Hello and welcome to this videocast in which we'll look at how businesses can stay safe from cyber threats during the holiday season. I'm Warwick Ashford, a Senior Analyst at KuppingerCole Analysts and I'm joined by Danny Jenkins, CEO and Co-Founder of ThreatLocker. Welcome. Good morning and thank you for inviting me today.
So Danny, the end of the year holiday season is coming up, supposedly the most wonderful time of the year, but we all know it can be the most vulnerable time of the year from a cyber crime point of view, with some reports claiming a 30% to 40% increase. In your experience, why is the holiday season from late November through December a popular period for cyber criminals to carry out attacks? Well really it's about time. The more likely a cyber criminal can cause damage, the more likely they're going to get paid.
So cyber criminals often want to keep as much time on your network, encrypt as many files, extract as much data as possible. You're less likely to be caught on a holiday season where socks are running thin, users aren't paying attention to what's happening on their machine. If one machine's left unlocked, they can get onto that machine, they can use the whole weekend, or long weekend even, to do as much damage as possible. And there's also an increase in online activity transactions as well, I guess that also is a factor.
Yeah absolutely, so people are traveling more, people are at the office more, they're more likely to click on things, there's people online more, they're more likely to get gift cards or be fooled into, oh you've been sent a Christmas gift card, or you've been sent this, and that's another reason they can gain access to those accounts. So now the next logical question would be, how can businesses protect themselves over the holiday period?
But I'd argue that the holiday season should make no difference to a well-designed cyber security strategy, it should work equally well at any given time of the year, would you agree? No absolutely, so if you're doing everything right, the holiday period isn't going to make much difference, and there are a few extra things you can do, advising people to shut down their machines when they go home for the weekend, it might seem small but it means it's less likely to happen.
Of course no one's bulletproof when it comes to security, but having the best technologies in place, and then putting an extra few steps in place, means that if the technology fails, if someone missed something, then it's less likely to be effective. Great thanks, so if we agree that the time of the year should make no difference to the level of cyber security resilience, I think what in your view are the key areas that businesses should focus on to reduce the likelihood of a successful cyber attack?
I think if I was to pick the two areas, I'm going to focus on software and network, and the reason being every major cyber attack comes in one of two ways, one is a piece of software, a piece of malware, whether it's a backdoor vulnerability, or just an executable someone downloaded quick assist, or go to meeting from an attacker, so making sure you block untrusted software, making sure you limit what software can do in your environment, bear in mind every piece of software you run can see all of your data, so ring fencing technologies are really really cool for saying, okay this program can't see my files if it happens to be backdoor, whether it's a holiday season or not, it won't be able to access my data.
The other thing is making sure you don't have open ports, shut down VPNs where you can, if you do have to have VPNs, make sure they're patched, make sure they've got limited access once they gain access to your environment, the amount of times I'll see someone get into a VPN then do a full network scan, gain access to servers, do remote encryption, again if you have a VPN it's probably to access one application, only allow it access to one application, so limiting open ports on your firewall, making sure your file, all those open ports are watched like a hawk, do regular port scans and make sure you're blocking untrusted software.
And what about backup and recovery processes, I mean I know those are kind of considered to be old hat, but I mean we still we still need them. Backup and recovery isn't just about security, it's about things fail and when you're away for a long weekend too, if the power goes out no one's going to know the power's out and the UPS is probably just going to die and the server's going to shut down, you're more likely to have failure.
Of course cyber crime is really about creating ransoms, making sure you don't get your data, if you can recover and restore your data having that in place is really really important as well, so make sure you've got a good backup, test that backup, but more importantly test the restore.
What I'll always say is once a month go and do restores from your backup, quite often attackers will come in and change your backups to back up two terabytes of empty files, so you get your nice green backup report every month or every morning, but the reality is it wasn't successful because it backed up fake data. So testing your backups, making sure you've got good backup and recovery is really important as well.
And how about automated response, something that kind of you know is going to just kick in even if somebody's asleep at the wheel or whatever at that time of the year, to kind of maybe complement the internal security team? Yeah actually and one of the things that has changed over the last two years is the speed in which attackers are I suppose causing impact. So an impact could be that they're encrypting your files or it could be that they're stealing your data.
If we go back three years ago, attackers would come into your network or even a year ago and they'd look around, they'd do a scan, they'd do an IP scan, they'd enumerate privileges, maybe they'll create some admin accounts in the you'll see an admin account created, you'll respond, you'll see a privilege emulation, the SOC can respond. I saw an attack probably two months ago now, seven minutes from the moment they gained access to when they're exfilling data. So one of the things that we'll often suggest is creating automated response to tighten up security.
So one of the policies I always recommend is in the event an indicator of compromise is triggered, you can't shut down a server automatically because the reality is 90% of indicators of compromise are false alerts, but maybe block admin tools. So if you go into my computer here and I went into PowerShell and try to enumerate privileges, I'll see PowerShell immediately close, I'll see command prompt close, I'll see registry editor close, I won't be able to open any of those apps within milliseconds that will happen.
Now what this does is this means the SOC team now gets more time because you've just basically as an attacker had your hands tied behind your back. Quite often attackers will quit at that point. So if you can do that, if you're talking about servers automating, shutting down browsers as well, so no one can exfill data, shutting down of tools like Microsoft terminal services client. At the end of the day, if it's a false positive, as long as users aren't upset, it's not going to impact the business.
But if it's an IT guy doing something, creating an admin account, enumerating privileges, they probably should have created a ticket and put a maintenance period in anyway. And if they didn't, hard luck, they're going to get delayed by 10 minutes. Sounds good. So any organization that's aiming to reduce its attack surface to an absolute minimum should consider getting an outside cyber health check to identify security gaps, the internal security teams may have missed. Would you agree? Absolutely.
People often ask me, should I have multiple EDRs or should I buy this level of detection if I've got this? And I would say, look, the answer is always going to be, if you can get more security, you're better off. But it isn't really a case of should I have multiple EDRs or an antivirus and an EDR or a detection response on the network and the client. The answer, the question should be, would I be better off spending my money elsewhere?
And quite often, I would always say, once you've put in basic controls, once you think you're secure, once you've got untrusted softwares blocked, once you've got an EDR in place, once you've automated your tools, have it tested. One of the things we'll actually do, this is an automated test. I think human tests are great as well, but we'll actually give you a report every day. It's called a defense against configuration report, where it will show you 170 checks on endpoint every day. Do you have these security controls in place? And we can do that even if you're not a customer.
We can just do a free trial and show you what that looks like. So in the UK, for example, there is the National Cyber Security Center, NCSC, that offers a kind of checkable cybersecurity service, which is a free government's tool for UK organizations to run simple external checks on common vulnerabilities. But in terms of sourcing other health checks, what would your guidelines there be? I would assume that there are some things that they should avoid.
Well, so I think being careful about, don't just download health checks on your machine. Make sure you trust the vendor. Make sure they're reputable. So I would always say you want an external pen test. We have multiple external pen tests in ThreatLocker. We have them organized by our CIO, but we also have them organized by the business side, the financial side, to make sure that the CIO isn't even necessarily testing. So having advanced paid pen tests is always a good idea. Unfortunately, it costs money. It could be $5,000, $10,000.
It's not, or pounds. It's not necessarily cheap. But even free health reports, we'll do free health reports. We'll show you what software. There are good cybersecurity vendors out there and say, this is what you're running. This is what your risks are. And just have a look at them and see if you can get rid of them. And quite often, 90% of the risks found on a health report by you configuring your system properly, they can go away with no cost to you. And they're just going to harden your environment and not even bother the user because the user aren't using most of those configurations anyway.
Great. Thanks, Danny. So in summary, the ways to reduce the likelihood of becoming a victim of a cyber attack at any time is to close any known gaps to reduce the attack surface of the organization.
One, by controlling what applications are allowed to run in your business IT environment and what they're to do. Two, by controlling who has access to what under what specific circumstances and for defined periods of time.
Three, by ensuring that you have tried and tested backup and recovery processes. And four, by ensuring that you have 24 by seven monitoring detection and response capability, supplementing internal capabilities with external services when necessary. Any closing thoughts from you, Danny?
No, I think that's really it. Making sure you put those basic controls in place, closing network ports, making sure you close internal ports as well, because untrusted devices on your own network can be a big problem. And having that 24 hour a day, it's really important because you want a service that doesn't go home on Christmas Eve and say, unfortunately, we have a whole bunch of people here in ThreatLocker that work 24 hours a day.
Well, they don't, but the team does. And they get to work on the Christmas shift.
It sucks, but for them, but it means that someone's watching your systems when you're at home, enjoying your holidays. Thanks, Danny, for joining us and sharing your insights into the key ways businesses can reduce their attack surface throughout the year and not just during the holidays. And thanks to you for watching. We hope that you found it useful. Thank you.