SlideShare ist ein Scribd-Unternehmen logo
1 von 2
Downloaden Sie, um offline zu lesen
GLOBAL RANSOMWARE ATTACKS - WANNACRY
McGRIFF, SEIBELS & WILLIAMS, INC.
URGENT CLIENT ALERT!
TherecentglobalcyberattackusingWannaCryransomwarereminds
usthatproperinformationsecurityhygieneandappropriateback-up
management and software patching protocols are critical to attack
prevention and loss minimization. To refresh, a ransomware attack
spread throughout the world over the weekend, infecting systems
in over 150 countries. The attack used software code stolen from
the National Security Agency that was posted online.
WHAT DOES THIS ATTACK MEAN?
What is interesting about this is how different it is and the
precedent it is setting. This is the second known usage of a hacking
toolset leaked from the NSA in 2017. It is the first time it was used
to execute this type of large scale extortion en masse. The hacking
toolset was tweaked just slightly and relatively quickly. Attackers
had to strike blitzkrieg-style – all at once and against many locations
-sincetheywerefullyawarethatafixwouldberelativelysimple.So,
itisclearthatthiswasacoordinatedandplannedevent,designedto
take advantage of a hunting technique within the attack itself that is
constantly looking for additional targets. That is why it propagated
so quickly and why, eventually, it will reach every part of the globe.
As already reported, this attack is primarily affecting Russia, Eastern
Europe, UK and Taiwan, which is an incredibly interesting mix - the
outliers in this initial attack were clearly Taiwan and the UK. While
we cannot know for sure, this could have just been opportunistic, or
possibly,agameofmisdirectionintendedtoobfuscateanyattemptat
attribution. The attack itself is new and unique, but not sophisticated.
Microsoft, for the most part, released a patch for this exploit
one month ago. Bottom line: the attackers behind this operation
developed an attack based upon new techniques disclosed in the
NSA leak and they preyed upon companies and their machines that
remained unpatched. In a sense, it was very avoidable.
MORE ON THE “HUNTER MODULE”
This is an exploitive feature that scans for any vulnerable systems
within a target organization’s ecosystem. Companies that have
adhered to the best patching protocols could still be accessed
through connections with their supply chain and external vendors
who have vulnerable devices. All the attackers need is one hook
(one weak machine) and then they can swim laterally within the
networktocausemaximumdamage.Asthesayinggoes,“anetwork
is only as secure as the least secure network connected to it.”
WHAT’S NEXT?
This is just the beginning. We can assume that the attackers used
this as a pilot project and that they will adapt based on what they
learned with this effort. The NSA toolset that was leaked was vast
and there are people analyzing these tools and working on ways to
alter them slightly for their own nefarious purposes. The key will be
knowledgeofthetechniquesandpersistentpatchingandupgrading
worldwide. But, keep in mind, not all of the tools the NSA used
involved unpatched computers - far from it. This hack was built to
exploit the blind spots in traditional security.
Even though responders were able to identify and activate a kill
switch (safety valve) that was embedded by the attackers, this
is no panacea and will be bypassed soon. Hackers have adapted
based on what they learned from this past attack and we can
expect the next wave within 24 hours. Plus, you should note that
corporations do not benefit from the kill switch since it takes
advantage of a network protocol that most large corporations
do not use. In other words, private citizens are currently safer
but companies must be hyper-vigilant.
In collaboration with our external cyber security advisors,
please review the following tips carefully with your Incident
Response Team (IRT)
One Premier Plaza, Suite 500 | 5605 Glenridge Drive | Atlanta, GA 30342
(800) 476-2541 | (404) 497-7500 | www.mcgriff.com
©2017 McGriff, Seibels & Williams, Inc.
McGRIFF, SEIBELS & WILLIAMS, INC.
Timely patching is a must. Do not leave it up to a third
partyanddonotputitonadelayedschedule.Malicious
actors conducting pre-attack surveillance can very
easily determine patch state of hardware and software
as well as exposed TCP/IP protocols such as Port 445.
Back-ups will be critical to your survival – prioritize data
and systems that must be redundant for your business
needs and for compliance with legal and regulatory
duties around the protection of the data of your clients,
patients, customers and employees.
Ensure that legacy preventative controls such as
anti-virus and firewalls are deployed and properly
configured.
Audit and reduce privileged account holders to only
those necessary.
Sunset (retire) outdated equipment and software – if
you do not maintain it, get rid of it. And, if the vendor
no longer supports it, upgrade to a higher version
immediately.
Take out of use equipment offline – disconnect and/or
shutdown machines that are no longer in use.
Conduct targeted susceptibility training with your
employees (i.e. spear phishing tests) and incorporate
awareness methodologies into the training
curriculum so that employees are kept updated on
current and emerging threats.
Manage your supply chain, hold them to the highest
informationsecuritystandardsandauditthemregularly.
Be diligent in your threat awareness and continually
update your Incident Response Team.
1 6
7
8
9
2
3
4
5
KNOW YOUR INSURANCE POLICY
‱ Check your K&R policy for possible coverage; note deductibles (maybe none?) and policy limits available for ransomware events
(sub-limits?); review and advise internal resources what the event notice obligations are and whether you will have access to
cyber security specialists provided by your insurer;
‱ Check your cyber policy for reporting obligations, policy limit and retention; verify whether you must have insurer consent prior
to engaging any cyber security resources; discuss with your internal resources whether you want to use insurer pre-approved
vendors or if you would retain your own specialists; seek and obtain insurer consent to use your own vendors prior to any event;
make certain your IRT fully understands insurance policy requirements and seeks Risk Management advice immediately upon
detection of any suspected or actual cyber incident.
‱ Many cyber policies contain exclusions or coverage limitations for losses arising out of the “failure to maintain minimum security
standards” or “failure to patch or remediate software errors or vulnerabilities”. Talk to your broker and check your policy
wording; ideally, it’s best to not have these exclusions or to secure a carve-back for otherwise covered loss (i.e. limit exclusion to
the costs to patch or remediate).
THE THREAT CONTINUES
According to our threat monitoring experts, current sensors are showing more than 1.5 million machines worldwide that are still
vulnerable to this attack (unless they have been patched properly in the last 24-48 hours). Beware that once the hackers relaunch
and remove the kill switch, all 1.5 million (or the remaining machines that have not been patched) could, in theory, become infected.

Weitere Àhnliche Inhalte

Was ist angesagt?

Detect Unknown Threats, Reduce Dwell Time, Accelerate Response
Detect Unknown Threats, Reduce Dwell Time, Accelerate ResponseDetect Unknown Threats, Reduce Dwell Time, Accelerate Response
Detect Unknown Threats, Reduce Dwell Time, Accelerate Response
Rahul Neel Mani
 
Cylance_Protect_Datasheet
Cylance_Protect_DatasheetCylance_Protect_Datasheet
Cylance_Protect_Datasheet
Tiana Henriks
 
Meet Me in the Middle: Threat Indications and Warning in Principle and Practice
Meet Me in the Middle: Threat Indications and Warning in Principle and PracticeMeet Me in the Middle: Threat Indications and Warning in Principle and Practice
Meet Me in the Middle: Threat Indications and Warning in Principle and Practice
Dragos, Inc.
 
kill-chain-presentation-v3
kill-chain-presentation-v3kill-chain-presentation-v3
kill-chain-presentation-v3
Shawn Croswell
 
Making Threat Modeling Useful To Software Development
Making Threat Modeling Useful To Software DevelopmentMaking Threat Modeling Useful To Software Development
Making Threat Modeling Useful To Software Development
ConSanFrancisco123
 
Cyber Security - IDS/IPS is not enough
Cyber Security - IDS/IPS is not enoughCyber Security - IDS/IPS is not enough
Cyber Security - IDS/IPS is not enough
Savvius, Inc
 

Was ist angesagt? (20)

Cyber Security protection by MultiPoint Ltd.
Cyber Security protection by MultiPoint Ltd.Cyber Security protection by MultiPoint Ltd.
Cyber Security protection by MultiPoint Ltd.
 
OFFENSIVE IDS
OFFENSIVE IDSOFFENSIVE IDS
OFFENSIVE IDS
 
Cyber Kill Chain Deck for General Audience
Cyber Kill Chain Deck for General AudienceCyber Kill Chain Deck for General Audience
Cyber Kill Chain Deck for General Audience
 
Damballa automated breach defense june 2014
Damballa automated breach defense   june 2014Damballa automated breach defense   june 2014
Damballa automated breach defense june 2014
 
Bridging the Gap Between Threat Intelligence and Risk Management
Bridging the Gap Between Threat Intelligence and Risk ManagementBridging the Gap Between Threat Intelligence and Risk Management
Bridging the Gap Between Threat Intelligence and Risk Management
 
Anatomy of a Ransomware Event
Anatomy of a Ransomware EventAnatomy of a Ransomware Event
Anatomy of a Ransomware Event
 
Detect Unknown Threats, Reduce Dwell Time, Accelerate Response
Detect Unknown Threats, Reduce Dwell Time, Accelerate ResponseDetect Unknown Threats, Reduce Dwell Time, Accelerate Response
Detect Unknown Threats, Reduce Dwell Time, Accelerate Response
 
Upgrading Your Firewall? Its Time for an Inline Security Fabric
Upgrading Your Firewall? Its Time for an Inline Security FabricUpgrading Your Firewall? Its Time for an Inline Security Fabric
Upgrading Your Firewall? Its Time for an Inline Security Fabric
 
The Best Just Got Better, Intercept X Now With EDR
The Best Just Got Better, Intercept X Now With EDRThe Best Just Got Better, Intercept X Now With EDR
The Best Just Got Better, Intercept X Now With EDR
 
Cyber kill chain
Cyber kill chainCyber kill chain
Cyber kill chain
 
Shadow IT
Shadow ITShadow IT
Shadow IT
 
TIC-TOC: Ransomware: Help your Customers be Prepared with Dominique Singer an...
TIC-TOC: Ransomware: Help your Customers be Prepared with Dominique Singer an...TIC-TOC: Ransomware: Help your Customers be Prepared with Dominique Singer an...
TIC-TOC: Ransomware: Help your Customers be Prepared with Dominique Singer an...
 
Defense In Depth Using NIST 800-30
Defense In Depth Using NIST 800-30Defense In Depth Using NIST 800-30
Defense In Depth Using NIST 800-30
 
Cylance_Protect_Datasheet
Cylance_Protect_DatasheetCylance_Protect_Datasheet
Cylance_Protect_Datasheet
 
The Internal Signs of Compromise
The Internal Signs of CompromiseThe Internal Signs of Compromise
The Internal Signs of Compromise
 
Meet Me in the Middle: Threat Indications and Warning in Principle and Practice
Meet Me in the Middle: Threat Indications and Warning in Principle and PracticeMeet Me in the Middle: Threat Indications and Warning in Principle and Practice
Meet Me in the Middle: Threat Indications and Warning in Principle and Practice
 
kill-chain-presentation-v3
kill-chain-presentation-v3kill-chain-presentation-v3
kill-chain-presentation-v3
 
Making Threat Modeling Useful To Software Development
Making Threat Modeling Useful To Software DevelopmentMaking Threat Modeling Useful To Software Development
Making Threat Modeling Useful To Software Development
 
Corporate threat vector and landscape
Corporate threat vector and landscapeCorporate threat vector and landscape
Corporate threat vector and landscape
 
Cyber Security - IDS/IPS is not enough
Cyber Security - IDS/IPS is not enoughCyber Security - IDS/IPS is not enough
Cyber Security - IDS/IPS is not enough
 

Ähnlich wie Global ransomware attacks_2017_final msw_g2_sg

Cylance Ransomware-Remediation & Prevention Consulting Data-sheet
Cylance Ransomware-Remediation & Prevention Consulting Data-sheetCylance Ransomware-Remediation & Prevention Consulting Data-sheet
Cylance Ransomware-Remediation & Prevention Consulting Data-sheet
Innovation Network Technologies: InNet
 
Information Securityfind an article online discussing defense-in-d.pdf
Information Securityfind an article online discussing defense-in-d.pdfInformation Securityfind an article online discussing defense-in-d.pdf
Information Securityfind an article online discussing defense-in-d.pdf
forladies
 
Industry_Brief_TrapX_Banking_Finance
Industry_Brief_TrapX_Banking_FinanceIndustry_Brief_TrapX_Banking_Finance
Industry_Brief_TrapX_Banking_Finance
Tony Zirnoon, CISSP
 
Ethical hacking a licence to hack
Ethical hacking a licence to hackEthical hacking a licence to hack
Ethical hacking a licence to hack
amrutharam
 
Project Quality-SIPOCSelect a process of your choice and creat.docx
Project Quality-SIPOCSelect a process of your choice and creat.docxProject Quality-SIPOCSelect a process of your choice and creat.docx
Project Quality-SIPOCSelect a process of your choice and creat.docx
wkyra78
 
Industry_Brief_TrapX_Medical_Devices
Industry_Brief_TrapX_Medical_DevicesIndustry_Brief_TrapX_Medical_Devices
Industry_Brief_TrapX_Medical_Devices
Tony Zirnoon, CISSP
 
LogRhythm_-_Modern_Cyber_Threat_Pandemic.pptx
LogRhythm_-_Modern_Cyber_Threat_Pandemic.pptxLogRhythm_-_Modern_Cyber_Threat_Pandemic.pptx
LogRhythm_-_Modern_Cyber_Threat_Pandemic.pptx
CNSHacking
 

Ähnlich wie Global ransomware attacks_2017_final msw_g2_sg (20)

Cylance Ransomware-Remediation & Prevention Consulting Data-sheet
Cylance Ransomware-Remediation & Prevention Consulting Data-sheetCylance Ransomware-Remediation & Prevention Consulting Data-sheet
Cylance Ransomware-Remediation & Prevention Consulting Data-sheet
 
Information Securityfind an article online discussing defense-in-d.pdf
Information Securityfind an article online discussing defense-in-d.pdfInformation Securityfind an article online discussing defense-in-d.pdf
Information Securityfind an article online discussing defense-in-d.pdf
 
M1_Introduction_IPS.pptx
M1_Introduction_IPS.pptxM1_Introduction_IPS.pptx
M1_Introduction_IPS.pptx
 
Cybersecurity: Take Back Control
Cybersecurity: Take Back ControlCybersecurity: Take Back Control
Cybersecurity: Take Back Control
 
Cyber Threat Intelligence.pptx
Cyber Threat Intelligence.pptxCyber Threat Intelligence.pptx
Cyber Threat Intelligence.pptx
 
Cyber security and AI
Cyber security and AICyber security and AI
Cyber security and AI
 
Industry_Brief_TrapX_Banking_Finance
Industry_Brief_TrapX_Banking_FinanceIndustry_Brief_TrapX_Banking_Finance
Industry_Brief_TrapX_Banking_Finance
 
Cybersecurity After WannaCry: How to Resist Future Attacks
Cybersecurity After WannaCry: How to Resist Future AttacksCybersecurity After WannaCry: How to Resist Future Attacks
Cybersecurity After WannaCry: How to Resist Future Attacks
 
Network Security of Data Protection
Network Security of Data ProtectionNetwork Security of Data Protection
Network Security of Data Protection
 
Ethical hacking a licence to hack
Ethical hacking a licence to hackEthical hacking a licence to hack
Ethical hacking a licence to hack
 
What's behind a cyber attack
What's behind a cyber attackWhat's behind a cyber attack
What's behind a cyber attack
 
Network Security
Network SecurityNetwork Security
Network Security
 
Cyber security do your part be the resistance
Cyber security do your part be the resistanceCyber security do your part be the resistance
Cyber security do your part be the resistance
 
Project Quality-SIPOCSelect a process of your choice and creat.docx
Project Quality-SIPOCSelect a process of your choice and creat.docxProject Quality-SIPOCSelect a process of your choice and creat.docx
Project Quality-SIPOCSelect a process of your choice and creat.docx
 
Advanced Endpoint Protection
Advanced Endpoint ProtectionAdvanced Endpoint Protection
Advanced Endpoint Protection
 
Firewall buyers-guide
Firewall buyers-guideFirewall buyers-guide
Firewall buyers-guide
 
How to Build and Validate Ransomware Attack Detections (Secure360)
How to Build and Validate Ransomware Attack Detections (Secure360)How to Build and Validate Ransomware Attack Detections (Secure360)
How to Build and Validate Ransomware Attack Detections (Secure360)
 
Industry_Brief_TrapX_Medical_Devices
Industry_Brief_TrapX_Medical_DevicesIndustry_Brief_TrapX_Medical_Devices
Industry_Brief_TrapX_Medical_Devices
 
LogRhythm_-_Modern_Cyber_Threat_Pandemic.pptx
LogRhythm_-_Modern_Cyber_Threat_Pandemic.pptxLogRhythm_-_Modern_Cyber_Threat_Pandemic.pptx
LogRhythm_-_Modern_Cyber_Threat_Pandemic.pptx
 
Building security into the internetofthings
Building security into the internetofthingsBuilding security into the internetofthings
Building security into the internetofthings
 

KĂŒrzlich hochgeladen

Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
Matteo Carbone
 
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service BangaloreCall Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
amitlee9823
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
Abortion pills in Kuwait Cytotec pills in Kuwait
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
amitlee9823
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Dipal Arora
 

KĂŒrzlich hochgeladen (20)

Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Service
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
 
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service BangaloreCall Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
 
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 May
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Century
 
Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League City
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
 
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
 
BAGALUR CALL GIRL IN 98274*61493 ❀CALL GIRLS IN ESCORT SERVICE❀CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❀CALL GIRLS IN ESCORT SERVICE❀CALL GIRLBAGALUR CALL GIRL IN 98274*61493 ❀CALL GIRLS IN ESCORT SERVICE❀CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❀CALL GIRLS IN ESCORT SERVICE❀CALL GIRL
 
RSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataRSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors Data
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with Culture
 
Business Model Canvas (BMC)- A new venture concept
Business Model Canvas (BMC)-  A new venture conceptBusiness Model Canvas (BMC)-  A new venture concept
Business Model Canvas (BMC)- A new venture concept
 
Falcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in indiaFalcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in india
 

Global ransomware attacks_2017_final msw_g2_sg

  • 1. GLOBAL RANSOMWARE ATTACKS - WANNACRY McGRIFF, SEIBELS & WILLIAMS, INC. URGENT CLIENT ALERT! TherecentglobalcyberattackusingWannaCryransomwarereminds usthatproperinformationsecurityhygieneandappropriateback-up management and software patching protocols are critical to attack prevention and loss minimization. To refresh, a ransomware attack spread throughout the world over the weekend, infecting systems in over 150 countries. The attack used software code stolen from the National Security Agency that was posted online. WHAT DOES THIS ATTACK MEAN? What is interesting about this is how different it is and the precedent it is setting. This is the second known usage of a hacking toolset leaked from the NSA in 2017. It is the first time it was used to execute this type of large scale extortion en masse. The hacking toolset was tweaked just slightly and relatively quickly. Attackers had to strike blitzkrieg-style – all at once and against many locations -sincetheywerefullyawarethatafixwouldberelativelysimple.So, itisclearthatthiswasacoordinatedandplannedevent,designedto take advantage of a hunting technique within the attack itself that is constantly looking for additional targets. That is why it propagated so quickly and why, eventually, it will reach every part of the globe. As already reported, this attack is primarily affecting Russia, Eastern Europe, UK and Taiwan, which is an incredibly interesting mix - the outliers in this initial attack were clearly Taiwan and the UK. While we cannot know for sure, this could have just been opportunistic, or possibly,agameofmisdirectionintendedtoobfuscateanyattemptat attribution. The attack itself is new and unique, but not sophisticated. Microsoft, for the most part, released a patch for this exploit one month ago. Bottom line: the attackers behind this operation developed an attack based upon new techniques disclosed in the NSA leak and they preyed upon companies and their machines that remained unpatched. In a sense, it was very avoidable. MORE ON THE “HUNTER MODULE” This is an exploitive feature that scans for any vulnerable systems within a target organization’s ecosystem. Companies that have adhered to the best patching protocols could still be accessed through connections with their supply chain and external vendors who have vulnerable devices. All the attackers need is one hook (one weak machine) and then they can swim laterally within the networktocausemaximumdamage.Asthesayinggoes,“anetwork is only as secure as the least secure network connected to it.” WHAT’S NEXT? This is just the beginning. We can assume that the attackers used this as a pilot project and that they will adapt based on what they learned with this effort. The NSA toolset that was leaked was vast and there are people analyzing these tools and working on ways to alter them slightly for their own nefarious purposes. The key will be knowledgeofthetechniquesandpersistentpatchingandupgrading worldwide. But, keep in mind, not all of the tools the NSA used involved unpatched computers - far from it. This hack was built to exploit the blind spots in traditional security. Even though responders were able to identify and activate a kill switch (safety valve) that was embedded by the attackers, this is no panacea and will be bypassed soon. Hackers have adapted based on what they learned from this past attack and we can expect the next wave within 24 hours. Plus, you should note that corporations do not benefit from the kill switch since it takes advantage of a network protocol that most large corporations do not use. In other words, private citizens are currently safer but companies must be hyper-vigilant.
  • 2. In collaboration with our external cyber security advisors, please review the following tips carefully with your Incident Response Team (IRT) One Premier Plaza, Suite 500 | 5605 Glenridge Drive | Atlanta, GA 30342 (800) 476-2541 | (404) 497-7500 | www.mcgriff.com ©2017 McGriff, Seibels & Williams, Inc. McGRIFF, SEIBELS & WILLIAMS, INC. Timely patching is a must. Do not leave it up to a third partyanddonotputitonadelayedschedule.Malicious actors conducting pre-attack surveillance can very easily determine patch state of hardware and software as well as exposed TCP/IP protocols such as Port 445. Back-ups will be critical to your survival – prioritize data and systems that must be redundant for your business needs and for compliance with legal and regulatory duties around the protection of the data of your clients, patients, customers and employees. Ensure that legacy preventative controls such as anti-virus and firewalls are deployed and properly configured. Audit and reduce privileged account holders to only those necessary. Sunset (retire) outdated equipment and software – if you do not maintain it, get rid of it. And, if the vendor no longer supports it, upgrade to a higher version immediately. Take out of use equipment offline – disconnect and/or shutdown machines that are no longer in use. Conduct targeted susceptibility training with your employees (i.e. spear phishing tests) and incorporate awareness methodologies into the training curriculum so that employees are kept updated on current and emerging threats. Manage your supply chain, hold them to the highest informationsecuritystandardsandauditthemregularly. Be diligent in your threat awareness and continually update your Incident Response Team. 1 6 7 8 9 2 3 4 5 KNOW YOUR INSURANCE POLICY ‱ Check your K&R policy for possible coverage; note deductibles (maybe none?) and policy limits available for ransomware events (sub-limits?); review and advise internal resources what the event notice obligations are and whether you will have access to cyber security specialists provided by your insurer; ‱ Check your cyber policy for reporting obligations, policy limit and retention; verify whether you must have insurer consent prior to engaging any cyber security resources; discuss with your internal resources whether you want to use insurer pre-approved vendors or if you would retain your own specialists; seek and obtain insurer consent to use your own vendors prior to any event; make certain your IRT fully understands insurance policy requirements and seeks Risk Management advice immediately upon detection of any suspected or actual cyber incident. ‱ Many cyber policies contain exclusions or coverage limitations for losses arising out of the “failure to maintain minimum security standards” or “failure to patch or remediate software errors or vulnerabilities”. Talk to your broker and check your policy wording; ideally, it’s best to not have these exclusions or to secure a carve-back for otherwise covered loss (i.e. limit exclusion to the costs to patch or remediate). THE THREAT CONTINUES According to our threat monitoring experts, current sensors are showing more than 1.5 million machines worldwide that are still vulnerable to this attack (unless they have been patched properly in the last 24-48 hours). Beware that once the hackers relaunch and remove the kill switch, all 1.5 million (or the remaining machines that have not been patched) could, in theory, become infected.