Listen to this episode

Unraveling The Complexities Of Cybersecurity, Compliance And Bitcoin Wallet Security

0:001:00:30

Recorded November 2023. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

The hosts of Petronella Technology Group's podcast open with a news story about a cybersecurity firm that pled guilty to hacking two hospitals in 2018 to boost its business, breaching phone systems and printers, stealing personal information from more than 200 patients, and tweeting data of 43 patients. Craig argues that healthcare organizations face added cybersecurity challenges because medical equipment can be dated and run old operating systems.

He then describes the Randstorm bug, which he says affects millions of cryptocurrency wallets built with Bitcoin JS, and urges anyone holding Bitcoin in a software wallet created before March 2012 to move it to cold storage rather than an exchange. Answering a listener question, Craig explains how organizations can begin compliance themselves using NIST publications, gap assessments, disk encryption, firewalls, and security awareness and role-based training. He outlines CMMC 2.0 requirements as they stood at the time of recording, including penetration testing and a single PoAM. The hosts also discuss compliance liability, fraud charges against the SolarWinds CISO, grant repayment penalties, and CMMC enclaves, before closing with a secret Black Friday offer and Thanksgiving wishes.

Worth remembering

Key takeaways

  1. Craig warns that software wallets created before March 2012 are vulnerable to the Randstorm bug and urges moving any Bitcoin in them to a cold storage wallet.
    “if there's anyone listening that has Bitcoin on a wallet a software wallet that was created before 2012 of March, you really need to move that to a ideally a cold storage wallet”
  2. Craig recommends starting with a gap assessment, and says a self-assessment is possible without budget, though hiring a certified third party is best.
    “If you don't have budget, it's always best to hire a certified third party, but you can roll up your sleeves and do it yourself a self-assessment.”
  3. Craig says anyone in a regulated environment should at minimum have disk encryption such as BitLocker or macOS disk protection turned on.
    “And if you're listening in your in a regulated environment, you should have something like BitLocker or Mac OS disk protection.”
  4. Craig argues security awareness training is the most underlooked item, saying organizations rarely have the role-based training, testing and evidence needed to pass audits.
    “but they don't take training and testing and drilling seriously enough in my opinion, and they don't actually have the evidence to prove that fact.”
  5. Craig stresses that buying Microsoft 365, an EHR, or any product does not make a company compliant, because compliance responsibility cannot be outsourced.
    “you cannot outsource the responsibility of compliance and you can't just go buy a product or a software service or a piece of hardware and assume that your job is done”
  6. Craig argues that IT providers, even dental specialists, are usually not cybersecurity and compliance experts, so customers should verify their work with independent assessments.
    “The IT provider is great at doing IT, but they're not a cybersecurity and compliance provider and they should not be doing cybersecurity and compliance.”
  7. Blake advises anyone entering healthcare or another complex regulated industry to address compliance first, before building the rest of the business.
    “If you're considering going into healthcare or complex regulated industry, you should probably look at compliance first before you even start about getting your business together”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

Do you think you're up-to-date with cybersecurity and compliance? This episode will uncover some surprising facts that you may not be aware of. Firstly, we'll be unravelling the complex challenges that healthcare organizations face, especially when dealing with outdated medical equipment. We'll look at a real-life case where a hospital was hacked, and we'll discuss the importance of third-party security testing.

Next, we're shifting gears to discuss the intriguing world of Bitcoin wallet security. We'll explain why wallets prior to 2012 are particularly vulnerable and why moving them to cold storage is a strategic move. We'll also be exploring the regulatory landscape and the importance of self-assessment. We'll introduce you to resources such as NIST and CMMC and emphasize the value of antivirus software, disk encryption, and firewalls.

Finally, we'll be discussing the crucial role of compliance within companies. Compliance isn't just a box to tick - it's about taking responsibility and making sure your company has tailored its own path to compliance. We'll explore the potential impact of personnel changes on compliance scores and delve into a recent case involving a CISO charged with fraud. This episode is for everyone - business owners, cybersecurity enthusiasts, or anyone interested in staying safe in the digital world. Tune in for an eye-opening discussion that will help you navigate the complex world of cybersecurity and compliance.

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.