By Gregg Wartgow, Special to the Association of Equipment Manufacturers (AEM) —
American manufacturers remain a top target of cyber criminals, particularly in the case of ransomware attacks. With AI helping to drive an increase in both attack frequency and sophistication, now is the time for manufacturers to make sure they are capable of defending and ready to respond.
The federal government can provide assistance.
One federal agency is the Cybersecurity and Infrastructure Security Agency (CISA), which is a component of the Department of Homeland Security. CISA is not a law enforcement or regulatory agency. Rather, CISA develops standards and best practices, shares data and information, and assists organizations with risk analysis and incident management efforts.
CISA delivers its cybersecurity support through 10 regional offices and regional security advisors. Manufacturers can reach out to their respective regional offices to learn about which training opportunities and other resources are available, and to inquire about setting up a site visit if desired.
The FBI is also there to assist organizations when a cyberattack takes place. The FBI has been further empowered over the past several months. Executive Order 14390, signed by President Trump in March, is aimed at combating cybercrime, fraud, and predatory schemes against American citizens. The FBI’s Operation Riptide, launched in June, implements the priorities set out in that executive order.
“We are really turning up the juice with getting arrests and making sure the cost of doing cyber crime is a barrier to entry for anyone thinking about getting into this ecosystem,” said Marc Smith, unit chief for the FBI Cyber Division’s Major Cyber Crimes Unit II, which coordinates ransomware investigations and response efforts across the FBI’s 56 field offices.
Smith participated in an AEM Member Education Webinar held earlier this month. He pointed to two websites that can assist organizations:
What does the FBI need to respond to a cyberattack?
Because cybercrimes like ransomware attacks typically involve a person’s or company’s private information, Smith said some organizations are hesitant to allow the FBI in. But certain information is needed to encourage a prosecution team to pursue a case, including:
- Attack vector (i.e. method used to breach a network)
- Relevant log files on the network/host
- Accounts and communications attributed to threat actors
- Files attributed to threat actors including ransom notes and malware
- Indicators of compromise (IOCs) and other tactics, techniques, and procedures (TTPs) observed
- Virtual currency addresses
- Number of affected endpoints
Tips to reduce cybersecurity risk
Smith said there is a long list of mistakes organizations make that elevates the risk of being harmed by a cyberattack, including:
- Lack of a tested incident response plan
- Slow enaction when a response plan does exist
- Too many people having privileged account access
- Insufficient monitoring of those with privileged access
- Weak or nonexistent network segmentation that makes it easier for threat actors to move throughout an entire system
- Inadequate or untested backup systems
“One of the biggest mistakes organizations make is failing to detect early warning signs,” Smith said. For instance, if a brand-new IP address is on the network at an unusual time and is moving abnormally large amounts of data, that should trigger an alarm.
“It’s important to get a human on this type of event immediately,” he added.
Chris Brogger, program specialist for CISA’s Infrastructure Security Division, joined Smith on the webinar. He offered some insights into how individuals can help mitigate the risk of falling victim to a cyberattack.
“There is really nothing that’s too complicated here,” Brogger said. “We often see that some of the most significant threats a manufacturer faces emanate from relatively simple TTPs (tactics, techniques, and procedures) on the part of threat actors. There are some general best practices you can use in your organization and message across your workforce to try and prevent some of these threats from gaining access and potentially causing harm.”
Use of electronic devices
Review privacy settings. Brogger said many people aren’t aware of the information their mobile devices are sharing because a mobile device’s privacy settings are often set to a factory default.
“I encourage everyone to take a look at both their work and personal devices,” Brogger suggested. “Make sure your privacy settings are set to something you’re comfortable with so you’re not inadvertently putting too much information out there.”
Location services. Unless there is a pressing need for capturing or transmitting location data, Brogger said it’s typically a good idea to turn location services off.
Device software updates. It’s important to receive all of those patch updates and software pushes you receive to ensure that your device can respond to the latest and most sophisticated threats.
Avoid nonsecure websites. Modern websites with the proper built-in security mechanisms have URLs that start with https, with the s meaning “secure.” On the other hand, http URLs are outdated and lack the property security mechanisms.
“Be skeptical of any websites you’re navigating through that do not have that secure connection,” Brogger said. “Any information you send through them or across them may potentially be compromised. This is really important when you’re talking about things like sensitive transactions involving money or simply information you don’t want to be made public.”
Use strong passwords. This sounds simple, but Brogger said it’s highly effective.
Enable multifactor authentication (MFA). The purpose of MFA is to establish a multilayered method of verifying a user’s identity, which helps prevent a singular act (i.e. stealing a password or other credential) from giving a threat actor access to systems, accounts, or data. Examples include verification emails or texts, one-time passcodes, and security questions.
“If you don’t have MFA enabled on your organizational devices, you should start yesterday,” Brogger said. “Some of the most devastating attacks we’ve seen against organizations have happened because they didn’t have MFA enabled.”
Phishing schemes
Phishing is when threat actors utilize email, texting, or social media direct messaging to try and get people to open harmful links or attachments that could request personal information or infect electronic devices. Sometimes phishing comes in the form of a phone call where the threat actor is looking to obtain certain information.
Regardless, phishing has been a common tactic for a long time. But it’s evolving and presenting a new challenge.
“Threat actors are sometimes using AI in their attacks,” Brogger pointed out. “Things like phishing emails may seem more believable now, making them more likely to bypass things people have been trained to detect. Always be suspicious and trust your gut and always take the most risk-averse approach.”
For example, say you receive what appears to be a legitimate email from your supervisor, right down to the supervisor’s email address. But the content of the email seems odd, or maybe the tone seems off. “Call your supervisor or stop over to their office to ask if they actually sent that email,” Brogger suggested. “Worst case, you spend a few minutes verifying the email. Best case, you could potentially avoid what could be a very damaging phishing attack.”
Brogger said the following best practices are also worth adopting.
- Recognize – Watch for untrusted or shortened URLs, urgent or emotional language, requests for personal or financial information, incorrect email addresses or links (i.e. amazan.com as opposed to amazon.com), and poor grammar.
- Resist – Don’t click links or attachments that seem too good to be true. Likewise, always confirm the source of QR codes before scanning. “Report any phishing attempt to IT if it happened on a work device,” Brogger advised.
- Delete – When you detect a suspicious message, delete it immediately. Furthermore, never click reply or click on any attachment or link, including “unsubscribe” links.
As cyberattacks continue to evolve — and U.S. manufacturers remain a top target — it’s important for companies to master these best practices, along with many others. And remember, a manufacturer doesn’t have to go it alone. Federal agencies like CISA and the FBI are available to help.
This is the first of a two-part series on strengthening cybersecurity in manufacturing. Read more in the July 27 edition of the AEM Industry Advisor.
About Member Education Webinars
AEM members have exclusive access to help them stay on top of emerging issues and trends via member education webinars. Experts break down industry issues and pinpoint critical changes in the landscape to help attendees refine their company’s strategy.
For more information on the upcoming series of member education webinars, contact your Account Success Advisor.
