Protecting your Company Against the Growing Threat of a Cyber Breach

U.S. companies are currently experiencing annual losses of more than $525 million due to cybercrime, with the majority of these losses stemming from malicious code and denial of service attacks.

And the extent of cyberattacks is not confined to companies. The list of high profile CEOs whose accounts have been compromised this year is long. Mark Zuckerberg’s Twitter and Pinterest accounts have been hacked, apparently due to a LinkedIn password leak 5 years ago.

Additionally, the Twitter accounts of Google’s CEO Sundar Pichai and Brendan Iribe, co-founder of Oculus VR, have been compromised. The latest addition to this list is Jack Dorsey, the CEO of Twitter himself. Most of those attacks were no straight forward brute force attacks, but were executed indirectly. In Pichai’s case, tweets were sent via an old Quora account that apparently had been linked to Twitter. It seems like in Dorsey’s case, tweets were sent via Vine.

Overall, large businesses that experienced a cyberattack saw an average of 3.6 successful attacks each. In the last five years, Symantec, the software security firm, saw a steady increase in attacks targeting businesses with less than 250 employees, with 43% of all attacks targeted at small businesses in 2015, proving that companies of all sizes are at risk. It’s not just Fortune 500 companies and nation states at risk of having IP stolen—even the local laundry service is a target. In one example, an organization of 35 employees was the victim of a cyberattack by a competitor. The competitor hid in their network for two years stealing customer and pricing information, giving them a significant advantage.

“43% of all attacks were targeted at small businesses in 2015, proving that companies of all sizes are at risk..

This serves as a clear warning that all businesses are potentially vulnerable to targeted attacks. In fact, spear-phishing campaigns targeting employees increased 55% in 2015. No business is without risk. Attackers motivated purely by profit can be just as technically sophisticated and well-organized as any nation state-sponsored attackers.

According to Root9B, a cybersecurity startup in Colorado Springs, CO, a hacker who infiltrated a computer network on Jan. 1 would typically operate unnoticed until August 17—229 days on the inside, stealing data and spying. It is like a burglar breaking into your home and living there for over seven months before being detected.

Old methods are ineffective
The current conventional approach of building an automated digital wall to prevent attackers from breaching one’s system clearly is not working. This may explain the rise of firms like Root9B that have come up with countermeasures. Staffed by former military and other intelligence experts at the National Security Agency (NSA) and CIA, Root9B identifies and shuts down adversaries in action, often within days of a breach.

Using something called their HUNT technique, which has been honed through cyber operations and training both within the Department of Defense and commercial community, the firm uses agentless software to patrol and monitor an adversary without the attacker being aware that he is being watched. This state-of-the-art defensive network method is a bit like the submarine chase depicted in the film, Hunt for Red October. The Soviet nuclear submarine Red October was closely followed by the American nuclear sub Dallas without Red October being aware for most of Dallas’ existence.

“The analogy is a good one,” says CEO Eric Hipkins, “except in our cyber world, there is no need for a Dallas following the adversary. We use agentless detection capability, thus we are invisible to the attacker.”

No doubt, for this reason, Root9B has been named the No. 1 firm on Cyber Security 500’s annual ranking of innovators—ahead of IBM, Cisco and other tech giants. The five-year-old company relies on “manned information security.” Its analysts engage in code-to-code combat with cyber attackers inside corporate and government.

Hipkins advises CEOs to train actively for defense and offers the following suggestions.

1. Most organizations view cybersecurity as a cost center within the organization. CEOs should think of a strong/effective cybersecurity program as “protecting future revenue,” not as a cost center.

2. It is important for today’s CEOs to recognize that automation alone will not solve the cyber problem or protect them from an adversary. This flies in the face of decades of IT development, computer science, and cyber product sales in the commercial sector. The adversary lives with automated technology, tests it, reverse engineers it, and understands its features, weaknesses, limitations, and vulnerabilities.

3. CEOs should be thinking about cybersecurity risk during mergers and acquisitions. Not only are network vulnerabilities and weaknesses being introduced, but these events present opportunities for adversaries to target the business and leverage the merger as a way to gain access to a hard/closed network.

4. As a follow-on, CEOs should be looking for threat “knowledge” vs. “data” when trying to protect their business. There are a lot of threat data sources on the market today, but these are not tailored to a client or their specific business.

Adversaries find and exploit the gaps in defenses that rely solely on automated tools. Firewalls, security sensors, telemetry tools, and post-incident response protocols are no match for them. The only effective counter is another human being who stands in opposition to the adversary’s malicious activities.


MORE LIKE THIS

  • Get the CEO Briefing

    Sign up today to get weekly access to the latest issues affecting CEOs in every industry
  • upcoming events

    Roundtable

    Strategic Planning Workshop

    1:00 - 5:00 pm

    Over 70% of Executives Surveyed Agree: Many Strategic Planning Efforts Lack Systematic Approach Tips for Enhancing Your Strategic Planning Process

    Executives expressed frustration with their current strategic planning process. Issues include:

    1. Lack of systematic approach (70%)
    2. Laundry lists without prioritization (68%)
    3. Decisions based on personalities rather than facts and information (65%)

     

    Steve Rutan and Denise Harrison have put together an afternoon workshop that will provide the tools you need to address these concerns.  They have worked with hundreds of executives to develop a systematic approach that will enable your team to make better decisions during strategic planning.  Steve and Denise will walk you through exercises for prioritizing your lists and steps that will reset and reinvigorate your process.  This will be a hands-on workshop that will enable you to think about your business as you use the tools that are being presented.  If you are ready for a Strategic Planning tune-up, select this workshop in your registration form.  The additional fee of $695 will be added to your total.

    To sign up, select this option in your registration form. Additional fee of $695 will be added to your total.

    New York, NY: ​​​Chief Executive's Corporate Citizenship Awards 2017

    Women in Leadership Seminar and Peer Discussion

    2:00 - 5:00 pm

    Female leaders face the same issues all leaders do, but they often face additional challenges too. In this peer session, we will facilitate a discussion of best practices and how to overcome common barriers to help women leaders be more effective within and outside their organizations. 

    Limited space available.

    To sign up, select this option in your registration form. Additional fee of $495 will be added to your total.

    Golf Outing

    10:30 - 5:00 pm
    General’s Retreat at Hermitage Golf Course
    Sponsored by UBS

    General’s Retreat, built in 1986 with architect Gary Roger Baird, has been voted the “Best Golf Course in Nashville” and is a “must play” when visiting the Nashville, Tennessee area. With the beautiful setting along the Cumberland River, golfers of all capabilities will thoroughly enjoy the golf, scenery and hospitality.

    The golf outing fee includes transportation to and from the hotel, greens/cart fees, use of practice facilities, and boxed lunch. The bus will leave the hotel at 10:30 am for a noon shotgun start and return to the hotel after the cocktail reception following the completion of the round.

    To sign up, select this option in your registration form. Additional fee of $295 will be added to your total.