Episode 139 ·
Christopher Gerg - CISO at Gilware
Today we are talking to Christopher, the Chief Information Security Officer at Gillware. And we discuss the rise of ransomware. Taking a proactive approach to protecting your assets and why it’s critical to educate your team to avoid getting attacked.
All of this, right here, right now, on the Modern CTO Podcast!
Christopher Gerg is the CISO and Vice President of Cyber Risk Management at Gillware. He is a technical lead with over 15 years of information security experience. Christopher has worked as a Systems Administrator, Network Engineer, Penetration Tester, Information Security Architect, Vice President of Information Technology, Director and Chief Information Security Officer. He has experience in the challenges of information security in cloud-based hosting, DevOps, managed security services, e-commerce, healthcare, financial, and payment card industries.
He has worked in mature information security teams and has built information security programs from scratch and leading them into maturity in wide variety of compliance regimes. While an expert in the theoretical aspects of information security best practice, he is also experienced in the practical aspects of building secure technical environments – and working with the boardroom to promote executive understanding and support. He also authored the O’Reilly and Associates book “Managing Network Security with Snort and IDS Tools.”
ABOUT Gilware:
Gillware provides incident response, digital forensics, cybersecurity and data recovery services to legal and insurance professionals, corporate IT, in-house security teams, law enforcement, and everything in between. Founded in 2003, Gillware supports a global network of partners and clients from its offices in Madison and Milwaukee, Wis., and Columbus, Ohio. Gillware’s digital forensics operation is led by Cindy Murphy, a leading forensics investigator and educator with over two decades of professional experience in the field.
Transcript
(Joel Beasley at 00:00:00) Hello, my friends. Today we are talking to Christopher, the Chief Information Security Officer at Gilware, and we discuss the rise of ransomware, taking a proactive approach to protecting your assets, and why it's critical to educate your team to avoid getting attacked. All of this right here, right now on the Modern CTO podcast. Here we go. This is the Modern CTO podcast.
(Joel Beasley at 00:00:35) Buddy.
(Christopher at 00:00:36) Hey, how are you?
(Joel Beasley at 00:00:37) Oh man, you are in a workshop. I love it. Yeah, feels like home.
(Christopher at 00:00:43) Yeah, it's one of our forensic labs. It looks a little like a storeroom.
(Joel Beasley at 00:00:48) Forensic labs? What are you guys doing over there?
(Christopher at 00:00:51) Well, we do a lot of incident response work. So Gilware started as a data recovery company. Your hard drive failed or your machine died, and we could pull the platters out of the machine and get the data directly off the platters. We've got machines here that can scrape the epoxy off of a memory chip, and we can micro-solder directly into the chip to pull stuff off. So that's kind of where our roots are, and out of that came incident response work.
(Christopher at 00:01:24) So either digital forensic stuff, cybercrime stuff, or more often these days, we're on several insurance panels for incident response. So if you get ransomware or you suffer a wire transfer fraud breach or something like that, you'll call your insurance company who will then call privacy counsel who will then call us. And we've got a team that will figure out what happened, how it happened, what kind of data was exfiltrated, if any, and then help you recover. And very often, the last conversation or the last thing we say with those customers is, clearly you've got some issues. How can we help you prevent this from ever happening again?
(Christopher at 00:02:05) And so that's where me and my team steps in, and we do proactive information security and risk management work.
(Joel Beasley at 00:02:12) That's actually really cool. What's going on in the crime world today? What's popular right now?
(Christopher at 00:02:19) It's actually insanity, and we could talk for hours about it, and I have. But ransomware is rampant right now. We got a call just last week from one of the big insurance carriers that said we've called seven other incident response firms, and they're all at capacity and not taking more cases. And 99% of the cases that we're seeing come in now are ransomware. It's an absolute epidemic.
(Christopher at 00:02:49) It is insanity. We've added four people in the last month, and we're probably going to add probably another 10 before the end of the year.
(Joel Beasley at 00:02:56) So give me a quick breakdown of how ransomware infects a computer.
(Christopher at 00:03:02) Well, it's not anything particularly new. There are some interesting wrinkles where, once you've got ransomware—and just to level set, ransomware is essentially malicious software that will encrypt your hard drive or at least important data stores and pop up a screen that says, "Hey, you've been infected with ransomware. If you send this much Bitcoin to this wallet using this code, we will send you the decryption key so you can get your data back." And it used to be that these were, you know, a couple hundred dollars.
(Christopher at 00:03:41) But now insurance companies sometimes are forced to pay the ransom because these ransomware attackers are encrypting your backups, and that's one of the first things they encrypt so that it makes it more difficult for you to recover your system. So you're facing months of downtime while you rebuild all of your servers and workstations, or you pay the ransom and you're back up and running in a day or two. But that decrypts your data, but it doesn't get them out of your system. So our incident response work very often is not just helping you get your systems back up and running, but also making sure that they're not persisting in your environment. Because when they attack, they come in through the normal ways.
(Christopher at 00:04:29) Right now we're seeing a lot of people coming in through remote desktop, Windows RDP protocol. If you had that exposed to the public internet, stop it right now, because there are a lot of known vulnerabilities and known exploits for that protocol. Another one that's been getting hit recently pretty often is MySQL. So just a basic, kind of middle-of-the-road database server. No offense to the MySQL people, but, you know, it's ubiquitous, but it's not hugely powerful.
(Christopher at 00:05:02) And it's added by default to a lot of web servers and that sort of thing. And if you have that exposed to the public internet and it's not entirely up to date with patches, if you don't already have ransomware, you're going to have it soon. And another one that we've seen is Exim, E-X-I-M, which is a mail server that gets installed by Linux by default very often and by a lot of hosting providers. And there's a very dangerous vulnerability that allows you to remotely exploit a machine running that service. So it's just like the old days. If you have something unpatched, you might get attacked.
(Christopher at 00:05:37) And they get in that way, or we're seeing very often—and maybe as much, if not a little more—it comes in through email, whether it's a phishing email or it's just spam email that has an attachment or a link to a website that has a tool running on it that will let them put a shim on your machine, a very thin, very difficult to detect piece of malware that usually runs whatever locally installed scripting tool you have. Very often it's PowerShell because Windows machines have PowerShell installed by default. And so it's very small. It won't trigger a signature-based antivirus because it is so small and actually built on the fly so that it doesn't look like it did the last time you generated it. It does this all automatically to make it—it's called polymorphism. It makes it polymorphic and very difficult to notice.
(Christopher at 00:06:32) And once it's on, then it downloads something that's actually useful, something that's going to call back and allow an attacker to get access to that machine. So one of the ones that is commonly used is called Emotet. The names of these are always pretty interesting.
(Christopher at 00:06:55) And then once Emotet has a foothold on your machine, it will then download a tool called TrickBot very often. And TrickBot is kind of a Swiss Army knife that if you double-click it in your email, it's running as your context. And if you're a local administrator on your workstation, then TrickBot runs as local administrator. And once it's there, they start looking for things on the network. Other hosts to infect, go look for your finance department so that they can do wire transfer fraud and trick you into transferring money to places, or once they find your backups, they find important data stores, they'll encrypt them with ransomware. That's the most common way that we're seeing people infected with ransomware.
(Joel Beasley at 00:07:37) That is horrible.
(Christopher at 00:07:40) Yeah, it is horrible. And one of the interesting things is when they're asking for these payments, you know, we negotiate with the ransomer. Sometimes we're forced to. If the insurance company says, "Yeah, we're facing two months of downtime, just try to pay the ransom." It's not our first method of attacking these incidents, but sometimes it's what you're left with if there's no other option.
(Christopher at 00:07:51) And when you're talking with these guys, you'll say, "Hey, we'll pay you X amount of dollars," and they'll say, "Well, I have to take this to my supervisor and see." And so they've got help desks. There's websites that rank the different ransomware variants on how reliable they are in getting your decryption keys and how good their customer support is.
(Joel Beasley at 00:08:24) Their customer support?
(Christopher at 00:08:26) Yeah.
(Joel Beasley at 00:08:26) Their customer support. It's like they're a business.
(Christopher at 00:08:28) They've got a website. They've got email addresses, and it all goes through VPN. So they're all using the Tor network or other VPN solutions so that it's on the dark web. So you can't just go to www.ransomware.com and find them. You have to—they'll give you an IP address to connect to, usually through an email, and they've got email set up through secure email mechanisms.
(Christopher at 00:08:55) So they're using tools that were created for good reasons, like folks in oppressive regimes who want to have access to information will use the Tor VPN or they'll use these secure email or messaging mechanisms. And I would fight that we need to have those mechanisms because they're really, really important from a privacy and liberty and freedom perspective. But these attackers and these criminals are using these to hide their traces, and actually they hide them very, very well. And then when they're using cryptocurrencies for payments, again, I think cryptocurrency should be there. There's good reasons to have cryptocurrency, but it's untraceable.
(Christopher at 00:09:37) So these tools that were built for good purposes are being used for bad, which again is another really interesting wrinkle.
(Joel Beasley at 00:09:46) What is the answer?
(Christopher at 00:09:49) The answer is, do the things you ought to be doing. It used to be that the HIPAA stick was a big one that would make people do information security-related things, or GDPR or CCPA, the California privacy law. I haven't seen a lot of—or they talk about reputation, right? If you get hacked, you're going to suffer reputation and people won't want to do business with you.
(Christopher at 00:10:15) Well, last I checked, Target's still in business, and people are still using Equifax, right? I mean, they're not out of business because of that. So that reputation argument is a little thin. So the answer is do the things you ought to have been doing.
(Christopher at 00:10:31) Have a good information security hygiene and best practices, and some of this is fairly low-hanging fruit. Don't expose services to the public internet that you don't need to expose. If you do expose something to the public internet, have it patched and updated as much as possible and have it well-configured. That's pretty easy. But even organizations with good information security programs are still going to have a problem if some user double-clicks an attachment in their email.
(Christopher at 00:11:15) So end user awareness is becoming more and more important, and I think that there's some really good tools out there to help users with being aware of what the threats are. But ultimately, if something comes in through email, don't double-click on it. And we've even had some clients who have notified their business partners that they will no longer accept emails with attachments. If you send an attachment, it's just going to go into the garbage bin. And they're using secure file transfer mechanisms like ShareFile or there's a bunch of others, so that they can securely authenticate the sender and scan the attachment pretty well before it comes in. And there's some good email things you can do too to protect yourself on the server side.
(Joel Beasley at 00:11:57) So what do you say to people that have smaller companies, like 20, 25 people, and they're just like, "This isn't a priority"?
(Christopher at 00:12:05) It's absolutely a priority because—I've done a lot of intrusion detection work where you're seeing the raw data coming in from the internet, and there's just automated scripts strobing across the internet looking for vulnerable hosts. So if you're Bill and Ted's Excellent Stereo Emporium or you're Sony Entertainment, you have an equal chance of being attacked. And if you have an unpatched Apache server or an unpatched email server or an unpatched service exposed to the public internet, you stand a reasonable chance of—well, you will be attacked.
(Christopher at 00:12:53) And if it's unpatched, you stand a reasonable chance that it's going to be successful. It doesn't matter your size. And in fact, the ransomware has no idea who they're actually infecting very often, and the ransom's going to be the same. It's going to be—these days we've seen ransoms go over $1 million if they do have an idea of who it is they've infected.
(Joel Beasley at 00:13:09) So is our government—I mean, you're in the United States, right? Yeah. So is our government—are you aware—are we doing anything? Is there anything we can do to protect the people? Because I know I've seen the cords that actually run around the world, like the fiber.
(Christopher at 00:13:27) Right, right.
(Joel Beasley at 00:13:27) Is there any—and I kind of imagine that as like an interstate, right? And it's like, okay, so they're on online lines that are in our country. Is there anything that can be done from that level or no?
(Christopher at 00:13:40) Well, they want to enable free and open communication. And part of the problem is if there's a—they're taking active steps that if they identify that this host is where this is all sourcing from, they'll block it. But like I said, they're using things like Tor and other VPNs so that they can pop up a point of presence anywhere in the world. So like, I'm going to block all traffic from—and I don't want to say bad things about a particular country, but let's just say—
(Joel Beasley at 00:14:11) Don't do it. Don't do it.
(Christopher at 00:14:12) Right. Say Country X. We want to block Country X because screw them. But we want to block Country X because very often bad stuff happens. Yeah, I'm not going to fall into the China or Russia hole. I just won't do it. I was just at a big government conference, and it was all about, you know, Vladimir Putin and China, and it just made me roll my eyes over and over and over.
(Christopher at 00:14:24) You can't do that because the attackers, by their nature, are just going to pop up. They're going to look like they're coming from Hoboken or something like that, and you should block Hoboken, by the way.
(Christopher at 00:14:49) That's a joke. So that's difficult. Not only are they able to pop up wherever they want, most traffic these days is encrypted. And so if I'm listening on the network looking for signs of bad things, I can't see it because it's being encrypted across the network. Almost all web traffic these days is encrypted with HTTPS, hopefully TLS 1.2 or newer.
(Christopher at 00:15:14) And you just can't see it. I did a lot of work with intrusion detection stuff. I wrote the book on intrusion detection—actually, I did write a book on intrusion detection. It's "Managing Network Security with Snort and IDS Tools." It's an O'Reilly book.
(Christopher at 00:15:29) And in those days, a thousand years ago, you could watch all the traffic on the network and look for signs of attack, kind of like a signature-based antivirus. "Hey, this looks like a bad thing. Block it." But these days everything's encrypted, and so network intrusion detection has become a lot less valuable. And it's underscored that we need to distribute your protections to more places than just the border of your network. And so for the same reason, the government has a tough time blocking it.
(Joel Beasley at 00:15:57) I want to take it in a different direction. I've got another question that just popped in my head. So I've seen posts about, like, at conferences, hackers being able to go in and turn on the cameras of the computers, saying that there are, like, maybe backdoors governments have put into systems, things like that. Is that true? Is there anything about that? Like, is everyone putting stuff over their camera for no reason?
(Joel Beasley at 00:16:24) It's a matter of trust. But I'm never surprised. But if you've got a vulnerable system, you have a chance of it being exploited. And I think I worry less about that than I do the other things simply because—so I was a pen tester for almost four years, and we didn't have a job where we didn't successfully get into an organization. I'm not patting myself on the back. It's a lot of times people don't patch things.
(Christopher at 00:17:00) And even companies with good information security programs, things fall through the cracks, and that's what we took advantage of. But we kept asking ourselves, why is one company a target and why is another one not? And it boils down to why is someone going to attack you. And there might be political reasons. There might be they just don't like your company.
(Christopher at 00:17:19) But more often than not, they want money. And so if you're in the payment business and you're collecting credit cards or you accept payments on your website or you're a payment processor or you're even a credit card company, you've got things people want, because if they could steal those credit card numbers, they can maybe do something with it. So that's an obvious thing. But now with ransomware, they can monetize almost any attack. They're more likely to try to infect you with ransomware than they are to try to break into your security camera.
(Christopher at 00:17:51) But that said, the recent stuff with Nest, the Nest cams, cooperating with local police departments where they're granting police departments access to your cameras so that they can look at your street, or if there's an accident on the street, they can get the Nest camera footage. That's crazy to me, and it's something that—I admit, I'm more sensitive to privacy things than the average bear just because of the work I do—but I don't like that. It doesn't feel good to me at all.
(Joel Beasley at 00:18:23) Isn't the Nest like your thermostat?
(Christopher at 00:18:26) Well, they also have these cameras. Oh, Ring. Ring.
(Joel Beasley at 00:18:28) Ring. Ring. Okay. Ring.
(Christopher at 00:18:29) Yeah. The Ring.
(Joel Beasley at 00:18:30) I was like, I don't want them to see how cold it is in my house.
(Christopher at 00:18:33) Right. Yeah. Hey, that's private. But that, I mean, that to me is an invasion of privacy even if it's only exposing the camera, your doorbell camera.
(Christopher at 00:18:43) You know?
(Joel Beasley at 00:18:43) What's going on on my doorbell camera? Like, these giant cat things. Like, I don't know if it's panthers or these little mountain lion guys, but these big cats.
(Christopher at 00:18:55) Are you really getting cougars?
(Joel Beasley at 00:18:56) Cougars. There you go. Man, my whole—I've got this—we got this app. My wife and I, it's called Neighbors, so people can post their clips to the—
(Christopher at 00:19:07) Where do you live?
(Joel Beasley at 00:19:08) Florida.
(Christopher at 00:19:09) Okay. Yeah. Yeah.
(Joel Beasley at 00:19:10) Yeah. And I swore I—I do early runs, like 5 a.m. runs, and I swore one day I saw one. I was like, I think there's one in the neighborhood. So I asked my wife to look it up, and she did. There are a lot of them.
(Christopher at 00:19:22) Yeah. Yeah.
(Joel Beasley at 00:19:24) And they're not rare.
(Christopher at 00:19:25) I went for a hike in Colorado at altitude, so I was stopping all the time because I couldn't breathe. But I was going along and I'm on a dirt trail, and I went about 10 miles or so and then turned around and was coming back. And as I was coming back, I was the only person on the trail. I saw mountain lion footprints that were following me at one point.
(Joel Beasley at 00:19:46) I just got back from Colorado last week, and we did a Jeep tour. You know, they took us up in the Jeep, the crazy four-by-four up in this mountain. And he said the only animal that he hasn't seen out there in 20 years is a mountain lion, and he's very happy about that because you don't want to see the apex predator.
(Christopher at 00:20:01) Well, you usually don't see them. They usually attack you from behind.
(Joel Beasley at 00:20:04) That's why you don't want to see one.
(Christopher at 00:20:06) Yeah. Yeah. Actually, the bears freak me out, though, too. The brown bears freak me out.
(Joel Beasley at 00:20:11) Have you ever seen one eating out of a stream or anything?
(Christopher at 00:20:15) Yeah, I've seen grizzlies out in the mountains. That's why I don't—we were going to go for this backpacking trip, and I went a couple times on expeditions just to kind of scout out areas. And every time I saw a bear, I was like, yeah, no. I'll rent a cabin.
(Joel Beasley at 00:20:31) Do you ever get inspired by nature for your technical problems that you're trying to solve?
(Christopher at 00:20:35) I usually escape my technical problems in nature. I turn everything off and then just sit in a hammock and read a book.
(Joel Beasley at 00:20:42) That's cool.
(Christopher at 00:20:42) Yeah. Just because I'm hip-deep in the internet all the time.
(Joel Beasley at 00:20:45) Right? It's like you have to have some sort of disconnect or some break. So what type of book? It's not a technical book, hopefully.
(Christopher at 00:20:53) Sometimes, but usually it's some kind of science fiction.
(Joel Beasley at 00:20:55) Oh, really?
(Christopher at 00:20:56) Big science fiction and fantasy nerd. Yeah.
(Joel Beasley at 00:20:58) What? So you like Elon Musk?
(Christopher at 00:21:01) Sure.
(Joel Beasley at 00:21:02) No? You don't—that was a hesitation, man.
(Christopher at 00:21:04) Yeah. No. I like him. I think he's become P.T. Barnum a little bit.
(Joel Beasley at 00:21:08) Oh.
(Christopher at 00:21:08) I love SpaceX. I love Tesla. I like the things his companies are doing. I like the direction he's taking, the fact that all of the battery technology that they've developed, they've open-sourced so that other companies can do what they—I mean, he's doing it the right way. He absolutely has, but his image and his Twitter account has gotten in his way too often.
(Joel Beasley at 00:21:32) Isn't his Twitter—I actually follow his Twitter, and every time I'm like, oh. Yeah. I don't know. I'm on board with most of this stuff, but then he just throws something on like a Friday night, and I'm like, ouch, dude. That was not okay.
(Christopher at 00:21:44) Yeah. He's a little berserk.
(Joel Beasley at 00:21:46) But it's also cool that he is using the fame or his wealth to make the world better. Yeah. Yeah. Yeah.
(Christopher at 00:21:55) Right? I haven't missed the SpaceX launch yet. I wish I could go see one in person, but I love it. I just love it.
(Joel Beasley at 00:22:03) And then if you could imagine, like, if you could actually have seen P.T. Barnum's Twitter, like, it'd be equally as bad.
(Christopher at 00:22:11) Probably. Probably worse because he didn't care whose toes he stepped on.
(Joel Beasley at 00:22:16) So we talked a little bit at the beginning about some different types of attacks, what people should be looking out for, some low-hanging fruit stuff. So advice—if you could have CTOs walk away with two things, what would they be?
(Christopher at 00:22:32) Well, it used to be a real struggle for information security people to kind of make a case for return on investment for information security spending. What we've found in our work is that very often, you've got the licenses you need or the tools you need, but you're maybe not using them in a way that they work well together. Or there's some fundamental things that you could be doing that are not only going to help your information security, but are also going to make your IT department more efficient. And a lot of organizations see their IT department as a cost center. I hope that perception's changing because we're not just talking about email and your website anymore.
(Christopher at 00:23:18) If nothing's been made more apparent to me than this, it's that if all of your computers are not available, if everything was encrypted with ransomware, your company is not going to work anymore. A good example is one that came up just yesterday where this group of hospitals, I think in Alabama, suffered ransomware, and they weren't taking any patients except for the most critical. They were unable to take patients except for the most critical cases because their computers were not available. It's not just a convenience anymore. So I think one of the best examples is asset management.
(Christopher at 00:23:55) If you've got a single pane of glass that'll show me all of my workstations, all of my servers, all of my network devices, the hardware inventory, the current software they're running, their patch level, that's going to go a long way towards you having a secure environment because you're going to know what's up to date and what's not. You're going to know when a new device gets plugged into your network and if you trust it or not or if you want to segregate it. From a—if I'm a CISO at your organization, I'm going to be very happy, and I'm going to probably sleep better at night. But your IT department is also going to be a lot more efficient because they're going to know what percentage of my machines are going to come due for renewal this year. If you call the help desk, the help desk could call up and say, oh, I see you're running X, Y, Z laptop running X, Y, Z version of Windows. Looks like you're behind in patches, or let me log in remotely and help you. Your IT department's going to be way more efficient, but you're also going to be a lot more secure. So sometimes information security will make your entire company more efficient and work better because if everything's up to date with patches, it's probably also going to be a little more reliable.
(Joel Beasley at 00:25:03) What type of software or tool will give you that single pane of glass that you mentioned?
(Christopher at 00:25:08) One of the really good ones out there is actually intended to be used for managed service providers. So there's companies that will be your outsourced IT department, essentially. It's a tool called Atera, A-T-E-R-A. It does a really, really good job. It was a little rough a few years ago, but they iterate quickly.
(Christopher at 00:25:28) They use some pretty agile software development methodologies that allow them to be responsive to what the end users are asking for. But because it's intended to be used for managed service providers for small and medium-sized businesses, it actually can be very, very cost-effective because they charge per agent. So if you've got two IT people and you only need to pay for two licenses, it's going to be hundreds of dollars a year for you to have that single pane of glass for all your workstations and servers. And it also does a really good job of distributing patches and updates and inventorying hosts and all that kind of stuff.
(Joel Beasley at 00:26:05) Oh, it can actually help do the updates?
(Christopher at 00:26:09) All of it.
(Joel Beasley at 00:26:10) Oh, A-T-E-R-A.
(Christopher at 00:26:11) Yeah. Yeah.
(Joel Beasley at 00:26:12) We'll put that in the show notes. No, that's a good one. Thank you. Do you guys build that tool? Is that your tool?
(Christopher at 00:26:17) Nope. No. We help—I'm a trusted advisor where I come in and I help, kind of a CISO as a service is what we call it. And I'll come in and help organizations assess where their current information security program maturity is, but also help them either build one from scratch or make it a little better. And so I've vetted a lot of tools, like anti-malware tools, logging and monitoring tools, SIEM, SOAR, USM tools, so that when they get to the point where, wow, we really have a gap here, we need a tool to plug in there, I've done a lot of the legwork for you.
(Joel Beasley at 00:26:55) So at Gilware, earlier you were mentioning that, you know, the insurance companies come to you and that a lot of them are backed up. And then you said something specifically that sometimes you'll pay the ransom. Right? So are they trying to get you to get around it first?
(Christopher at 00:27:14) Absolutely. Okay. We don't want to—and, actually, I've seen a few articles where they're asking the question, are insurance companies authorizing paying these ransoms making ransomware more profitable? The answer to that is yes. But they don't want to do that first.
(Christopher at 00:27:35) They would rather not have to pay those ransoms. They would rather that you had your backups in place. And if there was a second thing I was going to tell CTOs that's important, it's make sure that your backups are not just working, but that the people know how to use the backup software in a restoration environment, like when the red light's spinning and everyone's screaming. Do the people who need to restore your servers know how to do it? And then more importantly, are the backup archives stored in a way that if your internal usernames and passwords, so let's say Active Directory, if that was completely compromised, would they be able to get to those backup archives?
(Christopher at 00:28:14) And you should have things set up so that in the event that none of your machines were available and all of your user accounts were compromised, you've got kind of a—not a back door, but maybe a garage door into where you're keeping your backup archives. Even if it's last month's backups, you're going to be in better shape than if you have to rebuild every server from scratch. So there's companies—and, again, I'm not getting paid for this endorsement—but there's a company called Datto, D-A-T-T-O, that does a really, really good job of not just almost in real-time backing up your servers. They'll have an appliance on your local network, but they also have a cloud archive that gets replicated on a cadence of your choice that's inaccessible from your internal network and requires multi-factor authentication to access. So use multi-factor authentication for all administrator accounts, for all remote access accounts, and to lock down your backup archives because, ultimately, if you've got an incident or you're suffering a disaster, recovering and restoring from those backups is going to be your first step of recovery, and so making sure they're protected.
(Christopher at 00:29:32) It's also the first target for the ransomware, so it needs to be really locked away.
(Joel Beasley at 00:29:37) So eventually, you'll see these insurance companies, like, when you're getting a quote, forcing you to have these systems in place.
(Christopher at 00:29:46) You would hope so. Right now, the cybersecurity insurance business is still a little bit of a land grab where—I've seen between 20 and 40, and probably it's closer to 20% of companies have cybersecurity insurance. So right now, the premiums are remarkably low. If you don't have cybersecurity insurance and you've got a company that if your computers were not available for whatever reason and your business would be in trouble, if you don't have cybersecurity insurance, you're crazy.
(Christopher at 00:30:22) It's very inexpensive, and they do very little actuarial testing to see what your kind of risk level is. I think that's going to change as this ransomware stuff gets more and more crazy because it's going to get worse before it gets better. And we're working with the insurance companies we work with to help them come up with strategies to better assess the risk of the organizations that they're insuring.
(Joel Beasley at 00:30:47) So only 20% of companies have—you know what's interesting is we actually have cybersecurity insurance because my attorney told us when we took our venture capital money, like, hey, you need to get this insurance. And when I shopped around for quotes, I was like, this was unbelievably fast, easy, and they didn't need to understand anything about my company.
(Christopher at 00:31:06) Yeah. They might send you a spreadsheet that says how many records do you have. I mean, the questions they're asking don't even line up with what the risks are. So I think that's going to change and it's going to change soon. We're attending a huge conference called Net Diligence in San Diego in just a few weeks, and we're rolling out a tool that's going to help insurance companies assess that risk.
(Christopher at 00:31:28) Oh, cool. And we're actively building that and putting the finishing touches on it right now.
(Joel Beasley at 00:31:34) That is really unique. You guys are going to dominate with that tool.
(Christopher at 00:31:38) I think so. I mean, it's kind of a self-assessment questionnaire so that organizations can assess their risk for things that are focused specifically right now on ransomware, because it's an epidemic. You know, the second thing that we come across with incidences are wire transfer fraud, but by orders of magnitude, it's ransomware these days.
(Joel Beasley at 00:32:03) And so I send a lot of wires because I'm in business. Right? I've never had to reverse one, but are they reversible?
(Christopher at 00:32:12) Nope. Well, it's difficult. If the money is still sitting in the account where it was delivered, maybe. But when we're talking about wire transfer fraud, it's not necessarily all international money transfers or wire transfers, like literally wire transfers. It's any kind of one-off payment.
(Christopher at 00:32:31) We had a construction company, big contracting company that was buying some big heavy equipment from an offshore provider. And the attacker was in their email and saw that this conversation was going back and forth. And when it finally was, "Okay, yeah, transfer the money to this account," the attacker saw that and had forwarding rules so that they could just jump into the middle of the conversation and say, "Oh my God, I'm so sorry, Bill," because they knew the names involved. "But that's an old account. Don't transfer it there. It's gonna be a huge pain in the butt to get that money out, and it'll delay things. So use this account. It's newer. It's more secure. And, oh, by the way, have a great time on your vacation."
(Christopher at 00:33:10) And so the person saw that email, and there was context for the conversation they were having and trusted it and changed the account number. And so they transferred $1,400,000. And thirty days later, the person said, "Hey, I thought you were gonna be transferring that money." And by then, it was gone. And so they never got the money back because that account was liquidated and shut down, and it was, you know, who knows where overseas. So I think the answer, the short answer to your question is it's really hard. The actually shorter question is probably not.
(Christopher at 00:33:44) Wow. Okay.
(Joel Beasley at 00:33:56) So just because you don't always know that you're infected, like people will be patient and watch your emails and try to attack businesses.
(Christopher at 00:34:05) In most cases, the attacker's been in the environment at least for months, looking for the backups or watching the emails that your finance department are passing back and forth.
(Joel Beasley at 00:34:16) Really? In the cases you see, most of the attackers have been in the systems for months exploring.
(Christopher at 00:34:21) Mm-hmm. Yeah. And one of the first things they do is set up ways for them to persist in your environment so that if you patch the thing they got in with, they still have some tool running on one of your machines or multiple machines that kind of calls home and lets them have a tunnel into your environment.
(Joel Beasley at 00:34:41) So that's what the employees are doing. They're like hanging out, watching me check my bank account, seeing how much of a target I am, watching me do emails and transactions, and just waiting?
(Christopher at 00:34:51) Yep. So that's what they're doing. That's like the office they go into. There's people like waiting up. It's a business.
(Joel Beasley at 00:34:54) Yeah.
(Christopher at 00:35:00) And they pay those people $10 an hour or whatever. And because I mean, if the payoff is, I'm gonna put in, you know, forty hours of work to get at least a $50,000 payoff, that pays off pretty quickly. You know, you start 50,000 here, 50,000 there, pretty soon you're talking real money.
(Joel Beasley at 00:35:21) Do you think these people know what they're doing, or do you think they're like, do you think they tell them that this is like a hypothetical situation and you're being trained for something?
(Christopher at 00:35:30) I think they know.
(Joel Beasley at 00:35:31) You think they know?
(Christopher at 00:35:32) Sure.
(Joel Beasley at 00:35:33) Have you ever talked to any of them? Like or watched an interview of like—
(Christopher at 00:35:37) We've had email conversations back and forth. We've even had like Skype conferences like this one where we'll have a Skype call across to a dark web IP address. And usually it's just voice, but they'll be speaking with an accent, and you hear other people talking behind them. They're sitting in a call center with multiple people just doing this. And if the alternative, I mean, you think about some of these countries where these people are very well educated, but there's not a lot of opportunities for them, and maybe there's reasons they can't travel overseas or whatever. Sometimes this is a really good alternative for them. If you're making 10 to $20 an hour in a developing country, that's a decent amount of money.
(Joel Beasley at 00:36:20) Especially if they're training you in recruiting.
(Christopher at 00:36:22) Right. Right?
(Joel Beasley at 00:36:23) So you don't even, you just have to have the desire to make some money, and you just go and you do it, and then you could always sell the story of like stealing the apple because you have a family to feed.
(Christopher at 00:36:35) Right. Right. Right. Absolutely.
(Joel Beasley at 00:36:37) Wow. That gives a lot of interesting thoughts.
(Christopher at 00:36:40) It's an absolute industry. Like what usually, when I have a conversation with people about, "Yeah, hey, what do you do for a living?" It usually is that's the thing that raises their eyebrows is that this is a full industry. It's not gonna go away, I think, anytime soon, because they're still making money doing it, and people still don't have information security best practices in place.
(Christopher at 00:37:05) How big is it? Well, so one of the big ransomware variants is called GandCrab, G-A-N-D-C-R-A-B, and the last version of it was version 5.3. And they posted some like hacker forums every once in a while, and they said, "Well, we're gonna retire. We've made $2 billion in ransoms. We have about 200," and I think it was 200, I may be wrong, but it was like hundreds of millions of dollars like in Bitcoin just sitting there. "And so we're getting out of the business. We're gonna retire."
(Christopher at 00:37:36) And so we're like, "Wow. They're gonna retire." And then about a week or two ago, they said, "Yeah. No. We're gonna get back in the business." And what they probably did was just sold their business to somebody else. And so GandCrab is gonna, there's probably gonna be a version 5.4, and it's just gonna be other people getting money. And those people who retired are probably gonna get a cut, you know, because they're selling the stuff. And you can go on the dark web and buy packages to start your own flavor of that.
(Joel Beasley at 00:38:08) That's my next question. I just actually wrote that down as you're talking. Can I buy a franchise?
(Christopher at 00:38:13) Yep. Yep. You absolutely can. Yeah. For like, I've seen it for $5,000. For $5,000, you can buy everything you need to write your own variant of ransomware, and they'll give you like little online training classes on how to use the software.
(Joel Beasley at 00:38:28) Pretty soon, when you scroll on through Facebook, I can see like the Tai Lopez of selling security fix.
(Christopher at 00:38:35) That's crazy. Yeah. I should start using my powers for evil, not for good.
(Joel Beasley at 00:38:39) No. Well, no. Unless if we're on the same, unless if you wanna do a startup, I'm in.
(Christopher at 00:38:42) I'm in.
(Joel Beasley at 00:38:45) No. This is great, though. This is unbelievable. So wow. Datto, D-A-T-T-O, real-time backups. That's gonna help you out. Atera, am I saying that right? Managing your devices. So you manage your devices, you got your backups, you have some cybersecurity insurance, you stay away from GandCrab.
(Christopher at 00:39:05) Well and so I think if there's gonna be another thing you're gonna list, like currently, you run, you know, everyone I think everyone's running an antivirus. They're at least running like the Windows Defender. Right? It comes built in. But that, you, these days, I think you need more. You need more than just that traditional signature-based antivirus. You need like a lot of companies call it advanced threat protection. So in the Sophos world, there's an Intercept X with EDR is what they call it. It's such a, just rolls right off the tongue. But it's an add-on that watches all the system calls on the machine. It watches file system calls, and so it looks for signs of trouble. And when it generates an alert, it'll say, "Hey. You downloaded this file through email. You put it on your desktop, and then you ran it, and it tried to do these naughty things," and will block it. So it does more than just that signature-based stuff because the attackers have gotten really, really good at evading the traditional antivirus. So Carbon Black is another one that's very good, and there are others. Cisco AMP is another advanced threat protection tool that goes above and beyond just that traditional antivirus. So I wouldn't be doing it right if I didn't mention that you should be having that in place as well. So Datto advanced threat protection—
(Joel Beasley at 00:40:33) Nonetheless, if they have these things, do you still get customers that have these things?
(Christopher at 00:40:38) So we haven't had someone who had full-on Carbon Black or Sophos Intercept with EDR running on everything that has, well, I don't know that I can say never, because sometimes, like I said, you know, the attacker will have lurked in the environment for six months, and maybe it was two months ago that you rolled out Sophos Intercept with EDR or Intercept X with EDR. And so they're already there. Or if you've got users that are local administrators and this thing comes in through email and it double-clicks it and it says, "Are you sure you wanna double-click this?" And you say yes. It's gonna run under your context. And if it's particularly clever, it may just look like something that's okay. So all of these things reduce your risk, but they don't necessarily eliminate them. You still have users doing dumb things, and so they need to be educated to not do those dumb things as much as possible. But you also need to have the mechanisms in place to notice that an attack maybe is occurring or has occurred, and have the ability to respond to that. So I'm not gonna say never, but you're reducing risk.
(Christopher at 00:41:49) I always equate information security with health. You know, I go to my doctor, and my doctor says, "You should really run. You should not smoke. You should eat a lot of high-fiber, low-fat foods. You should do these things to reduce the risk of you having a health incident." But if I'm crossing the street and I'm looking right when a dump truck's coming from the left, I'm still gonna have a problem. So there's multifaceted to reducing the risk of you having a problem. Sometimes it's noticing that something's happened, but sometimes it's also making it less convenient for you to be an attack target and have that attacker move on to something else.
(Joel Beasley at 00:42:27) So let's say I'm a CTO, and I'm like, "You know what? This guy, he's absolutely brilliant," talking about you. Right?
(Christopher at 00:42:35) Oh.
(Joel Beasley at 00:42:35) And or let's say I'm pulling a CISO into my company. What are the biggest frustrations that that CISO is going to have? Like, do the developers, software developers, do they push back against the security practices? Like, what frustrates a CISO from just coming in here and putting in Datto and Intercept XDR and all the, putting in these tools in place, what do they face as resistance?
(Christopher at 00:42:59) Well, you've gotta get management buy-in to spend a little money. Sometimes you can replace four tools in the whack-a-mole way with one clever tool. And so like Atera and Datto might replace some multiple tools that you have in place. So assuming we've got management buy-in, where I've run into problems myself, and I was, I've been a chief technology officer at a startup, the thing you're fighting is go go go. Right? You've got you've got agile methodologies or you've got a DevOps shop that is constantly iterating, constantly releasing. Like, it's released when it's done, but they don't wanna slow things down. So it goes back to that awareness thing. You need to have developers that are building security in from the beginning because you're not gonna be able to bolt it on after it's built, because you just don't have time because you're moving on to the next thing, the next feature. So you need to not only have management buy-in that you might need to spend a little money on some tools, but you're not gonna buy a tool and plug it into your network and have your box of security. The developers need to be building secure code. Your IDE has to have some static code analysis tools built into it that are watching for the OWASP Top 10 application security stuff. But your QA team also has to have security checks built into their QA testing, and your release process has to at least have some low-hanging fruit application security checks so that before it goes live, before it's released, you've got some reasonable assurance that you've got information security in place. And will that slow things down? Yep. Yep. It'll slow things down a little bit. But it also is gonna let you sleep well at night and make sure that this thing, whether it's a SaaS solution or something, isn't going to compromise your clients is kind of a big deal.
(Joel Beasley at 00:44:58) Have you seen people, like—
(Christopher at 00:45:01) I don't—
(Joel Beasley at 00:45:01) I don't know how to form this question because it's on the fly. Have you seen people like watching the computer of a developer and injecting software trying to get it into deployment? Have you ever seen that happen?
(Christopher at 00:45:12) No. But I have seen insiders cause trouble. So if the same person who's writing the code is the one who's releasing the code, sometimes that's a problem. If you don't have a peer code review, and they'll catch those sorts of things, that'll be a problem. I've seen developers inject their own code in a payment portal that was just sifting off all the credit cards as people were paying for things.
(Joel Beasley at 00:45:38) What what's the name of that movie? Office Space?
(Christopher at 00:45:41) Yeah. It's a little Office Spacey. And like in the old days, you know, probably what, ten years ago, maybe five years ago, I worked for a company that did a lot of payment card industry stuff. And we saw a case where an organization was sifting off these cards and it eventually, this is gonna sound like a huge number, but it's not when you're talking about these payment processors, had sifted off, I think, 35 million credit card numbers. And at some online vendors, like if you're talking Lands' End or something like that, 35 million credit card numbers is you could probably gather that in a day or two. And so 35 million credit card numbers, all they did was put in a 25-cent service charge, and it just said service charge. Like, it was, you know, XYZ service charge. And people look at their bill and go, "Uh, 25 cents." And so every month, if you're pulling 25 cents off of 30 million credit cards, you're making some pretty good money pretty quickly. I think a lot of the fraud tools in place now would catch that sort of thing. But that's the sort of thing that is monetizing an attack.
(Joel Beasley at 00:46:48) Yeah. And the credit card companies are incentivized to stop that. Right? Because I get my stuff declined often when I don't know. It's usually when I use like the more international services, like a payment or something like that. But then I end up having to call up and deal with it. Yeah.
(Christopher at 00:47:05) Well, I was flying out of O'Hare, and I, I'm for sure not gonna name a name now, but I use one of those park and ride sort of services where they, where you park your car and then they'll give you a shuttle in. I live in Wisconsin, and so I'm a couple hours north of Chicago, and so I fly out of O'Hare pretty often. And I was on the plane and was fortunately on the internet doing some work, and I got a message saying that all these transactions were started and that that company that had collected my credit card to pay to park had someone at that company had stolen my card and was trying to make payments, and it got noticed by the credit card company and blocked while I was still in the air.
(Joel Beasley at 00:47:45) So you said you're over in like Milwaukee area?
(Christopher at 00:47:48) I'm in Madison. It's the capital.
(Joel Beasley at 00:47:50) Yeah. So I was just two weeks ago, I was in Waukesha. I think that's how you say it.
(Joel Beasley at 00:47:54) Yeah, the city. Their IT department that runs the whole city. I went and gave a talk there. It's pretty cool.
(Joel Beasley at 00:48:01) Cool. Yeah. And the guy's name over there was Chris. So shout out to Chris too.
(Christopher at 00:48:06) Good. Yeah.
(Joel Beasley at 00:48:07) Man, my mind is blown right now. This is the most useful security conversation I have ever had.
(Christopher at 00:48:14) I'm glad to hear that.
(Joel Beasley at 00:48:15) Yeah. I'm super glad that we got to hang out and talk today. As we wrap up, I know you mentioned that you have the tool that you're releasing. I think you call it Net Diligence.
(Christopher at 00:48:26) Well, NetDiligence is the conference we're releasing at. It's called—I don't know if we've officially launched it. I think we can talk about it. We can talk about it.
(Joel Beasley at 00:48:34) About it.
(Christopher at 00:48:35) Yeah. Just don't tell anybody. No. And actually, by the time this airs, it'll probably have been officially announced.
(Christopher at 00:48:40) It's called the Ransomware Stress Test. So if you remember when the financial industry and the banking industry, all the subprime mortgages were collapsing, they had a thing called the financial stress test for banks.
(Joel Beasley at 00:48:52) Yep.
(Christopher at 00:48:53) Or for people. And we're calling it the Ransomware Stress Test.
(Joel Beasley at 00:48:55) I love that. That's the software I was doing before I started all of this. Financial stress test software.
(Christopher at 00:49:02) Yeah.
(Joel Beasley at 00:49:02) Yeah. You—it would actually compare it.
(Christopher at 00:49:04) It would
(Joel Beasley at 00:49:04) take your portfolio and say, this is how it would have operated in this past crisis. And it would take all the past crises and show you what your report card grade was, how your portfolio would operate in the various issues.
(Christopher at 00:49:17) Cool. And essentially what it is, is it's I think about 55 self-assessment questions that you can ask that are focused entirely on ransomware, and we'll give you kind of a measure of your risk level. But it's asking all those things we talked about like, are things patched? How are you authenticating people? Tell me about your backups. What's your incident response plan? That kind of stuff.
(Joel Beasley at 00:49:38) Yeah. I just filled one of those out for a new customer. They're like, here, fill out this 70-question thing for our CISO about how you do everything at your company. I was like, okay. It resulted in us getting some physical security, which is pretty cool.
(Christopher at 00:49:50) Well, and it grew out of us working with this manufacturing company that had a single provider for a certain supply they needed to manufacture one of their biggest contracts. And that supplier got ransomware and was still, with delays and bad orders, able to supply them the thing they needed. But it underscored the need for them to do better third-party vendor due diligence. So that questionnaire you're talking about—and so we're envisioning this Ransomware Stress Test being used in that case where if I'm a manufacturer and I've got this list of suppliers, I'm going to make them go take this test and tell me how they did.
(Joel Beasley at 00:50:29) Okay. Interesting. So you're doing that for the insurance company. They send it to the customer and they take the test.
(Christopher at 00:50:34) Well, the insurance companies are going to be sending it to their insured.
(Joel Beasley at 00:50:37) That's right.
(Christopher at 00:50:37) So the people from whom they're getting insurance, and help them manage their cybersecurity risk, and in particular with ransomware. But I think it's not a big leap to think that the insurance companies are going to start measuring, in an actuarial standpoint, the posture of the people from whom, or for whom, they're giving insurance.
(Joel Beasley at 00:51:02) One last thing we didn't wrap up. You had mentioned educating people not to do the dumb things. What service—I know that there was one in my area. It's actually pretty global, but they're called KnowBe4.
(Joel Beasley at 00:51:14) Yeah.
(Christopher at 00:51:14) KnowBe4 is a big one. We work very often with a company called Infosec, or the Infosec Institute. They're a competitor with KnowBe4. They do kind of the same thing. They do phishing testing, which KnowBe4 does as well. I think if you were to pick one of those two, you'd be in good standing. We like what both those companies are doing.
(Joel Beasley at 00:51:36) Excellent. Man, this is great. These are going to be some of the most valuable show notes we've ever had for security.
(Christopher at 00:51:42) I love it. Very much. And if something comes up in the future and you want to talk again, just let me know.
(Joel Beasley at 00:51:47) Okay. Yeah. And then if people want to find out more about you, LinkedIn, could they connect with you there?
(Christopher at 00:51:52) Through LinkedIn or just go to www.gilware.com.
(Joel Beasley at 00:51:59) Excellent. Now this is exciting. I think we brought—I think you and I, mostly you, brought a ton of value to the audience today.
(Christopher at 00:52:07) Great. Thanks very much.
(Joel Beasley at 00:52:07) Alright. You have a fantastic day.
(Christopher at 00:52:09) Alright. It was nice meeting you.
(Joel Beasley at 00:52:10) See you. Bye.
(Christopher at 00:52:11) Bye.