Speaker A: Hello and welcome to Password on Resonance FM with me, Peter Warren. In this month’s program, how cyber attacks are driving up global tensions and the increasingly vocal demands for a response. Response to cybercrime. June was a brutal month for cyber attacks as news reports lurched from one disclosure to another. Over 37 ransomware and breach attacks, and as ever, the list of big names was impressive. Santander Bank, Ticketmaster, the auctioneers Christie’s, and the US telecom giant Frontier Communications were among the ransomware targets that made the news. Perhaps even more alarmingly, there were a number of healthcare providers featuring prominently in the utterly heartless gangsters’ hit list. Because let’s be clear about it, these are people without a shred of compassion or care for others, as they have proved. In one ransomware attack, a criminal gang called Quilin locked up the data on a number of London hospitals by attacking Synovis, a company that provided computing services to the London Hospital Trust, crippling in the process King’s College Hospital, Guy’s Hospital, St Thomas’s Hospital, the Royal Brompton Hospital, and the Evelina, London’s children’s hospital. And demanded $50 million to restore the system. I was going to use the word operation, but that’s what Quillen effectively denied to the patients as well as the hospitals, as they could not carry out blood tests and so had to cancel operations, cancer treatments, and transplants. And it’s not just hospitals. Individuals are now squarely in the criminals’ crosshairs because Technologically aided scams, according to the US news agency Associated Press, accounted for $137 billion worth of fraud last year in the States. It’s a dire situation, and one we will explore a little later, because the sheer scale of the criminal onslaught is beginning to show signs of a response from the Western nations exposed to it. There is the audible sound of governments and institutions saying, “Enough is enough.” And some people have suggested a kinetic response, the firing of weapons in response to a cyberattack. Last month, a congressional committee asked Brad Smith, the president of Microsoft, what he believes the federal government can do to better protect U.S. infrastructure from nation-state cyberattacks and criminal incidents. Smith said the US government needs to draw red lines so it is clear to the world what they cannot do without accountability. He said, we need collective action with the private and public sector and with allied governments so that when those red lines are crossed, there is a public response and people know what has happened. He said, “We need to start defining some consequences right now because these threat actors are living in a world where they are not facing consequences.” Something the billionaire Finnish entrepreneur and businessman Risto Silasma says is long overdue. Silasma, who as well as restoring Nokia’s fortunes following the company’s implosion, was also responsible for founding the successful cybersecurity company F-Secure, now known as WithSecure, finds this a subject close to his heart. Yeah, cybersecurity people are investing into securing AI models and coming up with technologies and solutions to identify attempts to influence AI models for nefarious purposes. And it has always been a race between law enforcement and criminals, or terrorists and counterintelligence or intelligence agencies. And that’s how it will be with, with the world, or in the world of AI as well. And that, that will never change. But we can use AI to try to identify those attempts to poison an AI system. We should also, though, prescribe some of this activity. We should say that in a world that is getting so complex, that to start to interfere with data in this way and the possible consequences of it We should say that really that should almost become something that the United Nations becomes involved in, saying that you, you mustn’t do this. I don’t know if United Nations would be the right party, but any country that is the, the victim of another state, nation-state’s attempt to harm the core systems of society should take that very seriously. And it’s, it’s a mystery to me why we are not doing that, because we know for sure that, for example, Russia has been very diligently trying to make people lose trust in the core societal systems like the judicial system or the parts of the political system that are essential to our societies. And we just, we just watch from the side. We don’t react, we don’t retaliate in any way. If we have a small shooting incident at the border, we are all up in arms and it’s very, very serious and and we talk about it in the, the media for days and days. And that’s, that’s a minor incident. You get an attack in the UK where hospitals are disabled, appointments are canceled, people can’t get operations. The ramifications of that are massive. And I mean, apparently the Russian supermarket system came under attack in the last few days. That could possibly have been a retaliation, we don’t know, but, uh, it’s very unusual for cyber attacks to occur in Russia. But again, if we’re in this tit-for-tat process, that itself becomes very dangerous if you start attacking people’s infrastructure in return for an attack on your infrastructure. And we shouldn’t, but we, we should issue sanctions, for example, for cyber attacks or, or attempts to influence elections, for example. We need to take it as serious as it truly is, and we haven’t. And it’s a, it’s a mystery. The entrepreneur Risto Silasmaa puzzling over why we have such a strange disconnect between technological incidents and those that happen in the real world, given our critical reliance on technology. It’s a situation that’s puzzling a number of people in the US too, because the attack being coordinated against it to ramp up those figures of $137 billion in fraud is done on an industrial scale, with the criminals organizing themselves into criminal enterprises who use offices and internal company departments identical to those of a modern business. A point Chris Grove, the director of cybersecurity strategy for Nozomi Networks, expands upon. As Grove says, not only are there offices for crime incorporated, but there are also specialist professions within the criminal fraternity and a willingness to adopt new technologies like AI. And without any of the rules used to control AI in business, it could wreak havoc, as the criminals have already proved when a program dubbed NotPetya, designed to attack one system, accidentally briefly threatened the global shipping giant Maersk. It’s actually quite a few factors, I think, playing into each other. One is the capabilities of the attackers have gone up. You may have heard for years now about this crime ecosystem crimeware ecosystem that is put together that enables them to do things easier. Like, one guy will specialize in breaking in, and he’ll sell that information to the next guy up the chain who specializes in doing the next level of the ransomware attack. And then someone else gets it after him or her, and their job is to launder the money. Someone else gets it, their job is to do the next piece. And then there’s even a double extortion tactic coming into play where someone else may even pick up a piece of this attack chain, but it’s gotten easier for them over the recent couple of years due to the efficacy of the system that they built. Their crime infrastructure essentially has enabled them to do a lot better than it used to be. And the, the speed also in which we’re connecting new systems together, especially when we get close to our critical infrastructure and automated sectors. They’re going through a phenomenal growth right now that different sides of the organizations may have already gone through at one point. So there’s things being connected that weren’t connected before, which results in millions of new devices and new— the threat surface is basically spread out really fast. So that makes for prime ripe playground for these attackers to take advantage of. So they have better tools, they have more things to go after. And then as a society, we have done nothing other than add ourselves into the, uh, dependencies. Uh, we have become so dependent on these systems, more and more dependent as we go, that we’re just putting ourselves at more of a disadvantage as days go by. We’re not moving in the opposite direction where we’re relying on them less, that’s for sure. So it’s sort of multiple the natural progression of technology, how society is growing, and then the capabilities of the attackers. And then now we have multiple world struggles happening at once, conflicts around the world. There’s a lot of governments and organizations that are heavily focused on other areas of things that, that like national defense, for example, and may not be so focused on crime that is impacting individual people. And one more thing I think that is coming into play is that the attackers have moved on from just— it used to be a while ago someone would write ransomware and the goal was to steal money out of grandma’s savings account. Those days have gone. They’re not even going to waste time on those people anymore. They started to target businesses, and then once they were able to target businesses successfully and they were able to launder their money and hide their identities, Then they moved on to whale hunting, essentially, where they’re targeting instead of going for crimes of opportunity, like which business is the weakest and I’m just going to break into them because they’re the easiest. They’re targeting now, picking their target, and then using all these new advanced technologies like AI to help with phishing and using their, the infrastructure that they have available. And they’re able to get much further in much larger and more critical organizations than they were before.. And so now you have an organization that’s able to make a major impact. For example, cost of gas going up in a country because part of their gas distribution infrastructure was attacked, or healthcare systems not able to provide services to its patients because of an attack. In some cases, the skilled high-end attackers are doing the whale hunting methodologies and they kind of know what they’re doing a little bit more. But just below that surface, you have the ones that that are still just spraying and praying essentially and seeing what they can get. Sometimes they may attack it like it’s a web server at a florist, but it’s actually a very critical piece of healthcare infrastructure. And the result is much bigger than even they understand that they could have caused because it’s not their area of expertise. They didn’t realize when they knocked out a billing server, for example, it was gonna take down or cause the organization to turn it down manually, this important infrastructure. So the side effects, the impacts, the ancillary impacts of these attacks can also be much greater than, than they initially thought that they set out to do. And I think all of that comes into play as to why things are getting worse today than they were before. As we have mentioned, the side effects have already been felt in numerous incidents such as the attack by Russian cyber groups on the Ukrainian infrastructure at the beginning of the war that took out a number of wind turbines across Europe. It’s a world where the edges are now blurring. Frequently, associations have developed between intelligence agencies and crime gangs, with both seeing advantages in that relationship. Intelligence agencies achieving deniability and the criminals in return seeking protection from their enemies. A dangerous situation when the criminals start to divert the funds from their operations into terrorism and guerrilla warfare, which has recently happened in the Far East where Karen warlords based on the Thai border with Myanmar have set up operations in casinos to generate funds from pig sticking, a term used by the crime gangs to describe the romance, sextortion and other scams that are now plaguing the US. It’s a trend that, according to Rahul Marna, a partner at EisnerAmper, an accountancy and consulting firm that advises clients on the personal threat to them, can only get worse due to the use of deepfake technology. From my perspective and what we’re seeing on the client side with AI, we’re seeing a lot of deepfaking. Starting. And so voice impersonations— I’ve had at least a half a dozen to a dozen clients this year that have come to me with stories of even family members on the true personal side where they thought they were taking a call from a family member that was in need, that needed money because of a surgery or a banking situation or police involvement. And so they rapidly moved money and found out that it wasn’t the person, but they could I swear it was the right person’s voice. And so deepfaking is something that keeps me up at night right now is how do we protect our clients? How do we protect them not only in the office, but their person? Peter, years ago, we used to say we’re protecting the castle. And so when they had an office, we spent a tremendous amount of time building the layers around the castles with the moats and the bridges. And now, because of this decentralized work environment, we’re really protecting the person. And so that extends from business. I think AI is facilitating perhaps the next 7-year wave or so, to use that metaphor. And I think AI technologies are being used on the good side as well as the bad side. And I think this will be the new paradigm that happens in this new shift where you’re seeing by way of example, nation-state actors doing things at a country level. You’re seeing organized crime much more involved, and you’re seeing entities such as healthcare where there really can be no downtime, and quite sadly, actually, where criminals are taking advantage of those situations. And so absolutely, we’re at a very difficult stage, and we, we see it here in the US tremendously. If you look at— we research different entities. And IBM puts out a study, the Ponemon Study, and year on year, the US is the number one targeted and ransomed country in the world. And so we see a lot of that here in the States. The analogy you can quite easily draw on all of this is that of the Barbary pirates in the 16th century. The Barbary pirates were holding all of the nations in the Mediterranean to ransom. They were breaking ransom agreements that they’d made with various different nation states and saying, you’re not paying us enough, we want more. They kept on going because people kept on paying them the ransoms. Then a new nation suddenly came into the Mediterranean. This was the Americans wanting to trade with Europe, and the Barbary pirates instantly went after the Americans for ransoms, which led to the Americans dropping the Monroe Doctrine, coming out of isolationism, and developing a navy because they wanted to protect it. And then, then the Americans responded by going into a few of the Barbary pirates’ ports and opening fire on them. Are we at that situation now? Your background in history is poignant, and I think a very accurate parallel to what is happening right now. In fact, there’s some ransomware groups that create ransomware products and they rent it out and say, if you want to become a pirate, here are all the tools, you could use them. And when you get the bounty, we’ll split it. And so we’re even reaching that state where you could become a pirate on demand. And it’s quite scary how easy it is to become a pirate on demand. Raul Mana of Eisner-Amper. As Mahner points out, as well as homing in on vulnerable individuals in the community, the criminals are now also cynically homing in on the most vulnerable in our society, the ill, and are increasingly targeting hospitals for both ransoms, personal details, and medical data. Just as with the pirates of old, the criminals acknowledge no moral boundaries in their pursuit of plunder because not only are the vulnerable in hospitals, so are some of the most vulnerable computer systems, according to Steve McEwen, the head of MacGyver Tech and McNerd. McEwen is a white hacker who specializes in finding the weaknesses in computer systems so they can be patched. The healthcare industry in particular is really old, meaning the software, the architecture, infrastructure is really dated. And a lot of them are hard to update, and it’s caused a little bit of a conundrum here where you have, you know, hackers are really accelerating their attacks and their technology ability. And then on the other side, you have the healthcare industry really not stepping up their game at the same level as the hackers are, which unfortunately I think it’s going to take government oversight for that to happen. My biggest concern is not just the what happened, is like the data that’s getting leaked. Some startling facts here. 1 in 3 Americans have their medical records on the dark web. If we have one more person here, one of us has all of our information there. And, you know, on the UK side, there’s estimated millions of UK residents are in the same boat and had their stuff compromised. So nothing’s sacred anymore. And it doesn’t seem like these companies are getting slapped on the wrist if they kind of allow a hack. I think if there’s more serious penalties of, you know, maybe defending your your digital garden, you know, you might have a better chance of being resistant. But I think that’s going to take some pushback from regulation because until they get hit with a hack, it’s not that important. Why are hospitals in particular so vulnerable? Why is their cybersecurity so poor? You said that they see security as a cost. Is it because also nobody’s updated any of their systems? Because as far as the medical profession is concerned, its priority is looking after people. Yeah, I mean, you hit the nail on the head. It is because they are not willing to invest in redoing the software applications to make them more resilient for today’s day and age. Some of these systems are decades old, and, you know, even the old way of thinking, if it’s not broke, don’t fix it. But the problem is, in today’s day and age with software, you can’t do that, especially with sensitive information. There’s like applications like Epic and stuff like that that run a lot of the medical billing stuff behind the scenes, and we dealt with it personally. That thing’s super horrible to work with, super archaic, and that’s just the tip of the iceberg. Most of these applications are not being updated and maintained the way they need to be to be resistant against the level of sophistication that’s coming now. Something that was built 10 years ago can’t defend itself against something today. Steve McKinnon of MacGyver Tech and McNerd on the spate of attacks on healthcare computing systems that have embraced the NHS, Change Healthcare, and Ascension Healthcare in the US, and the South African National Health Lab Service, amongst others. Of 37 ransomware attacks known, about 5 were on significant health systems. So what should we do about it? According to Chris Grove of Nozomi Networks, we should consider a range of options. After all, it’s what the Chinese government have done, demanding the extradition of 3 Myanmar-backed Chinese warlords who had run pig-sticking operations on Myanmar’s northeastern border with China. Why can’t we go after the operators of ransomware? Like, we go after— let’s think about this for a second. If a terrorist were to come to our country and do something, whether or not they killed people, let’s just say they blew up a dam and it wiped out power for a city, but no one died, we would still track them down wherever country they were in, and we would kick in doors, and we would either handcuff them or we would throw them off the back of a Navy ship out in the ocean. We would hunt them down. And I think that time has shown the evidence of that with multiple wars that have happened around the world. Ransomware operators have the capability and the risk of having the exact same impact. And we, I think, could treat them the same. Maybe we don’t have to invade a nation for it, but using special forces and using maybe some language and some legislation, some treaties or something. I mean, we should be able to treat them differently than just a criminal because they are moving beyond just being a criminal. They’re— yes, they’re trying to get money. But if I blow up a dam for $1 million, I’m not just going to be treated like a criminal. That’s a terrorist operation where I put millions of people’s lives at stake. If we treat these criminals the same, then I think it opens up a realm of new possibilities of ways to deal with them from secret black bases where we could lock them up and scan them and infiltrate the entire network and, you know, by force get access to these things, I think, uh, should be on the table. Chris Grove. But tempting as it is, the response at the moment, according to many experts, must be more nuanced, as was shown by the multinational police operation to take down the notorious Russian ransomware gang LockBit and place its leader, Dmitry Koroshev, on a sanctions list that is packed with Russian criminals and intelligence agents. Though their extradition is remote—Russia has never extradited one of its citizens to face charges in the West—retribution, according to Troy Hunt, head of the password credential loss alert service Have I Been Pwned, and a Microsoft regional director for Australia, is extremely difficult because of the problem of attribution. Yeah, I think the kinetic response one is interesting. The first question always comes to mind is, well, against who? You know, I mean, it’s one thing if it’s state-sponsored, but of course a lot of these might be state-tolerated, but that’s a different story to state-sponsored. And of course we’re in an era where on the list of things that let’s say Russia has done that might raise the ire of the West, ransomware is probably not right there in the top 1, 2, or 3 either. So in terms of kinetic response, you’d imagine there are many other reasons why that would happen first. I think drawing on examples like everything from LockbitSup to the Myanmar situation recently, I do agree that there’s an escalation, and I do think that the reactions are getting stronger. I mean, certainly here in Australia, we’re seeing our own government much more actively hacking the hackers, as they, they like to say, which we didn’t see even 3 years ago. So that’s, that’s changing very quickly. I haven’t yet seen kinetic response, but I imagine that would be something that, that might happen in, in genuine warfare, in genuine conflict. But, you know, in the interim, it’s, it’s certainly escalating in other ways, isn’t it? Some of the people that we’ve interviewed have been saying that what the Americans should be doing is using special forces or perhaps agents to go in and target particular individuals, perhaps extradite them forcefully. There is the beginnings of a loss of patience, isn’t there? I certainly think patience is waning and responses are getting more severe. I mean, even the naming and shaming of individuals. Yes, it’s quite interesting because some people look at it and they go, well, what’s it going to do sanctioning someone in Russia? What’s it going to do effectively doxing them? Yeah, clearly they’re not about to be extradited, but you’d have to imagine life will be much harder for them even in their home country, particularly those who are sitting on tons and tons of Bitcoin. Having your face all over the media, which of course folks there would see. So it’s definitely escalating, there’s definitely more severe responses. Where will it go from here? Well, I don’t think we’re about to have SEAL teams dropping into foreign soil to take out hackers. I think we’re a long way away from that. There’d have to be some sort of serious threat against national interest to get that far. But then the head of AIG in November, huge insurance company, said that as far, far as they were concerned, there were four main existential threats now: climate change— and these are in order— cybersecurity, geopolitical tensions, artificial intelligence. All of those are intrinsically linked. Things are actually getting serious. There is this strange inability to make a disconnect, to create this disconnect between the technological world and the real world, which is absolutely stupid because we’re all dependent on this technological world. Now, if somebody had attacked banks in the UK, for example, just to sort of expand the analogy of Lockbit, and taken them for a billion dollars, then, and that had been done physically, the British government would have been howling, they would have been screaming about for retribution. Yet in cyberspace we don’t do this. Why? Well, I mean, first of all, the technological world is the real world. I agree with that analogy. I think we’ve gone past using this sort of in real life analogy. It’s all real life. The first thing that comes to mind in terms of the parallels between a, let’s say, physical bank robbery and a digital bank robbery is clearly the first one involves violence, which is not a factor in the second case. I do think there are some places where it seems that violence is entering into cybercrime, but again, that requires physical presence. And once we get to physical presence, it’s a fundamentally different set of rules that are played by, not least of which physical presence means that there is someone to actually capture within your own territory, within your own domain. You know, even in cases where we see large-scale digital fraud, when that’s mounted from afar, there’s no violence involved. The victims are victims of digital crimes and financial crimes as opposed to physical crimes. And of course, very often they are well beyond the scope of reach of the law enforcement agencies in somewhere like the UK. And then the other factor again is the ability to have anonymity. Very hard to walk into a bank with a gun and have the same degree of confidence of anonymity as when you’re sitting a PC. I’ve been using the analogy of the Barbary pirates in all of this. The Barbary pirates in the 16th century went round holding nations to ransom, taking their ships, enslaving their crews, putting them in chains on the oars. Everybody started paying ransoms to them. Quite often the Barbary pirates would break the terms of the ransom because they felt that they could get more, which is a situation that is analogous to now. Then another nation rocked up into the Mediterranean called the Americans, and the Barbary pirates thought, wonderful, we’ve got some other people that we can extract ransoms from, which they started to do, which annoyed the Americans. The Americans didn’t have a navy at the time. As a result of the Barbary pirates’ actions, the Americans broke the Monroe Doctrine, came out of isolation, developed a navy, went into Tunis, Algiers, and Tripoli, and started shooting the place up. That stopped the Barbary pirates. We obviously can’t do that now, but it seems to be the only way to deal with ransoms. And to expand that analogy a little more, the Barbary pirates, we are essentially licensing other pirates to operate under their flag and go out from their ports. A situation— affiliates. Yeah, exactly. Very similar to cybercrime. So what do you do? Well, I think in that case, it’s— we’re back to sort of where we are at the moment as it’s escalating tensions. It’s just looking for responses which are increasingly severe compared to what they have been in the past. I think all of these things do take quite some time as well. We’ve had a bit of press here lately. We’ve had some major data breaches in Australia over the last 18 months that have had a lot of government response and a lot of dedicated government resources. And one of the things that they’re talking about at the moment is we’re not in a position to ban ransoms right now, but we’re on a path to a position where we should be able to do that at some point in the future. So I think it’s really interesting to look at what other levers are available to start trying to tackle this problem and recognising that it is something that happens very gradually over the course of time. Troy Hunt, head of the credential theft alert organisation Have I Been Pwned? Though there are signs of change. Indeed, Hunt is not alone. Commander Patrick Tyrrell, a former naval officer and intelligence expert who once advocated the installation of borders in cyberspace, is now less sure. Oh well, I think it’s very important that effective sanctions are placed against those who commit cybercrime. So to do that, you need to be able to track them down within a reasonable timescale, because you’ve got to be able to have good proof that that particular person that was sitting at that particular machine at that particular time is the person who has now benefited from the crime that has occurred, and then making sure that there are international sanctions which can be applied. And there will be a large number of people who will say, but I’m innocent, it wasn’t me, gov. But there are always lots of people who are apprehended or who were apprehended for bank robberies who said, no, it wasn’t me, I didn’t do it. So you have to make sure you have all the necessary bits bits of evidence, train of evidence, you know where it’s happened. So we need to get better at it, and banks need to be much more responsive. I mean, I know they’re trying, but you know, when large sums of money suddenly disappear out of somebody’s bank account, particularly if they’re, let’s say, an old lady or an old gentleman who has never ever done anything like that before, Banks need to be— bank systems need to be a lot more aware at doing these things. There was one in the paper today where a lady said that she was telephoned to be told that, you know, large sums of money had been misappropriated from her bank account, and she was then instructed on how to, how to type into her phone a certain code that would make everything better. And of course, the code disabled her phone so that all calls got diverted to presumably the person who was committing the affair. Now, you know, we need to make sure that People are more aware, but even when they’re aware, people tend to be— they want to be helpful. If someone rings them up and says there’s been a problem, your first idea is not to say, ‘I don’t want to talk to you,’ it’s, ‘How can I help you?’ And then, of course, that’s what the scammers are basing it on. Intelligence expert Commodore Patrick Tyrrell on the difficulty of attribution and retribution in cyberspace. Yet even though attribution is difficult, there are some signals that can help us understand where an attack is coming from when used with other information, says Simon Hodgkinson, a strategic advisor to the cybersecurity company Semperis and a former head of cybersecurity for the oil giant BP, who rather than advocating a physical response says our only real option is to improve our defences. I think the term has to be resilience. I think this, it really scares me, this whole notion of a cyber event causing a kinetic response. I mean, that’s, that doesn’t seem beyond imagination at the moment because people are targeting critical infrastructure. And I think if you’ve got a nation state that targeted, say, clean water, I’m sure that would actually provoke a full response from the organization. And you can already see that many water treatment organizations are being targeted in the, in the OT space. So it feels like the countries like Russia, like North Korea, Iran, etc., are almost testing their capability at the moment and building up an arsenal of weapons weapons that they could deploy in cyberspace, and I’m sure that would ultimately require a response presumably in the kinetic world. There would be definitely a cyber response but then potentially escalating into the kinetic world, and that’s pretty frightening, right? And it’s pretty frightening because cybercrime is readily available to anybody, so how do you know who the culprits are and what Who are they representing? I mean, somebody like Russia provides a safe haven to many criminal gangs. Are they working on behalf of the government, or are they proxies for state attacks, or are they just criminal gangs that are harbored in those nations? And so we’d have to be— it would have to be really clear that it was a direct attack from a nation-state on another nation, I think. I think, to actually lead to that escalation. We talk about criminal gangs being harboured by nations, but that doesn’t mean they’re physically there. There’s no border and no boundary to the cyber world. That’s the problem. Even if you can attribute attack to a nation, as you know, we’ve seen quite a few comments from the US government in particular about China recently, but even if you can directly attribute that, that doesn’t necessarily mean the actors are in there. And certainly back in the day, I saw attacks coming in from definitely proxies, so potentially Iranians acting on behalf of Russians. I mean, it’s, you know, because, because you’re looking at the tactics, techniques, and procedures and saying, well, that’s attributed to that threat actor, but it’s coming through essentially Russian infrastructure. So, so there’s collaboration in that world as well. So again, I’ll come back back to that attribution is going to be really difficult, and people would have to be really convinced before it escalates into kinetic space that this was directed by a state government. You mentioned something interestingly about North Korea. I saw a direct correlation whenever anybody turned up trade sanctions to attacks from those countries. So North Korea, when the trade sanctions increase, you’d see more cybercrime from Iran when their sanctions were really turned up in 2018 or around that period. Again, we saw so many more attacks because that’s a mechanism for funding the economy. So cybercrime is a mechanism. So actually, in some respects, there’s a correlation between the level of sanctions and the level of criminality that you’re seeing on, up front in a cyber realm. From those nations as well. I’d come back to— I mentioned the term resilience. I think both at a state, country, organizational level, we need people focusing on resilience. We need people to recognize that they’ve got to do the very best job they can to withstand some form of diverse event happening in cyberspace. But accept that it’s going to happen. So assume that actually that you are going to be breached and something, either data exfiltration or destructive malware, is going to be deployed. And therefore your ability to recover quickly from that event is critical. So I think we’re really talking about cyber as operational resilience now, and it needs to be on the on the board and the executive suite. It needs to be in— we’ve seen lots of attacks on healthcare organizations recently. It needs to be on the agenda of the board of the Department of Health and Social Care. It needs to be on the agenda of the board of NHS England, of United Healthcare. People need to be treating this in the same way as they treat any other risk in their business. And that requires a different level of understanding, in my view, with kind of the executive leadership so they can engage not in the technicalities of cyber but in the likelihood and the impact of a cyber event happening and therefore directing what every organization has, which is constrained resources, to try and make you as resilient as possible. Yet, in spite of the caution that Semperis Hodgkinson counsels, there are signs of change. Following the attack on the NHS, a popular Russian discount retail chain with over 1,000 stores nationwide was hit by a mysterious cyberattack that disrupted its services for several days. The unknown attackers took down the company’s website and mobile app. Due to the attack, Verney supermarkets couldn’t process bank cards or receive and deliver online orders. In the attack on Verney, no ransom was demanded and no one accepted responsibility, leading to speculation that it could have been some form of retribution. Retribution is difficult, and many of those we interviewed are still suggesting significant overhauls to our defenses instead. As McEwen pointed out, one of the issues with the hospitals is that their tech is outdated because their priorities are treating the sick, but perhaps it should be mandated that the physician should heal himself, to paraphrase Shakespeare. According to Melissa Ventroni, the head of the Chicago law practice Clark Hill’s cybersecurity team, who specializes in recovering from ransomware attacks and is a former U.S. Marine Corps intelligence specialist, the real problem is a lack of investment in cybersecurity and a failure to adopt cybersecurity best practices in the West. We really have to start looking at cybersecurity from a resiliency perspective, and we have to change the way that we operate. The threat actors know what’s valuable. They know in the US, Social Security numbers are valuable, and in the US, we’ve tied Social Security numbers to everything. And so you get the social and you can get a new loan for your house, for your car, you can get credit cards, you can access potentially healthcare. So we, until we really stop tying all that information and we devalue what it is they’re getting their hands on, they’re still gonna see value in it. And then on this concept of resiliency, I really think where, yes, we have this idea of locking people out, but if we could come up with a concept that enables or helps, for instance, in the healthcare space, let’s say a hospital gets hit by ransomware, are there facilities that we can set up that they could plug into almost immediately to still continue providing the care? And when they’re stood back up, then it gets transferred back over. I think it’s the resiliency piece we really need to look at because criminals are always gonna find a way to manipulate people or things or technology to try to make money. So do you think that resilience part should be mandated? Some of the people that we’ve interviewed have said that there is a need for the raising of awareness across the board in cybersecurity, that people should have those sorts of backups that you’re talking about, that they should be able to pull those systems back up very, very quickly. So do you think that should be mandated? Yes, I think it should become— it should come like the seatbelts. Seatbelts are mandated, you’re required to have them. If you have a business, you should be required to have this resiliency concept. So if something does happen, then you can, you can still continue to operate, provide services to consumers, customers, businesses, etc. I do think it should be mandated. So what should the role of government be in this? Should it be mandating this awareness, this resilience? Should it also be mandating, very much like the Securities and The Securities and Exchange Commission in the, in the US has been saying that you must have somebody on the board who knows about technology because they know what needs to be done. I do think we need to see mandating the resiliency side of it because that’s really the operational side of it and that’s what’s going to protect people from harm. If you have this resiliency combat for concept for hospitals, you have the resiliency concept for— I mean, look at the cyber attacks on the automobile industry. And so let’s say somebody has an old clunker they were going to turn in. Well, they can’t do it. So now they’re driving an unsafe vehicle. So really looking at it from the resiliency aspect of it, I do think the government can drive innovation a little bit more, working with the private sector on this concept of how to share information in a way that doesn’t create additional risk. Ransomware recovery expert Melissa Ventrone of the Chicago law firm Clark Hill on why companies everywhere should improve their cybersecurity to protect against an attack that most businesses say they expect to happen to them. And Ventrone has her supporters. Professor Suckinchetti, director of Old Dominion University’s Center for Secure and Intelligent Critical Systems, is an advisor to the U.S. government, and he is leading a research project into how to stop Hackers compromising hospital systems. When I look at the technology ecosystem in terms of the vendors who they work with, and I notice several weak links in terms of not holding the vendors accountable. And because you don’t have any, at least on the US side, I don’t know how things are across the pond, there aren’t enough checks and balances. You know, when you say shared account accountability, right? How do you hold the vendors accountable who are providing services that they would have the necessary checks and balances to protect the consumers? Usually the consumers or the customers or the agents in this case, for lack of training, for lack of technical know-how, are not prepared to properly do the things they’re supposed to do. And so yes, so I definitely see a rise. As a matter of fact, there are so many unreported That’s the part that’s scary, right? You’re mentioning the ones that we know about, but I know several, at least I’ve heard to the great point, some of the unreported. And if you notice, they’re always targeting organization units who don’t have a dedicated cybersecurity staff, and they know that they don’t know. It’s not a technology problem, right? The technology is there. If you were to ask me, haven’t we solved this problem? Yes. If you ask any cybersecurity expert, state-of-the-art practice. It’s all there. It’s just the same thing as health, right? Don’t we know that we need to eat right? Yeah, those options are there. So what you’re saying then is that you need mandatory reporting, and what you’re saying is that there needs to be some legal structure put in place. Well, I would say 3 things. I use 3 lenses. So you’re right, mandatory reporting for fact, because hear me out, right? So if let’s say Agency X, or let’s say a Hospital X, uh, gets attacked, I would like the hospital community to at least know. Imagine, you know, in the hospital IT community, for lack of better word, right, who are always plugged in. And if one gets attacked, how— what do we do? Because we are all sharing the same systems. So if they know what that infect one system, we are all connected to the same system. It’s just not a matter of is it probable, are they willing to come to us. So reporting will make sure that we all at the same time aware of it. So it’s almost like I use that within my security. How do I quarantine, right? If one portion of my system is infected, how do I quarantine so that the infection just stays localized, doesn’t spread? That’s number one. Number two is, and this is the hard part about, right? When you get into a service level agreement with a vendor, how do you put those within the contract language? How do you put those requirements that the vendor will support or provide necessary support when needed? So that goes into that agreement between the customer and the vendor. Notice that sometimes there’s a consultancy for consumers. I notice that they don’t know what they should require in those contractual language. And when they don’t make cybersecurity requirement as a requirement, and they don’t know what they should do. And so vendors will, you know, they want your business, so they’ll do. If you don’t tell them, they’re not going to offer it because it comes at a cost in price. And so obviously most of the consumers try to say, oh, we don’t need it, it’s an extra cost, why should we go for it, I’ll take a risk. And that goes to my third piece, right, the risk factor. So if you’re willing to take a risk What type of instruments do we have to protect you? You have cyber insurance, so then buy insurance, right? So cyber insurances do exist, so buy insurance so that you have some protection. And the last piece, I don’t want to always bring up the regulatory mechanisms, but that’s what I’ve noticed when, you know, when there is no better self-organization, when we as consumers and vendors don’t realize by ourselves, then we need the regulatory lens. Either use some sort of punitive measures, some incentive mechanism. I’m always about incentives than punitive measures. But if incentives don’t work, right, what the carrot and stick methodology works, that would be the last mechanism instrument to use. Because that’s the reason why in the US there is a White House executive order called the Strengthening American Cybersecurity Act. Act, which is now going to require in the next couple of years 16 critical infrastructure sectors to have some sort of cybersecurity insurance. They haven’t provided the details for it, but you got to describe how are you going to handle this. So for example, ransomware— do you have a backup in place that is air-gapped, not connected to the network? If your backup is also connected to the network, then they will infect the backup as well. So according to Professor Shetty of Old Dominion University, understanding the technology and the data you use so you know how to protect it is as much the individual and the business’s responsibility as the government’s. To be in the 21st century, you should understand it. And according to Ari Reitnam, the chief operational officer of CyberX Technologies, An Estonian cybersecurity company that literally sits on the front line of the conflict, nestling as it does against the Russian border. That does mean making sure you have good cybersecurity, something the Estonians have a deep understanding of. Estonia is the most internet technology developed government in the world, and as such plays a significant role in NATO cyber defense. So there are two types of attribution. One is technical attribution. The second one is the legal attribution. In one sense, we are definitely getting better and better how to detect where are the attacks coming from and how to go back to the original state. The other thing is the legal framework where we are operating. And now we have to distinguish the frameworks where we are operating. One is the Western countries and how we operate in the legal framework. And then there are countries that don’t obey to these kind of legal frameworks and operating in a totally different dimension. Because that’s another issue about this, isn’t it? Because according to everybody that I’ve spoken to, there are almost a grouping of, you could say, pariah states who are prepared to engage in this activity. Those states, according to the people I’ve spoken to, are China, Russia, North Korea, Iran, a few others, but those are seen as the main offenders. They’re pariah states. How can you have legal retribution on those? That’s one thing, is that if they don’t come under the same umbrella, then legally we can make decisions on our behalf, but they will not be impacted in any way. So what it means is that we say that it has been an unlawful you will be, let’s say, punished by this and that, but actually nothing happens. And now that is the thing why they are becoming more braver and braver. And every single time, like in the school, so you have bullies, until you will go and face the bullies in the same means as they are doing to you, then the bullies will, you know, remain and do the same thing. So, what it comes from that angle is that what we have seen is that in the early days in NATO CCD COE, they investigated how many countries countries in the world have in their cybersecurity strategy a point where they have this kind of offensive capabilities. When they started, I think that it was, let’s say, 10 countries. And in 2023, I think that it was close to, you know, 70 countries that told that now we have the offensive capability also built in the national cybersecurity field. If somebody attacks us, we have the capability to pushback. It’s very, very dangerous. And I’m just bringing you an example. For example, if somebody is attacking, there are two dimensions again. One dimension is that they don’t do the cyberattacks as wide that it will have a huge impact across, you know, one nation or in, let’s say, in several nations. So, what they are doing is they are attacking, you know, hospitals, some media houses, transportation companies, and they are halting their activities for a short time. So they understand what they are doing, and they are doing it in a limited pressure, but they are doing it constantly in different places. And then the second dimension there is that what happens if you shoot it back and do something? Then what we have seen is that cybersecurity doesn’t have borders. If you attack some system and the same system is not only used, for example, in Estonia, but also in Finland, in Germany, then the same thing can happen in different locations. And now when you have done one mistake, is that how do you then, you know, grab it together and say that I’m sorry, I wanted to attack this unit, but it spread from there to others. And now I have a chain of chaos in different places. Yeah, I mean, a good example of that is NotPetya, where they hadn’t actually intended to attack the huge shipping company Maersk, but they nearly destroyed it. Yes, and, you know, NotPetya was one good example. After that, what happened also in Ukraine with the wind turbines, so the same solution happened. So the Russians were attacking the wind turbines in Ukraine, but accidentally the same software was used in some of the NATO countries, and the same impact happened there. So it is overspill effect. So you can’t be sure that while you attack, you will not attack others. And if you attack back, then you have to somehow limit it by geography. But nowadays, all the systems are connected together. So even the systems that are in this kind of states, for example, you know, if we’re talking about Iran or Russia, then they still have, you know, connections outside. And if we attack it, then it might overspill and go to others as well. What you’re saying is these aren’t very accurate weapons. And as a result of firing one of them, you can essentially send something flying off in the direction of somewhere that you didn’t want it to. You want to attack the Ukraine and you destroy a hospital system in Spain. Yes. And the point there is that at the moment, what we haven’t seen is a proper cyber war. So everything what is done at the moment is a testbed. So we are testing and we are seeing and, you know, trying to understand what we do, what kind of impact it has. But at least it gives us an understanding that if we do that, then what might be the impact in this nation? CyberEXA Technologies, Ari Reichtnam, a frequent guest at NATO’s cybersecurity headquarters on why being protected against cyberattacks in an AI and internetted world is a safer strategy than going off half-cocked in a world where you cannot be sure of what will happen. In our metaversal world, we should really work out what we need to put locks on and why. You’ve been listening to Password on Resonance FM, presented and written by me, Peter Warren, and produced and edited by Blue Buffery. Thanks for listening and goodbye.
