{"id":8772,"date":"2021-06-23T15:03:10","date_gmt":"2021-06-23T19:03:10","guid":{"rendered":"https:\/\/archive-lynchlaw.pfgsandbox.com\/?p=8772"},"modified":"2023-03-14T15:10:10","modified_gmt":"2023-03-14T19:10:10","slug":"cybersecurity-threats-full","status":"publish","type":"post","link":"https:\/\/archive-lynchlaw.pfgsandbox.com\/?p=8772","title":{"rendered":"Today\u2019s Cybersecurity Threats: Not If, But When"},"content":{"rendered":"<h2>Determining best practices to prevent a cybersecurity breach from crippling your business should be on the top of your priority list.<\/h2>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"wp-image-9772 aligncenter\" src=\"https:\/\/archive-lynchlaw.pfgsandbox.com\/wp-content\/uploads\/2021\/06\/iStock-1204460701-3-1024x683-1-300x200.jpg\" alt=\"hooded man at computer\" width=\"720\" height=\"480\" srcset=\"https:\/\/archive-lynchlaw.pfgsandbox.com\/wp-content\/uploads\/2021\/06\/iStock-1204460701-3-1024x683-1-300x200.jpg 300w, https:\/\/archive-lynchlaw.pfgsandbox.com\/wp-content\/uploads\/2021\/06\/iStock-1204460701-3-1024x683-1-768x512.jpg 768w, https:\/\/archive-lynchlaw.pfgsandbox.com\/wp-content\/uploads\/2021\/06\/iStock-1204460701-3-1024x683-1.jpg 1024w\" sizes=\"(max-width: 720px) 100vw, 720px\" \/><\/p>\n<p><span data-contrast=\"auto\">Foreign hacking collectives, acting independently in some cases and under the guidance of malicious state sponsorship in others, have successfully infiltrated and paralyzed American businesses on an unprecedentedly massive scale.<\/span><\/p>\n<h3>What does a hack look like?<\/h3>\n<p><span data-contrast=\"auto\">Recently, the Colonial Pipeline\u2014responsible for supplying nearly 50% of fuel consumed on the United States\u2019 eastern seaboard\u2014was <a href=\"https:\/\/www.reuters.com\/business\/colonial-pipeline-ceo-tells-senate-cyber-defenses-were-compromised-ahead-hack-2021-06-08\/\">shut down entirely<\/a> by hackers who deployed ransomware to lock company administrators out of the pipeline&#8217;s operating systems. The underlying cause of the company\u2019s susceptibility? The company failed to implement a more secure (and today, incredibly common) two factor authentication system for administrators accessing its password-protected network. The result? A $4.4 million dollar ransom paid by Colonial to the hackers, and potentially billions in losses to the American economy. <\/span><\/p>\n<p><span data-contrast=\"auto\">Colonial is not alone in its major losses due to avoidable problems. Recently, major meatpacking company JBS paid hackers <a href=\"https:\/\/www.reuters.com\/technology\/jbs-paid-11-mln-response-ransomware-attack-2021-06-09\/\">upwards of $11 million<\/a> worth of cryptocurrency in response to demands after the hackers illegally accessed the firm\u2019s network and threatened to lock out administrators and begin deleting key files unless their demands were met.<\/span><\/p>\n<p><span data-contrast=\"auto\">These are only two examples of an exponentially growing problem facing businesses and professional entities: malicious actors hacking key systems and holding them hostage for profit. Analysts estimate that roughly <\/span><strong>$18 billion<\/strong><span data-contrast=\"auto\">\u00a0was paid to such hackers in\u00a0<\/span>2020<span data-contrast=\"auto\">, a figure expected to increase dramatically each year in the coming decade.<\/span><\/p>\n<h3>How could this impact me or my business?<\/h3>\n<p><span data-contrast=\"auto\">This is not a problem faced only by major multinational corporations. The American Bar Association surveyed members and found that, in 2020, 29% of law firms reported a security breach, with more than 1 in 5 saying they were not sure if there had ever been a breach and 36% reporting past malware infections in their systems. Hackers target individuals as well, freezing consumers out of their financial accounts and threatening to liquidate funds unless the victim pays thousands to have control returned. Annual reporting for 2020 estimates that <strong>300 <\/strong><\/span><strong>million<\/strong><span data-contrast=\"auto\">\u00a0ransomware attacks were carried out on businesses and individuals alike globally in 2020, up from 188 million in 2019. <\/span><\/p>\n<p><span data-contrast=\"auto\">In today\u2019s digital landscape, the question for business owners and professionals must ask themselves is not \u201cWill I be hacked?\u201d but rather \u201c<\/span><i><span data-contrast=\"auto\">When<\/span><\/i><span data-contrast=\"auto\"> will I be hacked?\u201d and, perhaps more importantly, \u201cWhat can I do to prepare?\u201d <\/span><\/p>\n<p><span data-contrast=\"auto\">The stakes to your company are great, and the potential ramifications for your company include: reputational damage, compromised customer safety, legal and compliance risk, business and supply chain interruptions, data loss (including customer, employee, and trade secrets), and extensive costs (legal, forensic, and ransom payment).<\/span><\/p>\n<p><span data-contrast=\"auto\">Most importantly, preparations can be made and countermeasures can be implemented to mitigate the effects of these attacks against precious digital systems. As with most potential catastrophes, preemptive measures and planning go miles further in warding off hacking efforts than panicked, reactionary measures. Companies and professionals must develop protocols to monitor for, prevent, and in worst case scenarios, respond to hacking with the same seriousness that they approach active shooters, workplace violence, sexual harassment, and other major threats to business operations that have become so prevalent in recent years.<\/span><\/p>\n<h3>How do I make these preparations?<\/h3>\n<p><span data-contrast=\"auto\">Considering preventative measures to this serious threat is essential. Security needs will vary from business to business, based on the type and scale of operations the firm is engaged in. However, we highly recommend these universally applicable protocols be implemented by businesses and professionals in order to begin down the path to a more digitally secure future:<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\"><strong>Develop internal policies and procedures<\/strong><\/span><\/p>\n<p><span data-contrast=\"auto\">Do you know what steps you need to take if you suspect someone is trying to hack you? Or if you know that a hack has taken place? Do your employees and associates know what to do in the same circumstances? Do you have the response proper incident response plan and procedures in place? <\/span><\/p>\n<p><span data-contrast=\"auto\">The minutes and seconds following a suspected hack are no time to for managers to be asking themselves \u201cWhat now?\u201d A key first step toward preparedness for any enterprise susceptible to hacking is to work with legal counsel, IT professionals, and business personnel to develop a response plan to be followed in the event of a hack or suspected hack, and to practice it routinely with employees so that the entire organization is aware of their duties and emergency responses. Think of it as a digital fire drill: when an alarm goes off, you want a calm, measured response that immediately and effectively begins to address the problem, rather than a panicked frenzy. <\/span><\/p>\n<p><span data-contrast=\"auto\">A well-selected response team must be engaged to contain, remediate, and notify the essential external agencies, insurance carriers, and technical assistance when an emergency arises. Key members of your incident response team should include legal counsel, information security professionals, human resources staff, risk management experts, finance representatives, and operations managers. <\/span><\/p>\n<p><b><span data-contrast=\"auto\">Perform an internal audit<\/span><\/b><\/p>\n<p><span data-contrast=\"auto\">What do your current contracts with clients, suppliers, or insurers say about hacking? This must be reviewed so that you are certain of your contractual obligations and coverage. Uncertain of where your business or professional firm stands? If so, that must change\u2014quickly. <\/span><\/p>\n<p><span data-contrast=\"auto\">The easiest way to achieve this is by performing an internal audit, with the assistance of outside professionals if necessary, in order to assess the extent of your liability in the event that you are hacked\u2014or your clients&#8217;, suppliers&#8217;, or insurers&#8217; liabilities to you in the event that they are hacked. An alert from your IT department informing you of a hack on your network is no time to discover that you have unfairly shouldered the burden of liability for something that could be attributable to an outside party working against your firm. It is an even worse time to discover that your insurance policies decline coverage in the event of a hack. Internal audits can discover and prevent such otherwise unavoidable calamities.<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Shore up your insurance<\/span><\/b><\/p>\n<p><span data-contrast=\"auto\">While an internal audit is a priceless tool in assessing your firm\u2019s readiness in the event of a cyberattack, it is a futile endeavor if you fail to follow through with a risk management response that adequately addresses your liability and exposure in the event of a hack. For this reason, it is of paramount importance that you collaborate with your insurance broker to address any shortcomings posed by your current policies in the event of a hack.<\/span><\/p>\n<p><span data-contrast=\"auto\">Hacking is an omnipresent risk in today\u2019s modern digital world. The risks it poses are real, severe, and costly. The most practical approach to mitigating those risks is to give serious consideration to the recommendations laid out above, and to stay vigilant in your digital dealings.<\/span><\/p>\n<h4>Pittsburgh Cybersecurity Attorneys<\/h4>\n<p><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\"><a href=\"https:\/\/archive-lynchlaw.pfgsandbox.com\/attorneys\/frank-c-botta\/\">Frank Botta<\/a>, attorney at The Lynch Law Group, assists businesses and individuals alike in matters related to cybersecurity. Please contact him at <a href=\"mailto:fbotta@archive-lynchlaw.pfgsandbox.com\">fbotta@archive-lynchlaw.pfgsandbox.com<\/a>\u00a0or by phone at 724-776-8000.\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Determining best practices to prevent a cybersecurity breach from crippling your business should be on the top of your priority list. Foreign hacking collectives, acting independently in some cases and under the guidance of malicious state sponsorship in others, have &hellip; <a href=\"https:\/\/archive-lynchlaw.pfgsandbox.com\/?p=8772\"><span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":9772,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[69,56],"tags":[404,405,401,402,403],"class_list":["post-8772","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-corporate","category-general-news-updates","tag-audit","tag-breach","tag-cybersecurity","tag-hacking","tag-risk"],"_links":{"self":[{"href":"https:\/\/archive-lynchlaw.pfgsandbox.com\/index.php?rest_route=\/wp\/v2\/posts\/8772","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/archive-lynchlaw.pfgsandbox.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/archive-lynchlaw.pfgsandbox.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/archive-lynchlaw.pfgsandbox.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/archive-lynchlaw.pfgsandbox.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8772"}],"version-history":[{"count":15,"href":"https:\/\/archive-lynchlaw.pfgsandbox.com\/index.php?rest_route=\/wp\/v2\/posts\/8772\/revisions"}],"predecessor-version":[{"id":10978,"href":"https:\/\/archive-lynchlaw.pfgsandbox.com\/index.php?rest_route=\/wp\/v2\/posts\/8772\/revisions\/10978"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/archive-lynchlaw.pfgsandbox.com\/index.php?rest_route=\/wp\/v2\/media\/9772"}],"wp:attachment":[{"href":"https:\/\/archive-lynchlaw.pfgsandbox.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8772"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/archive-lynchlaw.pfgsandbox.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8772"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/archive-lynchlaw.pfgsandbox.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8772"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}