Listen to this episode

Bitcoin, Cryptocurrencies, Ransomware Security Risk Assessments, Craig Petronella & Lisa Shasteen

0:0044:07

Recorded March 2021. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

In this March 2021 episode, Craig Petronella of Petronella Technology Group welcomes attorney Lisa Shastine to discuss Bitcoin, ransomware, and security risk assessments. Lisa explains that, at the time of recording, the financial regulator had opened financial institutions to serving as stewards of cryptocurrency under new guidance, and she questions whether protections like Secret Service involvement would extend to Bitcoin.

Craig, who has mined cryptocurrency, argues that coins held by others are not truly yours and warns that safely storing private keys requires technical skill most individuals lack. They discuss the Hafnium attacks targeting Microsoft Exchange servers reported just before recording, and Craig recommends encrypted email on top of Exchange. The conversation covers identity theft monitoring, free credit freezes, and weakened trust in vendors after SolarWinds. Craig advocates security risk assessments, ransomware fire drills, tested offsite backups, and redundancy, while Lisa urges everyone to have a trusted technologist. They finish with cyber insurance questionnaires, PCI self-assessments, cloud shared responsibility, and CMMC, which Lisa says required companies serving federal contractors, at the time of recording, to prove compliance through trained assessors rather than self-certification.

Worth remembering

Key takeaways

  1. Craig argues that cryptocurrency held by someone else is not really yours, so controlling your own private keys matters.
    “Ultimately, if you don't control your private keys, you don't really have your Bitcoin or your crypto.”
  2. The guest recommends placing free credit freezes with Equifax, Experian, and TransUnion so nobody can open credit without the PIN.
    “And they will, for free, put a credit freeze on your account. And you should just do it because that way nobody's getting in unless they have your PIN number.”
  3. Craig says an independent security risk assessment works as a checks and balance even when a company trusts its existing IT provider.
    “It's not going to hurt you to have a security risk assessment done in working with that vendor, if you choose, and do a checks and balance.”
  4. Craig urges companies to run ransomware fire drills to learn how fast they can recover and how much downtime they can tolerate.
    “Your company should be doing fire drills around ransomware and pretend that you just got ransomware today.”
  5. Craig says that with strong data backup, disaster recovery, and business continuity, a company does not have to pay the ransom.
    “if you have strong data backup, disaster recovery, and business continuity, if you have strong systems in place to protect your organization, you do not have to pay the ransom.”
  6. The guest warns that a backup connected to the production system is likely to be encrypted by ransomware too, so keep backups separate.
    “But if you have your backup connected to your production system, it's likely going to be ransomware too.”
  7. Craig stresses that outsourcing to providers like Amazon AWS does not remove an organization's responsibility to secure its own systems.
    “Just because you're outsourcing or paying a monthly fee to them, does not take that responsibility away from you.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

Craig Petronella and Attorney Lisa Shasteen talk about the latest news on Bitcoin, Cryptocurrencies, Ransomware, the importance of Security Risk Assessments now more than ever. Cybersecurity insurance requirements, vendor security questionnaires. Visit to purchase DIY products to help you proactively protect your organization from cybersecurity threats like Ransomware and malware. Practice proactive fire drills on your data backup, Disaster Recovery and Business Continuity to score your organization and fill your gaps.

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.