News: 1630922473

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

When the bits hit the fan: What to do when ransomware strikes

(2021/09/06)


Feature When I first became a company chief techie, the finance director patronisingly explained the basic asymmetry of prevention vs cure. Spending money on assets to stop an attack come out of capex, but spending after the disaster would be up to the insurer, with premiums deducted out of opex. Also, prevention costs reduced current bonuses.

But according to Bill Mew, founder and CEO of Crisis Team, who advises companies on how to escape the hole they are in, if you're expecting cyber insurance to come to your rescue – don't. His experience is that if it is a small claim, you will probably get paid eventually, if only to keep you from complaining too loudly.

The odds are... at least some of your backups have been compromised, since not only do ransomware flingers target them, but it's entirely possible they've been with you for months

However, as we have seen in the cases of the insurer [1]Zurich American Insurance Company , which fobbed off damage claims after its client suffered NotPetya ransomware infections, if it's a large claim, there are exclusions that may mean you don't get a payout. Zurich infamously cited "Act of War" exclusion to its client Mondelez. Yes, really. (In october 2018, Mondelez sued Zurich for breach of its "all-risks" property insurance policy, looking to be made whole for $100m in losses. The litigation is ongoing.)

The reason Zurich could reach for this contractual clause is that both the US and the UK government pinned the blame for NotPetya on Russian criminals trying to damage the Ukrainian government. The logic from the insurer was that since the malware could be traced back to nation state actors, this could be considered "an act of war" (excluded in most insurance policies) - like finding a WWII bomb under your data centre. Of course, given that much malware is attributed to nation state groups, this does not bode well.

OK, so you've gone with an insurer anyway. Here's what to look out for

Some of the insurers sell themselves on having a list of recommended firms to help you in a crisis, from law to technical and – given that attacks now make front pages – PR.

But here's the thing. The technical people work for the insurer, not you , so while they provide help and untangle your systems, they will also be looking for the ways you have not complied with the "reasonable" precautions mandated by your policy.

Providing that every single piece of software is patched up to date, there are scanners on everything, a full inventory, all access is at least 2FA, you don't ever ignore alerts, your backups are regularly validated as is pentesting, and all this is documented – then that might not be a problem. But back in the real world, it is.

[2]

Keeping the "helpers" isolated is simply not an option as their work requires they go everywhere. And they will report back, because they want the next lucrative remediation. This means you might need to ask around for someone who will definitely be on your side.

In ordinary everyday screw-ups, there is blame to be redirected, shared and dodged, but in the worst cases the game theory switches from trying to blame others to absorbing it

Of course, if you're using an external firm to process data, this could be seen by the insurer as akin to letting your teenager drive your Ferrari and your claim may well fail, so your supply chain is exposed and likely uninsurable in any useful way.

Also, as we saw with the pandemic, some insurers will simply refuse to pay up if a lot of people get hit at once – and it's not all that hard to imagine ransomware causing just such an occurrence.

[3]

[4]

Mew compares it to assessing fire risk from looking at your office across the street, because a full examination of the risk surface and consequential losses for when it goes titsup is so hard and expensive that we both know you've never done it yourself.

Dead man's handle

So let's say the worst happens – and you discover data ain't your data any more.

Your first thought will be to cut internet access, which is rational but may move you to the next ring of Hell.

Thieves attacking your servers in search of credit card and other valuable data want to stay covert for as long as possible, but when they find they can't call home, they will go for the second bite and start encrypting your data. So you will need to shut down everything, but don't start with internet. Start with your backups, in case they are still viable.

[5]

The odds are, however, that at least some of your backups have been compromised, since not only do ransomware flingers target them, but if their motive is primarily theft, then it's entirely possible they've been with you for months. Infosec firm Cerberus Sentinel has quoted an average of 206 days, which like any other crime statistics is probably wrong, but in the right ballpark.

This means that restoring from storage is unlikely to get you out of this. And that applies to your offsite disaster recovery too, since it relies on those backups and quite likely those machines are infected as well.

You have been assimilated

Before you even think about connecting up to anything again, your machines need to be gone over with a fine-toothed comb, which goes beyond scanning machines for signatures but monitoring the network as they are brought back to detect anything that might be phoning home, and to sniff out unexpected data access patterns and spreading.

But there is an arms race. Infoseccers at Cerberus explained malware they have christened the Borg, which they said goes beyond the dead man's handle and tries to detect when network scans and other probes have gone quiet before it kicks into action. Scrupulous scans of your systems are necessary, said Cerberus, because 8 to 12 per cent of the assets the crooks find on the network aren't on the official lists, so if you are dealing with one of the more professional gangs, it's possible they know things about your estate that you don't and are hiding there.

In the age of the cloud, shadow IT needs little more than a corporate credit card and a contempt for the ability of IT to deliver. This means that when you take a look at your estate, you may find critical systems you never knew about, as well as the traditional Microsoft Access database or spreadsheet that turns out to be the only copy of vital customer info.

[6]

If they feel you're worth the effort, the ransomware gang will have spent time and effort casing the joint. So you will be faced with a hard choice of junking your hardware – which is Mew's preferred option – or having someone decontaminate it. Either way you're going to lose data and experience downtime, but as an IT pro you need to be upfront about this with management. This is survivable provided you set clear expectations and deliver on them, which is often more important than what you deliver.

That can mean paying a ransom. I've dealt with negotiations before, but it may be that the encrypted data is simply too critical to be lost and you have to pay. That's not yet illegal - although many strongly advise against it - and it will stick in your throat, but if you've reached that point, you need to make certain that your data can be retrieved. Do not expect for a second this means the crooks have destroyed their copy, however.

For Pete's sake, have a plan

Alternatively, any proper crisis plan that you've actually tested would be nice. Attacks are quite different to the system failures - for which most companies have at least a basic business continuity plan.

When you take a look at your estate, you may find critical systems you never knew about, as well as the traditional Microsoft Access database or spreadsheet that turns out to be the only copy of vital customer info

You need to be able to say what you are going to do. Everyone I've spoken to said that something like 90 to 95 per cent of those hit by ransom gangs have no proper cyber crisis plan. And like any other piece of software, you can't say it works because it looks like it does – you need to test it. This must go beyond one or two members of IT: you need a proper tabletop work-through with the people who would actually be dealing with such an attack in real life – not a team of a developers whose productivity won't be missed, a networker who was hired to keep corporate onside, or a new SOAS graduate representing finance – and no one from sales (who will moan they don't like geeky stuff and refuse to waste their time on it and tell you 'Sales outranks IT'.)

That's a fight you need to win, and there's lots of gory evidence to present to hammer the message through. In an attack you are dealing with a skilled active adversary and you should not be naïve enough to believe they will go along with your expectations. The person with an actual plan, even one that's not 100 per cent, is the one who gets to set the agenda and has a shot at saving their job and the firm that supports it.

You can't hide behind a cloud

As well as insurance exclusions for "hardware you don't own," a scary percentage of people seem to believe that if they use Amazon or Google's hosted services, their companies' data is under big tech's protective wing. However, the harsh reality is that if you can access the data, a piece of malware on your computer can do that too, even if some of the lower level attacks can't work on the cloud.

Let's not forget [7]insider threat – there have been instances of disgruntled and/or bribed staff helping in an attack, and although there has been a stream of media coverage of breaches, a lot of them simply aren't reported sometimes because they fear reputational damage or, as Cerberus tells us, because governments fear that publicising the fact that critical parts of their supply chain have been compromised is giving too much detail away.

[8]Fighting an insurer over lockdown payout? UK policyholders just won an important COVID-19 test case

[9]Black-hat sextortionists required: Competitive salary and dental plan

[10]Cyberlaw wonks squint at NotPetya insurance smackdown: Should 'war exclusion' clauses apply to network hacks?

[11]How do we stamp out the ransomware business model? Ban insurance payouts for one, says ex-GCHQ director

[12]Cover for 'cyber' attacks is risky, complex and people don't trust us, moan insurers

I hope it doesn't shock you to learn that extortionists don't put all that much effort into their decryption software, so although – as [13]ransomware negotiator Nick Shah has told us , you need to prove they can get your data back.

[14]Ransomware victim Colonial Pipeline , which is said to have paid criminals $5m in May this year for a [15]decryptor , reportedly found that it ran so terribly slowly that they might as well restore from backups and just take the hit of the data loss despite having paid the ransom.

So it may be that you need to spin up a whole pile of cloud instances to get your data back quickly enough, after all - your systems mean the business can still make sales. This also lowers the risk of the ransomware re-infecting your systems. But if you do pay the ransom and use a decryptor, you need to be ready for the fact that the data may have been mangled unintentionally – since encrypting live files is an inherently unreliable action and the criminal developers won't have been trying all that hard to manage its integrity.

Learn and survive

The worst time to learn crisis management is during one. You need to think hard about how you might protect your own position in what may be your first major crisis. In ordinary everyday screw-ups, there is blame to be redirected, shared and dodged, but - as mentioned - in the worst cases the game theory switches from trying to blame others to absorbing it.

Specialists usually find out what went wrong and that will tend to lead back to you, someone or something you manage. But in a Tier 1 crisis, once top management have got their heads around how bad it is and what you are doing to make it less bad, blaming others means you've created enemies who will bog down crisis meetings in their efforts to bounce it back at you, which seriously affects your career prospects.

You need to own the problem. If someone fires some blame at you, take it on board and try to make it part of what you are doing to get out of the hole, and let them make themselves look like part of the problem, while you are part of the solution.

You also need to set realistic timescales for how much data can be retrieved. They need to be pessimistic enough that you can most likely over-deliver but not so bad that you spread so much despair that you are ignored, replaced or make people give up. ®

Get our [16]Tech Resources



[1] https://www.theregister.com/2019/01/11/notpetya_insurance_claim/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YTY7Pvr5uDxoUdGZJPapUgAAAEo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YTY7Pvr5uDxoUdGZJPapUgAAAEo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YTY7Pvr5uDxoUdGZJPapUgAAAEo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YTY7Pvr5uDxoUdGZJPapUgAAAEo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YTY7Pvr5uDxoUdGZJPapUgAAAEo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2018/09/13/nittf_insider_threat_self_analysis/

[8] https://www.theregister.com/2020/09/16/clauses_offering_protection_against_disease/

[9] https://www.theregister.com/2019/02/21/black_hats_sextortion_275k_salaries_helpers/

[10] https://www.theregister.com/2019/07/26/do_insurance_war_exclusion_clauses_apply_to_cyberattacks/

[11] https://www.theregister.com/2021/04/09/ban_cyber_insurance_payouts/

[12] https://www.theregister.com/2020/02/03/cyber_insurance_fic2020/

[13] https://www.theregister.com/2021/09/03/how_to_be_a_ransomware/

[14] https://www.theregister.com/2021/05/13/colonial_pipeline_ransom/

[15] https://www.bloomberg.com/news/articles/2021-05-13/colonial-pipeline-paid-hackers-nearly-5-million-in-ransom

[16] https://whitepapers.theregister.com/



Did Mr Connor ask the finance director

alain williams

if his patronising explanation could be quoted to the press if/when something went wrong ?

I suspect not as it would be career limiting as most of the board would want to maintain their current bonuses. However the chief techie will take the rap even if he was not allowed to do the right thing.

But prevention is the best way out. It might cost a bit but how much will shares & bonuses be hit when an attack happens ?

Re: Did Mr Connor ask the finance director

Dominic, Writer of this aritcle

Good point, but FDs are lamentably poor at grasping cyber risk.

Excellent argument, but only part of the picture

Mike 137

" Spending money on assets to stop an attack come out of capex, but spending after the disaster would be up to the insurer, with premiums deducted out of opex. "

Very true if you take the technocentric approach to security. However, in some 20 years of security consulting I've found the most prevalent problem that leads to or facilitates data breaches is not lack of appropriate tech kit but abysmal security management. Just for example, Equifax [1] having acquired numerous third party services via mergers and buy-outs, didn't have an applications inventory. So when the critical vulnerability was announced (with sufficient notice) they couldn't find the vulnerable system. [2] The attackers found on the network a list of access credentials in clear for critical servers on the same network. The list goes on...

Improving security management doesn't cost capex, but it's hard because lousy management results from cultural flaws intrinsic to the enterprise. However it's almost always the most important starting point for improvement of security.

Re: Excellent argument, but only part of the picture

Dominic, Writer of this aritcle

Security and resilience costs Capex and running costs, though the mix can be varied to optimise share price and bonuses.

Opportunity

elsergiovolador

When ransomware wreaks havoc, it's a great opportunity to rise from that like a phoenix - independent and more resilient.

By adopting Linux across the company.

The only reasons, in my opinion, why Windows is widely installed across corporations are kickbacks, minesweeper and solitaire.

Now that more people play games under their desk using their phones, Microsoft wants to lure them in back to desktop with ability to run Android games on Windows 11.

It's going to be another golden era for procurement. All that hardware that needs to go, so it can be replaced to meet W11 specs...

Re: Opportunity

the spectacularly refined chap

When ransomware wreaks havoc, it's a great opportunity to rise from that like a phoenix - independent and more resilient.

Really? The business is probably paralysed and in the midst of that chaos you want to do an unplanned company wide migration at the same time? The key is restoring as much capability as possible as quickly as possible. Instead of perhaps two or three weeks of noticeable disruption (probably followed a long tail period for the less critical stuff) you want to put everything on hold for what? 18 months? Two years?

I spent three months this summer upgrading a dozen servers from NetBSD 7 to ... NetBSD 9. Not full time of course but as migrations go that's quite straightforward. Pouncing on something like an attack to push a personal agenda in fast way of getting yourself ignored or even maneouevred somewhere you can't do any harm.

Re: Opportunity

Dominic, Writer of this aritcle

You have had a better life than me. You seem to think it insane to do a migration in the midst of a crisis, well

a) as a CTO in the midst of them it has been demanded of me

b) one *VERY* important database got ported from Oracle to SQL Server during the crisis because it was the only way I could fix it quickly. It was a bit of a SciFi moment for me.

I "knew" like Spock or McCoy or House MD that a certain "brave" tech decision would make things better, but knowing and doing are quite different. So I pressed OK and went and had a coffee whilst my laptop which was about to become the server had a good hard think. This was because I both needed caffeine and also to project absolute confidence that the ugly fix would work.

Which it did. First time.

You and I both know that whereas this happens in the last scene of SciFi quite a lot, but the reality is a lot more messy and success more equivocal.

There was two consequences. A polite but difficult conversation since it was my personal laptop, hence it had extra tooling not to be found on most corporate PCs and also a shed load of money for a permanent fix.

Re: Opportunity

Dominic, Writer of this aritcle

Windows is more vulnerable than Linux, but it is naive to believe Linux makes you safe.

Re: Opportunity

vtcodger

Also keep in mind a good deal of the software businesses depend on is Windows only. Yes Open Office (or whatever we're calling it this month) works fine and even (I'm told) runs some Excel macros nowadays. And yes MS support for it's products is at times a bit wobbly. And their QA is rather ...ahem... problematic. But a lot of stuff -- likely including mission critical software isn't available for Unix and probably won't run under Wine without a daunting amount of tinkering. Unix is probably a non-starter for most businesses.

BTW, the finance folks who would probably need to approve the funding for the switchover often understand Excel macros and use a lot of them. All the time. They will surely be less than enthusiastic about a world without MS Office. And their managers won't be wild about a world without Power Point.

Now a new operation with no dependence on some sort of special software that everyone in their sector uses? THEY probably ought to seriously consider Linux for a lot of reasons -- including security.

If it smells it's chemistry, if it crawls it's biology, if it doesn't work
it's physics.