
Sign up to save your podcasts
Or


Today’s interview looks at ways state and local government entities can prevent ransomware. Traditionally, these organizations are understaffed and underfunded when it comes to cybersecurity professionals.
The unintended consequence of this budget constraint is making them vulnerable to ransomware attacks, with its thousand-fold cost. The interview will give you a plethora of free resources to help your organization prevent a ransomware attack if you have a limited budget.
A part of the Department of Homeland Security, Cybersecurity and Infrastructure Security Agency (CISA) has assembled a Joint Ransomware Task Force. It had its first meeting in September of 2022. One of the ambitious goals was to provide free information to help organizations, like State and Local Governments, with ransomware prevention.
Well, they delivered. StopRansomware.gov https://www.cisa.gov/stopransomware is authentic. It provides information on DNS blocking and even offers a free phishing assessment. Additionally, they offer best practices for backups, multi-factor authentication, and user training.
During the interview, you will learn there are over 90,000 State, Local, Tribal, and Territorial (SLTT) groups who lack the resources to establish a reasonable defense against attack. Many do not realize that just because you pay the ransom does not mean they will not attack again. Even worse, you may pay the ransom and then the data can be released anyway. There is no honor among thieves.
Doug Levin, K12 Security Information Exchange, gave an intriguing four-part summary of risks SLTT organizations face:
1 Primary attack vector will be email phishing – CISA can help in training
2 Legacy systems may not be patched, making them exposed
3 Due to a lack of budget, organizations may have vulnerable legacy applications
4 Passwords can be compromised (The result of a phishing attack)
SLTT groups are not alone in ransomware prevention. Federal organizations are stepping into the gap by helping in many ways.
When one reads the current literature on federal systems and zero-trust architecture, one gets overwhelmed by diagrams, charts, and prescriptive messages.
Lots of “should” and not many “we did.”
Well, this podcast will fill in the gaps. This is a discussion between a subject matter expert from Palo Alto Networks and a federal zero-trust practitioner. They dissect the best approaches to Zero Trust and give practical guidelines for migrating to a zero-trust architecture for a federal environment.
The discussion starts with how to select priorities. Everyone knows that Zero Trust is not a minor change that is merely adopted overnight. If zero trust is a journey, where does one start, and what priorities should be set?
Drew Epperson Palo Alto Networks provides the most practical advice on this concern. He suggests that you should identify the public attack surface and gain an understanding of where your valuable assets are located. The fantastic point he makes is that if you have a zero-trust system that does not allow the protection of assets dynamically, then you should start from scratch.
Beau Houser, US Census Bureau, makes a valid point when he suggests that a move “left” in the software development process will make Zero Trust much easier to deploy. In the parlance of software developers, a security move “left” means, on a timeline for a project, security considerations are given during the actual process of putting together the code.
One risk that is pointed out is that a systems administrator may be relieved that the code is being developed with security considerations, some may say “baked in.” The concern is that that person may get lulled into not worrying about continuous monitoring of the code. There very well could be a zero-day attack built into the code that will only be released later.
The interview concludes on a positive note. Beau House relates how his agency is having remarkable success in training technical staff. The dual benefit is it aids in staff retention and makes the transition to zero trust much smoother.
Ransomware is targeting vulnerable populations at hospitals. A hospital presents a “perfect storm” for attackers: thousands of apps, a multiplicity of medical equipment connected to the Internet, and sensitive information being stored.
In today’s podcast, Scott Pross applies his healthcare background and technical savvy to offer suggestions to prevent these attacks.
From his background in healthcare, Scott Pross knows that healthcare professionals have a wide variety of applications that they can use. He suggests that a good approach is to interview users to see exactly what applications they constantly use and what ones are relegated to the back shelf. Armed with this knowledge, a systems administrator can prioritize which applications to lock down.
Also, there are several areas to monitor and the approach he suggests is to develop a dashboard system that has areas for topics like the network, Email server, Accounting, and Marketing. This way, managers can get an idea of which systems can be used and which ones should be avoided.
Scott Pross suggests a dashboard system provides three main benefits, especially in a healthcare environment. First, the simplicity of a dashboard could translate IT issues into business issues. Rather than being informed of a specific event in a log, a graphical description could be given to show how that incident would impact the functions of, for example, the Email server. That way, managers could inform staff about issues and resolutions.
Second, because leaders have a visual element in front of them, it stops them from physically going down to the server area to interrupt network administrators doing their work.
Third, information from the dashboard could empower managers to make business decisions. For example, if there were storage issues, a business decision could be made to add storage arrays to eliminate concerns in the future.
When you read the current literature on cloud systems management, one key factor is what is called “observability.” With so many moving parts, one tends to focus on a specific group of indicators and miss the overall activity.
When Vivek Kundra started to talk about “Cloud First” back in 2009. He had no idea the size and complexity of clouds that would evolve in his desire to reduce cost and increase flexibility for federal projects.
SolarWinds has been a leader in system observability for decades. Today, we have a person who has successfully used Solar Winds on a variety of systems and relates some of the best practices for gaining this elusive observability.
Scott Pross has seen systems managers look at specific aspects of federal systems in silos. For example, a manager may have data coming in on servers, or even the network itself. Another set of metrics may give information on applications. Managing virtual environments has evolved into a category in and of itself.
When a problem arises, a troubleshooter may microfocus on an area, but not realize how it impacts the entire ecosystem. Scott suggests that using solutions from SolarWinds can give a systems analyst a view from 40,000 feet instead of ten feet off the ground.
Another consideration is how to monitor activity in a cloud when its architecture is changing. The change may be for compliance reasons, expanding applications, or something as basic as running out of room and having to adapt to an influx of data.
Leaders of federal agencies are not interested in extremely detailed observations about logs. They want to know when their application will be available for citizens or employees. Addressing this issue, Scott details how, using SolarWinds, he can assemble dashboards to give leaders a better understanding of what has gone wrong to enable them to make data-based decisions.
We all read the Executive Order on Improving the Nation’s Cybersecurity when it came out. It was great at telling federal technology leaders “what.” Unfortunately, it was not too detailed on “how.” Today’s discussion gives the listener a fantastic dose of practical applications.
We have tech visionaries from the DoD, CISA, GSA, and CrowdStrike. They offer suggestions based on years of federal experience. The discussion ranges from gap analysis to prioritize needs to the evolution of the Trusted Internet Connection (TIC) from 1.0 to 3.0. Further, an analysis is given of the progress of agencies on incorporating point of a reference architecture to specific recommendations for the DoD to comply with zero trust.
Kevin Gallo gives an overview of TIC. Initially, its goal was to limit the number of connections a federal agency had to outside sources. Since its inception in 2007, the federal government has seen an explosion in endpoints and cloud services. As a result, some view TIC 3.0 has a distributed cybersecurity policy enforcement tool.
Speaking of the multiplicity of clouds, there are so many moving parts that any solution must include the ability to interconnect with many systems. Ned Miller from CrowdStrike talks about the millions of endpoints CrowdStrike has already secured in an incredibly complex system.
For civilian agencies, the GSA is offering a Buyer’s Guide that can assist leaders in assessing offerings that can lead to a stable zero-trust architecture. Additionally, they offer free workshops on implementing Zero Trust where hundreds of federal technical people have participated.
From the DoD Randy Resnik gives the listener a detailed description of the 45 capabilities and the 151 activities that must be accomplished before an effective deployment of Zero Trust can be accomplished.
If that is not a full plate, the interview ends with a serious overview of threat hunting. Perhaps this august group and meet again and provide more details on this important topic.
Veeam has a focus on making sure its solution is powerful but user-friendly.
Well-regarded technology guru Bruce Schneider once said, “Complexity is the enemy of security.” This maxim is an effective way to describe how Veeam helps its customers all over the world. Veeam protects over eleven million accounts with systems that are easy to use and able to be integrated into other parts of the environment.
Today’s focus is on assisting schools to improve their defense against ransomware. We have a technology specialist from Northeast Technical College in Wisconsin sit down with Aaron Murphy from Veeam. They discuss topics like the ease of use, the hybrid cloud, and platform and tools.
Karl Reishi makes a profound observation when he says that the use of the cloud has matured. Rather than the old phrase, “Cloud First,” he suggests that the best practice is to have a reasonable plan of what you want your system to look like after the transition. Flexibility is key in the world of multiple clouds, especially when it comes to disaster recovery.
Another aspect of “cloud maturity” is realizing the two environments you plan to have this year may transition to four or five in the future. Aaron Murphy adds to the discussion when he observes that a recovery process must be in place, and assessed, for each of these environments.
From Karl Reishi’s experience, the cost of moving to the cloud is a wash. The main benefit he sees is it releases technical talent from the drudgery of security checklists and maintenance so they can concentrate on understanding the needs of students and teachers.
Few technology discussions include the concept of protecting the application in the whole lifecycle. That means protection must start during development, continue through testing, and then until the application is ended.
Today’s discussion could not be timelier. COVID has brought an increase in ransomware attacks on schools. Here, experts sit down and describe the kinds of attacks schools are encountering and offer practical remedies.
It is front-page news that COVID has impacted learners from kindergarten to high school (K-12). Assessments are being challenged, teachers are quitting, and students are frustrated. If that were not enough, we have seen that this shocking transition has left school systems open for attack.
From a strategic perspective, it makes sense. It has been drilled into adults not to click on a strange-looking email. However, COVID has forced all communications between teachers and parents to be via email. Harried and under pressure, it is not surprising that someone clicks on a phishing email.
Further, at least adults can check their credit scores and may get emails from a credit card or bank of suspicious activity. No true with a ten-year-old. An identity can be compromised online, and a malicious actor can run up thousands of dollars of purchases in a mere 30 days.
It has been reported that a school district in Iowa recently paid the ransom to get school data back.
The story must start at the school itself. Elvis Teah from the Baltimore Public School System states that the main problem is with phishing emails; he also reinforces the concept that you need an infrastructure to listen to traffic entering and exiting.
Small school districts all over the country have limited staff. When COVID hit, the limited staff had to spend most of the time making sure students and teachers had access to online resources. As a result, we have seen a spike in school attacks.
Doug Levin from K12 Security Information eXchange has a deep understanding of the situation. He thinks that smaller schools must take advantage of the information on cybersecurity available from CISA and organizations that provide K12-specific information.
Federal agencies are pushed and pulled in different directions. A notable example is the entire process of adding staff. It takes an estimated one hundred days to make a hire. Human resource professionals are pushed to speed that up. On the other hand, agencies must also comply with mandates to increase diversity. How many hours are in the day to review resumes?
The answer may be by applying artificial intelligence. Today’s discussion focuses on the ability of artificial intelligence to help speed through applications and, at the same time, be able to increase diversity in the workforce.
Joe Biden’s sweeping Executive Order improves the federal workforce by improving diversity, equity, inclusion, and accessibility (DEIA) in the federal workforce. It was announced on June 25, 2021. It is getting some momentum because in September of 2022 the Chief Diversity Officers Executive Council will look at making suggestions to help agencies achieve compliance.
It is a challenge to apply these mandates to the volume of applications received. Greg Singleton from HHS estimates they have 90,000 direct employees. A big number for a stressed human resource group to review diversity.
Dan Hopkins from Eightfold AI states that applying artificial intelligence to this problem will start by creating overall efficiency. It can also provide deeper insights into what is required for the role. Finally, it can help oversee the hundreds and thousands of applications the federal government gets a year.
Carol J. Smith from the DoD has had an experience where she has seen bias in the methods to produce artificial intelligence. If the data is going to be collected and curated by humans, then it could have a bias. She recommends a human be integral to the process of any applied intelligence.
The federal government is trying to update much of its neglected infrastructure. They have grants available to replace bridges and roads, and even improve broadband access for everyone.
Unfortunately, many of the systems the federal government uses to manage these grants are as outdated as some of the bridges that are targeted with the funds.
Now, this would not be a cause for concern if the grants were small and manageable. However, there has been an explosion in the amount and number of grants federal agencies must manage.
In today’s discussion, the traditional way grants have been managed could be viewed as a system that needs to be updated as well. The number of grants and the amount of money is going from the millions to the billions.
Brette Fisham, Department of Treasury begins the podcast with a fantastic overview of where federal grants management was, where it is now, and where it is headed. She describes a decentralized system where each of the fifty awarding agencies had its grants management system, at one time. The systems did not talk to one another.
She mentions that it was only in 2013 that the federal government enacted grant regulations, until that time, each agency was operating under its own rules.
To add to the structural inadequacies of grants management, the application process itself has become burdensome. For example, some organizations may submit a 200-page application for a grant. Paper-based systems are inherently slow and can have constant bottlenecks.
During the discussion, the concept of centralizing and digitizing the process of application, management of the grant, and then, closing it out was described in detail.
The example of expanding broadband was brought up as a case in point. The old paper-based system was designed for a set of applicants who knew the inner workings of the government, limiting the equity of the application process.
Another benefit of a centralized grants management system was physically determining where new broadband service should be installed. A digital system would allow for a graphical depiction of geography, allowing agencies to accomplish their goal of equally distributing access to high-speed Internet.
If you want to cover the breadth and scope of protecting assets in today’s rapidly changing world, it is best to get a wide range of opinions. The diverse group who sat for this discussion come from local, state, and federal backgrounds and, because of that background, give the listener a tremendous perspective on this important topic.
The interview examines priorities, sharing threat information, and the responsibility of management to provide the time and tools for security professionals to do their job.
It is headline news when an oil line gets attacked, but our experts agree that a topic that is not newsworthy is key to keeping data safe: the basics. All three technology leaders said that one must get methodical with basics, like patching, eliminating weak credentials, and instructing staff about social engineering.
Sharing information is a much-debated topic in the cybersecurity community these days. During the discussion, Terry McGraw talked about some of the legal liabilities of disclosure in the commercial world. He suggests that systems administrators who want to share information on attacks are hamstrung by legal considerations.
This is contrasted with some of the new ways threat information is shared in state and local organizations. Jeremy Wilson from Texas lauds the ability of the Multi-State Information Sharing and Analysis Center (MS-ISAC) to help with distributing threat knowledge.
He also mentions the value of training. One department in the wide-ranging realm of the state of Texas information technology was looking at a 30% click-through rate with phishing attacks. He says that a training program dropped that click-through rate to 4%.
Terry McGraw’s final comments were very transparent. He stated that proper protection of assets may not always involve the latest and greatest offering. He suggests that leaders can get the most value from establishing best practices for patching and protecting authorized access to information.
From the publisher's feed