ICAEW.com works better with JavaScript enabled.

Transcript: Is your identity at risk?

Published: Today at 10: 50 AM BST Update History

Cyber criminals spend much of their time working on identity theft. If you hold a responsible position in your organisation, they might very well be working on you. Or worse – they might be lurking in your smart coffee machine.

Identity theft is now recognised as the best path to success for cyber criminals and with more and more information about ourselves and our organisations online, we make it easy for them.  So how can we identify the likely targets on our workplace teams and protect our businesses? 

Host

Philippa Lamb

Guests

  • Kay Daskalakis, Senior Solutions Architect, SpecterOps
  • Oli Venn, Watchguard Technologies

Producer 

Natalie Chisholm

Series Lead

Mark Rowland

Transcript:

Philippa Lamb: Welcome back. Have you ever wondered what cybercriminals actually do all day? Well, chances are they're working on identity theft, and if you hold a responsible position in your organisation, they might very well be working on you. Identity theft is recognised as the best path to success for cybercriminals right now, and with more and more information about ourselves and our organisations online, we make it easy for them. So, how can we identify the likely targets on our workplace teams, and of course, protect our businesses?

[Teaser audio] Oli Venn: It only takes about five seconds of audio now to get an 85% likeness of somebody.

[Teaser audio] Kay Daskalakis: People will create specific apps that serve their own micro use case, and they will sell these apps. And some of these apps will contain risks.

PL: Joining me to discuss this, identity specialist Kay Daskalakis, a senior solutions architect at SpecterOps. He knows all about the mindset and techniques at work in identity theft, and Oli Venn is a cybersecurity expert from Watchguard Technologies. He'll be talking us through the defences organisations can use to protect their people's personal details and their businesses. Welcome both.

OV & KD: Thank you. Hello.

PL: So, Oli, identity theft, as we understand it, its top favourite now as cybercriminals. Just how prevalent is it?

OV: From a recent survey by IBM, they're actually saying that 95% of most breaches occur through some kind of identity theft.

PL: Okay.

OV: Basically, hackers are just logging in rather than breaking in these days.

PL: That's astonishing to hear. What sort of people are most at risk in a business context.

OV: Everybody is the honest answer. It's often we think about it's probably the C levels that are most at risk because they carry the title. But the real truth is that everybody is at risk because a hacker can get into an account at any level and then leverage from there. Obviously, if they can get straight into the keys of the CFO, that's great. But they may start with somebody much lower down in the organisation.

PL: I'm thinking it would be good if we imagine as a scenario, say an organisation, medium-sized law firm, maybe operating in Manchester. Cybercriminals are looking for a way into the organisation. They're planning to use a stolen ID. They're thinking about a ransomware attack. How do they pick their target? The firm first. How would they choose which firm to go for?

KD: Choosing might be random at first. It depends on what you're after. But fundamentally, let's say that they've chosen a firm because their website includes a lot of information that should otherwise be much more concealed.

PL: Okay

KD: This would help them gain some information about the account, and from there pivot into something like LinkedIn or any other social media profile to target someone from that organisation. And maybe there's an associate that just wants to get a new business, so you could start as potentially a client. Let's say I'm a client and I want my master services agreement for this. So here's my secure file transfer solution that you can use, and that could be used to gain initial access. Initial access is the easiest part.

PL: I'm guessing it's not usually a case of one business they're targeting either. Presumably, they target multiple businesses at the same time, do they?

OV: Yeah, unless there's a specific reason to target a specific business, it's often not worth the effort to go after one. So they will just blanket everybody and anybody is often the case.

PL: And just look for an opportunity.

OV: Yeah, exactly.

PL: So, is social media going to be a likely starting point?

OV: It's a very good starting point. We've seen where there's been compromises, where they've scraped data from social media, the likes of LinkedIn, and then use that in the attack. So, a phishing campaign, if you're sending an email to a colleague or a victim saying, "Oh, we met last week," or "I'm away on leave, but I need you to make this payment," it has more credibility to it. So this information that we put on social media is then used in the attacks as well.

PL: So what sort of things should we not be putting on our LinkedIn profile then?

KD: LinkedIn is a CV, right? Fundamentally, but people will put - you can't talk down people to not put what they have achieved, right? So you just have to... we have this part of zero trust that is always calling for assumed breach, and we almost always forget about it. We need to improve our verification points. This is the answer. The answer is not stop what you're doing, because you might be using LinkedIn, for instance, like to draw new customers, and you need to talk about your case studies. You need to talk about what you're doing. Yeah. So that legal... that law firm will have reasons to disclose what they have done with a certain customer. Perhaps someone would misuse that angle, right, and go through that supply chain to say: "I'm part of that customer, etc", like this, to impersonate.

PL: It feels to me, and I think I've seen written about that, LinkedIn's getting more social now, but there's more crossover with actual social media rather than business and workplace media, and so people bring quite a lot of personal stuff to their LinkedIn profiles now, don't they? And the comments that they make and the things that they post, is that posing a danger?

OV: It is, and it is this battle because, really, we shouldn't put anything on LinkedIn. But the trouble is, our marketing wants us to put things on LinkedIn to get the engagement, and the trouble is with the likes of LinkedIn is you get so much more engagement when it's not seen to be corporate.

PL: Yes, or generic.

OV: Yeah, and I mean, I put stuff on LinkedIn and I get a good following and good likes and stuff. But if I put something that's slightly away from work, for example, I do kart racing. If I put that on there, I get like 20/30, times the engagement as I would do a corporate one. And it secretly maybe has a corporate edge to it, so that's why people still do it. But it's being mindful of what's going on LinkedIn.

PL: And those personal insights, they must be useful to cybercriminals because it gives that sense of knowing you as a person.

KD: They can be during targeting, but again, that part, like identifying targets, in the past it might have included a level of effort. Today, it's completely random and probably also AI driven.

PL: How does it work then in that sense?

KD: Someone would, let's say, a bad actor here, right, could use an one of the open source models that doesn't have any sort of guardrails on a harness, or which they could have created themselves. So a harness for anyone that doesn't understand the term is effectively when you use, for instance, Claude.

PL: Okay.

KD: That is a harness. Which people when you use codecs, that is a harness that includes some guardrails. So attackers would go, let's say, outside of that, of those guardrails, wherever they can, or they might even use one of those harnesses that are commercial to say that they're doing a security test. Effectively trick that model that may be frontier and commercial to do something that it shouldn't. Which falls into that kind of cyber security misuse, , and everything else. Once they have achieved that kind of spread and get that information. They will get some of those targets that are more prone to misuse. Like, for instance, someone's website might not carry a current certificate, or one thing that I've seen is that a company was including on their signature, a workplace site where they had links to their privacy policy, which were PDFs, and an attacker injected payload into this part of their website because they they forgot about the permissions - that they allowed permissions - to anyone that was receiving the signatures.

PL: We'll get more into defences I think as we go on. But I did want to ask you, Oli, what sort of people, just looping back to the 'who is targeting' - What sort of people have you seen targeted?

OV: It depends on what the attacker wants to achieve, really, because there are two types of attacks. There are the, I say the simple type, where they're just trying to influence an accountant, for example, to make a bank transfer, and we've seen some big, high-profile cases of that, where they may impersonate the CFO. The CFO has put on LinkedIn, "Hey, I'm just about to jump on a plane for nine hours, or I'm flying off to this conference, and they've then used that. But generally, it's because they've already been doing reconnaissance on the company and know that this sort of thing might happen. But then there's also like trying to get in with some kind of vulnerability, and so it all depends on what their ultimate goal is and whether they're looking to deploy ransomware or to take them down, in terms of operationally, or whether it's an immediate payout - let's get somebody transferring a lot of money to where they shouldn't be.

PL: Yeah, I mean, you allude to this kind of - the CFO and the deep fakes and you know mirroring of actual people and live conversations created by AI. All this stuff hits the media. How common is that?

OV: It's becoming more and more common. There was a UK engineering firm, I believe it was 2025, it may have even been as early as 2024, where exactly that happened. A message came through from the CFO to one of the accountants in the Hong Kong office. Asking them to secretly, or, it was a deal that was going on at the moment, and that he needed to make some transfers. Now, rightly so, the accountant was suspicious, and they replied with, "Okay, let's set up a Teams call". And what the bad actors have done is they were basically able to use AI to take the CFO and other C-level execs at this company and emulate them in a Teams call. So these synthetic people in a Teams call. So this accountant joined a Teams call. He sees the CFO. He sees other board members and or C-level execs on this call. They're saying, "Yep, we need you to make these transfers. He goes off and makes it, 25 million US dollars it totalled, and it wasn't until, I think it was a few days later, he followed up, saying, "Right, is there any - now what? And they were like, "What do you mean?" And by this point, the money's gone. This isn't like in the last few weeks or months. This is a good year or so ago that this actually happened.

PL: So just to be clear, they sampled existing video and audio to do that, and of course we all have existing video and audio up on LinkedIn and other places that we are handing them this opportunity on the website?

OV: Yeah, and they say it only takes about five seconds of audio now to get an 85% likeness of somebody.

PL: Five seconds?

OV: Yeah.

KD: But you see, this is exactly the problem. We need more verification. We need to assume that this is going to happen. There's just so many ways that kind of initial access or first level impersonation can be achieved. We just need to be more skeptical about who we're talking to and what they're asking us to do, and if that falls outside of the norms. So I would say to anyone listening that we really need to focus more on verifying and validating whether what we're being asked to do falls outside of habit, because that is a signal. And then it's not bad even to ask a senior, "please, can you verify that you are right? What did we do last week?". Ask them something that only you and them would know. Yes, because even verification of identity might not be enough. And there's so many ways, and controls that you can push, like using your identity and biometrics, but even those can be stolen.

PL: Interesting. So I was going to ask you about verification, and yeah, we think about multi-factor, we think about biometrics, and we're thinking this is solid. No?

OV: Unfortunately not. No, and that's the trouble with cybersecurity, we put things in place and then we kind of go, oh, it's okay, I've got MFA. It must be secure, but the reality is even MFA is easy to breach.

PL: Is it? This is news to me.

OV: Yeah, so there's something called a sort of cookie stealing, or cookie hijacking, using what's called man-in-the-middle technique. So effectively, I could send you a phishing link. It might look like a Microsoft login, for example, you click the link, and it looks like a Microsoft page. So you enter in your credentials. It asks you for MFA because you've got MFA enabled.

But what's actually happening is you're on a rogue server, and the details you're entering are being passed to Microsoft, so the authentication is happening. But we're then capturing all that information. So, we've now got username and password, but really importantly, Microsoft will pass you back, and other vendors are not just people from Microsoft.

They pass you back what's called a session cookie. This tells your browser, “Hey, you are now permitted to log in as you.” But this third-party server that you've actually logged in through has now stolen that session cookie, and they can now log in and access your mailbox, or whatever it might be, as you.

PL: How common is this?

KD: That’s what I'm focused on day to day – identity offensive tradecraft. So, this falls well within those boundaries. We're talking now about session theft or any kind of hijacking. This is all post authentication, right? So, we're talking about a scenario now where someone has authenticated, and we are whoever has authenticated – and that token may already carry their MFA and credentials. That is why we keep hearing about step-up authentication, as in requesting another verification.

PL: And what might that be?

KD: Perhaps for specific sensitive functions, you might require a technical control that requires phishing-resistant authentication at a later point. But honestly, even that, and what we're seeing, at least with SpecterOps, is that the ability nowadays of autonomous agents is such that we'll always find a path – we call it an attack path – towards a target. Because if you give an LLM a mission, it will try to accomplish it.

PL: Absolutely, as we all know, this is really interesting, this question of authentication, because everything springs from this.

OV: Yep.

PL: So, what is the answer here? Because as you mentioned earlier, Kay, this idea of you saying, “What did I do last week? I just want to check that you are you”, does seem to possibly be the most robust way of doing it, isn't it?

OV: Yeah, but they'll always try and find a way around it. Whatever we adapt to, like the video calls where you could say to people, “Just grab something in your background and bring that into display.” There are now videos that are available on YouTube showing that AI can do that. You literally grab a picture off of the wall, for example, and show it.

PL: Yes, because we all used to feel quite confident about that.

OV: No, and I mean, pretty much the only techniques at the moment, if you're on a video call, is get them to turn to the side, maybe put fingers in the front of their face or touch their nose, but even then, it's probably only going to be a period of time before they work out how to do that, and then we're tricked.

PL: So you can't have a system either. You need to be random, presumably, in your procedures as well, don't you? Because otherwise, your bad actors are going to learn your procedures and presumably come up with tech solutions to meet them.

KD: You need to control what happens after they [authenticated], so we really need to enter that “assume bridge plus-plus” situation. We need to assume that security is imperfect, and it will remain imperfect.

PL: Just to be clear, so you're essentially saying we can't keep these people out of organisations. So actually, the defensives must be in here. What do we do now that battle is lost effectively?

KD: It's not lost. It's worth fighting for. You can't just leave open doors everywhere because then the attack surface becomes … you're just creating the risk for yourself. But you need to focus more inside. There is the perimeter that needs to be protected. Do the foundation. Do the basics.

PL: Like locking your front door, locking your windows at home. You do the obvious things.

KD: But also do the basics inside – and the basics inside are no longer MFA. MFA was a basic in 2015. Perhaps at some point we also had phishing resistant authentication in, I don't know, 2024, 2023. Today we are evolving the conversation beyond inside the risk and around what kind of design decisions you made a year ago that will come back to bite you because it enabled someone that is sitting under the lower privilege to step up and go and read something that they shouldn't. I keep on seeing every day – a printer that is effectively a domain admin – and it's not a direct privilege. The printer has some privileges to access something on a service account, and that service account has access to a group, and that group has access to a GitHub.

PL: So, that GitHub is tied in a printer essentially, because the printer then, as you say, has a network of access that goes on and on and iterates higher up the organisation.

KD: It is part of mapping; it's part of reconnaissance.

PL: What else can they hide in?

OV: Well, I do a few talks, and quite often I would say to people, "How many of you have got coffee machines that are Wi-Fi enabled and you've connected to your Wi-Fi?”. And it's amazing how many people just suddenly look at the IT guy, or look around. And people come up to me. Admittedly, they were like, "No, no, no, we don't have anything like that connected to our network.” And then they come up afterwards and they’re like, "Yeah, I've just discovered I've got a coffee machine connected to my network. What is it doing?”.

And the hackers, if they do breach and they get in, often they will look for things like coffee machines and printers and other IoT (Internet of Things). So, these are things that are connected to the internet that you can't control. It's not like a laptop where you can put antivirus or anti-malware on there. How do you install anti-malware on a coffee machine? You don't.

PL: So, this is the equivalent of the stuff we hear about in domestic security around baby alarms, Wi-Fi enabled house alarm systems. That whole thing of, ‘How good is the security on this kid?’. Same idea?

OV: Yeah, exactly that. And often hackers will find a door in somewhere. It may be that they got access to a PC, but they can't do anything on there because they've got good security. They will then pivot to something else that doesn't have great security, and then start launching attacks from there.

PL: So, what's the time frame on this? So, assuming bad actors are living in your coffee machine, then what? I mean, do they sit there and wait and watch? Is this a thing that happens in a day? Is this a week, a month? How does it work?

KD: We are definitely seeing that the window between that kind of lingering around and building reconnaissance to executing is becoming less and less. In the past, an attacker would have to pretty much reside for months, depending on the size of the organisation as well, right? If it's now a small law firm, perhaps the whole reconnaissance thing might be days, or if it's AI driven, it might be minutes on a larger enterprise because they understand that there are also enterprise defences in place. The aim is to evade them, which means that you spend more time understanding what could trigger a tripwire, what could be a honey token, what could be a trap in there, but the execution itself [might be] eight seconds minutes because it's well planned.

PL: So, yes, when you're actually at that point, but the getting there, the route map, and getting to that point where they can execute this theft, or whatever it might be, depends on the organisation. How might they show up? As you say, they might trigger good defenses inside internal systems. But what do organisations need to do to make sure that's actually happening?

OV: So, we've spoken about AI sort-of from an offensive side, but AI can actually be really good for defence as well because one of the things that AI is great at doing is spotting anomalies, like unusual behavior. OK, so if you're using AI inside your network, it's what I call baselining the traffic, so it understands what's happening inside a network. Every network is different, even if you've got the same equipment, it will still be used differently.

What AI can do is understand, “OK, what is the normal behavior for that?”. So, if a coffee machine suddenly starts doing port requests or SMB (server message block) requests or port scans, that's unusual behaviour, and the AI can flag that up, and you can automate defences, whether that's shutting down network ports or even just generating an alert to to go and unplug the coffee machine, for example. AI can actually detect that really quickly, and the same on a user's laptop.

If somebody comes into their day [and] their normal activity is accessing Teams or maybe a file share and printing, that's their normal behaviour. They then start connecting to the coffee machine because actually their device is looking for other bits that it can move to. Then again, it can flag up an alert if they've got connected to the endpoint.

We can isolate the device as well, so we can use AI to actually look for the noise, which often these bad actors bring in when they're looking for vulnerabilities and sort-of sniffing the network that generates a lot of noise. But in most businesses, they just don't see that noise because how do you understand the data?

PL: Yeah, who's looking for it as well, isn’t it? Because it's having the systems that can actually spot it, and then the training for the team – if you have a team – or an individual who then looks at those and thinks, yeah, that might be a red flag for us. And I'm guessing most organisations just don't have that?

OV: No, and it's been a problem worldwide for years – there is a severe lack of cybersecurity engineers or experts. And if you think probably 15 years or so ago, most businesses thought, well, we'll either have an internal IT team, and they will do everything, and security would fall under their remit. But in today's world, because cybersecurity is so much easier for the bad actors, there are a lot more bad actors out there. It's more accessible, but just internally, you can never keep up with that.

PL: Do you get the sense that organisations are still in the place where they're thinking, yeah, if we've done penetration testing, if we've done a review six months ago or a year ago, it's kind of fine, we're on top of this? And they're not understanding this is an everyday problem?

KD: So, enterprises understand that this is an everyday problem.

PL: They do?

KD: Right. Large enterprises especially, they understand. They have the maturity required to sort-of understand this is a continuous problem. Most CSOs (chief strategy officers) are very, very well aware of that. They do rely on the teams to some extent to sort-of give them the upstream understanding of whether the risk decisions that they made have been implemented.

Unfortunately, the operational teams – because they inherit those decisions and sometimes they inherit tools as well – do have a tendency to sort-of say yes, this has been done and that has been done. It's that gap that an attacker would misuse in smaller organisations. I would say the maturity is not there.

PL: And the resources? I mean, this is a resource-heavy issue.

KD: It’s also a model problem as well, to some extent – and they're changing. But they have that kind of reactive model in place where they wait for a ticket to appear. And I understand that the UK, especially, is putting controls in order to sort-of make MSPs (managed service providers) more security aware, but if we're talking about a small business, like a law firm in Manchester, they would probably have an MSP, and that MSP is would be probably charging additionally for kind of incident response or continuing budget as well. But that's no longer an option. You either get something that is proactive and looks for this, and you support your customer, or your model is a bit behind.

OV: I agree. And going back to “Hey, if we do cyber essentials…” is a good one in the UK. The amount of people I've heard go, “I've done cyber essentials, so I'm good for a while.”

But what I always say to people is that it's a bit like your car MOT. You can take it for an MOT today and it will pass. But if you decide tomorrow you're going to go and change your exhaust and your brakes and everything, and that's not being verified to make sure that the changes you've made are actually roadworthy, you could then fail the MOT the following day. But if you're waiting a whole year, you're not going to find out about it – and that's what happens in the cybersecurity world.

We do these pen tests, we do cyber essentials. A lot of especially mid-sized businesses see it as a bit of a tick-box exercise: “Yes, yes, we've done this” – and then, “Sorry, IT teams.” The IT teams run wild for a year and do whatever changes they make they want to make – and sometimes they can leave gaping holes.

PL: And create these vulnerabilities. What do you say then to clients about how they can deal with this? I mean, it can't be an unlimited cost for businesses, can it?

OV: No, no, exactly. So it is often, especially for sort-of mid-sized business, [which are] the majority of businesses, especially a law firm, it's partnering up with an MSP, a managed service provider, who can often have the guidance as to where to focus efforts.

I think we do need to realise though that there is more budget required for cybersecurity. It's kind of annoying the amount of conversations I've had over the years where you speak to a company and they're like, “Oh, we just can't afford it, so we skip it”, and then six months down the line, you speak to them again, and suddenly they've got budget, and you're like, “What happened?” “Oh, we got breached.” Yeah, and you're like, “Okay, so that breach has now cost you more money, and you're now still buying the tools, whereas if you bought them before it would be better…

So, this is a board level problem. Often, IT is like, “Well I just let the IT team worry about that and give them as minimal a budget as possible.” But in reality, people do need to wake up to the fact that the IT budget, especially around cybersecurity, needs to be increased and taken seriously.

PL: There's so much talk about AI now in the business space and people understanding the sheer pace of change and iteration. Do you think that's going to leverage understanding of this issue; that people will see if this stuff six months ago is like a different country; everything is different now because everything is iterating so fast? Are you feeling that perhaps there might be a bit more traction for guys like you?

KD: It's like everyone is creating micro applications for their use cases, especially in mid-sized businesses. I guess there are not even controls in place to control what these applications are doing or how they're pulled, and people might even have local administrator access on their devices to just do whatever they need to do, because that's part of the convenience, especially if there's not a mature IT environment.

Of course, you have bigger problems there, but let's say these sorts of risks are amplified. People will create specific apps that serve their own micro use case, and they will serve these apps. And some of these apps will contain risks, or what I have seen, for instance, there was a famous extension. I don't remember the name [but] it was a very popular extension that was actually disclosing all your chats, whether it was ChatGPT or Copilot to a third party. And that was downloaded millions of times, even on devices where the local admin protections were there because the browser was not protected.

You had the extensions that are Microsoft inside the browser, which is primarily what we use today, effectively being allowed and enabling some third party to do the same thing: exfiltration of data.

PL: And we haven't really talked much about penetration testing, pen testing. Is it worth doing? Because it is just today. Is it useful?

OV: Yes, but again, it shouldn't just be a tick-box exercise. I think it's a good way of understanding where you're at.

PL: Particularly with legacy systems, presumably?

OV: Yeah, in particular, legacy systems, but in today's AI world as well, it's kind of like you can do a pen test today, and then there'll be some completely new vulnerabilities disclosed tomorrow or discovered tomorrow.

PL: So, it's just part of the toolkit?

OV: Yeah.

PL: And we haven't talked about what these criminals do when they're there. They're inside your organisation. We all know about ransomware and data theft and so on. What's the most usual scenario? What do they usually want?

KD: Well, ransomware is the obvious that is being heard, right? But most of those that go silent are the ones where there was data theft or information theft to achieve another target, and sometimes you might not even target, for instance, that law firm in our scenario. You might target a supplier.

PL: Or a client?

KD: Right, or a client, to get information that would enable you to target something else. And this is like the kind-of supply chain attacks, which is even another target. In some cases as well, criminals might be just in the market to sort-of get that initial access, build that persistence, and then sell it to another more capable group that can actually do the execution.

PL: Oh, interesting! So there's also a half-formed product; they'll sell it on to a different team.

KD: Like, “We have access to that, so we're offering that for X, Y, Z.” Of course, there are other risks in there that need to be accounted for, and we've seen those in the wild where people had an outsourced firm, some where employees of that firm were enticed to give their own credentials. To provide the access. That happens. But it just proves that, as to your original point, that any access is enough.

PL: So, in the same way that a junior employee might be a route to a more senior employee, your organisation might just be a stepping stone to a whole bunch of other organisations?

OV: And if you think about the law firms, say, if they did decide to disrupt you, I mean, for a bad actor or a hacking group, it may be that they're going to just look to disrupt you. And one of the questions I often hear is like, “Well, why would they care about my data?” And often they don't, but you do. And if you can't access your data, you're then out of business. You're not able to trade. So, it's valuable to you to get that data back as quickly as possible. So, you then pay the ransom fee to gain access to it.

PL: That's an interesting point because I think we've all wondered that. You know, data. So what? And presumably, it's also if it's a client situation or a supply chain situation, you don't want that data in the public domain. It's not really your data, is it? So there's a risk to the relationship.

OV: And ultimately, you're dealing with criminals. So, say if they run somewhere due, so they encrypt your systems, and prevent you from accessing it, you panic. You're a mid-sized firm. You haven't got redundant backups, or they've been able to encrypt your backups as well. So, you you go, OK, I really don't want to do this, but I'm going to pay the ransom fee. You get access to your data. You think everything's rosy.

Two weeks down the line, you get an email come through: “Oh, we want some more money, otherwise, we're going to start disclosing your client information.” And then you're kind-of stuck that you're having to pay again because otherwise they're threatening to leak your client data.

PL: Is there anything to be done about that, or do you just have to pay?

OV: Well, it's up to you then whether you take that risk of paying because, OK, you're dealing with criminals. You may pay – and they may still leak the data or sell the data, or you don't pay and they may leak it. They may not do. They may sell the data. So you're kind-of stuck in this rock and a hard place, which is why you never want to get to a position where your data's stolen.

PL: I'm interested to know how they think about how much to ask you for as an organisation. So, they're highly organized people, right? They've done a lot of research. How do they work out the number of what this ransom figure is going to be? Because it needs to be doable, doesn't it? It needs to be something the organisation can pay. Is it usually a very big number, or is it a number where the board can think, OK, we'll pay?

KD: Yeah, I mean, like this is more or less like a sales process where you throw a number in there and we might get 50% of that.

PL: They negotiate?

KD: Yeah, but it's like this is part of the as-a-service. So, we're now talking about ransomware-as-a-service. These are professional businesses. They run like an organisation. They run as a business. So they will sell you back your data under a quotation that starts at the number…

PL: At a price they think you can afford?

KD: Yes. The worst thing that you can do in those cases is start negotiating, but it depends on the organisation [and] what level of resilience they had in place, which is another topic on its own.

PL: If an organisation has a ransomware attack, they literally saying, “We want whatever it is, half million”, what should they do at that moment?

OV: I would always seek professional help. Like, there are people out there that are trained to deal with this. Don't try and negotiate yourselves.

PL: So, that might be you, and you would negotiate?

OV: It wouldn't be me or the company I work for, but there are [companies]. I mean, the national crime agencies themselves say that it should be reported to them, and they may even have negotiators that would go in.

PL: Do they?

OV: Yeah.

PL: OK, I didn't know that.

OV: Sometimes – going back to your figure or your question of how they come up with the figure – they may just do a simple LinkedIn search, work out the size of the business, maybe even just based on what they've gained access to.

There has been one UK case where they produced a number. It was several million. The company replied with, “We could never afford that.” And then the cybercrime group replied with, “Here's a copy of your cyber insurance that shows how much you're covered for.”

PL: Wow!

OV: And it was the figure that they were asking for. So it depends on who it is and what data they've got. But they're not stupid. Like you said, they do this as a professional business. It's how they fund their states, their businesses, whatever it might be, so they're well equipped to find out things like how much you are covered for cyber insurance.

PL: Well, yes, because I guess it's payback for them. It’s that they put a lot of work in for no reward until they get paid.

KD: All in all, you can't assume ethics with someone that's a criminal, right? And you can't expect that they may not attack you again, so this is part of why it matters to bring in professional help at that point.

I hope for everyone listening that we sort-of move into that kind of proactive preventive stance more than just discussing the resilience and the disaster recovery part. But this is also needed. You need to have backups in place. You need to have your data somewhere else. You need to be able to restore and have tested this.

And to your point of whether pen testing is required, security testing, I would say this is absolutely required. Why? Because you always need a third-party independent audit on what your IT team is doing. You might have a very competent security team and IT team. You always need some third party to validate because it's easy to sort of cross out my homework and say yes, yes, giving me a pass. And that happens either because this is part of my interests, so my job description is to ensure that this has a pass, or because of a lack of depth, and depth is only going further, right?

So, we used to be generalists and had a wide sort of understanding in IT of what works and what not. Today, we see that identity security has so much depth. For instance, network security has so much depth. You can't keep up. You can't expect one person, for instance, or a two-person team, or even a 10-person team to know everything.

PL: OK, that sounds like that might be the most useful lesson from this. That grasping, that understanding.

OV: Yeah, it's defence in depth. There's no one solution that's going to protect you from everything. There's no one person that's going to protect you from everything, and it is sort-of layering up as much as possible.

PL: And just understanding your internal team – if you have one – is just the starting point.

OV: Yeah.

PL: OK, thank you. Sobering, but absolutely fascinating. Thank you very much indeed.

KD: Thank you.

PL: If you're an ICAEW member, remember to click through from the show notes to the ICAEW site to log your listen to this podcast as CPD before you forget to do it. We have a bonus episode next. We'll have the Department of Business and Trade on the podcast talking about the modernisation of corporate reporting. After that, we'll be on location at the ICAEW annual conference. Do not miss it. Thanks for being with us.

Open AddCPD icon