I.T., Blog Deidre Frith I.T., Blog Deidre Frith

Tropical Storm Technology Checklist

As Tropical Storm Fred makes its way towards Florida and the Southeast U.S., now is the time to take action and be prepared to protect your computers, printers, files and data.

Image courtesy of Florida Division of Emergency Management

Image courtesy of Florida Division of Emergency Management

As Tropical Storm Fred is traveling towards Southeast Alabama, now is the time to take action and be prepared to protect your computers, printers, files and data.

1. ENSURE YOU HAVE A BACKUP

  • Backup your files! It's good practice to frequently backup your data files. We recommend a hybrid-cloud image-based backup that can be used to restore data and applications even if your server is destroyed, and that can restore data from different points in time.

  • Print a copy of your important/emergency contacts and take them with you if you do not have access to them from your phone or computer, you'll have them available to use via a landline.

  • RealTime Clients: Everyone who is on our Business Continuity Service – Your servers are backed up and replicated offsite daily. If there is a problem, we correct that as part of the service. As hurricanes approach your physical location, we’ll be talking with you and confirm things are backed up and replicated prior to you shutting your operations down as part of your storm prep.

2. SECURE YOUR EQUIPMENT

  • COMPUTERS

    • Shutdown the operating system.

    • If connected to a surge protector or UPS - unplug from the wall outlet (or unplug power cables from the surge protector or UPS if wall outlet isn't accessible).

    • Unplug Ethernet cable from the back of computer or docking station.

  • PRINTERS

    • Power off the printer.

    • If connected to a surge protector - unplug as described above.

    • Unplug the Ethernet cable from the back of the printer.

    • Unplug the phone cable from the back of the printer (if a fax line is connected).

  • SERVERS AND NETWORK EQUIPMENT

    • Perform a normal shutdown of the servers. RealTime clients: Please coordinate with RealTime service desk. 

    • Unplug all connections - Take photos to document how things were prior to the event. 

    • Firewalls, Switches, Access Points - unplug them from power. Unplug the firewall from the internet connection as well. Ideally, unplug all the network connections (surges can travel through the network cabling).

    • Battery backups - power these off and then unplug them.

    • Phone systems - Check with your vendor to see what steps you can take to protect it.
       

3. PROTECT FROM WATER/WIND

When a major storm is predicted, elevate your CPUs, printers, servers, and other network devices, as well as other electrical appliances like space heaters, off of the floor.  For high winds, move computers away from windows.  If there is a possibility of water leakage, cover computer equipment with plastic.

4. CONTINUING OPERATIONS AFTER THE STORM

  •  If you are in the path, power and internet connectivity may be hard to come by for a few days. Generators can provide enough power to run your critical computer equipment – just be sure you are connecting up to something that can deal w/ the power fluctuations many generators have. Please ask RealTime before connecting things up to generators as they can damage sensitive equipment. Modern battery backups may have the capability to condition the power off of a generator – check with the manufacturer to confirm before trying this.

  • 4G USB modems or Mifi can get you connected in an emergency. Everything you do may not work, but basic web browsing.

  • Forward your phones – If the office is expected to be out a few days, most phone service providers have a way for you to forward calls to your business to a cell phone or alternate number. Get the steps now, before you need them.

5. BE PREPARED

Knowing what steps to take ahead of time will help you be prepared in the worst-case scenario. RealTime is committed to ensuring our clients are prepared with the proper technology to meet their current/future needs as well as advising them about safeguarding their business from weather-related, cyber and other disasters. 

If you would like further information about RealTime managing Information Technology for your business, contact us at info@realtime-it.com.

Read More
I.T., Blog Deidre Frith I.T., Blog Deidre Frith

What lessons can we learn from the Colonial Pipeline ransomware event?

If your business falls victim to a ransomware attack or some other type of breach, how would your company handle recovery? In talks with business owners over the past couple of years, no one thinks too much about what recovering from an event looks like for them. At RealTime we hear “I’ll call you guys!” or “our insurance will handle it”, “our IT guy will deal with it.” Are these courses of action something to stake your business on? Let’s use a real world example happening now with Colonial Pipeline.

20210513-danny-beth-pipeline.jpg

Blog: Todd Swartzman, RealTime Chief Information Security Officer

LET’S BEGIN AT THE END

Let’s go a bit out of order and focus on the end of these types of events, the recovery. After all, if your business falls victim to a ransomware attack or some other type of breach, eventually you will get to the recovery phase. In talks with business owners over the past couple of years, no one thinks too much about what recovering from an event looks like for them. At RealTime we hear “I’ll call you guys!” or “our insurance will handle it”, “our IT guy will deal with it.” Are these courses of action something to stake your business on? Let’s use a real world example happening now:

COLONIAL PIPELINE EVENT/RECOVERY FACTS

  1.  Event May 5, 2021

  2. Took five days and there are still intermittent service interruptions happening.

  3. Budget? Unlimited. This was a recover at all costs exercise.

  4. Government help – there for the asking

  5. Temporary lifting of regulations to help deliver product.

  6. Colonial Pipeline paid $4.4 million in ransom within hours of the attack. They opted to pay the ransom because it was unsure of the extent of the breach. The hackers provided the company access to a decryption program following the payment, but Colonial Pipeline was not able to immediately restore operations with the tool.

 HOW WOULD THIS COMPARE TO YOUR BUSINESS RECOVERY?

  1. Do you have unlimited funding and is FedGov offering every assistance available to you?

  2. Can you go 24x7 until it’s recovered? What about your primary business serving customers, who’s going to do that while all hands are on deck dealing with the current fire? If you have one IT guy, this isn’t realistic, even if they did have the requisite skills, and they probably don’t.

  3. Do you assume you’ll only be down for a few days? Average time to recover a small business is about two weeks, but that can vary wildly.

 CLOSING

CYBERSECURITY IS NOT JUST A TECHNICAL PROBLEM. IT’S A BUSINESS PROBLEM.

Use this as a lesson you can learn at someone else’s expense. Review your own controls, backups, response plans, insurance policy, and your budget to make sure that your plan is documented, understood, and most importantly is realistic.

 CISA (Cybersecurity & Critical Infrastructure Agency) put out an alert on Best Practices for Preventing Business Disruption from Ransomware Attacks. And if you are curious, yes, Colonial Pipeline would be subject to adhering to CISA requirements as they are critical infrastructure.

Article link: https://us-cert.cisa.gov/ncas/alerts/aa21-131a 

Read More
Deidre Frith Deidre Frith

Dealing with a Cyber Insurance Claim

Paying the ransom doesn’t guarantee you’ll get your data back. These are criminals after all, and some are very professional, and some are careless. It may be that the attacker corrupted the data during the encryption process. To mitigate some of the risk, use a professional negotiator and Incident Response firm. The pros generally know which gangs and ransomware variants are reputable and recoverable and which are not. DO NOT TRY AND DO THIS YOURSELF.

BY TODD SWARTZMAN, REALTIME CISO

At RealTime, we highly recommend setting up an appointment with a breach coach through the insurance carrier. Use this call to better understand the process in case you do need to make a claim. Having a reasonable expectation on what the process looks like will take some of the stress off of you in the event you have to make a claim. 

images-8.jpeg

PAYING THE RANSOM

Paying the ransom does not guarantee you’ll get your data back. These are criminals after all; some are very professional, and some are careless. It may be that the attacker corrupted the data during the encryption process, or they never intended for you to be able to recover because hey, they are criminals. To mitigate some of the risk, use a professional negotiator and Incident Response firm - these are usually part of your cyber insurance coverage. The pros generally know which gangs and ransomware variants are reputable and recoverable and which are not. DO NOT TRY AND DO THIS YOURSELF

Even if you do pay the ransom and you get the decryptor keys, and they work, the process to decrypt is pretty slow. This slow process is exacerbated by having to juggle multiple decryptors; the standard is one decryptor per machine, so if you have 500 computers and 20 servers, that is 520 unique decryptors. Some ransomware events have used unique decryptors per file share, or even worse, per file (probably due to mistakes during the encryption process.) Can you imagine dealing with a tens of thousand individual keys? That is basically impossible without serious automation and expertise on the part of the incident response firm.

Even if you manage to recover, you still are at risk of the criminals exposing your private data online, as an additional bite at that extortion apple. Why? The past 18 months has seen the threat of exposing your data online become commonplace.

A step everyone needs to take in any cyber incident is to have a professional confirm that the criminals no longer have presence on your information systems before you try and go live again. It’s a common tactic that the criminals will wait until you recover everything (whether you paid the ransom or were able to recover on your own from good backups) and then they hit you again, but this time they nuke your backups first.  

If you do get to the point where you need to make a ransom payment in order to recover your data, make sure that you understand what the policy covers and how the process is supposed to work. In the past, the insurer paid the ransom directly, now some policies are requiring that the policy holder pay the ransom and then the insurance will reimburse the policy holder.

This opens up some questions such as: If the ransom is $500k and I have to pay it, where am I going to come up with $500k? And, since they want payment in bitcoins, how the heck do I buy $500k worth of bitcoins?

Coming up with the money might be on you, but the insurance breach coach and incident response team should be able to provide guidance on the whole payment process and bitcoin subject. Be sure to ask before you ever need to use that policy! Another thing to ask is about ransom negotiations: Will the insurer help with that? On this note, it may even be illegal to pay certain ransomware gangs – see OFAC advisory (PDF Warning). 

CLOSING

What this should help you realize is that you want to take reasonable steps to reduce your risks of becoming a victim in the first place. Solid cybersecurity and a good backup strategy that will allow you to recover your data in a reasonable amount of time is a necessity these days. Not only is this generally a much faster way to recover than leveraging your cyber insurance (which can take weeks or months to fully recover from) you will save yourself a lot of stress. Questions? Let us know…

Read More
I.T., Blog Deidre Frith I.T., Blog Deidre Frith

Cyber Insurance Sample Questions

The cyber insurance questionnaire(s) you fill-out may have some definitive questions that want Yes or No answer. Not all applications will have the same questions as each insurer and even many insurance brokers have their own questionnaires that they use as part of the application process.

EXAMPLES OF QUESTIONS ON A CYBER INSURANCE APPLICATION

By Todd Swartzman, RealTime CISO

Finance-Guru-Cyber-Insurance.png.jpeg

The questionnaire(s) you fill-out may have some definitive questions that want Yes or No answer. Not all applications will have the same questions as each insurer and even many insurance brokers have their own questionnaires that they use as part of the application process. 

You can ask the broker to help you better understand what these questions are really asking, and you can even add an addendum to better explain the answer to any questions that aren’t really a Yes or No given the question.  

That policy questionnaire is an excellent (free) way to measure how your business is positioned as far as your basic cybersecurity, your controls, policies, your compliance status, etc. If you find yourself answering “No” to many of the questions, this is your opportunity to improve your security to better protect your business, and maybe help you get better cyber insurance premiums. 

The questions being asked are proven steps businesses should already be taking to reduce their risks of a breach or ransomware event. 

Here I’ve listed some sample questions that insurers may use to help them qualify your business (aka, how risky are YOU to the insurer) for cyber coverage; having these things in place will  make it less likely you’ll need to use that shiny new cyber insurance policy: 

Email Security 

  1. Do you filter emails for malicious attachments or links? 

  2. Do you strictly enforce SPF on incoming emails? 

  3. Do you train your email users to recognize phishing and other email based threats? 

  4. Do you use Office 365 in your organization 

  5. If yes, do you enforce MultiFactor Authentication for all Office 365 accounts? 

Internal Security 

  1. Do you use Endpoint protection products across your enterprise? There may be choices or a listing of common products to help answer. 

  2. Do you use multi factor authentication? 

  3. For remote access? 

  4. Do you have a process to apply critical security patches rapidly? 

  5. Do you use web content filters to block potentially malicious content? 

  6. Do you use protective DNS services (Open DNS, Quad9, etc.?) 

  7. Do you provide your users with a password manager software? 

  8. Do you have a firewall with active security services such as Intrusion Prevention Services, malware scanning, or similar? 

Backup and Recovery Policies 

  1. Are your backups kept separate from your network (offline) or in a cloud service designed for this purpose? 

  2. Do you use a cloud syncing service (e.g. Dropbox, OneDrive, Sharepoint, Google Drive) for backups? 

  3. Have you tested the successful restoration and recovery of key server configurations and data from backup in the last 6 months? 

Other Ransomware Preventative Measures 

  1. Please describe any additional steps that your org takes to detect and prevent ransomware attacks. 

Once you purchase a policy, you still have some work to do in order to get the most out of the policy and further reduce your business risks. Every reputable underwriter has resources that their policy holders can use to shore up defenses, create policies, and help train staff. Use them, after all, you are paying for it. Many have resources like policy samples, virtual CISO services, Incident Response Planning guides, courses on HIPAA and PCI, awareness training content, just to name a few. 


Read More
I.T., Blog Deidre Frith I.T., Blog Deidre Frith

Cyber Insurance - Application Tips

Your business is a target, whether you care to admit that fact or not.

Having a good cyber insurance policy is a safety net for your business in case of a breach, data loss event, business interruption due to a cyber event, assistance in a ransomware event, etc. Each policy is worded differently, and some policies won’t cover all things, or with the same limits.

Why does my business need cyber insurance?

By Todd Swartzman, RealTime CISO

RealTime IT_Cyber Insurance 1.jpg

Your business is a target, whether you care to admit that fact or not. 

Having a good cyber insurance policy that helps mitigate some of your business risks is a safety net for your business in case of a breach, data loss event, business interruption due to a cyber event, assistance in a ransomware event, etc. Each policy is worded differently, and some policies won’t cover all things, or with the same limits. 

[Contact your insurance broker to get the process started. If your agent doesn’t seem to be very conversant on this subject, a good agent will loop in a cyber expert from the underwriter.]

FILLING OUT THE CYBER INSURANCE APPLICATION

WHAT SHOULD MY MINDSET BE WHEN FILLING OUT THE APPLICATION?

Think liability. Your job isn’t to make your business look good to the broker or underwriter. Be 100% forthright with your answers and be sure to answer accurately.  Ask the broker or underwriter to define their terms. What we commonly understand a term to mean isn’t necessarily what the insurer says that these policy terms mean, so be sure to get clarification. One policy I was working on included a 28-page document explaining the terms of their one-page proposal. Remember, what you think a term means may be quite different than what the insurer says that term means for their policy – go with the insurers version.

WHAT IF I DON’T KNOW THE ANSWER TO SOME QUESTIONS?

If you don’t know the answers to some of the questions, just tell the broker; or if you’ve been asked to answer the questions on behalf of a client, let the client know you don’t know the answer. This is especially important if the question is a legal or compliance type question. Your goal is to answer accurately, and it is critically important that you do so.

Here is why:

cyber-insurance-infographic-final.jpg

Cottage Health Systems got sued by their insurance company for failure to follow “Minimum Required Practices”. This is an example of what can happen if you have to make a claim and you answered inaccurately during your application. Cottage Health said they were doing something preventative relevant to the event, but they actually were not. READ MORE HERE…

TYPES OF QUESTIONS

The questionnaire(s) you fill-out may have some definitive questions that want a Yes or No answer. Not all applications will have the same questions as each insurer and even many insurance brokers have their own questionnaires that they use as part of the application process. Ask the broker to help you better understand what these questions are really asking. You can include an addendum with your responses to better explain any answers where a Yes or No isn’t the best answer.

That policy questionnaire is an excellent way to measure how your business is positioned as far as your cybersecurity, your controls, policies, your compliance status, etc. If you find yourself answering “No” to many of the questions, this is your opportunity to improve your security to better protect your business, and maybe help get better cyber insurance premiums. 

The questions being asked are some basic, proven mitigations that businesses should already be taking to reduce their risks of a cyber event such as a breach or ransomware. Here is a list of some sample questions that not only will help you qualify for insurance; having these things in place will  make it less likely you’ll need to use that shiny new cyber insurance policy.


Read More