Tuesday, 13 January 2026

What is a Security Audit and How Do You Prepare for One?

 

Man writing on a clipboard inside a data center.

Security audits have become increasingly important for businesses of all sizes. They can help protect your company from cyber threats, protect your data, and ensure compliance with industry regulations. But what is a security audit, and how do you prepare for one?

What is a Security Audit?

A security audit is an assessment of an information system's security posture to identify vulnerabilities and risks and make remediation recommendations. In the case of a security audit, this includes assessing what types of security technologies are in place and what weaknesses or risks exist. It also includes performing tests to identify potential areas of improvement and providing a summary report that outlines recommendations on how to improve security. The goal of a security audit is to ensure that an organization's systems are secure and conform to established security standards.

It typically involves analyzing the system's hardware, software, and networks, as well as its policies and procedures. A security audit is an essential component of any cybersecurity strategy, and its purpose is to identify weaknesses or areas of risk in the system. It is done through a combination of manual examination and the use of automated tools to inspect the system's configurations, code, and data flow. This helps to assess vulnerability levels and detect any malicious activity. By conducting a security audit, organizations can better understand what needs to be done to protect their assets from potential threats.

Security audits are an important part of maintaining a secure environment, as they help organizations remain compliant with regulations and industry standards. Thereafter, what is a marketable security audit risk? It is simply any potential vulnerabilities or threats that could be exploited by malicious actors. Security audits are an important tool to identify, assess, and remediate any risks present in an organization’s system. A successful security audit should include the assessment of policies, procedures and technical controls to ensure compliance with regulations and industry standards. Regular security audits further ensure that organizations can maintain reliable data security, protect their customers’ data, and remain secure against cyber threats.

Benefits of a Security Audit

A security audit helps identify potential vulnerabilities in your system’s security infrastructure before they can be exploited by malicious attackers. What is a security audit? A security audit is an in-depth analysis of the existing security state of an organization's infrastructure. It evaluates the security policies, infrastructure configuration, implementation, documentation, and effectiveness of an organization’s cyber defense. It also checks for compliance with applicable industry standards and regulations. The goal of a security audit is to identify areas where the organization’s security posture needs to be improved and what steps are needed to achieve this improvement.

Conducting regular security audits allows you to stay ahead of the latest threats, mitigating risks for your organization. A security audit log is a record of what has happened in your system and what was attempted to happen. It can help you detect malicious activities on your network, identify what compromises have occurred, and what access levels different users have on the network. By analyzing these audit logs, you can implement appropriate security measures that are tailored to your organization’s needs and address any security issues before they become a problem. Regular security audits are essential for keeping your system secure and protecting sensitive information.

Security audits can provide valuable insights into how your organization can better protect its critical data and systems from external threats. Also, what is a marketable security audit risk? Auditing is the process of assessing an organization's security posture, including what regulatory requirements must be met and what policy requirements should be implemented. It can help identify systemic risks that potentially put the organization's data at risk. A security audit can provide valuable insights into how your organization can better protect its critical data and systems from external threats by identifying what risks must be addressed and what steps must be taken to mitigate them.

Security Audit definition

Advice to Help You Plan for Your Security Audit

It is essential to have a clear understanding of your IT environment before starting the security audit process. A security audit looks at what is in place to protect your organization's IT systems, such as what protocols and tools are being used, what personnel have access to the system, what data is stored and processed on the system, and what other security measures are in place. By conducting a thorough audit of the environment, you can identify any vulnerabilities that could be targeted by malicious actors. This will help you take the necessary steps to protect your networks and data from future attacks.

You should also create a timeline for the audit and plan ahead for any potential security vulnerabilities. Knowing what cybersecurity measures to take can help protect your business and mitigate the risk of a data breach. Establishing a regular schedule for monitoring, auditing, and updating your system can be essential for a secure infrastructure. It's also important to train all employees on what constitutes safe online behavior and what malicious activity looks like. In addition, you should create an incident response plan that details what actions need to be taken if a security incident does occur. By implementing these cybersecurity measures, businesses can be better prepared for any potential cyber attack.

Lastly, make sure to have robust policies and procedures in place so that your team is prepared to respond quickly and effectively to any security threats. Moreover, what is a security audit log? This is a record of activity on a system or network that allows security administrators and auditors to quickly identify any suspicious activity. Having a robust and up-to-date security audit log is an important part of any cybersecurity strategy and can help in the event of a security breach. It's important to have reliable policies and procedures in place so that you and your team can respond quickly and effectively to address any security concerns or threats.

Implementing the Security Audit Results

Auditing the security systems and processes in place is important to ensure that any potential risks are identified and addressed. Cybersecurity is an ever-evolving field, so regularly assessing what is in place can help protect individuals and businesses against large-scale data breaches and cyberattacks. By understanding which systems and processes are in use, the threats they face and any gaps that might exist, organizations can work to ensure their cybersecurity is properly managed. Additionally, having a strategy in place to detect suspicious activity can be beneficial, as it allows organizations to take appropriate action quickly should issues arise.

Once the security audit is complete, it is essential to implement the recommendations made in order to strengthen the organization’s cybersecurity posture. A marketable security audit risk is a risk or vulnerability that could potentially be exploited by a malicious entity once they gain access to the organization's systems, networks, and data. It is crucial to identify what these security audit risks are and be able to accurately assess the organization’s current cybersecurity status in order to protect against cyber threats. The audit will help identify what cybersecurity measures should be implemented in order to mitigate and manage any potential risks.

This will involve implementing new technologies, training staff on security protocols, and regularly monitoring for any changes in the digital landscape. Also, a cybersecurity audit is essential for any organization that wants to ensure it has the most effective defenses against cyber threats. This will include evaluating what technologies are in place, training staff on best practices, and monitoring the system for any changes in the digital landscape. By carrying out such an audit, businesses can ensure they have a secure foundation in place to protect their confidential data.

Following Up on Results and Updates

It is important to regularly check the results of security audit tests in order to identify any potential vulnerabilities. A cybersecurity audit is a comprehensive review of the technologies, processes, and operations that an organization utilizes to protect its sensitive information from cyberattacks. This type of audit helps organizations identify any weak points in their security infrastructure and proactively address them before attackers can take advantage of them. By conducting regular cybersecurity audits, organizations can ensure that their systems are secure and up-to-date with the latest measures.

While it may seem tedious, updating systems and applications with the latest security patches is essential for keeping data safe. Security audits serve as a way of testing what is currently in place and what could be improved. In order to have an effective security audit, it is important to have the right measures, such as an assessment of the latest technology, applications, and system security. What is the purpose of a security audit? It helps detect any weaknesses that may exist within the system or applications and advises what can be done to fix them. It also helps identify existing threats that could pose risks to the system and provides solutions to prevent these potential attacks. By carrying out regular security audits, organizations can be sure their systems are kept safe from potential intrusions.

Additionally, following up with customers on any new safety protocols should be a priority in order to ensure maximum protection. Next, it is important for companies to conduct what is known as a security audit, which is a thorough examination of the security measures in place. This audit should be conducted regularly to make sure all customers are secure. Additionally, following up with customers on any new safety protocols should be a priority in order to ensure maximum protection.

Security Audit is

Benefits of Ongoing Security Auditing

Regular security auditing helps organizations identify any potential weaknesses or vulnerabilities in their systems. A security audit is a thorough examination of an organization's network to identify any potential vulnerabilities or risks that could be exploited. It is important for organizations to regularly conduct security audits to ensure their networks are secure, reliable and compliant with industry standards. The audit assesses what technologies and tools are in place, what processes are currently in use and what access controls are being implemented. It is a necessary step in maintaining the security of an organization's cyber infrastructure and can help prevent cyber threats from becoming larger problems down the line.

It also allows organizations to stay ahead of the latest cyber threats and make sure their systems are up to date with the latest security measures. Cybersecurity is an important consideration in today's world, as more and more of our business and personal lives are becoming digitized. By investing in cybersecurity, companies can ensure their data is secure from malicious actors, including hackers, viruses, and other forms of attack. Furthermore, cybersecurity provides the necessary protection for organizations to remain compliant with laws and regulations concerning online data. With comprehensive cybersecurity measures in place, organizations can rest assured that their digital assets remain safe.

Ongoing auditing can also help organizations ensure their data is protected and that they are compliant with all applicable laws and regulations. In conclusion, organizations should develop and implement a comprehensive cybersecurity plan that includes frequent auditing. This ongoing auditing helps ensure that their data is secure and fully compliant with legal requirements. Regular auditing is the best way to stay informed of the latest cybersecurity threats and techniques to protect data from being compromised.

So, What is a Security Audit, and How Do You Prepare for One?

In conclusion, it is important to remember that security audits are key components to keeping your business safe from cyber threats and ensuring compliance with industry regulations. It is essential to have an understanding of what a security audit entails before undergoing one so that you know what to expect and can adequately prepare. Knowing the right questions to ask, having an understanding of the key components of a successful assessment, and working with a qualified auditor are all important steps in the auditing process. Call us at 213-398-8771, or use our online contact form to learn more. 

Cybersecurity Undone by Insider Threats

Man behind a clear screen with people icons in one row, pressing one that looks like a crook.

What does a dishonest FBI employee have to do with your company’s cybersecurity? More than you think. Kendra Kingsbury, a 48-year-old FBI intelligence analyst, was indicted on May 18, 2021, for “having unauthorized possession of documents relating to the national defense.” According to the FBI’s special agent in charge of this case, “Every FBI employee swears to support and defend the Constitution of the United States,” and Ms. Kingsbury allegedly violated that promise for reasons not yet publicly apparent.

Now, let’s think about all the people who work in and for your company, including employees, contractors, vendors and service providers. They may not have made a promise as important to national security as those made by FBI agents, but they could be just as likely (if not more likely) to be an insider threat, to betray your trust and do great harm to your business.

What are insider threats?

We often write about modern threats against organizations, including Ransomware, Data Exfiltration, Data Breaches, Zero-Day attacks, Hacks, Viruses, and other malware and cybercrimes. But the assumed context of all of those attacks is that they’re initiated by business outsiders, often Eastern European hackers, Rogue nation-states, or just plain old-fashioned individual cyber criminals writing viruses in their basements.

Over the last two years, we’ve reported on just one story about a potential insider threat, and that was to a company we’ve all heard about, Tesla. A cybercriminal attempted to bribe a Tesla employee with $1 million to insert a ransomware-filled thumb drive into his desktop PC. But the employee was trustworthy and reported the bribe to his supervisors, who, in turn, involved the FBI. The cybercriminal and one of his associates were caught because the honesty and integrity of a Tesla employee neutralized the threat before the attack could occur.

Would your employees and your third-party vendors do the same for you and your business? All business owners and managers hope the answer is yes, but most also know it’s unlikely.

So what are insider threats? Those are any of the incidents mentioned above (Ransomware, Data Exfiltration, Data Breaches, Zero-Day attacks, Hacks, Viruses and other malware and cyber crimes) perpetrated by someone who works in the company or a trusted vendor.

Are all insider threats malicious?

Interestingly, not all insider threats are malicious, where the actor intends to do harm to the company. According to Verizon’s Insider Threat Report, insiders are often motivated by these malicious motives:

  • Financial Gain -- But not necessarily to do harm to the organization
  • Espionage -- For the benefit of themselves or another organization
  • Grudge -- Potentially against the business, but also potentially against specific employees
  • Ideology -- The insider may be opposed to an action or philosophy of the organization

But insiders could also be motivated by these less-malicious reasons:

  • Fun -- Can this be done?
  • Convenience -- the desire to work around cumbersome security procedures.
  • Fear -- perhaps fear of an impending financial catastrophe, or fear of being fired.

verizon-insider-threat-motivations

Supporting those statistics is Verizon’s assessment of who the insiders are. Three of their actor-types are malicious:

  • The Inside Agent -- An employee motivated to act for the benefit of some other bad actor.
  • Disgruntled Employees -- Potentially those passed over for raises and promotions, or who feel they were otherwise wronged by their employers, who are just out to harm the organization or other specific employees.
  • Malicious Insider -- Those who steal data, usually for personal gain.

But two of them are not:

  • The Careless Worker -- Employees who incorrectly address emails, install unpermitted software, inadvertently expose sensitive data, and work around security measures.
  • The Feckless Third Party -- Business partners who do not support the same high security measures as the organizations they serve.

(Note: In the above list, the labels were from Verizon’s report, and the descriptions were our own.)

Reducing The Damage of Insider Threats

So your company has done all that it was supposed to do in order to protect itself from cyber attacks: you installed the latest firewalls and reinforced those with the best cybersecurity software. You’ve got endpoint protection, VPNs, multi-factor authentication, secure password policies, SIEM analysis of your device log files, a Security Operations Center monitoring your network 24/7...so you sleep well at night.

Despite doing all the right things, insider threats can undo several layers of cybersecurity in moments.

What can you do to help reduce the Damage of Insider Threats?

Cybersecurity Awareness Training

Cybersecurity Awareness Training helps to train your employees to look out for signs of Phishing, Business Email Compromise, and other signs of attempted attacks. But it can also train employees how to notice when other employees are doing things they shouldn’t be doing -- insider threats that may potentially harm your company.

Employee Background Checks

But Awareness Training depends on whether your employees actually want to protect the company. How can you ensure that they do? Trustworthy employees begin with the hiring process, and in particular, by running background checks on your employees.

Robert Glucroft, of BackgroundRunner.com, a Los Angeles-based background check company, says, “When you’re interviewing a prospective employee, they will often say whatever they need to say to get you to hire them...and not all of it is going to be true.” Glucroft continues, “You could be hiring people who have long histories of embezzling from their companies, or people who are in severe financial trouble or have substance abuse issues, all of which make them much more likely to betray your company for the right price or reason.”

But background checks are not only for potential new employees. Background checks should also be conducted on an annual basis on existing employees. “Situations change for employees just as they do for the general public. Sharp increases in debt, signs of substance abuse, and even a lengthening criminal record can indicate that an employee is under stress and may potentially harm the company,” says Glucroft.

Vendor Management and Review

We’ve been brought into companies with the goal of either reviewing or improving their current cybersecurity practices and those of their vendors and suppliers. We’ve discovered instances where our clients had the foundations and policies of a solid cybersecurity strategy, but all their efforts were undone by outside vendors.

  • We’ve seen the aftermath of VOIP vendors and Video Security installers leave huge holes in previously-secured company firewalls in order to simplify the configuration of their own equipment.
  • Software publishers have had their own software hacked and then installed their software onto the networks of other businesses, immediately adding backdoor access to your business and all its data.
  • Even an improperly configured QuickBooks system can allow hackers to steal your data.
  • Vendors for proprietary equipment, such as specialized medical equipment, have sometimes left security holes in their own products that will allow access to your office network in much the same way as smart light bulbs can give hackers access to your wifi network.
  • Vendors can even install their own software via thumb drives without knowing that those drives contain malware.

Businesses often let vendors into their company without questioning their cybersecurity policies and procedures, it often leads to a disaster for the company. The only solution to this problem is to manage and review your vendors’ cybersecurity policies.

Conclusion

Business IT networks are getting more complex every day, and that means your cybersecurity strategy needs to adapt in order to be effective. But a huge, often overlooked part of your cybersecurity strategy includes the people who work in and with your organization. If you don’t know how to protect yourself from these dangers, let Digital Uppercut help. Use our online contact form or call us at 213-398-8771.

 

Heroic statue in the Greeco-Roman style of a man with chains on his arms.

New cryptocurrency coins are created by solving complex mathematical problems, a process called “mining.” Those who mine cryptocurrency do so by building farms of extremely powerful computers designed specifically for these mining operations. Not only are the computers expensive, but so is the maintenance, networking and electrical power required to keep them running, sometimes making the effort unprofitable. But now cybercriminals have designed malware that seeks to avoid all of that expense by infecting millions of computers with code that will do the mining for them...on YOUR computers.

The malware, named Prometheus (after the Greek god of fire) and “Prometai” in Russian, exploits two vulnerabilities in Microsoft Exchange, collectively known as “ProxyLogon,” to help it spread to users of the Exchange server. But the threat doesn’t stop there.

How The Prometai Malware Works

According to a report on Cybereason.com, the attack begins with a hack of unpatched Microsoft Exchange servers that exploit the two ProxyLogon vulnerabilities. From there, it infects other PCs on the network.

Threatpost says that “ProxyLogon consists of four flaws that can be chained together to create a pre-authentication remote code execution (RCE) exploit – meaning that attackers can take over servers without knowing any valid account credentials.” That means that no matter how complex your passwords may be, your Exchange Servers may still be at risk.

The malware's main payload is to run a cryptocurrency-mining application. Miners do well when the costs of the machines, maintenance and network infrastructure are lower than the value of the coins generated by the application. And the venture becomes even more profitable when those costs are born by others.

Which Cryptocurrency is Mined by Prometai?

Most of us are familiar with Bitcoin, the most popular cryptocurrency, but this malware mines Monero, a lesser-known cryptocurrency. Why Monero? According to Genesis Mining, Bitcoin is optimized to run on specialized hardware that uses ASIC chips, and most office computers do not have high-performance ASIC chips. On the other hand, Monero is “designed in such a way that ASIC computers do not have much of an advantage over ordinary computers. As a result, ordinary people can use a simple CPU and start mining right away.”

That makes mining Monero ideal for the untargeted distribution of this malware, because any computer it infects can be used for mining the coins.

Why is the Prometai Malware Dangerous?

The damage to the owners of these computers occurs on many levels.

  • The users of infected computers suffer from poor performance from their PCs, as processing power is diverted to the mining operation.
  • Computers use additional electricity for the additional processor power required to run the mining software.
  • The malware can affect the stability of the infected computers.
  • It spreads to other workstations by using brute force techniques to guess user credentials, trying hundreds of common passwords
  • It spreads to Microsoft SQL Servers and PostgreSQL servers

But the real danger of the malware is that it provides a backdoor for loading other software that could do even more damage to your computers and your company. The backdoor could be used for:

  • Stealing Credentials
  • Stealing Intellectual Property
  • Installing Ransomware
  • Allowing Remote Control and Takeover of the computers

How To Protect Your Company From Prometai

The first and best thing you and your company can do to protect yourselves from this and similar malware infections is to keep your software up to date. The entry point for Prometai is two vulnerabilities in Microsoft Exchange that Microsoft has already fixed. However, if your IT team has not installed the patches, your company remains vulnerable.

Systems that detect and prevent unauthorized installation of software on servers and workstations are another line of defense, as they could prevent the installation of the malware or detect its presence early enough to minimize the damage.

SIEM systems, which view and analyze your entire IT infrastructure as a whole (rather than as separate components), can help to detect unusual activity across your network.

If you run a business, from a single laptop up to large enterprises, your business is vulnerable to this or similar malware, and there is no way to protect your business except to take an active role in defending yourself. Digital Uppercut offers all of these services and more as part of our Business Protection Toolkit, which contains 10 separate business protection tools and is growing.

Call Digital Uppercut

The Business Protection Toolkit allows Digital Uppercut to provide big business protection on a small business budget. If your business isn’t protected, or you aren’t sure if your current IT team is protecting your business well enough, call Digital Uppercut for a free consultation and a discussion of your situation. Make an appointment using our online contact form, or call us at 213-398-8771.

Monday, 12 January 2026

How Much Should Good Cybersecurity Cost?

 

Man working at multiple monitors in a data center

How Much Should Good Cybersecurity Cost? Business owners and CEOs are very familiar with the financial ratios they use to run and monitor their businesses. Good Inventory turnover often varies between 2 and 10, depending on the type of business. A 2-to-1 “Current Ratio” of assets over liabilities can indicate a healthy business.

Healthy Quick Ratios over 1.0 tell you how effectively the business can pay financial obligations...including emergency obligations, such as the hundreds of thousands or millions of dollars it takes to recover from a cybersecurity breach. So then what is the proper financial ratio for calculating how much you should spend on your company’s cybersecurity to prevent a breach? Like with other ratios, it depends on a number of factors.

How Much Should Good Cybersecurity Cost?

Good and bad assessments of the ratios mentioned above all depend on the type of business you’re running. Certainly, a wholesale business will have different ratios than a retail business. An online business will have different ratios than a brick-and-mortar business. And of course, service businesses will have different ratios than product businesses.

So how much should good cybersecurity cost? The problem with answering this question is that IT, in general, and cybersecurity, in particular, are generally considered cost centers rather than profit centers. So any number greater than Zero is going to be too much for some business managers.

Cybersecurity Economies of Scale

When asking what good cybersecurity costs, economies of scale hold part of the answer. As with most products and services, larger companies benefit from lower relative cost-per-user because their investment can be spread over more workstations and infrastructure. As a result, according to a report by InfoSecurity Magazine, which discussed the cost of cybersecurity as a percentage of revenue, large companies can often spend “anywhere from a fraction of a percent to a couple of percent on implementing and sustaining security.”

Larger companies enjoy lower per-user costs, such as software upgrades, security software, workstation purchases and upgrades, simply because they are buying larger quantities and can demand larger discounts. They can also spread high infrastructure costs, such as network servers, firewalls, backup systems, Security Information and Event Management (SIEM) and Security Operations Centers (SOC), among more users.

By contrast, small companies typically have fewer endpoints than larger companies, and cannot demand the same large discounts that their big brother companies can. And they need to spread their infrastructure costs over that smaller user count. The result is that, according to the same InfoSecurity Magazine article, small companies can spend 4% or more of their total revenue on Cybersecurity.

These percentages are not hard and fast rules. For both large and small companies, costs increase not only by the number of workstations and servers, but also by…

  • The number of locations
  • The number of remote workers has increased recently due to COVID-19
  • The number and type of mobile devices
  • The age of equipment and software
  • The company’s efforts to update software and keep technology current
  • The type of data being secured, especially as it relates to medical data
  • The number and type of specialized devices, including medical devices, CAD/CAM equipment, manufacturing equipment and other diagnostic equipment

...and so much more. Whatever the circumstances, good security costs more for small businesses than for large companies.

How To Keep The Cost of Cybersecurity Down

Whatever size organization you have, there are ways to keep the cost of cybersecurity down.

Start when you’re small

It may sound counterintuitive, but starting your cybersecurity plan when you’re a small business allows you to grow cybersecurity incrementally, which can save the organization a lot of money.

Maintain The Cybersecurity You have

Creating a cybersecurity budget and maintaining your technology diligently costs far less, in both time and money, than letting your technology age without updates and then replacing everything a few years down the road. Plans like this not only cause you to incur huge costs all at once but also leave you vulnerable to attacks as your cybersecurity technology ages.

Don’t Wait For An Attack

We often gain new clients after they’ve been attacked. They often tell us that they were just about to upgrade their cybersecurity. By then, of course, it’s too late. The costs of upgrading your technology after a cyber attack are many times higher than before the attack.

Big Business Cybersecurity for Small Businesses

What if your small or medium-sized business could get the same cybersecurity economies of scale that large businesses get every day? Digital Uppercut’s Business Protection Toolkit is designed to provide big business cybersecurity to small and medium-sized businesses like yours. And the good news is that you can decide how much good cybersecurity should cost, and we can customize the Toolkit to fit not only your business, but your budget, too. Together, we can choose big business cybersecurity technologies such as SIEM, SOC, Cloud-based firewalls, Awareness Training, Advanced Endpoint protection, and more. Contact us online or call us today at 213-398-8771 to talk about how Digital Uppercut can help protect you and your business.

More Intelligent Phishing Attacks: Click Here To Claim Your Two Night Stay at Marriott Hotels

 

Digital brain hovering over a laptop in a man's hands.

Imagine this email subject line: “Click Here To Claim Your Two-Night Stay at Marriott Hotels.” Would you read an email because of a subject line like this? It’s pretty attractive, and a similar message was sent to millions of people via email with a similar offer. The problem is that the offer was fake, and part of a more intelligent phishing attack designed to take advantage of a recent real Marriott International breach that affected approximately 5.2 million guests. This very sophisticated phishing campaign first referenced the January 2020 breach -- a true and widely publicized story -- and followed it up with the fake offer.

 Phishing Is Your Biggest Threat

Phishing, researchers say, is the number one “attack vector” affecting enterprises, mostly because it works. And while it’s no surprise that cyber criminals are coming up with new tactics for those phishing attacks, what is very surprising is the depth, intelligence and sophistication used in these new attacks, including advanced psychological techniques.

The Marriott 2018 Data Breach

According to an article in Security Boulevard, the Marriott 2018 data breach “may have taken personal details such as names, birthdates, and telephone numbers, along with language preferences and loyalty account numbers,” which gives the cyber criminals additional credible information for future cyber attacks. Imagine, for example, a subsequent Happy Birthday email offering you a free night’s stay to celebrate your birthday. Its authenticity could be very convincing.

But in this case, Marriott announced in its own press release that it “is sending emails to guests involved.” To Marriott customers who are aware of the original breach and this specific announcement, the phishing email looks very authentic.

We predict that there will be more phishing campaigns leveraging the news of other hacks and breaches to make their attacks look more legitimate as well. But the increasing sophistication of cybercriminals gets even more clever than this.

Making More Intelligent Phishing Attacks More Believable

Leveraging real breach news is one way that cybercriminals are making more intelligent phishing attacks, but there are others. If you’ve ever negotiated a deal on a new car in a buyer’s market, you know that your willingness to walk away from the deal puts you in control of the negotiations. The same holds true for the sales representative in a seller’s market: If the buyer is not willing to meet the price, all the seller has to do is threaten to take away the offer.

According to ThreatPost Magazine, there’s a new phishing technique that uses CAPTCHA challenges to actually prevent users from accessing a phishing site. This may seem as counterintuitive as leaving a negotiation that you’d like to win, but it’s actually quite clever.

The ThreatPost article describes how users are actually exposed to not one, but three separate CAPTCHA challenges, and quotes researchers at Menlo Security who gave two reasons for the effectiveness of this technique:

  • CAPTCHA prevents security spiders from identifying these dangerous phishing sites
  • CAPTCHA is used by legitimate “benign” websites, not fake sites. In other words, the user assumes the site must be legitimate if it’s using a CAPTCHA challenge.

But we recognize a third reason for this technique being effective:

  • CAPTCHA...especially repeated CAPTCHA...may frustrate users, so that once they succeed at answering the challenge questions, they will be more eager to fill out the credential screen and less aware of the deception that is part of every phishing site.

Thinking back to the car sales analogy, it’s as though the seller has rescinded the offer twice, but finally agrees to your terms. You can imagine yourself eagerly filling out the contract terms.

So not only does this technique help the phishing site hide, but it also convinces the victim that the site is more legitimate AND makes the victim more eager to comply.

That’s a dangerous combination.

Could Your Users Resist These More Intelligent Phishing Techniques?

The first example above was a travel site, but it could just as easily resemble a recently hacked bank website, such as Bank of America (Hack reported in May 2020 related to PPP applications), CitiFinancial, Wells Fargo and others. It could also be a health-related organization, such as American Medical Collection Agency, lab sites like Quest Diagnostics, or other breaches involving health data records

Imagine having your best employee fall for one of these more intelligent phishing attacks, and the damage it could do to your own company (thousands or millions being wired to the criminals’ bank accounts) or to your medical practice (the breach of thousands of HIPAA-protected medical records).

Awareness Training Educates Your Staff

We have many techniques for protecting your business from breaches and hacks, including the more intelligent phishing techniques described here. Firewalls prevent direct attacks on your networks. Advanced Endpoint Protection protects individual workstations and devices from malware. Our Advanced Web Protection can even identify phishing sites. And we have a dozen other methods of protecting your organization from threats. But if your staff unknowingly cooperates and forfeits credentials to valuable resources -- especially on personal or unprotected devices -- the attack has a good chance of getting through.

It’s as though your staff has unwittingly joined the attacker’s team.

That’s why we recommend Awareness Training for all of our clients. Because C-Level executives are the most prime targets for phishing attacks, the training consists of a series of lessons that teach your staff at all levels, from clerical and maintenance staff up to the CEO. And not only do we offer the training, but we offer a console to help you organize and manage the enrollment of each of your employees, and the refresher training needed to keep your staff aware of the latest threats.

If you have cybersecurity insurance, and certainly if your company is required to follow HIPAA regulations, Awareness Training is required to be part of your cybersecurity plan.

Fight More Intelligent Phishing Attacks Today

Cybersecurity always feels like it’s too much until you discover that it’s not enough. Taking a few hours each week to keep your company safe may seem like too much, but you’ll know for sure that whatever you’re doing now is not enough once your company falls victim to a more intelligent phishing attack. As important as Awareness Training is, it’s not nearly as expensive as you might think, and is even added at no additional cost to some of our cybersecurity packages. Contact us online or call us today at 213-398-8771, and let’s talk about protecting your business from a phishing disaster.

Penalties for Uber Exec Who Covered Up Data Breach

 

Woman looking at smartphone with the Uber logo filling the screen.

Uber was hacked in 2016, revealing the personal information of 600,000 Uber drivers and 57 million Uber passengers. If you joined Uber in or prior to 2016, there’s a good chance your data was exposed in the Uber Data Breach. Why are you learning about this now? On August 20, 2020, the Federal Trade Commission filed a criminal complaint against Joseph Sullivan, Uber’s former Chief Security Officer, because he not only didn’t report the crime, but he also actively worked to “conceal, deflect, and mislead the Federal Trade Commission about the breach,” according to the FTC.

About the Uber Data Breach

This wasn’t even the first time that Uber had been hacked: Uber had been breached in 2014, and Sullivan was selected by Uber to respond to the FTC’s inquiries into that data breach. About ten days after Sullivan provided his testimony to the FTC, he was contacted by two hackers and told that they had accessed Uber’s data. According to Uber in its own blog post on the same day as the FTC and FBI’s announcement, the hackers accessed "data stored on a third-party cloud-based service that we use. The incident did not breach our corporate systems or infrastructure."

The Uber Driver data that was breached included names and driver's license numbers, but it was also among the 57 million Uber Rider Data records, whose names, email addresses, and mobile phone numbers were among the breached data.

Concealing the Uber Data Breach

Sullivan and his team took less than 24 hours to confirm the Uber Data Breach. However, he then worked with the hackers to pay them “hush money” in exchange for a promise not to reveal the hack to the public.

The payment was made to the hackers via Bitcoin under false names, which were also used on a written non-disclosure agreement, which included a “false representation” that no data was actually taken. In order to help conceal the breach, the payment was facilitated through a “bug bounty” program. Such programs are used to reward white-hat hackers when they discover, but do not exploit, data vulnerabilities.

The true identity of the hackers was later discovered to be Brandon Charles Glover of Florida and Vasile Mereacre of Toronto. Sullivan sought to have them re-sign their non-disclosure agreement under their true names. At least one other Uber employee was involved in the preparation of the agreement, but according to the FBI, "When an Uber employee asked Sullivan about this false promise, Sullivan insisted that the language stay in the non-disclosure agreements."

Sullivan Reveals the Breach to Uber Management

Uber Founder Travis Kalanick resigned as CEO in 2017, and new management, including a new CEO, Dara Khosrowshahi, was hired in August. Sullivan told the new CEO about the 2016 breach and then asked his team for a summary of the event to present to Khosrowshahi. Sullivan then edited the draft summary prepared by his team by removing details about the data that was taken, and then by adding false information that the payments were made only after the true identities of the hackers were known.

Uber’s new management ultimately discovered the truth and disclosed the Uber data breach publicly, and to the FTC, in November 2017.

Had Sullivan reported the breach rather than trying to cover it up, the FBI says that no charges would have been filed. But given the current facts, the criminal complaint filed on August 20 alleges that Sullivan deceived Uber’s new management team about the 2016 breach. The FBI is charging Sullivan with “obstruction of justice, in violation of 18 U.S.C. § 1505; and misprision of a felony, in violation of 18 U.S.C. § 4.” (The term “misprision” is the deliberate concealment of knowledge of a felony or treasonable act.)

What You Can Learn From The Uber Data Breach

There are several lessons to be learned from this story, not the least of which is that cloud-based services require the same or higher level of security as your in-house data. All cloud-based systems come with security by default, but they also come with security holes by default, and it’s your cybersecurity team’s responsibility to plug them. Not only are there optimizations that can be done within most cloud-based systems, but you can also increase and optimize your security around the cloud services with cloud-optimized firewalls, mandatory file and folder-based encryption, SIEM and Security Operations Center technologies, and other techniques.

The other lessons concern cover-ups. While data breach penalties that corporations can face can range into the tens or hundreds of millions of dollars, failing to report data breaches can result in even worse consequences, including criminal penalties.

What You Can Do

Some data security breaches have one level of penalties in the event of a breach, and a much higher level of penalties if there is no plan to deal with the breach, or if the plan is not followed. All of this serves as a warning to not only secure your business data but also to have procedures in place in the event of an incident like the Uber data breach. Digital Uppercut is here to help you with both your security and your plan. Call Digital Uppercut at 213-398-8771 or contact us online today.

How To Penetrate Your Network Security? Cash!

 

Person in handcuffs holding a stack of money.

Sometimes, cyber-attacks enter your company network when an employee stumbles upon a virus-filled web page. Other times, the cyber-attack begins when an employee falls victim to a phishing attack or is tricked into downloading a virus-filled file. Other times, it’s a brute force attack on your network. Now here’s something else to worry about...a technique that might seem new but is as old as commerce itself: Dishonest employees willing to allow the bad guys to penetrate your network security for cash.

The FBI announced that on August 22, it arrested a man who bribed a Tesla company employee with a $1 million payment. What did they ask him to do? Plant one piece of malware -- Ransomware, actually -- onto his office computer. The story actually unfolds like a spy novel and holds a cautionary tale for any company’s cybersecurity team.

The Insider is Approached

Egor Igorevich Kriuchkov is a 23-year-old Russian citizen. According to an article on ClearanceJobs.com, Kriuchkov and his colleagues had inside information about which Tesla employees had access to the resources necessary to place the intended malware. They identified and contacted a non-U.S. citizen working at Tesla’s Sparks, NV facility who spoke Russian as their inside man.

Kriuchkov and the employee’s early contact, beginning mid-July, was through WhatsApp, a communications tool owned by Facebook that features end-to-end encryption for all communications. The two, along with other Tesla colleagues, met in Lake Tahoe between August 1 through 3. Initially, all contact was social, but on August 3, Kriuchkov asked the insider to participate in a "project."

Kriuchkov asked the insider if he would place some malware that Kriuchkov and his associates would customize and provide. In exchange, the insider would receive $500,000. After being contacted by Kriuchkov, the employee reported the contact to company officials, who then notified the FBI.

How the Malware Attack Would Work

According to the insider, he was told how the attack would work.

  • The malware would be placed by the insider.
  • Kriuchkov’s colleagues would initiate a Red Herring -- a Distributed Denial of Service (DDOS) attack, with the goal of keeping Tesla’s Cybersecurity team busy.
  • While the Cybersecurity team was busy fighting the DDOS attack, Kriuchkov would spread the malware throughout the network.
  • Sensitive corporate data would be exfiltrated, and the network files would be encrypted.

It’s at this point that a ransom demand would be made on the company, for many millions of dollars.

How The Cybercriminals Were Captured

For his fee, the insider was expected to provide additional inside information about Tesla so that its ransomware software could be customized. Communication happened via burner cell phones, WhatsApp, TOR and Bitcoin wallets.

Working with the FBI, the employee extracted additional information about the plans for the attack, and also demanded a higher payment, eventually settling on $1 million. During these conversations, Kriuchkov boasted that they had done this several other times, and that one of their previous insiders was still working at his company three and a half years later.

How To Defend Against Threats To Penetrate Your Network Security

You would want to believe that a company as large and sophisticated as Tesla would have network infrastructure strong enough to defend against such an attack. The cybercriminals seem to think otherwise, and fortunately, Tesla didn’t have to find out.

Would you be so lucky?

So what does this all mean to companies like yours? The first and most obvious question is whether your own employees would be honest enough to forego a huge payday in order to take down your company. Although this wasn’t mentioned in the research for this story, employees with large debts, gambling problems, and other serious issues and secrets would be most vulnerable to an approach like that received by Tesla’s insider. Background checks for current employees and new candidates could be helpful here.

It’s also possible that companies like yours might have already been targeted by cybercriminals, who may have already sent compatriots to apply for and take jobs in your company, with the express purpose of placing malware from the inside. These scenarios suggest it may be wise to add thorough candidate and employee background checks to your normal cybersecurity procedures.

The problem is that firewalls alone can’t protect against an inside job like this, and typical antivirus software isn’t strong enough to defend against more sophisticated malware. Most cybersecurity defenses exist in a silo and are designed to look at only a very narrow range of activities.

Only with a sophisticated SIEM (Security Information and Event Management) system can such threats be identified. That’s because SIEMs collect data from all parts of your organization -- every workstation, firewall, server, network appliance, access point, browser, and email program -- and view it all holistically, finding clues in one system that it can follow into another system in order to get a complete picture of the attacks you are facing.

Having a Security Operations Center (SOC) review the SIEM’s findings and other data makes the SIEM even more effective.

What Should You Do Now?

As you can see, attacks designed to penetrate your network security are getting more sophisticated every day. If your cybersecurity system isn’t designed to withstand these more modern, more sophisticated, and more elaborately planned and patient attacks, you might find that you’re on the losing side of a Ransomware attack...and that wouldn’t be good for you, your company, your employees, your vendors and your customers. Let Digital Uppercut help prevent that. Call us at 213-398-8771 or contact us online to set up an initial conversation and a preliminary risk assessment. Keeping your company safe is our business. Let’s talk.

What to do About Microsoft Ending Support for Your Software

  Microsoft has announced that it will no longer be supporting a long list of its software. On that list could be many programs you might ha...