By Gregory Hale
When Captain Chesley “Sully” Sullenberger took control of US Airways flight 1549 that suffered a bird strike shutting down both engines, within seconds he knew what to do and how to react because he had simulated emergency procedures time and time again.

Yes, he may have gone an entire career and never had to ever employ the emergency plan or invoke extreme measures, but he was ready just in case, and 155 people aboard that jet walked away from that landing in the Hudson River.

Or take an even closer case that stunned the United States, if not the world, only a few short days ago when Damar Hamlin, a football player for the Buffalo Bills, made a hard tackle that resulted in him going into cardiac arrest.

If not for the medical personnel that rushed on to the field in seconds knowing exactly what to do in this emergency situation, he may not have pulled through. Those athletic trainers, doctors, and technicians train for this type of scenario all the time and, like Sullenberger, they may never have to go to those extreme measures, but they were ready, and they are heroes and Hamlin is alive today.

Schneider Bold

Countless hours of tedious and monotonous training paid off.

Ready for an Attack?
Now, let’s bring this over to the operational technology cybersecurity environment. Maybe this will sound like a broken record, or the ultimate Monday morning quarterback, but when will companies understand and take to heart a ransomware attack is only a few clicks away and they need to be prepared? A company’s livelihood depends on it.

They have to just understand they will end up a victim and prepare for it. Hopefully they will never have to use it, but let’s face it, unlike a plane landing in the Hudson River or a football player in prime shape falling victim to a cardiac arrest in the field of play, they are more likely going to have to react to some kind of attack.

There are plenty of examples, let’s look at Wabtec. In that scenario, ransomware operator, LockBit, said it stole files from U.S. engineering giant after it was able to infiltrate the company.

Wabtec first discovered a ransomware attack in late June after the criminals breached the company’s systems. Back on June 27, workers at Wabtec’s Erie, New York plant said the ransomware had an impact on the ability of employees to log onto the company network and do their jobs. Wabtec is a global provider of equipment, systems, digital solutions, and value-added services for the freight and transit rail sectors.

While the company has not said if they paid the ransom or not, it doesn’t really matter because there are big recovery costs involved in an incident such as this.

Delayed Notice
“Ransomware continues to be a challenge for organizations, with the Wabtec breach being no different,” said Ron Fabela, CTO & Co-Founder of security provider SynSaber. “This attack appears to be a straightforward double-extortion attack with the sensitive files published back in August 2022. What’s intriguing is that although the files were published back in August, Wabtec is just now reporting the data lost. This lag in breach reporting is not uncommon and continues to be a focus for industry and government policy makers.

“Although Wabtec being a freight rail company has some interest, there’s no evidence anything specific to the industrial control systems, plant operations, or other non-HR data was affected by this attack. While industrial processes are not the intended target, widespread IT outages can have a splash damage effect on processes. All organizations, including those within ICS, must continue to be vigilant as successful ransomware attacks trend upwards.”

But put that case aside for a moment, in another ransomware attack, cloud computing provider, Rackspace, completed its forensic investigation after suffering an assault December 2 on its Hosted Exchange service.

“While there has been widespread speculation that the root cause of this incident was the result of the ProxyNotShell exploit, we can now definitively state that is not accurate,” the company said in an advisory. “The forensic investigation determined that the threat actor, known as PLAY, used a previously unknown security exploit to gain initial access to the Rackspace Hosted Exchange email environment. This Zero Day exploit is associated with CVE-2022-41080. Microsoft disclosed CVE-2022-41080 as a privilege escalation vulnerability and did not include notes for being part of a Remote Code Execution chain that was exploitable.”

So, one IT system at Wabtec suffered an attack which hurt the company and a cloud computing provider’s IT system fell one month after a Zero Day exploit became public knowledge.

Understand and Defend
The point is, it doesn’t matter where the attack is coming from, it only matters the defenders understand their systems and clearly see what is happening so they are ready to react and take on whatever the threat actors are throwing at them.

From my perspective there are two words the cybersecurity industry is truly known for, and they are vigilance and resiliency. No matter the marketing words of the day/month/year, those two words are what protecting your environment is all about.

Everyone needs to understand the potential consequences of what an attack can bring. They need to be prepared and ready to go – the company’s livelihood depends on it.

ISSSource

Pin It on Pinterest

Share This