91Ƶ

OP-ED: Businesses ought to be on alert for possible cyberattacks

By: Stephen Scott//March 3, 2022//

OP-ED: Businesses ought to be on alert for possible cyberattacks

Stephen Scott//March 3, 2022//

Listen to this article
Stephen Scott

“Stephen – America is under attack.” These are the words that my dad woke me up to on Sept. 11, 2001. Talk about a jarring way to come out of a deep slumber as a middle schooler. It’s a story that I have shared with many friends and colleagues. There is a collectiveness related to world events and where you were when something happened.

Now that I am the dad, I am faced with the realities of these tough conversations that no one wishes to have. That brings us to last week, when Russia invaded Ukraine. While I had to have a tough, esoteric conversation with my son, I also engaged in others with business professionals as the Russia-Ukraine conflict triggered a ripple effect. In fact, federal cybersecurity officials have issued warnings to American businesspeople to get their “shields up,” because Russian cyberattacks against U.S. interests are all but certain to be launched in the coming days. What are 10 steps people can take today to help prevent these malicious attacks on their businesses, and what should people do if they fall victim to them?

What does modern warfare look like for American businesses?

Modern warfare has evolved beyond local, on-the-ground, physical conflict, as Russia has proven that its cyber capabilities span worldwide. Recently, Russian hackers have been linked to numerous cyberattacks on Ukraine, including reports of mass distributed denial-of-service (DDoS) attacks this week coinciding with the invasion. And other events have demonstrated that the United States is not off-limits. Last year, suspected Russian hackers were successful in launching a ransomware attack that resulted in the shutdown of the Colonial Pipeline, one of the largest refined oil pipelines in the U.S.

In the past, Russian APT actors have been known to deploy spear phishing, credential harvesting, brute force/password spray techniques, and known vulnerability exploitation against networks with weak security. These cybercriminals exploit unknowing employees, simple passwords and unpatched systems in order to gain access to the existing networks, and then acquire and steal company data. These hackers have been successful in infiltrating cloud-based networks and enterprises such as Microsoft 365, and have utilized malware in order to extricate sensitive data from these networks.

10 steps businesses should take today to get their shields up

U.S. financial institutions, government contractors and critical infrastructure sectors, such as electric utilities, are on alert for any Russian activity. However, a “shields up” warning has been issued to all U.S. businesses to protect against potential cyberattacks. Thus, it is wise for U.S. employers to take the following steps today to shore up all cyber defenses:

  1. maintain remote access vigilance, especially in light of the multitudes of workers who continue to work remotely;
  2. require multifactor authentication to access internal networks;
  3. keep security software up to date and institute timely system patching;
  4. enable robust spam filters;
  5. enforce strong, unique passwords with multiple characters (including numbers, letters and symbols) and require that they be changed routinely;
  6. encrypt data at rest and in transit whenever possible;
  7. implement robust cybersecurity user awareness and training programs for new workers upon hire and at least annually for existing employees;
  8. immediately disable credentials upon employee departure;
  9. create data backups with regularity; and
  10. ensure there is a strong cybersecurity team in place to not only monitor the network for vulnerabilities and any suspicious activity but also to develop and deploy an incident response plan (including response and notification procedures) in the event of a compromised system.

Despite these 10 points, the past two years have taught employers to be ready for the worst. That begs the question: What should I do if my company is successfully attacked?

Six things to do if one’s business falls prey to an attack

If your company becomes the victim of a cyberattack, your cyber incident response plan should be immediately deployed to take the following steps:

  1. determine which systems were impacted and immediately isolate them;
  2. if affected devices cannot be removed from the network (or if the network cannot be temporarily shut down), power infected devices down to avoid further spread of the ransomware infection;
  3. triage impacted systems for restoration and recovery;
  4. engage your internal and external stakeholders;
  5. consider retaining a third-party incident response provider with experience in data breaches; and
  6. notify affected individuals and report the incident to your local FBI field office.

Companies that become victims of a cyberattack should hire legal counsel with data breach experience to provide advice on potential notification obligations and to ensure compliance with reporting requirements. Companies should also engage appropriate vendors to assist in investigation of the incident.

Stephen Scott is a partner in the Portland office of Fisher Phillips, a national firm dedicated to representing employers’ interests in all aspects of workplace law. Contact him at 503-205-8094 or [email protected].

The opinions, beliefs and viewpoints expressed in the preceding commentary are those of the author and do not necessarily reflect the opinions, beliefs and viewpoints of the Daily Journal of Commerce or its editors. Neither the author nor the 91Ƶ guarantees the accuracy or completeness of any information published herein.



News

See All News

Commentary

See All Commentary

COMMUNITY CALENDAR