Analysis: The Path Back to Business as Usual After COVID-19 episode artwork

EPISODE · Apr 3, 2020

Analysis: The Path Back to Business as Usual After COVID-19

from Info Risk Today Podcast · host InfoRiskToday.com

The latest edition of the ISMG Security Report offers an analysis of the phases businesses will go through in the recovery from the COVID-19 pandemic, plus an assessment of new risks resulting from the work-at-home shift and lessons learned from the Equifax breach.

Episode metadata supplied by the publisher feed · Published Apr 3, 2020

Embed this episode

NOW PLAYING

Analysis: The Path Back to Business as Usual After COVID-19

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

A disaster recovery experts prognosis of the path of back to normality, how cyber attacks are shifting to the home of his worker, and some valuable lessons from recent reports from the 2017 Equifax breach. These stories and more in this week's ISMG Security Report. Hello, I'm Nick Holland. There's no hyperbole in stating that the COVID-19 pandemic is like nothing we've ever seen before.

And for folks in the realm of disaster planning, the magnitude and sustained nature of this specific disaster is causing some reevaluation of traditional models of planning, awareness, activation and response. One of the more unsettling things relating to the pandemic is not being able to comprehend what the end of it will look like and the nature of work and life in this post-coronavirus landscape. This week, Tom Field, ISMG's SVP of editorial, once again spoke with renowned disaster management expert, Regina Phelps, about where we are today and what the off-ramp from the pandemic will look like for businesses. Here's an excerpt of that interview.

Now really what we are is we're calling the reevaluation plays and let me explain that with a little bit of detail. Always when you have an activation, you're always continually doing reevaluation. Yes, but this is very, very different. And I'll tell you on all the calls I sit on with my clients, I see this over and over again.

So let me give you an example. Let's say that there's 100 mission critical activities in your business that you must do on a regular basis, daily basis, let's say. I will tell you now that people are looking at that list of 100 and now it's maybe down to 75 and maybe next week it might go to 50 and maybe the week after that it could go to 30. What's happening is that we are digging so deep in this reevaluation, we are down in some cases to the barest of barest of barest things we have to do in order to keep the animal living so to speak and that's the business.

And so there's this reevaluation that's occurring at the very tactical level, the tactical crisis management team in our client population. But then also on the strategic side of the house, which are the executives, they're also reevaluating what's going on in their business, what's happening, where are they going, are there things that they should start thinking about stopping doing, are there things that they want to expand into, are there deals now that they need to get out of, I mean all of that reevaluation is happening. And that's really happening now because we're still kind of physically active in this space, if you will. Then I think what's going to happen, and this is probably happening in New York probably next week and probably in the West will happen in another couple of weeks, it's what I call two things, cocooning.

What does that mean? We will have cut down all of those mission critical activities to the barest of bone and then we're going to kind wrap them up, if you will, and just keep everything running into the best of our ability. So it's really like almost like a medically induced coma, if you want to get sort of a visual of that, we are just cocooning, we're keeping things, we're not doing anything different, we're just keeping things alive. At the same time, there needs to be simultaneously two efforts on reentry.

One is on the tactical side, I would hope you in your crisis management team, you have spun off a group of people who can then figure out how do we reenter the business once the situation becomes more stable and the disease is less present. That's not just automatically going back to work. It's going to be how do you unfold it. So that's a whole tactical response that needs to be considered because we're still going to have disease, we're still going to be infectious.

If we go out too quickly, we're going to have another spike, so that has to be really considered. But then simultaneously, I think executives are also going to be thinking about reentry. What does that mean? Are we going to maybe do emergency acquisitions because now it's a great buying opportunity?

Are we going to be selling off things? Are we going to be looking at real estate deals to get into or out of? All of those big strategic issues that executives are going to be really putting some energy behind, and that's going to be happening in this what I call cocoon and reentry planning phase. That's probably going to start happening in the next week or so from those people on the East, and it's going to be a little bit later for those people in the West and the Midwest.

Then once we've actually in a place where the diseases started to really come down, we're coming down the first wave, then we're going to figure out and start moving into reentry. But as I mentioned, that's not going to be like turning on the switch and we all go back, it's going to be some sort of stage reentry that hopefully you were planning during that cocooning phase. And that will go on probably a month, six weeks. We're not just going to all of a sudden go back, it's going to be staged.

And then my last stage that I think is going to happen is what I call reinvention. We will have been working in very different ways, no more traveling, for example, and all of a sudden people are working from home. That's going to maybe cause people to look at how can we do things differently going forward? Do we just go back to what we've always done?

Or do we do things differently? So for example, well, there's still be lots of conferences that people would go to, probably not so much over the next 18 months in particular because the disease is going to likely come back in the fall. What about the idea related to working from home? Are you going to bring everybody back?

Are we going to do some sort of hybrid or maybe people will work from home all the time? So I think there's a big reinvention that's going to happen that will be very unique to this experience. And I think we're going to be at the end of this 18 months period, probably very different than we were before we started in December of 2019. You're listening to the ISMG Security Report on ISMG Radio, your number one source for information and security news.

The rapid transition to work from home culture for many organisations is still very much underway, with significant teething travel still being sorted out. This period of flux pronounced criminals with a gold rush for scams, deception and fraud. Here, Andy Bates of the Global Cyber Alliance do tell some of his observations based on intel gathered from members of his organisation. Here he is.

Yeah, I mean, certainly it's so disappointing to see that we had, you know, not for profit associates, I would say, in Madrid, who found 20,000 domains related to the COVID virus scam and they don't have to be just a subset of dinner at the 60,000 that we discovered. So there has been a change of landscape. I mean, you know, the criminal fraternity, it never amazes me to think what they do to seize on opportunities, whether it's technological or in this case, global pandemic. So that has shifted the landscape a little bit.

I mean, I think the attack vectors are pretty similar, though, especially in those websites. So, you know, if you look at criminology and you look at cyber, the methods of either deception or coercion, they apply across sideboards to do across conventional crimes. So I think that there are new sites and new keywords that people are using, you've seen it under news where people are selling alleged COVID virus cures for many thousands of pounds and people have been, you know, sucker pumps into that. I think there's an element of good news, which is, you know, people we talk to about sharing intelligence.

And you know, I'm a big fan about collaboration and sharing. I've found people in the past two weeks who have just been really leaning forward into doing that kind of thing. In fact, you know, with the word for home campaign, to see 10 people, 10, not the similar not for profits just within 48 hours get involved in a project. People don't normally move that quickly.

Is that because they're not in planes, not in coffee shops, maybe, but is that because, you know, the good folks have just decided to value together then, then I think so. So yeah, I think it's going to change a landscape. I think we've seen it a little bit. The thing also that worries me is that so many other organisations are effectively de-dossing themselves by trying to do the good thing, which is rightful, but we should do that quickly.

And then remember that the vast deal, normal businesses to run in the cyber business, if we start focusing on the core cyber challenges, then the bad guys are just going to get a leap ahead of us and we may be distracted by the virus. So yeah, I think it's important to do the bad thing, but in motivation to the core business objectives. It may be hard to believe that there is any cybersecurity news not relating to COVID-19, but there was a time, not so long ago, when massive data breaches roamed the Earth. The Bronx source of these was arguably the 2017 Equifax breach that exposed the PII of 145 million Americans.

Three years on, we're still learning lessons from the prolonged post-mortem of this event. It's on its own physics activity today to reach today, and Europe, Matthew Schwartz, with some very recent findings. What went wrong at credit reporting joint acro-facts in 2017, leading to hackers successfully stealing personally identifiable information for 145 million Americans? The answer to that question has built multiple reports, including from the GAO, two House and Senate committees, Britain's privacy watchdog, and most recently, an unsealed US Justice Department indictment that charges four Chinese military officers with the hack attack.

Security researcher Adrian Sinabria says these reports are a goldmine for all cybersecurity professionals. I wish we got this level of detail more often. It really helps to solidify some of the best practices and recommendations that we give, and clearly we can see that the industry is too focused on fixing problems with tools, and not focused enough on leadership and on the people and processes parts of things. For anyone who needs an Equifax database recap, one of the vulnerabilities available to hackers included an unpatched version of Apache structs, which contained a critical flaw.

That's how attackers got in. And the kicker is that Equifax had tried to find and patch every version of Struts being used. When the breach became public, however, Sinabria says Equifax was getting a lot of flack, including having to be accused of being lazy or failing to be serious enough about patching. But he says that wasn't actually the case.

In fact, if you read the documents, they were really sweating this out. When that Struts vulnerability came out, they were aware of it. They had some big meetings. They said, hey, this is a big deal.

Let's figure out if we've got Struts and if the versions we have running are vulnerable, and they looked for it, and they looked for it, and they searched many different ways using many different tools, and it was there, and it was vulnerable, but they failed to find it. And part of the reason for that is the security team didn't really understand Struts. They didn't understand the right ways to look for it, and they didn't have any documentation of their own systems that they could search through and find Struts that way. So there's no bill of materials, no software bill of materials for their own products, for their own applications.

And what actually had Struts in it and got hacked was an older legacy system. All the people that knew how it worked had left, sounds like from the report, and nobody knew where Struts was there. So at one point, they actually run a tool to look for Struts, and they're one directory below where Struts is sitting, and they don't use the recursive flag on the tool, so it misses it. You know, they're only scanning the current directory, and not the deeper directories from that one.

Acrophaxis fate and the causes of its megabreech are now well-known. And he sees those, who want to avoid a similar fate in their firm, would be wise to do a close study of the Acrophaxis breach reports that have come out to ensure they're not making the same mistakes. For Information Security Media Group, I'm Matthew Schwartz. That's it for this week's Ice and Security Report.

The music is by ethical audio. I'm Nick Collins. Catch you next time.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on April 3, 2020.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!