blending in with regular enterprise patterns, and even taking out subscriptions for legitimate Microsoft 365 backup solutions. Not an easy group to detect.