Wondering how to tell the world you've been hacked? Here's a handy guide from infosec academics
(2020/09/24)
- Reference: 1600965969
- News link: https://www.theregister.co.uk/2020/09/24/how_to_admit_youve_been_hacked/
- Source link:
Infosec boffins at the University of Kent have developed a "comprehensive playbook" for companies who, having suffered a data breach, want to know how to shrug off the public consequences and pretend everything's fine.
In a new paper titled "A framework for effective corporate communication after cyber security incidents," Kent's Dr Jason Nurse, along with Richard Knight of the University of Warwick, devised a framework for companies figuring out how to publicly respond to data breaches and similar incidents where servers are breached and customer data ends up in the hands of criminals.
Those hoping the paper will give them a set of tools with which to mug off journalists and others asking pointed questions about a breach will be disappointed, however: "With incidents involving an unintentional exposure of data, typically the organisation (via its employees or stakeholders) is indisputably at fault and thus cannot reassign blame away from itself or act as a victim."
Published in the Computers and Security journal, the academics' paper draws on previous well-known data breaches and security incidents such as [1]the Ticketmaster hack before devising a flowchart for execs and their PR flunkeys alike to follow when bad things happen.
It also quotes from infosec personalities such as Troy Hunt, Brian Krebs, and Graham Cluley.
The flowchart and process does not advise the use of phrases such as "we take security very seriously," Nurse confirmed to The Register . That phrase has become [2]a standing joke (read the replies to that tweet) within the infosec world whenever a company has suffered a data or security breach affecting individual customers. The framework does, however, advise execs to ask themselves "are you really taking security seriously?" when wording public messages in the aftermath of a breach.
It can be read on [3]this scientific journal website , provided your browser doesn't block cookies.
It's all in the way you say it
Post-breach PR in the last few years has largely ranged from the "Feck, how do we get out of the headlines?" approach to "Crisis? what crisis?”, especially as state authorities [4]turn a blind eye to companies buying off criminals , often with the [5]active help of insurance companies .
One strong example of poor post-breach behaviour is cloud fundraising CRM purveyor Blackbaud, which was not only hacked by miscreants but then bought them off for a pinky promise that they wouldn't make use of the stolen data. Data breach notifications percolated through the world's charities and universities in the following months, while Blackbaud execs [6]ignored the tidal wave of negative publicity and insisted insurance covered the ransom, so all was well.
Another example of behaviour that falls short of ideal is Carlson Wagonlit Travel, aka CWT. When The Register [7]broke the news that CWT had been hacked , the firm issued a contrite statement but insisted personally identifiable information hadn't been stolen – a claim with little credibility (why infect a travel agency's servers with ransomware if you're not intending to steal the most ransom-worthy data it keeps?). At least one of CWT's corporate customers (a big US tech firm) fell into line with this policy of denial.
It is to be hoped that companies become a bit more forthcoming about breaches and a bit less ready to pay off criminals or persuade insurers to do that on their behalf. The current direction of travel, however, suggests the situation will get worse before it gets better. ®
Get our [8]Tech Resources
[1] https://www.theregister.com/2018/12/12/ticketmaster_denies_fault_website_magecart_infection/
[2] https://twitter.com/bad_packets/status/1308163139725262855
[3] https://authors.elsevier.com/a/1bmEEc43usGpu
[4] https://www.theregister.com/2020/08/06/ncsc_cyber_insurance_guidance/
[5] https://www.theregister.com/2020/08/21/utah_pays_ransomware/
[6] https://www.theregister.com/2020/08/03/blackbaud_glosses_over_ransomware_payoff/
[7] https://www.theregister.com/2020/07/31/carlson_wagonlit_travel_ragnarlocker_ransom_paid/
[8] https://whitepapers.theregister.com/
In a new paper titled "A framework for effective corporate communication after cyber security incidents," Kent's Dr Jason Nurse, along with Richard Knight of the University of Warwick, devised a framework for companies figuring out how to publicly respond to data breaches and similar incidents where servers are breached and customer data ends up in the hands of criminals.
Those hoping the paper will give them a set of tools with which to mug off journalists and others asking pointed questions about a breach will be disappointed, however: "With incidents involving an unintentional exposure of data, typically the organisation (via its employees or stakeholders) is indisputably at fault and thus cannot reassign blame away from itself or act as a victim."
Published in the Computers and Security journal, the academics' paper draws on previous well-known data breaches and security incidents such as [1]the Ticketmaster hack before devising a flowchart for execs and their PR flunkeys alike to follow when bad things happen.
It also quotes from infosec personalities such as Troy Hunt, Brian Krebs, and Graham Cluley.
The flowchart and process does not advise the use of phrases such as "we take security very seriously," Nurse confirmed to The Register . That phrase has become [2]a standing joke (read the replies to that tweet) within the infosec world whenever a company has suffered a data or security breach affecting individual customers. The framework does, however, advise execs to ask themselves "are you really taking security seriously?" when wording public messages in the aftermath of a breach.
It can be read on [3]this scientific journal website , provided your browser doesn't block cookies.
It's all in the way you say it
Post-breach PR in the last few years has largely ranged from the "Feck, how do we get out of the headlines?" approach to "Crisis? what crisis?”, especially as state authorities [4]turn a blind eye to companies buying off criminals , often with the [5]active help of insurance companies .
One strong example of poor post-breach behaviour is cloud fundraising CRM purveyor Blackbaud, which was not only hacked by miscreants but then bought them off for a pinky promise that they wouldn't make use of the stolen data. Data breach notifications percolated through the world's charities and universities in the following months, while Blackbaud execs [6]ignored the tidal wave of negative publicity and insisted insurance covered the ransom, so all was well.
Another example of behaviour that falls short of ideal is Carlson Wagonlit Travel, aka CWT. When The Register [7]broke the news that CWT had been hacked , the firm issued a contrite statement but insisted personally identifiable information hadn't been stolen – a claim with little credibility (why infect a travel agency's servers with ransomware if you're not intending to steal the most ransom-worthy data it keeps?). At least one of CWT's corporate customers (a big US tech firm) fell into line with this policy of denial.
It is to be hoped that companies become a bit more forthcoming about breaches and a bit less ready to pay off criminals or persuade insurers to do that on their behalf. The current direction of travel, however, suggests the situation will get worse before it gets better. ®
Get our [8]Tech Resources
[1] https://www.theregister.com/2018/12/12/ticketmaster_denies_fault_website_magecart_infection/
[2] https://twitter.com/bad_packets/status/1308163139725262855
[3] https://authors.elsevier.com/a/1bmEEc43usGpu
[4] https://www.theregister.com/2020/08/06/ncsc_cyber_insurance_guidance/
[5] https://www.theregister.com/2020/08/21/utah_pays_ransomware/
[6] https://www.theregister.com/2020/08/03/blackbaud_glosses_over_ransomware_payoff/
[7] https://www.theregister.com/2020/07/31/carlson_wagonlit_travel_ragnarlocker_ransom_paid/
[8] https://whitepapers.theregister.com/
Not really what the GDPR intended
' a "comprehensive playbook" for companies who, having suffered a data breach, want to know how to shrug off the public consequences and pretend everything's fine '
I recently had a discussion about infosec with a European data protection lawyer, and the final question he asked was " how would help your client avoid reporting a data breach to the regulator? " My answer ("I won't. My job is to minimise the chance of it happening in the first place") effectively terminated the conversation.
The "get out of jail free" approach is one hundred per cent contrary to the obligations imposed by the GDPR, which is there primarily to prevent data breaches happening in the first place, but also to mandate transparency, even when they do. A fundamental principle of the legislation is that openness to data subjects is an inescapable obligation (even while there's no data breach)
Obviously you don't want to do a Dido and put your foot in your mouth as at Talk Talk, but it's perfectly possible to be honest with the press without exposing too much, and particularly without trying to evade responsibility. It should be recognised that attempts to minimise or conceal a breach are typically pretty obvious and are likely to be taken into account by regulators when setting penalties.
Despite which the ominous words " We take your privacy seriously still prevail.