News: 1703836865

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

CEO arranged his own cybersecurity, with predictable results

(2023/12/29)


On Call It’s the last Friday of 2023, but because the need for tech support never goes away neither does On Call, The Register ’s Friday column in which readers share their tales of being asked to fix the unfeasible, in circumstances that are often indefensible.

This week, meet a reader we will Regomize as “Jack” who told us he was a consultant/client liaison for a managed security services provider (MSSP) that worked with an African banking outfit.

“We provided a lot of services after they were penetrated by a state actor”, Jack told On Call, adding that this incident sparked a “panic purchase” of defensive tools and the know-how to run ‘em.

[1]

Jack rated the client’s CEO as “ possibly happy with our service but not happy with the amount of money.”

[2]

[3]

That attitude led to some robust exchanges between Jack’s boss and the bank CEO.

While the two CEOs were butting heads over whether the service provider’s offerings represented good value, Jack’s job involved monitoring a WhatsApp group used as an incident management tool.

[4]

And one Saturday evening, that group lit up.

Someone was on the network! Which was bad news in and of itself but also, perhaps, proof that Jack’s outfit was indeed a waste of coin.

[5]‘I needed antihistamine tablets every time I opened the computers’

[6]Superuser mostly helped IT, until a BSOD saw him invent a farcical fix

[7]'The computer was sitting in a puddle of mud, with water up to the motherboard'

[8]You don't get what you don't pay for, but nobody is paid enough to be abused

[9]Bank's datacenter died after travelling back in time to 1970

[10]Bank boss hated IT, loved the beach, was clueless about ports and politeness

[11]Techie labelled 'disgusting filth merchant' by disgusting hypocrite

Working with the bank’s staff, Jack triaged the incident. All soon concluded the intruder was inside the bank’s building. Further examination suggested the intruder was in fact on the floor that housed the CEO’s office … indeed, in that exact office!

“It turned out the CEO had used their favorite cybersecurity provider to do an unannounced test,” Jack told On Call.

Jack’s CEO protested strongly, which did wonders for the already-strained boss-to-boss relationship because the bank client promptly conducted a formal assessment of the MSSP’s work. In his mail to On Call, Jack described that experience as “like meeting an unhappy proctologist” and lamented that it was four long months before the relationship returned to a viable footing.

[12]

Have your clients worked against you and caused tech support troubles? If so, [13]click here to send On Call an email so we can tell your story some time in 2024. ®

Get our [14]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZY6m1V7pPAZMXQUlFYVIVwAAAco&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZY6m1V7pPAZMXQUlFYVIVwAAAco&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZY6m1V7pPAZMXQUlFYVIVwAAAco&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZY6m1V7pPAZMXQUlFYVIVwAAAco&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2023/12/28/on_call/

[6] https://www.theregister.com/2023/12/22/on_call/

[7] https://www.theregister.com/2023/12/21/on_call/

[8] https://www.theregister.com/2023/12/15/on_call/

[9] https://www.theregister.com/2023/12/08/on_call/

[10] https://www.theregister.com/2023/12/01/on_call/

[11] https://www.theregister.com/2023/09/15/on_call/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZY6m1V7pPAZMXQUlFYVIVwAAAco&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] mailto:oncall@theregister.com

[14] https://whitepapers.theregister.com/



Customers are the security liability

Anonymous Coward

Worked with a CxO customer who through stupidity and ignorance kept doing things that compromised their security, he was the companies biggest liability, he on one memorable occasion lost his laptop but taped to the underside were the passwords to the applications he used along with the laptop username and password. Did not disclose this at the time of reporting the theft about a week after it was actually stolen (From a pub, but of course). So we had activity of the systems that were via the stolen laptop, some key data deleted and various other issues, luckily for us the laptop seemed not to have fallen into the hands of someone who could have really done some damage. The CxO of course blamed IT as the systems should be secure against this type of thing even after telling us he had the account and passwords taped to the bottom of the laptop.

Fun times, thankfully he was moved one about a year later as he stupidity caught up with him.

Re: Customers are the security liability

John Riddoch

Humans are the weak point in most company's security because they're fallible and prone to try and help. Just yesterday, El Reg [1]reported that attackers just needed a "10-minute call with the help desk" to break in.

Various companies are now working on this, with education for staff on how to not be an idiot, test phishing emails etc and people still fall for it.

[1] https://www.theregister.com/2023/12/28/casino_ransomware_attacks/

Re: Customers are the security liability

The Oncoming Scorn

I get these e-mails from the client side & my employers.

The only one (It was the first time they had given me a fake email test) that gave me real concern was allegedly speeding on site (Through roadworks on site), the link given was so fake looking it was unreal.

I then did a search of the URL & discovered it was the US equivalent of the DVLA & it was the crappiest unprofessional URL for a Govt Agency I have ever seen & apart from a character change or two you would be hard pressed to tell the difference between the one received, I hit the Phishing attempt reporting tool as I hadn't been in the US for five years much less driving my current vehicle.

One I clicked the reply to in error & was rewarded with a GOTCHA.

The rest have been too well phrased\implausible to be genuine attempts, including one on the run up to Christmas was "a family member has sent you a e-greetings Christmas card" which as no family member has either of my works email addresses &\or spoken to me in 5 years made it really easy to spot (Along with the fact they used my middle name instead of of surname.

I got a txt tonight from my bank (Correct as it happened) with a tinyurl link advising me there was a critical alert on my account, which was ignored.

Icon Friday Beer O'Clock\NYE - Maybe my last post of the year so Happy New Year Commentards Everywhere.

Re: Customers are the security liability

KittenHuffer

My favourite turned out to be from the company that I was working for, that ticked more than half of the 'signs of phishing' listed in the email that they had sent out the previous day. I had great joy in clicking the 'Report Phishing' button for that email.

Re: Customers are the security liability

Doctor Syntax

The emails purporting from your bank that tick all - not just half - the phishing email boxes usually are from your bank.

PostIt Note Security

trevorde

Developed one company's design software where the boss insisted on it being password protected because "Our competitors desperately want to get their hands on it". The password changed every month & he only ever doled out 3 months worth at a time. Apart from being trivially easy to defeat, all the engineers kept the passwords on a PostIt note on their monitors.

A Bit Puzzled?

Bebu

I would have thought all service providers including security thespians, would have drafted watertight service level agreements (SLA) that basically relieved them of all responsibility for anything after such a reckless and thoughtless act while still entitled to, enforceably, the compensation agreed in the service contract.

You break it, you get to keep the pieces but you must still pay for it.

If the the CEO in this story wasn't specifically (formally) authorized to access these IT resources __OR__ such access was not a part of his role formally or customarily this CEO almost certainly breached corporate polices and very likely committed a number of criminal offenses in many jurisdictions. CEOs don't hold unplanned and unannounced fire drills off their own bat without consultation. Presumably even their impenetrable skulls appreciate that if they managed to survive defenestration by irate Firies*, those CEOs would also be criminally responsible any other resulting deaths and injuries.

*en_AU firey/firies= firefighter(s)

* Dry-ice can't code his way out of a paper bag
<Coderjoe> dry-ice: int main() { ExitPaperBag(); return 0; }
<Knghtbrd> Is that how that's done then? *takes notes*