Home / Business and Politics / Marko Gulan: Most companies pay the ransom, but a certain number of companies lose both money and data

Marko Gulan: Most companies pay the ransom, but a certain number of companies lose both money and data

Cyber threats and cyber attacks are part of our daily lives that are equally dangerous for all layers, both for individuals and legal entities. Although most attacks aimed at individuals do not cause significant damage, for businesses, this damage is becoming an increasingly serious problem. The market is generally familiar with the concept of cybersecurity, but in practice, most are not aware of what exactly needs to be done to make the company safer, i.e., how to demotivate the attacker from carrying out the attack. An attacker is successful to the extent that their path to the ultimate goal is complicated. Usually, from the attacker’s perspective, two factors are important: resources, money, and time. On the other hand, companies make significant mistakes in their perception of cyber threats and often associate cybersecurity exclusively with technology. Technology is one of the three elements of cybersecurity, and the other two are people and processes.

Some research tells us that only 14 percent of successful attacks are caused by technology deficiencies, while as much as 86 percent of attacks occur due to human error. Therefore, in establishing cyber-secure environments, people and processes/procedures are equally important factors. Furthermore, a significant challenge for the market is the belief that cybersecurity is solely the problem of the IT security department, and all of the company’s focus is directed towards information technologies. As if we are not aware that digital transformation has long since stepped into the industry, i.e., into automated plants that are often the companies’ ‘money factories’ and which, due to attacks directed at them, can have significant consequences for business, but also for the entire supply chain. What to do, and how to protect against increasingly frequent cyber attacks was explained to us by Marko Gulan, cybersecurity consultant (Schneider Electric SEE)

What to do if a cyber attack occurs?

Today, the question is not whether a cyber attack will happen, but when it will happen. Experiencing a cyber attack is not a shame, but it is certainly a very stressful event for companies and their management. Especially when considering the fact that they were aware of the need and importance of establishing cybersecurity solutions, yet neglected it under the pretext of ‘it won’t happen to us’ or ‘we’re not important enough to be attacked.’ Every individual and company, no matter how small, is equally important to the attacker. The attacker does not necessarily look at whom they are attacking, but sees them as a channel through which they will reach their goal, which is most often money. Of course, there are also targeted attacks where the attacker prepares for the attack over a longer period using all sources of data and techniques, and with a targeted and sophisticated attack, ultimately extorts the victim.

What to do if a cyber attack occurs is a question that does not have a straightforward answer. One thing is certain, the company must get out of the attacker’s grasp as soon as possible and continue to operate smoothly. There are several possible attack scenarios.

The first is, conditionally speaking, first-generation ransomware where, most often, employees of the company are targeted to perform the desired activity, i.e., click on a link that leads them to the worst-case scenario. In a large number of cases, instead of a link in the text of the email message, there was an attachment, seemingly a regular document (e.g., PDF or Excel or Word file) that was an infected file, and upon opening the attachment, malicious code would activate, locking or encrypting the entire computer, but also spreading across the computer network and encrypting the computers of all employees on that network. The message on the screens contained instructions on how the company must pay to receive the key that would make the data accessible again.

Second-generation ransomware attacks are essentially very similar to the previous case, only the attacker opens a path for themselves through links and/or malicious files and takes data, and only then communicates with the victim extorting them. The extortion that the attacker carries out is aimed at publishing data on one of the public services or even how they will inform all of the company’s users and partners that they have been successfully attacked. Companies, out of fear of losing trust and reputation, find themselves in a very stressful state and often make wrong decisions. Conditioned, the silver lining in this situation is that business continues, more precisely, the company does not have a standstill. However, even in such a situation, you can never be sure when an unwanted effect may occur. If someone has been or is still present in your system, you cannot confidently assert that a lockout will not occur.

It would be best to remain calm in the event of an attack, as the attacker counts on the fact that they have created stress for you and that in such situations you will surely make poor decisions. However, theory is one thing, and practice is another. If we were to use the old saying ‘the full does not believe the hungry,’ we could say that ‘the un-attacked does not believe the attacked.’

The best advice for companies would be that prevention is the best protection. Likewise, well-structured processes and procedures can be of great help in situations of cyber attacks. In a large number of cases, employees who have become victims remain silent about having clicked on the wrong link out of fear of consequences and hope that others will not notice. That is why it is important that procedures are clearly written so that every employee can act according to the procedure. The most common fault of a successful attack is caused by a lack of investment in employee education.

Where to seek help, remain silent about the attack or report it immediately, pay or bear the consequences of hacker threats?

Depending on the size, complexity, and level of technological maturity of companies, some companies can solve such problems on their own, but the share of such companies is measured in per mille. It is also important to know which segment and which part of the business is affected by the attack. Companies are increasingly experiencing attacks on their automated plants, and such attacks usually cause enormous damage, jeopardizing the sustainability of the business, but also causing instability in the entire supply chain.

One thing is certain, companies need to seek help from companies specialized in certain segments of business. It is certainly important to note that attacks on IT differ in scope and complexity from attacks on industrial automated systems, i.e., the production parts of companies. Accordingly, for help, one should turn to a competent partner. The worst choice would certainly be a ‘small garage guy’ who, in the event of an attack, will use your system as a training ground.

We should not remain silent about attacks, as this will prevent the market from knowing that attacks and consequences are present in the market. We actually have such a situation today; official statistics are moderate, but unofficial data is alarming. If we just take the example of someone breaking into your company, coming to you, and whispering in your ear that they have stolen your data and are demanding a ransom in a certain monetary amount, and then leave your company, you will most likely report an attempted extortion or blackmail. Why do we not behave this way when we are extorted in the virtual world?

It is also best that your partners and users receive information from you. Crisis communication is never pleasant, but the damage is less when the company communicates itself than when it learns about the attack and consequences after some time or, worse, from the attacker. By remaining silent about attacks, we support and encourage attackers to launch new attacks.

To pay or not to pay? This is a million-euro question. Although every attacker leaves a payment instruction during the attack, which seems to us like the only way out, it is worth considering whether this is really our only way out. One must take into account before deciding on (not) paying that on the other side is a person who has, as is usually the case in crime, attacked you without valid reason and is extorting you. You have no negotiating position; the instruction is one-way. And in the end, nothing guarantees that you will actually get your data back in full.

Most companies pay the ransom, but a certain number of companies lose both money and data. Paying the ransom should really be the last option, and that money should be money that the company is prepared to lose.

What would your advice be regarding cybersecurity and what are the experiences of those extorted in practice?

In practice, there is hardly a company that has not faced challenges and/or been a victim of cyber threats at least in some form. It is alarming that companies that have been attacked once take the stance ‘it won’t happen twice?’ Unfortunately, it will, once attacked companies will surely be attacked again. If it is added that companies were willing to pay the ransom, they become regular ‘customers’ for attackers.

Cybersecurity is not a one-time task, and once you invest, it does not mean that the process is finished. Security is a process that requires changes, stepping out of the comfort zone in which companies have learned to operate. Likewise, security is not there to limit you in business, but to help you define how you will safely conduct business. Security is not a job you entrust to a ‘small garage guy’ because it runs through all segments of business.

We should not be afraid of cyber threats; we simply have to learn to live with them and accept the fact that investing in cybersecurity is not a cost, but an investment in stable business in accordance with the challenges and opportunities in the market.

Tagged: