Why a top US cyber spy urges: 'Get religion on backups'
- Reference: 1680518048
- News link: https://www.theregister.co.uk/2023/04/03/nsa_joyce_backups/
- Source link:
Yes, backups.
The rest of the world should take this lesson learned from the Russia-Ukraine war to heart, said Rob Joyce, director of the US National Security Agency's cyber security arm, speaking at the recent Silverado Policy Accelerator summit.
[1]
"Ukraine has been under tremendous cyber pressure for years, long before the invasion," Joyce said. "And so they, by necessity, had to learn from that. They got religion about backups; they got to the point where their sysadmins understood how to respond to a breach, clean up, and move on. They were practiced."
[2]
[3]
Backups aren't sexy. But in a real-word cyberwar, they kept the Ukrainian communications, government and critical infrastructure online despite a year of dozens of [4]data-wiper and other types of attacks .
And in addition to having backups in the first place, "think about the practical step of checking your backups," Joyce said. "You don't want to find out in a crisis that your backup process didn't work and it wasn't able to restore a key aspect of your business."
[5]
Another defensive strategy that isn't as exciting as, say, AI-based threat hunting tools to help warfighters defend their networks? Practice. Ukraine had years of practice repairing their networks in the wake of Russian cyber attacks, including recovering from [6]NotPetya – which wiped data from energy firms and banks – and the related [7]Bad Rabbit malware.
[8]Ukraine's secret cyber-defense that blunts Russian attacks: Excellent backups
[9]US cyber spymaster calls TikTok China's 'Trojan horse'
[10]US Cyber Command, DARPA ink cyberwar R&D pact
[11]How to shave years off the journey from military lab to real-world use
The February 2022 invasion wasn't the first time Ukraine had to think about what to do in case of an attack; it has arguably been at war since Russia invaded Crimea. Likewise, a data breach shouldn't be the first time an organization considers what to do in the event of a security incident.
Companies need to have playbooks that outline how they will respond and who will be involved for different types of cyber threats, according to the NSA's Rob Joyce and Mandiant's Head of Global Intelligence Sandra Joyce ( [12]no relation ), who also spoke at the Silverado event.
According to Sandra Joyce, Google-owned Mandiant responds to more than 1,000 breaches every year. "And for the most part, this is a survivable incident," she said.
The companies that are best equipped to deal with a breach already have implemented security basics including two-factor authentication and vulnerability scanning, Sandra Joyce said.
[13]
In addition to the basics, she also suggests having processes to run in case anything goes wrong. "That's another piece I would give as advice," Joyce added. "Run a table top. Get the key players in place." ®
Get our [14]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/defensetechweek&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZCr4I5I7Vk6jTLqyZQQdZAAAAIE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/defensetechweek&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZCr4I5I7Vk6jTLqyZQQdZAAAAIE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/defensetechweek&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZCr4I5I7Vk6jTLqyZQQdZAAAAIE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.welivesecurity.com/2023/02/24/year-wiper-attacks-ukraine/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/defensetechweek&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZCr4I5I7Vk6jTLqyZQQdZAAAAIE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2020/10/19/russians_charged_olympics/
[7] https://www.theregister.com/2017/10/24/badrabbit_ransomware/
[8] https://www.theregister.com/2022/06/08/silverados_alperovitch_viasat_attack/
[9] https://www.theregister.com/2023/03/29/china_tiktok_trojan_horse/
[10] https://www.theregister.com/2023/01/24/us_cyber_command_darpa_constellation/
[11] https://www.theregister.com/2023/01/26/darpa_tech_incubator/
[12] https://twitter.com/NSA_CSDirector/status/1549413111429566464
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/defensetechweek&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZCr4I5I7Vk6jTLqyZQQdZAAAAIE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://whitepapers.theregister.com/
Good backup is expensive
Wasn't it an IBM redbook that specified: "When planning backup, start by adding and hiring a backup team to be backup for your backup team."?
With the current climate of reduced spending, what are the chances of structural backups?
And, besides, the beancounters will look at the monthly bills and complain all the way up to the board that huge amounts of money are used on that backup project that has not had any ROI during its existence. The C-suite will surely act accordingly to improve money flow back to investors.
Re: Good backup is expensive
It's the board that needs to get the message first. Then they can kick the complaints all the way back down the ladder. There does seem to be an inkling in govts that critical infrastructure is - well - critical. They might even be getting insistent about it. We can only hope that they work out PDQ what they need to insist on.
Hot Off The Interweb......Stuff You Really Need To Know!!!
Quote from "expert": "You don't want to find out in a crisis that your backup process didn't work"
He'll be saying next "....and you need to ensure that you keep offsite backups too....."
And then he will add even more value by saying ".....and of course, you need to do a test restore immediately after taking a backup, so you know the backup is OK...."
Yup......you can always rely on "experts" to tell you things that you and your colleagues have known for years...........
.......and you can rely on the media to transmit the "expert advice".......breathlessly......because it's "hot news"................."new stuff"........"stuff that you REALLY need to know"..........
Please.......give us all a break!!!!
P.S. Next time round we'll get a puff piece for "cloud" backups......Please, again, give me a break!
Backups are the first step, testing them regularly is the second one.
Free secure data backups! Now!
And that is why we at the NSA will be offering free back-up services, for the Enterprise and Consumers alike. Completely free of charge!
Actually, the service has been retroactively running for the past 20 years! No matter what, a copy of your data is safe with US!
Re: Free secure data backups! Now!
But restores are such a legal hassle.
Why do so many people overlook backcups?
I know they are second nature to those of us who have worked in IT for many decades, but the message doesn't seem to filter down to individuals. There are regular desperate moans from folks saying they've lost their entire PhD thesis or twenty years of photos or messages because their phone or computer malfunctioned or there was a glitch in their cloud service. They always blame someone else for their lack of foresight and lack of effort in backing up their personal data. External USB storage is so cheap. Keeping several backup copies of your data is easy. Ideally off-site (maybe with a family member) or at the least a copy in an outdoor garden shed or garage, suitably encrypted in case of burglary.
The USA, religion, and backups
I thought the whole point of religion is that no backup is necessary, you just need to believe. Rather like those "good God-fearing Christians" who won't get covid because they believe in the words of some people whose names are unknown writing centuries after a supposed man/son of God/Holy Spirit which supposedly happened.
How many takers for my new company: 666beelzebubbackups.com.
> And in addition to having backups in the first place, "think about the practical step of checking your backups,"
NO!
This is not an addition! This is THE critical part of taking backups. If you don't do this you're just masturbating tapes.
I've been in this boat before with somebody telling me how good their backups are. They had the reports that all the jobs were complete, etc. Tried restoring? Oh, it doesn't actually work properly. It mostly works, but then there are hours left to fix up what is broken. I've seen $boneheads making tar balls of mysql data directories when the db was live. Yeah.
I agree.
With validating your ability to restore (and that means REALLY testing it) you don't have a backup, you have just a waste of time.
The companies that are best equipped to deal with a breach already have implemented security basics including two-factor authentication and vulnerability scanning
Which is only tangentially related. You would rewrite that as "folks who care don't do dumb shit" or similar, the key point is to have a safe verified copy of your data, ideally at another site. And said data is not modifiable by anyone on the first site, so no shared admin passwords (or AD entries) for file system snapshots, tape machine control, etc.
.. and drop the most unsafe platform on Earth
Restoring crap means you still have crap..
But, but...
Profits!
Need I say more?