a) would help the ransomware & hacking crisis, and, b) is practically enforcable at scale?
a) would help the ransomware & hacking crisis, and, b) is practically enforcable at scale?
Sadly I have to report what you state is possible, but not plausible in today's modern heterogenous enterprise.
If I had a static environment with no new software or business processes, then NO PROBLEM. I can lock it down in every kinda way and it stays locked down to a known baseline.
Add to that new biz processes and now I have interconnection internally and externally which make detection and prevention difficult. Things are much more difficult now.
Add to that new software, ever changing dev env, OS updates, firmware updates, software version updates, dev env dependency updates, now you're talking near impossible to keep up.
And that's the state we're in today. There are some generic mostly effective controls that if implemented correctly can stop most advanced attackers (the so called "20 security controls") https://www.yumpu.com/en/document/read/6582321/20-critical-s...
But even in spite of that, any major nation state had an arsenal of "capabilities" that allow them to dominate most cyber warfare area of operations in the civilian sector. US can do it, UK, Israel, China, Russia, probably even India and others!
Against nation states, there is no stopping nation states in the civ sector, despite what every F500 company's CSO wants you to believe.....sad but true.
These ransomware attacks are so devastating in no small part due to decisions Microsoft made many years ago. Combining authentication, remote administration, file sharing, printing, event monitoring, security policy updates, and the kitchen sink into Windows Networking. An attacker compromises a single Windows machine and has leeway to attack critical servers across the network. If real segmentation of services were reasonably possible in a Windows environment a single credential couldn't be used to hop between systems and encrypt file services everywhere. Not to say some segmentation isn't possible in these environments but the skills and hours needed to accomplish it are far beyond what most companies have available.
And that doesn't even begin to cover the Exchange/Outlook dominance and poor security choices that lead to the higher rate of success for phishing attacks.
This is true for almost all types of malware these days, especially when it comes to privilege separation/escalation attacks. All of your observations about segmentation/AD are true here.
As for ransomware specifically, a lot can be done to stop most ransomware, especially small-time stuff. Unlike most malware ransomware is intentionally loud, and performs the same generic actions of enumerating and encrypting files, which makes detecting and stopping most samples with heuristics much more effective than a lot of people would admit: https://www.youtube.com/watch?v=3pH13DxClag
A lot has happened with ransomware in the past five years, but a lot really hasn't - this stuff still works, and would have an effect against the big RaaS strains that people are talking about today.
Realistically, the only way for an organization to actually be secure is if it's part of the culture from the start.
For a long time, people like insurance companies had an "enforceable standard" for 60/90 day password rotation. And in every single business I looked at, they "had a password rotation policy", but then three key executives didn't like it so "do not expire password" got ticked on their accounts as some "accepted exemption". This sort of thing always passed audits, and marketing always wrote information about how the business had a strict password expiry policy. And those executives were the most likely to be compromised.
I think if you go too far down a "minimum standard" path, that's the sort of thing you're going to see.
I've worked a bunch of places that have passed various audits and certifications, you know, PCI, SOC, and unfortunately the audits of infrastructure isn't as deep as the average Joe would expect. They place heavier weight on processes over technical safeguards. It's like what they say about the CISSP exam, a mile wide and an inch deep.
There's obviously way more to it than that, but a huge problem today is that once an attacker gets into a network they can hop around as they please due to implicit trust. Removing that implicit trust and checkpointing access via u2f are huge barriers.
It's also not super hard imo to gradually move to.
It’s also possible to eliminate these attacks entirely, but it probably requires corporate tech infra that looks totally different from what most orgs now. If it were my job to set up some sort of hardened corporate setup, my first step would probably be to restrict most employees to iPads. There’s not really any reason a shift manager at a meat packing plant or whatever needs or benefits from a Windows box.
Hold product managers and non-tech execs accountable for security breaches. Stop treating IT/ops like the suckers. Since that's never going to happen, buy some Monero to increase your bargaining leverage on the ransom price.
The bar is not very high, it's bike theft economics. Your stuff only needs to be less vulnerable than the next guys, unless you are a political target. If you are a political target, please forget my name.
The Pulse VPN has a history of security issues (see e.g. https://arstechnica.com/information-technology/2020/01/unpat...) - so much so that the second and third Google autocomplete results are "pulse vpn vulnerability" and "pulse vpn hack". One practically enforceable at scale rule is to pay attention to whether your vendors have a bad security track record and also be meaningfully prepared to switch (switching VPNs is no fun, but it's doable).
Another one is to ask your vendors what they're doing about their security track record and whether they are taking systematic measures to make zero days less frequent and not just fixing individual bugs. "Stop using memory-unsafe languages" is one of my favorite answers to that, but there are a lot of others: "use sanitizers," "test your code with fuzzers," "use open-source components for the privileged portions," "get frequent third-party audits," etc. are all potential answers too. Some work better than others; any of them is better than not having an answer.
> “The M.T.A.’s existing multilayered security systems worked as designed, preventing spread of the attack,” said Rafail Portnoy, the M.T.A.’s chief technology officer. [...] there was “no employee or customer information breached, no data loss and no changes to our vital systems.”
The other really good answer here is to not have an all-or-nothing architecture for your network, and it sounds like the MTA is doing that already. Don't wire the train-switching network to the email-checking network just because you can. This is much harder to practically enforce at scale in an environment that wasn't designed for it, but it's a great rule to enforce in new systems. Any time you build something that would be worse to get taken over by hackers/ransomware/whatever than the rest of your company's computerized systems, build it separately and make limited interfaces for people to interact with it.
The move to put everything in the cloud really ought to make this easier: you can make a new cloud account for new systems and use bastion hosts etc. for developer access to them, instead of throwing it in your existing account.
it comes down to training and cost cutting. If the penalty for failing miserably is 0 you won’t see any change. I would hold the companies responsible for things like this liable to the point they would be put out of business after an event like this. If the cost of being sloppy is that you no longer have a business people will start paying attention really quickly.
99% of these standards are completely useless and exist only to reduce legal liability. The other 1% are only incidentally slightly useful.
You will never ever create a secure company by following some stupid checklist, unless the checklist is so extreme as to be useless to most orgs. “Step 1: only run OpenBSD…”
you cannot just say: oh this is so complicated that we cannot possibly have a system for it and we have to rely on the people to do the “right thing”
Not one of those but since they are [apparently] inadequate anyway...
I read an analogy that pinning this on "cyber security" is like accusing a mugging victim of having a lack of personal security guards. That's just not how civil society works.
Minimum safety standards: laws and ability to enforce them.
This is a short-term win for the bad actors. Just wait until the next "great firewall." Well gain safety, but we'll lose access to those low cost eastern European dev talent. That's more likely than every single US business being forced to hire private security just to operate.
This is a cope and also irrelevant.
Civil society works a certain way because of its social interaction dynamics. The internet works much differently (namely, retribution is much harder, which rules out most tit-for-tat transgression management strategies, and the scale is much larger than is possible with human interaction).
Civil society does punish businesses when bad things happen due to negligence. Especially when the result of the negligence negatively effects someone else.
The parent comment:
> Minimum safety standards: laws and ability to enforce them.
So it's not just the law but also the potential for repercussions, of which there are currently zero.