Colonial Pipeline was looking to hire cybersecurity manager before ransomware attack shut down operations
- Reference: 1620909339
- News link: https://www.theregister.co.uk/2021/05/13/colonial_pipeline_hiring_cybersecurity_manager/
- Source link:
The job advert came to light in the wake of the ransomware attack, which [1]shut down one of America's largest pipelines on Friday 7 May .
"Employees find exciting opportunities to grow and develop their careers at a stable company which offers a generous compensation and benefits package that includes annual incentive bonuses, retirement plans, insurance coverage and a host of other features that support a happy, active, productive and rewarding life," says the [2]advertisement (also available [3]here ).
[4]
[5]
The advert called for a degree in compsci or infosec, five years of "technical experience" in infosec and/or incident response – and for the successful applicant to have a "strong foundation and in-depth technical knowledge of security engineering, computer and network security, authentication, and security controls."
By Saturday (8 May), the pipeline company had said it was "actively in the process of restoring" operations, only for its website to fall offline at the time of writing.
It seems highly unlikely that the recruitment of a new cybersecurity manager had anything to do with the attack, but the timing is unfortunate. Whoever got the job, assuming it was filled before the attack, is going to have a helluva task on their hands.
[6]
The Darkside ransomware gang is said to be responsible for the attack. Infosec firm Secureworks reckons the Russia-based criminals (it has named the group Gold Waterfall) have been operating since August last year as a commission-based affiliate operation, and are an offshoot of the notorious REvil ransomware crew.
"Darkside ransomware appears to be created independently of REvil or GandCrab but shares several architectural similarities that suggest that the Darkside author is familiar with those families," said Secureworks in a research summary.
South Korea, meanwhile, ordered [7]a review of its energy infrastructure's digital security in the wake of the Colonial Pipeline shutdown. A minister said the Asian nation would be checking "whether cybersecurity preparations and countermeasures for our energy-related infrastructure are properly in place." Next to South Korea is North Korea, a well-known hotbed of malicious people who use ransomware to fund their pariah state. ®
Get our [8]Tech Resources
[1] https://www.theregister.com/2021/05/10/colonial_pipeline_ransomware/
[2] https://colpipe.wd1.myworkdayjobs.com/en-US/Search/job/Atlanta-Alpharetta-GA/Manager--Cyber-Security_R0000017
[3] https://www.indeed.com/jobs?q=Scada%20Cyber%20Security%20Manager&vjk=a90bdae0ec795630
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YJ1NHzg2URIFyC2r--ByfwAAAIc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJ1NHzg2URIFyC2r--ByfwAAAIc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJ1NHzg2URIFyC2r--ByfwAAAIc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2021/05/12/south_korea_security_review/
[8] https://whitepapers.theregister.com/
Yep, I would think this Job Request would sail through the approval process now and get posted. I bet they may even be looking at the resumes that are coming in and forwarding them to the IT department real time.
It would be interesting to sit in on the interview process as both sides ask questions to each other...
Advertise for a cybersecurity manager and simultaneously advertise that you might not have had one previously. A bit like painting a target on your back.
I suspect the compensation package will much more "generous" now.
Maybe not
" I suspect the compensation package will much more "generous" now. "
Practically no organisation actually learns from data breaches or really adapts after them. They just fire and hire "responsible" personnel and then carry on much as before.
As one who has attempted to improve security in numerous enterprises, I find that the fundamentals that underpin vulnerability are cultural, not technical. So taking on a new (or replacement) technical expert post-breach most likely leads not to improved security but to increasing frustration of the said expert as they establish that they can't get anything significant changed for the better because of management inertia.
The prime example is Equifax, whose management processes were so sloppy that they couldn't even find out whether they were vulnerable having been alerted to the hazard, and they had let a primary intrusion detection mechanism cease to function for months without noticing. And that's just the pinnacle of a point haired pyramid of management failures. The specific exploit they fell foul of was just one of many possibles, given that their security was effectively unmanaged.
Re: Maybe not
Tell me about it. The C-suite demanding admin access to their boxes, and the ability to install any software they want.
Marketing demanding that they can access their personal email via a webmail client.
BYOD.
Need I go on ??
Re: Maybe not
When somewhere close to my heart paycheque had a bit of a security "incident" lessons were most definitely learnt. Lots of changes, polices, etc were put in place to try and stop all sorts of nasty stuff.
As a side effect it obviously raised the concept of cyber/information security within the company and so when things suit my needs I hitch my changes to that flag and get what I want pushed through (after years of having the same things kyboshed because no-one else cared).
Re: Maybe not
The issue with many security systems is that they necessarily implement some form of tighter access control. That has its upsides and downsides. It may very well be more secure to intrusion (physical or electronic), but if the implementation also makes it even slightly more onerous for the users and clients then 1) many users start to look for short cuts, or easier means of achieving an end; and 2) clients conclude the effort is worth less than the reward and start to look elsewhere. So, poorly implemented security measures from the point of view of those who have to deal them. People start writing down "more secure" gibberish passwords that are hard or impossible to memorize except by savants, meaning the "keys" to the kingdom can be on a thumb drive or a slip of paper.
I used to war drive around the city where I live and the unsecured access points were most numerous in state government buildings. I pointed this to a friend who worked for a state agency and was actually responsible helping maintain security, eliminating viruses, trojans, etc. He told me that the biggest problem were work bottle necks, issues such as one printer available to anywhere from ten to some times 50 personnel! Bureaucracies run on paperwork. So people would bring a personal printer, usually run off an unauthorized personal router in order to meet deadlines. Effectively their wireless routers created back doors into secure systems. The security staff were running their legs off suppressing this, but the people committing the acts were also the most productive. So, they might be chewed out by a superior, but you can't shoot the cow and improve milk production.
He said they were continually monitoring this (war driving themselves). There were other security problems as well. He had spent a month chasing a virus source that seemed to skip around town from one building to another, but always within the same unit. The head of said unit was complaining bitterly about this. In desperation my buddy created a board tracking dates of new outbreaks in places previously cleared, sometimes several times. It finally emerged that the very complaining supervisor had been carrying around a 3.5-inch disk from section to section of the unit to "backup work" and "monitor" work progress. The floppy was one from his home (to save the unit budget he said). Ultimately my friend had to physically catch the supervisor inserting the disk into and have him stop while the disk was scanned. Some of the unit sections affected had physical access limitations that required authorization before a person could physically enter the building or suite. So the problem was the fellow with the boss of the unit.
I wonder if someone saw the advert, thought that they must be vulnerable, and sent an email, "I have tremendous cybersecurity experience, please follow this link to download my resume, it's encrypted so you will have to click OK to view it" ... ?
Gold Waterfall?
Someone's taking the piss.
I'd have thought that getting budget and approval for cybersecurity will be quite easy for the new manager.