Is Deloitte a new poster child for bad security practices?
techbeacon.com
techbeacon.com
Security firms have so many keys to so many kingdoms it’s frightening.
The fact that they are such a company both explains the situation and makes it worse. First, one should realize that 99.8% of people working at these companies don't know the first thing about cyber security. The 0.2% of people that do might actually be really good [2] but these consultancies don't tend to put their employees on improving the internal state of affairs.
Second, attackers getting access to security-related material might be bad, but it will be much worse for Deloitte if people get access to the financially sensitive data that the majority of their employees work on. Not only can this be more directly damaging to their clients, this data and the responsibilities around it are affected by many more laws and regulations.
[1]: https://en.wikipedia.org/wiki/Big_Four_accounting_firms
[2]: This typically also depends on which local franchisee of the Big Four brand you're talking to, but let's not go down that rabbit hole.
I think your percentages are off (over ~60% of the firm's revenue is now consulting, a large part digital), but this hits the nail on the head. On the external consulting side, I was regularly in fruitless heated argument with internal IT.
As bad as it is, I think the recovery spin to clients (it's an important point and true) is the the engineers they are getting in a consulting capacity are completely separate to the people managing the laptops.
I do think your second footnote is important too, these are totally separate companies. This is a Deloitte US breach, the IT systems are totally separate. The brand damage (the value of the information in the audit records if unreleased is astronomical) will be shared, but at least the scope of the actual leak will be limited to that member firm.
We are all security experts with different degrees of paranoia, you won't find such a high usage of PGP, Signal and other tools in a different company.
From what I have seen, it really seems that the shoemakers aren't usually wearing shoes themselves. My experience is that the internal systems for example in Big Consultancies are often something that the companies wouldn't be proud to design/deliver for their clients.
I know stories of departments / teams having their own rogue infrastructure because official internal IT resources are so ineffective.
I bet their accounting practices are just as screwed up.
The difference is that proper accounting has laws behind it. If your accounting practices are crooked enough, executives can go to jail and/or be personally liable for losses. If there were similar information security laws, I suspect we'd have far fewer breaches like this.
Like McDonalds is #1 in burgers.
https://www2.deloitte.com/cy/en/pages/about-deloitte/article...
"Deloitte announced today that Gartner, the world’s leading information technology and advisory company, ranked Deloitte #1 globally, based on revenue"
Compared to your average remote employee network, it’s pretty rigorous. And comes with loads of training. I wouldn’t doubt this security breach was targeted as extremely sophisticated. Just casually sending an email attachment would not have worked.
At that scale, even near-perfect controls will have enough chinks to sink you.
Strupid IT guys,they must have changed the password again!
Then called his secretary/assistant (with the speakerphone on):
Hey, Susan, what is the new password?
And Susan, promptly replied:
It is "123456", I have written it on a post-it I put in your left top drawer.
Admittedly the above happened a few years ago (roughly 2008 or 2009), but I wouldn't be so sure that anything has changed much in the meantime.
However, not having 2fa on email server story.. what happen? Was email server directly on internet? (who has mail gateways right??) or was owa configured without 2fa. Those 2 things should come out in any pentest or external network audit. Seems a bit silly oversight. That being said. i repeat, nothing is 100% secure.
99.8% of people working at this company dont know anything about security is very inaccurate. They do have a big team of hackers (40+) besides all of their security officers, auditors and whatnot. So i think ,as they really push for the cyber side of things also, they will have a little more aware people. And really, i think these companies should practice what they preach. If they miss such a missconfiguration on their own servers, why trust them auditing mine????