This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Ransomware Through The Supply Chain: Becoming Antifragile – Turning Ransomware Stress Into Strength

Download resources

About this session

Cindi Carter, Field CISO at Check Point and a former healthcare CISO, opens GoSec 2022 by reframing ransomware from a disaster to survive into a stressor an organisation can grow from. She lays out the basics for a mixed audience: ransomware is malware with a price tag, its variants (crypto, locker, scareware and deepfake voice scams, leakware), the ransomware-as-a-service split between developers and affiliates, prolific gangs (Ryuk, LockBit, REvil, Maze), and the escalation from single to quadruple extortion. She explains why change itself creates exposure, illustrated by a CIO who wanted sign-off to move the corporate network to Azure with no network diagram, and by a supply-chain breach where a subcontractor's unpatched ColdFusion server exposed member data. Colonial Pipeline, JBS and Kaseya anchor the supply-chain and holiday-timing lessons. Her prescriptions: patch and segment unpatchable systems, keep immutable backups with rehearsed restores, treat people as the strongest ally, and build prevention-first architecture. Borrowing Nassim Taleb's antifragility, she describes fixing a recurring breach traced to hard-coded credentials through tiered secure-coding training, inline scanners and threat modelling. A brief Q&A touches on privacy fines and No More Ransom.

Ransomware has made its mark in cybersecurity since the first reported case of an attack in 1989 that targeted Healthcare. As time has progressed, we have seen an evolution in the quality of ransomware code, delivery mechanisms, and extortion methods. History has a way of teaching us ways to look at things differently, and becoming antifragile is an approach to acknowledge the chaos from ransomware and grow stronger.

Key takeaways

  • Refuse to sign off on any cloud migration or architecture change without a current network topology diagram and a data-flow threat model showing who touches what data and where.
  • Put third-party and fourth-party data handling in contracts: ask vendors whether they subcontract, and treat a vendor breach of your data as your breach.
  • Segment or isolate legacy systems that cannot be patched, keep immutable backups, and rehearse both the restore and the incident communication plan before you need them.
  • Raise vigilance around long weekends and holidays; Kaseya hit on the US July 4th weekend when fewer eyes were on the console.
  • When incidents repeat, fix the root cause in the code: fold security fixes into every sprint, give developers tiered secure-coding training, and run scanners inline so security is frictionless.

Speakers

Cindi Carter
Cindi Carter
Chief Information Security Officer · Check Point
Cindi Carter is a global, multi-industry Cybersecurity and Information Technology Executive with more than 15 years of experience as a transformational leader for both startups and enterprises. Cindi’s expertise includes building Cybersecurity… Read moreRead less

Cindi Carter is a global, multi-industry Cybersecurity and Information Technology Executive with more than 15 years of experience as a transformational leader for both startups and enterprises. Cindi’s expertise includes building Cybersecurity practices in highly regulated industries, turning strategic goals into actionable outcomes, influencing a “secure from the start” culture, developing secure architecture & engineering platforms, and highly collaborative engagement (C-Suite, Board, Clients and Industry) for managing risk. At Check Point Software Technologies, Cindi is a Chief Information Security Officer in the Office of the CISO, committed to helping other CISOs achieve success in both strategic and tactical initiatives and contributing to Check Point’s own security practices. Cindi possesses a firm grasp of the challenges surrounding the security, privacy, and risk management landscape, and is a trusted advisor within Check Point as well as for our customers. More recently, Cindi was the CISO for IntSights Cyber Threat Intelligence, where she was responsible for driving the company’s internal security initiatives, as well as serving as an external-facing advisor and subject matter expert in the areas of threat intelligence, cybersecurity resilience and risk management. Cindi also served as VP and Chief Security Officer at MedeAnalytics, a healthcare analytics software-as-a-service (SaaS) leader; prior to that Cindi was the Deputy Chief Information Security Officer at Blue Cross and Blue Shield of Kansas City.

Resources

Tags

More from GoSec 2022

Also from Cindi Carter

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.