
The Cyber Crime Lab Podcast · 2023-03-15 · 28 min
Key moments - from our scoring
Substance score
45 / 100
Five dimensions, 20 points each
Koen Backers, managing principal incident response consultant at SecureWorks (in the role since 2003), discusses the human and technical sides of responding to cyberattacks. The first case involves a nonprofit director whose Instagram account with 15,000-20,000 followers was hijacked by a Turkish threat actor demanding ransom; Backers leveraged his industry network to recover it within 24 hours without formal IR engagement. The second involves a customer notified of data on a Name and Shame dark web site - only to discover through threat intelligence driven analysis that the 400GB supposedly belonging to them actually belonged to a Southeast Asian financial institution, which the threat actor later corrected. Throughout, Backers emphasizes the emotional trauma of victims during scoping calls, the importance of breaking down complex incidents into manageable blocks, and the operational reality of incident response: two to three weeks of around-the-clock work, isolated networks, forensic preservation, and the challenge of maintaining resources across the entire engagement. He details how SecureWorks deploys agents for triage data rather than traditional full disk forensics, builds complete visibility of attacker footprint and pivot points, and plans eviction using a clean point of return (the last uncompromised backup). Key vulnerabilities discussed include lack of multi-factor authentication, bypasses of MFA on vulnerable underlying platforms (firewalls, VPNs), and MFA fatigue attacks (as seen in the Uber breach).
Incident response engagements typically last 2 - 3 weeks of continuous 24/7 effort, during which organizations must maintain quarantined networks, preserve forensics, and plan eviction without full access to their systems or data.
The IR team conducts a scoping call to understand the initial alert, affected machines, and any preceding suspicious activity (phishing, credential requests, or system anomalies), then builds a timeline of the attacker's initial access, lateral movement, and objectives.
Throttling downloads to take 30+ days puts pressure on victims by making it impossible to verify or download the data within the threat actor's stated deadline for ransom or public release, encouraging faster payment.
The clean point of return is the latest backup prior to the first confirmed threat actor activity; organizations rebuild systems and data from this point to ensure complete removal of attacker access and persistence mechanisms.
Yes - if the underlying platform running MFA (such as a VPN, firewall, or SSO provider) is vulnerable, attackers can bypass MFA entirely; additionally, MFA fatigue attacks (constant approval requests) can cause users to eventually approve unauthorized access, as happened in the Uber breach.
Our reviewer’s read on each dimension, with quotes from the episode.
There are pockets of genuine operational value - the clean point of return concept, the throttled 400GB download as a pressure tactic, and the risk of getting hit twice during partial remediation - but the episode is heavily padded with obvious advice (patch systems, use MFA, watch phishing) and conversational throat-clearing that dilutes the signal sharply.
I've seen customers being hit by ransomware twice, actually not at least once in I think two months difference. So while they had not correctly remediated the previous incident, then they got hit by the second group
the actual download of the 400 gigs would have taken about 30 days...to put the pressure on you is my take on this
The name-and-shame misattribution story and the throttled download observation are mildly novel, but the episode closes with the most recycled possible cybersecurity advice (patch, MFA, watch out for phishing), and most frameworks presented are standard IR 101 with no contrarian or first-principles thinking.
things can be prevented for a large part, obviously, if you have your latest security patches, your latest updates installed
using multi factor authentication on all accounts. It basically provides you at least with a second layer of security
Koen Backers is a genuine practitioner - managing principal IR consultant at SecureWorks with 20+ years in the field - who has clearly done the work at scale; however, he is not a senior executive or widely recognised authority, and the podcast is transparently a marketing vehicle for the host's insurance firm, which limits depth.
I've been in the CyberSecurity space since 2003, mainly operating in what I call the ecosystem of security, operations center, instant response, and threat intelligence
SecureWorks is operating as a business, but we're also humans behind those hotline numbers
A handful of concrete details appear - 400GB dataset, 30-day throttled download, 15 - 20K Instagram followers, 2 - 3 week typical engagement length, the Uber MFA fatigue incident - but most case details are anonymised, dollar figures are entirely absent, and the bulk of claims remain illustrative rather than evidenced.
they were claiming to have 400 gigabytes of one of our customers ready for download on that site
the actual download of the 400 gigs would have taken about 30 days
The host occasionally lands useful follow-ups on logistics (spare laptops, remote workforce, timeline expectations) and pushes on the semi-compromised state risk, but there is significant filler, no genuine challenge to any of the guest's claims, and several tangents that go nowhere productive.
I have a friend and he's always joking. He's like, I can only deal with one problem at a time
pays to know the right people
Computed from the transcript - who did the talking, and the words that came up most.
Going through a cyberattack can feel like having a heart attack, and sometimes those calling in for help during one actually are having them. something that Coen Bakkers , Managing Principal Incident Response Consultant at Secureworks has experienced firsthand. Coen joins host Andy Anderson to describe what it takes to get a victim from their first call to a state of recovery, including: - Listening and building trust: hearing out someone in their early stages of panic and reassuring them. - Setting timelines: often Coen and his team are engaged for 2-3 weeks in solving a problem, and clients have to pace themselves so as not to drop from exhaustion. - Starting an investigation: where to look and what to rule out. Coen Bakkers - Secureworks - The Cyber Crime Lab Podcast is
Transcribed and scored by The B2B Podcast Index.
Speaker A: I offered to her and said, listen, I can try to basically activate my network within the community and try to see if we can get your account back. We're going to solve this problem with you, together with you, end to end. You don't have to worry. Everything's going to be fine. And, um, so the next day, I basically sent some emails off to people I know in the industry, and within 24 hours, she had her account back.
Speaker B: This is the Cybercrime Lab, a podcast about true cybercrime stories, the impact on victims, and what businesses can do to protect themselves and their customers. And if you think you're not at risk, that is exactly where attackers want you to be.
Speaker C: My experience, it only takes hearing what these attacks are like a few times to realize you need to prepare yourself for what could be a business ending experience.
Speaker B: That's Andy Anderson, the founder and CEO of Data Stream Insurance. For over a decade, Andy has been working with victims of cybercrime. He's seen firsthand the human impact of a cyber attack. Now he's on a mission to shed light on the threats we all face from a world we can't see. Today, Andy has invited Cohen backers to the Cybercrime Lab. Cohen is the managing principal Incident response consultant at SecureWorks, a leading international cybersecurity firm. He's been in the cybersecurity space since 2003, and in that time has helped countless victims bounce back from cyber attacks. He'll walk us through two very specific incidents that were recently encountered at SecureWorks. And unlike many of the stories we've shared, these both have happy endings, which longtime listeners know isn't always true in the world of cybercrime.
Speaker C: Cohen, thank you so much for joining us on the Cyber Crime Lab podcast. For those who don't know you don't know your firm, I'd love if you'd just take a minute and introduce yourself and who you work for.
Speaker A: Sure. My name is Koen Backers. I'm working at, uh, SecureWorks currently since, uh, about three and a half years. But I've been in the CyberSecurity space since 2003, mainly operating in what I call the ecosystem of security, operations center, instant response, and threat intelligence.
Speaker C: I was excited to have you on to sort of give us a day in the life of what it's like to deal with these incidents and how they often play out. But we were talking and it sounds like we have two different incidents that we can talk about and maybe use them to highlight what that experience is like. So why don't you kick it off and tell us what these two incidents were like?
Speaker A: Well, maybe foremost I'll start. How does an incident start on our side? So basically starts with a scoping call. The scoping call is someone that calls in into the IR hotline, basically with a problem that they'd like us to solve and help them with. Usually these people are quite in distress on the time pressure. And, uh, sometimes we even operate as some, uh, form of psychologist. During those incidents, we've had actually multiple customers being close to getting heart attacks as well while we were talking to them. So quite stressful.
Speaker C: We've had some other guests talk about this, but, you know, it's not the first thing that you think about, but the sort of emotional distress of one of these incidents, it's because it's often scary, it's different. And it's often like the business that you have been building or running is suddenly crumbling to the ground.
Speaker A: But the first thing to do is win the trust of the customer that you are going to basically help them with the distress moment that they're currently going through. So if you actually feel with them in the first moments, build that level of trust, then you can start talking about, okay, now let's get this sorted. Let's get you started. We're going to solve this problem with you, together with you, end to end. You don't have to worry, everything's going to be fine.
Speaker C: Is it that trying to get them to, like, see, you know, that there's a plan and a process and whatnot, is that sort of the big thing that you're trying to do is to say that this isn't.
Speaker A: Usually customers feel overwhelmed and you try to basically break it down in manageable blocks. Once you start basically pulling everything apart and saying, we've got several elements in this part of an attack, and you basically start discussing, here's how we're going to address each of these different elements. Then obviously people start to think in it in a more controllable way and feel more on top of things than just looking at the big bang that basically occurred in front of them.
Speaker C: I have a friend and he's always joking. He's like, I can only deal with one problem at a time. We'll deal with one and then the next and then the next. But like, I can't deal with three all at the same time.
Speaker A: No, that's true.
Speaker C: Okay, so, and it's literally like a hotline. People call in and how do they usually find you? How do they come to connect?
Speaker A: So Usually they start looking up just websites, and it's a response via, uh, your best friend, Dr. Google on which will likely show up. Obviously, we get a lot of referrals, too, from people that have worked with us in the past. Usually people just Google us. So one of those links ladies that I was recently talking to, she'd actually read an article that one of our counterfeit unit researchers had published about ransom demands on hijacked Instagram accounts. She was in a case where her Instagram account had been compromised, taken over by what we believe to be a Turkish threat actor group. And they were basically asking for a demand of money for her to get back control over her Instagram account. Now, she was using this Instagram account for a nonprofit organization, but it was very strong. She had 15 or 20,000 followers and strongly using that channel for her to get donors to donate for a nonprofit organization. And she had tried to contact Instagram support, Facebook support, and trying to get the account back. Unfortunately, she did not get anything useful out of that. And actually, she was crying when I was talking to her the first time over the phone.
Speaker C: Wait a minute. So this woman has a big Instagram account and someone's taking it over? They grabbed the credentials. You can't just call, like, Facebook and Instagram. Like, they won't listen to you. I mean. Well, yeah. What number would you call? Do they even have a number?
Speaker A: Obviously, there's support forums for these kind of things, but you have to imagine the level of scale that these social media websites deal with. There's thousands of people that have security breaches and issues on a daily basis, and obviously they can only deal with X amount per day. And sometimes it just falls below a particular threshold, I assume, based on my experience.
Speaker C: Yeah. So you're just, like, screaming into the abyss, basically.
Speaker A: Exactly. Yep.
Speaker C: All right, so she calls your hotline. So we'll hear how that one plays out in a minute. But let's hear the other one, a slightly different one.
Speaker A: So the other one was an existing customer of ours, was basically notified by the press that there was some, um, data leak on a Name and Shame side of a known threat actor group.
Speaker C: For those who don't know what that is, what's a Name and Shame website?
Speaker A: Name and Shame is basically a website on the dark web where ransomware threat actors will publish victim information, the name of the victim, potentially some details about the company and what businesses they are in. And then sometimes a sample or a part of a data dump will be published or revealed with the intent of having basically the Victim, obviously, pay the ransom or the full data will be, uh, released.
Speaker C: Which is kind of wild, right? I mean, I think we've talked about this, like, the double and triple threat. It's not just like they'll mess with people, but they'll also shame them and then even sometimes contact their customers or other parties. So one of the reasons that we started this podcast was to get rid of the victim shame and the victim blaming. That often happens. And the biggest concern is, oh, my God, I'm going to be perceived as not having good security, not doing the right things, not taking care of my customers, and that's going to destroy my reputation and my business because I'll see. That's like I'm tainted or something. All right, so take us back to these two that you're dealing with. The lady who calls who lost access.
Speaker A: The lady, when she called me, was really crying on the phone, and I really felt for her. SecureWorks is operating as a business, but we're also humans behind those hotline numbers. And so when she called in, I really felt that from a business perspective, there wasn't anything I could do for her. The poor lady had lost control of her Instagram account that she was using for a nonprofit organization and was using that Instagram account with what, 15 or 20,000 followers to get donations for a nonprofit organization. So losing control of that account was like almost losing her pet project, her thing, basically. Now, obviously, I couldn't do anything for her directly as a business. However, I offered to her and said, listen, I can try to basically activate my network within the community and try to see if we can get your account back. And, um, so the next day, I basically sent some emails off to people I know in the industry, and, uh, within 24 hours, she had her account back.
Speaker C: Pays to know the right people.
Speaker A: Unfortunately, it's still a lot about personal connections in the business.
Speaker C: I wouldn't really think of that as a thing that people were targeting. You know, you saw some Twitter stuff where, like, some crypto scams were done where Elon Musk and other big, very big name accounts were taken over. But, yeah, it's sort of sad. That's a way that people are doing it. And I guess you don't realize how valuable it is to you as a business until you lose access to it.
Speaker A: No, exactly.
Speaker C: How about the other one? Because that's a slightly different case.
Speaker A: Oh, absolutely. So the other one is actually an existing customer of ours got notified by the press that it was basically a post on a name and shame leak. Site of a known ransomware threat actor group, and they were claiming to have 400 gigabytes of one of our customers ready for download on that site. One of the interesting parts is when we started downloading the data to try to analyze it, we noticed that the speed was throttled, and the actual download of the 400 gigs would have taken about 30 days, which is quite interesting. We actually actually tried this from multiple locations. Since we're a global company, some people in Asia and the US And.
Speaker C: And why would they do that?
Speaker A: Basically, to put the pressure on you is my take on this. Obviously, I don't have any hard facts, but honestly, it's a good way to put more pressure on the victim and saying, oh, I'd never be able to. Within the time that the threat actor threatens to release my data or threatens to publish my data, will I be able to actually download that data? So for me, it's a good tactic if it is an intended tactic, and
Speaker C: I want to download it so that, like, I know that it's mine or.
Speaker A: Well, exactly. Now, what I didn't know when I started downloading is, is actually when you download the pieces of the archive, you could actually see what's inside the archive. And when I started looking at the data, I was like, weird, this looks so different from what I would expect from this particular customer. And I started doing some keyword searches across the raw data just with some letters of my customer name. And I did find a match, but it was only matching basically part of the customer name. And then the more I started downloading this data with my colleagues in the Threat Research Unit, we discovered that this was basically not at all a customer based out of Europe, but basically some Southeast Asia financial institution.
Speaker C: It was the wrong name.
Speaker A: It was the wrong name. And the customer basically said, well, first of all, I don't know anything about ransomware. The only link to a incident that I have is what's published on this name and shame site. And they basically said, well, it's not our data. And now here comes the fun part. About 10 days into the incident, the threat actor must have noticed this.
Speaker B: Between social media takeovers and ransomware attacks, Cohen has seen it all. What makes his story so heartwarming is that even when he knows the firm couldn't completely save the victim, they still went out of their way to try people like Cohen make the world of cybersecurity more human. And they aptly remind us that there are real people on the other side of those hotline numbers. Next, Cohen talks about how Threat actors manage to get a hold of data and what the first few hours of an incident report look like.
Speaker A: I mean the reality is from all the cases I've worked so far, we still keep it way too easy for threat actors to come in and compromise a network, A, uh, machine, an account. A lot of customers are still dealing with not having multi factor authentication, so just a password to protect their account. And that obviously makes it easy for threat actors having at their disposal a lot of weapons and methodologies to get to that password. And once they have the password, they're uh, just straight in.
Speaker C: You've been doing this for a long time. What's the sort of normal, what's the process of an incident response? What actually happens in the couple of hours, minutes and hours after that call comes in.
Speaker A: So first of all we do a scoping call with the customer to try to understand what occurred based on their experience, based on their findings and notes. So we ask things about when did you observe the first alert? Which machine did you notice this on? Was there anything prior to that that you've noticed that could have be of interest? A phone call, maybe a phishing email or an email that looked fishy, that asked to provide some credentials? It's really poking into the story with little knowledge of what's actually going on or what has actually happened. And it's actually quite challenging. Once you get to that point and you finish the scoping call and you basically put out a proposal to the customer to engage with, if they approve, is then you then start getting more to actually start building the story or the timeline of events, which usually will start with an initial access where the threat actor gains the initial foothold on um, a victim network, then expanding the access and potentially working towards the actions objectives, which will be different depending on the threat actor that you're dealing with.
Speaker C: This is one of those things that I'm curious about is how you do that. So do you deploy agents across like their whole network? How do you know kind of what's been touched and what hasn't been? That must be the level of spread that an incident has reached. It's got to be a really interesting one.
Speaker A: That's true. And I mean if you look at it from an analysis and what we call forensics perspective, I think the way we do forensic today is different than for 10, 15, 20 years ago where you would do traditional disk analysis of one specific system. The problem is today you're dealing with a lot of more systems. The data is also in multiple locations. People no longer Just have their data on their laptop or their desktop, it's in the cloud, so you actually have to look at other data sources and obviously getting visibility with that. One of the ways we are successful at this is by deploying our agent if the customer doesn't already have one. So our existing customers often have it. Uh, customers that are, we call New Net, new customers don't have that agent. And then deploying that agent allows us basically to do what I call threat intelligence driven analysis. And what that means is instead of doing a full disk forensics, which is what we would have traditionally done, we basically deploy the agent, gather quick triage data. Uh, look at, okay, so this account was used, where did the threat actor came from? And then we move on to the next point and then we basically first built the entire footprint of what are all the entry, the access points that the threat actor might have used, and then basically push on towards the more in depth analysis and the second wave.
Speaker C: How similar are the patterns? If they already had your agent on, like why were they. I guess because they came in with, you know, if they didn't have multi factor, they come in as like a privileged user and then there, there's nothing stopping them from bouncing from place to place. And so until you start looking for that activity, it's not getting blocked automatically by the kind of the systems that are in place.
Speaker A: No, I mean the reality is Multi factor authentication is a good thing. But if the underlying platform on which you're running Multi factor authentication is vulnerable, and this is actually what we've seen happen time and time again in history, your firewall, your VPN products that you're using your MFA on is vulnerable. Well, guess what, they can bypass mfa and then basically your MFA is not operational at that point. This is one part. The other part is, and we saw this recently at Uber where the breach actually occurred because someone was sending MFA messages to the victim all the time. And at some point the victim basically just said yes, and I approved the access. And then the threat actor was in.
Speaker C: Yeah, we were talking about that and how to rate limit and include rate limiting in all of your systems. All right, so you deploy the agent, or you use the agent that's there and start to see, okay, what have they touched? Right, what's next?
Speaker A: Well, we build the story. So obviously we want to get full visibility. We basically build visibility with uh, either the agent and OR logs until we know for sure what all the entry and the exit points are and which hosts were basically used by the threat actor to pivot from or to. And once we have the full story, we basically started preparing for the eviction phase or the eviction planning, so to speak, which is usually running on multiple streams at the same time. Most customers will have active directory running for authentication purposes even on some smaller networks. And usually active directory is compromised. So that's one of the things you're going to have to address and basically take back control over your active directory, which basically means you need to go to your clean point of return. And the clean point of return is what is the latest backup that you have prior to the first threat actor activity. Once you've determined that point, that's where you're going to work towards and say, okay, all my backups from day X is the clean point of return and we're going to be basically be rebuilding. In most cases, most of the machines that were touched by the threat actor, they actually changed the attribution this case to the right Southeast Asian financial institution and basically apologized in the comments of the website. Apologies, this is actually not customer X, which was my customer.
Speaker B: Just like investigators and the police try to piece together different ways a burglar was able to end, Cohen and his team attempt to figure out how the threat actor was able to enter into their client's network. Once they understand that, they move on to determining how to get them out. While this particular victim's story has a quick and humorous ending, it doesn't always work out that way. Next, Cohen will share more about the process.
Speaker C: As you describe this process, how long does this take? I mean, is this like I call you in like two hours later or like 15 minutes? Or is this like four days? And what am I supposed to do in the meantime? Am I just like go hang out on a beach or like go to a movie because you can't touch anything? What's that timeline and what's it like for the victim?
Speaker A: It's actually one of the first questions that customers ask me once they start to engage with us. And in reality we see everything between two to three weeks is the time that we usually are engaged. So it's a quite a long time. Which also means that from a resourcing perspective, customers need to think about how am I going to sustain this level of effort. 24 by 7. Follow the sun, whatever model you use. But you're going to have to have the resources aligned. You're going to have to give people rest. Because I see customers trying to run through with one person the first 24, 48 hours and then usually after the 72 hours. They're so tired that they just drop.
Speaker C: Wow, two to three weeks, that's even longer. So what am I, if uh, this hits me like, am I going to basically go like. You're like, don't touch it. Because again, one of the things that we've talked about is that you don't actually want to necessarily start restoring anything yet because you can destroy the forensics on this. So am I going and like buying laptops? Am I working from home and like trying to use a different thing, or am I going to buy like new laptops or am I hitting virtual machines? What do I do?
Speaker A: It's actually quite challenging because first of all, if you lost your control of your active directory, you mostly lost control over your entire network. So usually we try to keep all of the compromised assets and machines in quarantine or an isolated vlan while we basically, basically just continue to analyze and gather evidence. And at the same time we tell the customer, well, you can start thinking about building some new machines if you have spare ones. Although in these times, obviously with supply chain problems, no one has 50 or 100 laptops available. Spares, I mean most customers will have what, five, 10, 15 machines? One of the cases I'm currently working, that's actually the case. They just have 15 spare laptops and that's basically what they need to work with. The second problem is how do you actually, I mean you can image those machines, how do you get them to the end users with all the remote workforce you need to send laptops out or you call everyone in into an office. But if people actually work throughout the country, which is quite getting the norm nowadays, that becomes a huge challenge from a logistics point of view.
Speaker C: Are you seeing people set up like Citrix virtual machines or some other version of a virtual machine where like, oh my gosh, it might not be able to do everything, but you can get to it maybe from a home computer or something else.
Speaker A: We ask our customers to generally if they want, for example, if they have on prem email and they were for example in the process of moving to Office365, we usually force our customers and say, listen, let's just push the migration to Office365 forward because we know it might actually be a well separated tenant that is not basically impacted by the incident, which basically give them access back to their email while we work on the rest.
Speaker C: But for any organization of any size, that's probably like now we can at least talk. But how are we going to get back to any of the like Core assets that maybe we needed.
Speaker A: It's a race. I mean nowadays we usually have to have the discussions with our customer about severing Internet access in the first days, uh, until we actually get the complete picture. Some organizations are prepared for that question, others are basically saying and taking a totally different stance and saying no, the business must continue to run. So then obviously we can only advise, can provide the best practices to do in those cases. But in the end the business decision is going to make the last call. So sometimes the business continues to run in a compromised or semi compromised state and sometimes they'll just go black for a few couple of days. Wow.
Speaker C: Uh, and what's the risk if you were sitting there with someone, what's the risk of running in that like semi compromised state?
Speaker A: So I've seen customers being hit by ransomware twice, actually not at least once in I think two months difference. So while they had not correctly remediated the previous incident, then they got hit by the second group, which is kind of interesting. Wow.
Speaker C: Um, all right, what's next? You now have like identified what's the eviction stage look like.
Speaker A: The eviction stage is that first of all you take back control over your active directory, so you build a clean active directory that you know is secured, hardened due to Microsoft's recommendations and obviously start reimaging machines and preparing for that. And then at the same time you're blocking out the threat actor with any means that he had at his disposal, disposals or any accounts that were used, any IP addresses that the threat uh, actor was using as infrastructure, any tokens, anything, any keys that might have been used in the cloud infrastructure will just be revoked and cut off the access from the threat actor.
Speaker C: And then what's next? They're back up to normal? Or how does this get wrapped up?
Speaker A: Well, first of all you have to monitor for reentry. Kind of depends what threat actor you're dealing with. But if you've closed the door, the entry door, and the threat actor has obtained what they wanted, it depends on what type of threat actor you're dealing with. If you're dealing with a nation state threat actor and you have interesting data for these particular groups, you will continue to be basically at risk of seeing re entry of these groups. And we do see this happen with some of our customers, but others basically stay out after they've obtained what they wanted. Once the entire recovery process and the post eviction monitoring has been done, we wrap it basically up with a report. In the report we write an executive summary, root cause Analysis. We provide recommendations on how to prevent this type of incident in the future.
Speaker C: Yet another case of not exactly these threat actors being the super criminals that we sometimes imagine them to be, and obviously a nice outcome for your customer. I mean, in that case, do you end up, like, trying to contact the real customer who's maybe impacted or, you know, you do anything like that? How do you think through those?
Speaker A: Usually we work through our, uh, legal departments to determine whether we actually want to do this, because there's some implications to this as well, obviously, because we're looking at someone else's data in that case. And obviously you want to make sure that from a legal aspect, it's actually okay to notify the affected institution. In most cases, we ask the customer themselves to decide whether they want to contact them from a due diligence perspective.
Speaker C: Yeah, yeah. Unfortunately, Good Samaritan rules are not always in effect. Well, Conan, this has been great. I really appreciate you taking the time. Just as we look to close the episode, what recommendations would you have for the regular business owner who might face these types of incidents in the future? How could they avoid them? If they do end up happening to them, what would you suggest that they do all those sorts of things?
Speaker A: Well, first and foremost, things can be prevented for a large part, obviously, if you have your latest security patches, your latest updates installed on the assets and the infrastructure that you're using, you're putting yourself at much less risk compared to if you actually have vulnerable systems exposed to the Internet. The Internet is constantly being scanned for vulnerable devices. It's really just a matter of hours, really, before a machine basically gets noticed by threat actors. These days, the second aspect is using multi factor authentication on all accounts. It basically provides you at least with a second layer of security, not perfect layer, again, because the end user can be tricked into approving the MFA request, which is what we've seen at Uber, but also which, uh, we see with our customers. I'm currently working a case where this is exactly what happened. And then the last piece is really, uh, being careful with emails that you don't trust. Phishing emails start looking better and better, I must admit. Threat actors also now start to impersonate existing email threats or compromising vendors that you're working with, and then basically interjecting themselves in these conversations, making it look, look to the victim, like, oh, this is my IT vendor. I need to click on this offer or on this receipt. And then they basically get compromised that way.
Speaker C: Well, thank you so much for joining us and walking us through all these potential scenarios. It sounds like we heard two sort of happy endings. That's pretty unusual for this podcast. So nice for us to have some positive stories. We don't always get those, but yeah, thank you so much. I really appreciate it.
Speaker A: No problem. Anytime.
Speaker B: Thank you for listening to this episode of the Cyber Crime Lab brought to you by Data Stream Insurance. When the worst happens, you're going to want the best financial, legal and technical support to get you back up and running again. With Cyber Insurance from Data Stream we find the most comprehensive insurance coverage on the market alongside critical post incident customer Support. Go to datastreaminsurance.com today and see how we can help you secure your business data. That's datastreaminsurance.com if you enjoyed today's episode, be sure to subscribe and give us a five star review. You'll find show notes and any resources mentioned@cybercrimelabpodcast.com we hope you'll join us next week episode. Until then, stay safe. More importantly, stay ready.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.