How to Communicate During a Cyber Incident

580 views
β€’
May 2, 2018
by
RSAC Cybersecurity
YouTube video player
How to Communicate During a Cyber Incident

TL;DR

Prepare secure communication methods before a cyber incident, because compromised email, phones, messaging, and webcams can leave a communications team unable to coordinate safely. Kaspersky Lab's Duqu 2 investigation showed that disclosure planning, encrypted tools, air-gapped devices, executive support, technical collaboration, and trained internal stakeholders must be established without creating behavioral signals that could alert an attacker.

Transcript

This session. Um, my name is Pavel. Um, I'm gonna talk you through something, um, that we experienced as a company a few years ago. Um, as a communications team, which I was part of at the time, and still am, uh, we learned some new stuff, and it, it was, um, it's definitely something that we wanna share with the industry and, and, and share that q... Read More

Key Insights

  • Cyber-incident communication is an operational-security challenge when attackers may monitor the organization’s systems. Kaspersky Lab's PR team was instructed to behave normally and avoid unusual emails because visible changes in communication patterns could have revealed that the Duqu 2 intrusion had been discovered.
  • Executive commitment is central to deciding whether an organization will disclose a cyber incident. Eugene Kaspersky insisted that the company disclose the intrusion because an attack against a technically advanced cybersecurity company demonstrated that other organizations could also be exposed to sophisticated threats.
  • Normal workplace tools can become unusable during an active investigation. Kaspersky Lab's communicators were told not to use email, phones, VoIP, direct messages, SMS, mobile phones, or webcams, forcing them to develop messages and coordinate plans through less familiar channels.
  • Secure communication tools require advance training, not merely last-minute installation. The PR team suddenly had to become proficient with Silent Phone, Threema, PGP, and air-gapped laptops while ensuring that no participant accidentally sent an unencrypted message that could expose the confidential response.
  • A single insecure message can compromise the secrecy of an incident response. The team understood that one break in the encrypted communication chain might allow malicious code or people inside the system to detect suspicious activity and infer that an investigation or announcement was underway.
  • Internal security controls can obstruct emergency communications when administrators lack authorized context. A London IT administrator initially resisted requests to install normally prohibited applications and considered contacting a manager in Moscow, creating a risk that the confidential response process would become visible through ordinary escalation procedures.
  • Public-relations materials should be developed alongside the technical investigation. Kaspersky Lab's communications team drafted messaging while researchers examined the intrusion, allowing the evolving announcement to reflect findings about the attacker’s access and the types of information apparently being sought.
  • Cyber-incident planning must account for every internal and external communications participant. As Kaspersky Lab developed its announcement plan, it had to identify relevant PR stakeholders and consider how numerous external agencies could be involved without weakening the secure communication chain.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How should a communications team prepare for a cyber incident?

A communications team should establish secure channels, approved devices, trained users, administrator procedures, and a clear stakeholder list before an incident occurs. Kaspersky Lab's team had to adopt encrypted applications and air-gapped laptops during an active investigation, while some members had never used those tools. Advance preparation reduces confusion and the risk that one ordinary message will expose confidential response activity.

Q: Why did Kaspersky Lab disclose the Duqu 2 intrusion?

Kaspersky Lab disclosed the intrusion because CEO Eugene Kaspersky regarded disclosure as essential, even though the company was not necessarily required to announce it at the time. His stated reasoning was that if a technically advanced cybersecurity company could be exposed to such a sophisticated attack, then any organization could be exposed. That executive decision removed uncertainty for the communications team.

Q: Why did the PR team have to pretend everything was normal?

The PR team behaved normally because Kaspersky Lab suspected that the attackers, or malicious code operating inside its systems, might watch communications personnel. An attacker expecting eventual discovery could monitor PR activity for drafts or unusual exchanges connected to an announcement. Avoiding strange emails and major behavioral changes helped prevent the team from signaling that the intrusion had been detected and was under investigation.

Q: Which communication channels were restricted during the investigation?

The communications team was told not to use email, phones, VoIP, direct messages, SMS, mobile phones, or webcams. Those restrictions removed nearly all of the tools that communicators normally use to coordinate strategy and prepare announcements. The team therefore had to find secure alternatives while continuing to develop public-relations materials and collaborate with the technical investigation without revealing its activity.

Q: Which secure tools did Kaspersky Lab use during the incident?

Kaspersky Lab's team used Silent Phone, Threema, PGP, and, in some cases, air-gapped laptops to coordinate during the investigation. These tools were introduced quickly because ordinary communications were considered unsafe. The PR staff had limited familiarity with them, so they had to become competent while handling an active crisis and maintaining a consistently protected chain of communication.

Q: Why can IT administration become a risk during a confidential investigation?

IT administrators can unintentionally expose a confidential investigation when unusual software requests trigger normal enforcement and escalation procedures. In London, an administrator initially refused to permit prohibited applications and considered asking a manager in Moscow what was happening. Because the communications employee could not explain the secret investigation, this routine reaction nearly weakened the controlled information chain and highlighted the need for advance authorization procedures.

Q: How did the communications team work with technical investigators?

The communications team developed its messaging in close collaboration with the ongoing internal investigation. As technical colleagues learned more, communicators gained a clearer view of what access the attackers did and did not have and what kinds of information they appeared to seek. This enabled the team to prepare public-relations assets that reflected current findings while still using secure, restricted communication methods.

Q: What is the main crisis communication lesson from the Duqu 2 case?

The main lesson is that secure crisis communication capabilities must exist before ordinary systems become unavailable. Kaspersky Lab's PR staff had to learn encryption tools, negotiate installation barriers, coordinate with investigators, identify stakeholders, and draft an announcement while concealing changes in behavior. Planning these processes in advance helps preserve confidentiality and allows communications work to continue during a sophisticated attack.

Summary & Key Takeaways

  • In April 2015, Kaspersky Lab discovered that a sophisticated advanced persistent threat had entered its corporate network. The communications team had to support a confidential, roughly three-month investigation while behaving normally, because the company suspected that attackers or malicious code might monitor PR activity for signs of a planned public announcement.

  • Ordinary communication channels became unsafe during the investigation. Team members were told not to use email, phones, VoIP, direct messages, SMS, mobile phones, or webcams. They quickly adopted Silent Phone, Threema, PGP, and some air-gapped laptops, despite having little prior familiarity with those tools or the required operational discipline.

  • Kaspersky Lab chose disclosure because CEO Eugene Kaspersky considered it essential to show that even a technically advanced cybersecurity company could be exposed to a sophisticated attack. The experience demonstrated that secure crisis communications require preparation, cooperation between investigators and communicators, approved tools, informed administrators, controlled stakeholder access, and executive decisions made before an incident.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š