Stephen Scott//March 3, 2022//

“Stephen – America is under attack.” These are the words that my dad woke me up to on Sept. 11, 2001. Talk about a jarring way to come out of a deep slumber as a middle schooler. It’s a story that I have shared with many friends and colleagues. There is a collectiveness related to world events and where you were when something happened.
Now that I am the dad, I am faced with the realities of these tough conversations that no one wishes to have. That brings us to last week, when Russia invaded Ukraine. While I had to have a tough, esoteric conversation with my son, I also engaged in others with business professionals as the Russia-Ukraine conflict triggered a ripple effect. In fact, federal cybersecurity officials have issued warnings to American businesspeople to get their “shields up,” because Russian cyberattacks against U.S. interests are all but certain to be launched in the coming days. What are 10 steps people can take today to help prevent these malicious attacks on their businesses, and what should people do if they fall victim to them?
What does modern warfare look like for American businesses?
Modern warfare has evolved beyond local, on-the-ground, physical conflict, as Russia has proven that its cyber capabilities span worldwide. Recently, Russian hackers have been linked to numerous cyberattacks on Ukraine, including reports of mass distributed denial-of-service (DDoS) attacks this week coinciding with the invasion. And other events have demonstrated that the United States is not off-limits. Last year, suspected Russian hackers were successful in launching a ransomware attack that resulted in the shutdown of the Colonial Pipeline, one of the largest refined oil pipelines in the U.S.
In the past, Russian APT actors have been known to deploy spear phishing, credential harvesting, brute force/password spray techniques, and known vulnerability exploitation against networks with weak security. These cybercriminals exploit unknowing employees, simple passwords and unpatched systems in order to gain access to the existing networks, and then acquire and steal company data. These hackers have been successful in infiltrating cloud-based networks and enterprises such as Microsoft 365, and have utilized malware in order to extricate sensitive data from these networks.
10 steps businesses should take today to get their shields up
U.S. financial institutions, government contractors and critical infrastructure sectors, such as electric utilities, are on alert for any Russian activity. However, a “shields up” warning has been issued to all U.S. businesses to protect against potential cyberattacks. Thus, it is wise for U.S. employers to take the following steps today to shore up all cyber defenses:
Despite these 10 points, the past two years have taught employers to be ready for the worst. That begs the question: What should I do if my company is successfully attacked?
Six things to do if one’s business falls prey to an attack
If your company becomes the victim of a cyberattack, your cyber incident response plan should be immediately deployed to take the following steps:
Companies that become victims of a cyberattack should hire legal counsel with data breach experience to provide advice on potential notification obligations and to ensure compliance with reporting requirements. Companies should also engage appropriate vendors to assist in investigation of the incident.
Stephen Scott is a partner in the Portland office of Fisher Phillips, a national firm dedicated to representing employers’ interests in all aspects of workplace law. Contact him at 503-205-8094 or [email protected].
The opinions, beliefs and viewpoints expressed in the preceding commentary are those of the author and do not necessarily reflect the opinions, beliefs and viewpoints of the Daily Journal of Commerce or its editors. Neither the author nor the 91Ƶ guarantees the accuracy or completeness of any information published herein.