Listen to this episode

Petronella Technology Group Podcast 12-16-20

0:0053:28

Recorded December 2020. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

Craig Petronella of Petronella Technology Group speaks with cybersecurity and data privacy attorney Lisa Shasteen about the SolarWinds hack, which some have called one of the worst hacks in history for the United States government. They discuss how attackers allegedly used social engineering to insert malicious code into a patch for the Orion platform, and Lisa Shasteen notes that the attackers can get around multi-factor authentication.

Craig argues that many businesses give too much trust to vendors, assuming patches from trusted sources are legitimate. Lisa Shasteen says the hack was supposedly a nation-state's sophisticated, targeted effort, and that from a legal standpoint organizations must take reasonable precautions now that the breach is common knowledge. Craig argues the incident proves the need for the CMMC process, and the two discuss evidence requirements, third-party assessments, and defense supply chain deadlines at the time of recording. They also cover layered security, passwordless technology, phishing awareness training, deleting unused phone apps, biometric risks, and the security challenges of storing health records online and on blockchain.

Worth remembering

Key takeaways

  1. Craig argues that businesses give too much trust to vendors and should put more pressure on them to show updates are legitimate.
    “But the reality is that many folks put a lot of trust in our vendors. They give too much trust in the assumption that patches coming from our trusted vendors in our circle are legit.”
  2. Lisa Shasteen says that, with the hack now common knowledge, it is a good time for MSPs using SolarWinds to change platforms.
    “And if you as an MSP or someone are using that as your platform, probably, it's a good time to change because it'd be reasonable to think that you're looking at alternative solutions.”
  3. Craig recommends layering as many security controls as possible, protecting all entry points rather than just the front door.
    “It all boils down to adding in as many layers as you possibly can to protect yourself.”
  4. Lisa Shasteen warns that without regular cybersecurity training and simulated phishing tests fed back to employees, a company is vulnerable.
    “But if you are not doing cybersecurity training, and refreshing that training and having someone like Petronella come in and do some testing or efficiency in a simulated phishing test and feeding that information back to your employees, you're vulnerable.”
  5. Craig explains that, at the time of recording, CMMC requires two forms of supporting evidence for each of the 110 plus controls and is pass-fail.
    “You have to show the two forms of supporting evidence for each of the 110 plus security controls. And it's a pass-fail.”
  6. Lisa Shasteen argues that unwritten policies do not count in court, so procedures need to be documented.
    “Yeah, but it doesn't count if you don't have it in writing in court. So if you want me to prove it, how may I do that?”
  7. Lisa Shasteen recommends deleting every unused app from your phone as a practical step to reduce risk.
    “So what we need to do is look at our phones. And we need to delete every single app that we don't use.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

Petronella Technology Group Podcast 12-16-20 with Craig Petronella of Petronella Cybersecurity and Digital Forensics and Expert Data Privacy Attorney Lisa Shasteen discuss the latest breach with FireEye, breach of several government systems, HIPAA Compliance, CMMC, Cybersecurity, Policies, Procedures, Compliance Risks, Challenges, and more!

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.