enterprisesecuritymag

| | NOVEMBER - 2019ENTERPRISE SECURITY8he world of Malware and Cyber threats has grown significantly since the early 90's, when PC Cyborg, the first known ransomware attack occurred. With a disgruntled biologist, and 20,000 floppy disks, Healthcare organizations across 90 countries had their computers impacted intermittently once powered on after the 90th time. The message demanded an initial payment of $189, with another $378 for software lease. Fast forward to present day...the years of floppy disks are behind us, and as the world's technological prowess rises, so too does the desire for some, to meet and beat this evolution on its own turf. Cybercriminals, and their threats are increasing in maturity.From the 2017 Wannacry ransomware attack mentioned in the detail below, which impacted the National Health Service (NHS), to Atlanta's SamSam ransomware event, the cost and impact has grown. Relative to the 2018 SamSam event, while the request was $51,000, the lost productivity, and subsequent clean-up continues to carry with it varying figures. Add Non Petyaand Cryptomining to cyber threats over the past few years, and how can Enterprise Security practices continue to keep up? Is this a losing game? I say no. Now is the time to: 1) leverage practices from other industry mitigations, and 2) fight fire, with fire. Leverage Practices- Business ContinuityA significant practice that can be used as a complement to Cybersecurity is Business Continuity (BC). When looking at BC, two aspects should be noted: Business Recovery/BR (focused on Business Process) and Disaster Recovery/DR--focused on Technology. An example of related DRincludes the planning required to support protective measuressuch as a firewall which would prevent unauthorized access, and reduce the potential for intentional disruptive acts. Direct DR efforts include securing a backup of critical data to be stored offsite should restoration be required. What then is the recourse should that access be compromised, and the backup corrupted, based on a cyberthreatimpacting both production and backup?Case in point... Wannacry ransomware attacks. In these instances, having a well-rounded business continuity strategy, bringing to bear both the BR, and DR aspects, could be helpful. Conducting a Business Impact Analysis (BIA) to understand what services, if impacted by a business interruption, would cause significant reputational, operational, legal and financial THE EVOLUTION OF CYBER ATTACKS, EVOLVING WITH THE TIMESBy Michele Turner , SME, Risk and Compliance Industry,Head of Corporate Business Continuity, AmazonTIN MY OPINION
< Page 7 | Page 9 >