How Should Companies Prepare for Cyber Breaches?

440 views
•
August 2, 2017
by
RSAC Cybersecurity
YouTube video player
How Should Companies Prepare for Cyber Breaches?

TL;DR

Companies should treat cyber breaches as unavoidable business risks, reduce their probability, and prepare to respond quickly and correctly when they occur. Targeted attacks can be more serious than indiscriminate ransomware because attackers deliberately pursue a specific enterprise, while effective preparation requires management, security teams, and IT operators to share responsibility for limiting damage.

Transcript

Hi, this is Britta Glade. I'm senior content manager with RSA Conference. Um, we're here today in Singapore for the last day of RSA Conference 2017, Asia Pacific and Japan. I'm very happy to be joined today by Vivek Chugh, who is the senior director at Mandiant. Thank you so much for joining us. Thank you, Britta. The, the pleasure is mine. Vivek p... Read More

Key Insights

  • Every investigated breach can cause disruption, even when it does not resemble highly visible ransomware or denial-of-service incidents. Organizations should therefore evaluate the full operational impact of intrusions instead of defining disruptive cyber events only by their most familiar forms.
  • Targeted attacks are more serious than indiscriminate malware when attackers deliberately select an enterprise and intend to cause harm. WannaCry and Petya were described as spreading broadly, with affected organizations becoming victims because they happened to be in the malware's path.
  • Cybersecurity risk is already present across Asia-Pacific, not merely a possibility for the future. Mandiant began operating in the region in 2013 and observed breaches of the same nature and scale as those in the United States, sometimes on an even larger scale.
  • Organizations in smaller countries can also become targets because attackers have varied motives, objectives, and reasons for pursuing them. A company's location or national market size does not, by itself, place it outside the path of determined threat actors.
  • Management involvement is essential because cybersecurity is not solely a technical problem. Executives and boards that experience major breaches often change their perspective dramatically and drive organizational improvements after recognizing the operational pain and seriousness of the risk.
  • Security tools cannot eliminate the possibility of a breach. Spending on firewalls, intrusion detection systems, antivirus software, and other controls can minimize probability, but management must still prepare for incidents and support timely, correct containment when prevention fails.
  • Incident preparation is a form of business risk management comparable to preparing for fraud or theft. A practical plan should define how the organization will respond when an incident occurs, enabling responsible teams to act promptly and contain the resulting damage.
  • Security is an IT responsibility as well as a security-team responsibility. Security managers can navigate and advise, but IT personnel drive implementation because they access, operate, and maintain systems while balancing security against uptime, availability, and performance requirements.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How should companies prepare for a cyber breach?

Companies should recognize that controls can minimize the probability of a breach but cannot eliminate it. Management should establish a plan before an incident occurs, clarify how the organization will respond, and ensure that responsible teams can act on time and correctly. Preparation should focus on containing damage while treating cyber incidents as ordinary business risks, much like fraud and theft.

Q: Why are targeted cyberattacks especially serious?

Targeted attacks are especially serious because attackers deliberately choose a specific enterprise, pursue access, and intend to cause harm or damage. This differs from broadly spreading malware such as WannaCry and Petya, where victims were affected because they happened to be in the malware's path. Understanding the attackers, their methods, motives, and intended impact is therefore critical to breach preparation.

Q: How do targeted attacks differ from widespread ransomware?

Widespread ransomware can propagate without selecting each affected organization in advance, leaving victims impacted because they are in its path. A targeted attack instead begins with an attacker intentionally pursuing a particular enterprise and seeking to breach it for a defined harmful purpose. That deliberate focus can make the incident more serious and demands preparation for consequences beyond the initial technical compromise.

Q: Why is cybersecurity a major issue in Asia-Pacific?

Cybersecurity is a major Asia-Pacific issue because serious attacks are already occurring throughout the region. Mandiant began operating there in 2013 and subsequently investigated breaches comparable in nature and scale to those seen in the United States, with some possibly larger. The incidents were not limited to Singapore, Australia, or Japan, since organizations in smaller countries were also successfully targeted.

Q: Why must company management participate in breach planning?

Management must participate because a breach can affect the whole enterprise rather than only its technical systems. Executives and boards involved in large incidents experience the operational pain directly, and their understanding often changes significantly afterward. Once leaders accept that prevention cannot guarantee safety, they can support a response strategy, allocate attention appropriately, and drive the changes needed to contain future damage.

Q: Can firewalls and antivirus software prevent every breach?

Firewalls, intrusion detection systems, antivirus software, and related spending cannot guarantee that a breach will never happen. Such measures may minimize the probability, but they do not remove the need for preparation. Management should assume an incident remains possible, establish a response plan, and ensure the organization can act promptly and correctly to contain damage when preventive controls fail.

Q: Who is responsible for cybersecurity inside a company?

Cybersecurity is not solely the CISO's or security team's responsibility. Security managers can serve as navigators by setting direction and providing expertise, but IT personnel are the drivers because they have system access and operate the infrastructure. Effective security therefore requires IT to treat protection as part of its job while continuing to manage uptime, availability, and performance.

Q: What can organizations learn from companies that suffered breaches?

Organizations can learn how executive assumptions, priorities, and actions change after a serious breach. Leaders who once believed their defenses would prevent an incident may recognize afterward that cyber risk requires preparation, fast response, and containment. Their experiences can provide practical lessons to others, although affected companies and executives may hesitate to discuss those incidents publicly for various reasons.

Summary & Key Takeaways

  • Disruptive breaches extend beyond ransomware and denial-of-service incidents. While malware such as WannaCry and Petya spread without selecting particular victims, targeted attackers deliberately pursue specific enterprises to cause harm. Investigations show that these breaches can produce serious operational disruption and require organizations to understand attacker motives, methods, objectives, and likely business consequences.

  • Cybersecurity is no longer primarily viewed as a United States problem. Since beginning regional operations in 2013, Mandiant had investigated Asia-Pacific breaches comparable to, or larger than, incidents seen in the United States. Organizations in major markets and smaller countries can become targets because attackers operate with varied motives, objectives, and capabilities.

  • Management should accept that security products can reduce breach probability but cannot eliminate it. Organizations need a response plan that enables timely, correct action and damage containment. Security teams can guide the effort, but IT personnel operate the systems and must balance security with uptime, availability, and performance as a shared business responsibility.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚