How Should Businesses Respond to Cyberattacks?

473 views
β€’
February 26, 2020
by
RSAC Cybersecurity
YouTube video player
How Should Businesses Respond to Cyberattacks?

TL;DR

Businesses should prepare for cyberattacks by using existing security tools effectively, monitoring cloud and third-party exposure, and planning for incidents with severe financial and operational consequences. Criminal groups increasingly research large targets, reinvest profits in malware development, and compromise service providers to reach multiple organizations, while nation-state operations continue to expand in sophistication and scope.

Transcript

Okay. Good afternoon, and, uh, welcome to the session, uh, Tales from the Front Lines, uh, 2020. Uh, so this session is a panel, so it's my pleasure to introduce the moderator for, for the panel, who is, uh, Rob Sloan, research director at Dow Jones and Wall Street Journal. Please come on stage. Thank you. Thanks. Ladies and gentlemen, good afterno... Read More

Key Insights

  • Cybersecurity is becoming harder because threat actors are increasing, malware families are becoming more varied, and defenders are no longer confronting the same repeated patterns. Many organizations may already have necessary security tools, but their ability to operate those tools effectively remains a significant challenge.
  • Cybercrime is increasingly organized around large targets rather than individual victims. Attackers conduct extensive reconnaissance, identify how much disruption they can cause, and use that knowledge to increase the amount demanded from an organization after a successful ransomware intrusion.
  • Big game hunting continues across IT, government, education, finance, retail, and healthcare. The groups conducting these campaigns can resemble highly capable businesses because they maintain support organizations and reinvest profits from successful attacks into the development of tools and new malware variants.
  • The impact of a single security failure has increased dramatically. Financial threat actors can attempt transactions involving six, seven, or even eight figures, while ransomware operators seek enough access and operational knowledge to make a targeted organization suffer maximum disruption.
  • Cloud infrastructure is an expanding target because organizations are moving critical assets into it. Threat actors seek footholds in cloud environments and show interest in public key infrastructure, creating additional defensive requirements beyond the protection of traditional organizational networks.
  • Third-party compromise magnifies an attacker's reach because one service provider, managed service provider, or vendor may support many organizations. Targeting that shared access can let a threat group cause damage more quickly and broadly than attacking each customer separately.
  • APT41 is unusual because it has been observed conducting financially motivated crime and state-sponsored operations during overlapping periods. Its targets have included gaming companies, telecommunications organizations, healthcare, and high-technology entities, with some of the same tools appearing across different operational purposes.
  • Chinese targeting became more specific rather than disappearing. The panel described a movement away from rampant intellectual-property theft toward focused espionage, while observing no overall drop in attack activity and continuing to regard Chinese operators as highly capable adversaries.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How should businesses prepare for increasingly complex cyberattacks?

Businesses should focus on using their existing security tools effectively, because possessing defensive technology does not guarantee that it is operated well. Preparation should account for a growing number of threat actors, increasingly varied malware families, cloud infrastructure, and third-party access. Organizations also need an incident response approach designed for attacks that can cause major financial loss and operational disruption.

Q: Why are cybercriminals targeting larger organizations?

Cybercriminals are moving away from attacks focused primarily on individuals because larger organizations offer opportunities for greater financial and operational impact. Attackers research targets, determine where disruption will hurt most, and use that understanding to increase their demands. This approach is especially visible in ransomware, where criminals seek broad access before deciding how much pressure they can apply to a victim.

Q: How do modern cybercrime groups operate like businesses?

Modern cybercrime groups can maintain strong support organizations and reinvest profits from successful campaigns into developing better tools. That investment enables faster production of new malware variants and supports continuing attacks across multiple industries. Their structured operations, financial resources, and deliberate targeting make them more difficult to defend against than isolated individuals conducting opportunistic attacks without comparable organizational capabilities.

Q: What is big game hunting in cybercrime?

Big game hunting is the practice of pursuing substantial organizational targets where a successful compromise can produce a large payoff. The panel describes this trend as continuing across IT, government, education, finance, retail, and healthcare. Attackers perform detailed reconnaissance, evaluate the disruption they can cause, and tailor their demands according to how severely the targeted organization could be affected.

Q: Why are cloud environments becoming cyberattack targets?

Cloud environments are becoming targets because organizations are moving infrastructure and critical assets into them. Threat actors seek footholds inside those environments and have shown interest in cloud-based public key infrastructure. As a result, organizations need to treat cloud systems as part of their primary attack surface rather than assuming that moving assets away from traditional networks makes those assets inherently secure.

Q: How can a third-party provider compromise affect multiple companies?

A third-party provider may hold access to systems belonging to many customers. By compromising a service provider, managed service provider, or vendor, an attacker can potentially reach a broad group of supported organizations through a single intrusion. This strategy expands the available attack surface and lets threat groups create damage more quickly and broadly than targeting every customer organization separately.

Q: What makes APT41 unusual among Chinese threat groups?

APT41 is unusual because the group has been observed pursuing financially motivated crime while also conducting state-sponsored activity. It began with attacks involving the gaming industry, backdoors, and stolen certificates, then expanded into state-sponsored targeting of sectors such as high technology and healthcare. The overlap of tools and purposes distinguishes it from Chinese groups described as conducting only state-sponsored operations.

Q: How did Chinese cyber targeting change during the period discussed?

Chinese cyber activity became more specifically focused, with the panel describing a move away from rampant intellectual-property theft and toward more selective espionage. The observed volume of attacks did not decline, however. APT41 also demonstrated strong operational capability, sometimes appearing when other groups could not obtain access, while continuing activity against targets such as telecommunications and gaming organizations.

Summary & Key Takeaways

  • Cybersecurity became harder as the number of threat actors and malware families increased. Although many organizations already possessed suitable defensive tools, effective use remained a central challenge. Nation-state capabilities continued expanding, while organized cybercriminals shifted from attacking individuals toward larger organizations where a single successful intrusion could create much greater financial and operational impact.

  • Criminal groups increasingly operated like sophisticated businesses. They maintained support functions, reinvested campaign profits in tool development, produced malware variants faster, and targeted industries including IT, government, education, finance, retail, and healthcare. Detailed reconnaissance helped attackers understand each victim, maximize disruption, and determine how much money they could demand through ransomware or fraud.

  • Cloud infrastructure and third-party providers created broader opportunities for attackers. Compromising a managed service provider or vendor could provide access to many supported organizations rather than only one target. The discussion also highlighted APT41, a Chinese group observed conducting state-sponsored operations alongside financially motivated attacks using overlapping tools against gaming, telecommunications, healthcare, and high-technology targets.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š