Deloitte hit by cyber-attack revealing clients’ emails
theguardian.com
theguardian.com
Senior leaders at large companies tend to use firms like Deloitte for their most controversial and sensitive potential projects, ideas, etc. And they confide with them with a lot of candor.
I would not be surprised to see unabashed discussion of tax evasion, for example. Or leaders within a single company using Deloitte to undermine their peers. Or debates of the merits of layoffs designed to be age discriminatory.
Basically, there would a much higher percentage of "good stuff" in a dump of these emails than say, in the Sony dump.
Deloitte is so entrenched politically (both figuratively within large companies' C suite as well as literally with state and federal governments) this will barely register for any of their RFP or RFQ responses. Nobody signing the checks will care about this, if they even hear about it.
In the face of so many questions, one thing is clear: Current approaches to managing cyber risk, many of which are focused on “securing the perimeter,” aren’t enough.
( https://www2.deloitte.com/me/en/pages/risk/articles/changing... )
"The account required only a single password and did not have ”two-step“ verification, sources said."
"In 2012, Deloitte, which has offices all over the world, was ranked the best cybersecurity consultant in the world."
Hits close to home though. Anyone can get owned. Even elite teams and individuals have had their email compromised. (Matasano, Kaminsky).
Everyone make sure your users have and use good 2 factor authentication. Make sure you don't keep much sensitive data on your email servers. Encrypt sensitive documentation in email. Have sane retention policies (1-2 months max on a cloud server). Lock down your admin accounts. Kick out all the old accounts completely. Take the time to talk with each person at your company about email security and suspicious emails. Especially administrative and HR staff. Of the deep penetrations into orgs I know of a high percentage happen thru email. Oh and do some internal phishing, FWIW. It's good to get discussions rolling and get everyone's attention.
Boutiques to tend be more hardcore technical, breaking into applications.
It is the same with any assessment or consulting. We always try to leave recommendations, strategic and tactical, which advise them on next steps. Often, those next steps involve us helping them with more assessment work, directed at the most security sensitive areas to maximize usage of often limited security budgets. What will get them hacked next, basically.
Smaller firms with more technical staff definitely shy away from risk assessment and compliance work because it is, honestly, repetitive and boring. But, it also drives a tremendous amount of hard technical work into any firm because if you can't sell someone a pen test or technical assessment after doing advisory work you aren't very good at things.
Sorry if that sounds cynical or like "everyone needs more of our services and pen testing", but that is the model. It is also why boutiques exist. We don't just give brain dead "yep, you need pentesting, and it is going to be expensive" recommendations. We tailor it and focus on what the customer actually wants/needs. Whereas, a big4 tends to rotate consultants and lose knowledge unless it is staff aug. The relationship and understanding engineer teams really matters when you want to do the most interesting assessment work AND provide value to the customer and not just "sell them pen tests" :)
Of course, I was a bit cynical. But the kind of statements I see on their website are just too much.
I have to imagine there are far more capable experts out there, especially with this breach.
https://www2.deloitte.com/global/en/pages/risk/articles/delo... (click the read more button for the text)
Come to think of it, should have taken the deal and ran with it.
Based on what I know, my impression is that email is significantly worse, and somehow I'd never considered that. But I'm not sure if I'm missing something...
Contrast with more recent messaging protocols (e.g. iMessage, WhatsApp) where the server doesn't have access to the message, they're decrypted on the client (while potentially also authenticating the sender).