Opinion

Don’t Be The Next Sony

Alexander Jones Chief Information Officer, Trojan Horse Security
Font Size:

Last month’s data breach left mud on the faces of the leaders of Sony Pictures Entertainment with the release of thousands of files including financial documents, E-mails, and unreleased movies. The hackers stole and deleted much data from Sony’s servers, and journalists downloaded and released reams of sensitive data. Sony’s network was down for days as IT staff members attempted to repair the damage.

How did this attack occur? How could it have been prevented?

For well over 20 years, I have consulted for thousands of companies worldwide finding vulnerabilities, advising on how to avoid a breach, and offering suggestions after one has occurred. I’ve seen clear patterns in the decisions of and results for the companies I’ve worked with.

We can’t change what happened to Sony – nor to Target, Home Depot or any of the other companies that endured major breaches. But we can step back, learn from those tragedies, and work to ensure that similar events don’t happen to us.

Here are five lessons from this fiasco:

1. Think ahead — Assume attackers will try to breach your company, because they probably will. They are often unsuccessful – but that risk could be catastrophic. Strong leadership can make the difference by taking these matters seriously and spending what is necessary to secure their company. Given that a breach can cost millions – Sony may lose more than $100 million – the right spending can drastically minimize the risk both to the company and to its personal reputation. A company should do a simple risk analysis; how much can it lose if I breached? How much is it wiling to spend to guard against this?

2. Focus on the basics — Most companies don’t even do many of the preliminary steps that stop an attacker from gaining a foothold on a network, such as sufficient patching (fixing potential vulnerabilities) and setting strong passwords. A Sony-sized company is usually hard-pressed to keep track of all its systems. For some, a system inventory database can keep management informed about every system on its network – as well as its operating system, software, version levels, and more. As an ethical hacker, I can tell you that just one unsecured system can give intruders a foothold, which is very dangerous.

3. Follow the patterns — Although the FBI described the level of sophistication for the Sony breach as “extremely high” and the malware was sophisticated enough not to be picked up, as with all attacks, it followed a pattern. Hackers may probe a network, scan its ports for vulnerabilities, attempt to login using default or simple-to-guess passwords (causing failed login alerts), look for and reuse admin credentials, copy data, and more. No guarantees, but a company can pick up these patterns with proper monitoring systems. Although it may not detect stealthy attackers right way, it’s more likely to detect them he longer they are in its network. The hackers who breached Sony transferred terabytes out of the network – and weren’t even detected.

Every log should be collected from servers, firewalls, intrusion prevention systems, etc., and sent to a Security Information and Event Management (SIEM) tool. It should be monitored 24/7 by an organization with expertise in reading the alerts. If a company tries to do this independently, the system will either sit in the corner gathering dust or it will – as Target did – dismiss all alerts as false positives.

4. Protect the crown jewels — Obviously, if data is a company’s main business, it needs to do all it can to protect it, a process known as data loss prevention (DLP). How did Sony not know that such huge amounts of data were being sent out of its networks? Did they employ no DLP technology, or even monitor key systems to know when such things occurred?

Any company that wants to protect key data assets simply must have a strong DLP program. Some of these steps are easy: segmenting and placing sensitive data in its own network, protecting the data by using a firewall, only giving access through the firewall to those that need it, and setting strong outbound (egress) filtering on all firewalls to prevent data leaking out. Additionally, it might consider purchasing DLP software that stops data from being e-mailed, printed, or copied onto a thumb drive, and tying its logs into its managed SIEM systems. There. You’ll have another way to know if a breach is occurring.

5. Plan for the worst. Accept it — Companies get breached. But a company must be able to continue operating after an attack. The fact that that some Sony employees had to use whiteboards because they lost all access to sophisticated technology makes me wonder if they had a Business Continuity / Disaster Recovery (BCDR) plan in place. With a good BCDR and employees trained about what to do in event of an emergency, the company can continue to operate despite the attack. Historically, companies would only have emergency plans in case of fires, tornados, and earthquakes. Nowadays, companies also need written plans for the event of an attack, so they won’t be sent back to the 1800s if a major breach occurs.

These lessons aren’t a magic bullet for preventing or minimizing a breach. They do, however, offer good strategies to avoid Sony-style mistakes.

Alexander Jones is the chief information officer of Trojan Horse Security (TrojanHorseSecurity.com), a Washington-based security-consulting firm with headquarters. A recognized expert in cyber security, he has consulted for many of the world’s largest companies.

Tags : hacking sony
Alexander Jones

PREMIUM ARTICLE: Subscribe To Keep Reading

Sign up

By subscribing you agree to our Terms of Use

You're signed up!

Sign up

By subscribing you agree to our Terms of Use

You're signed up!
Sign up

By subscribing you agree to our Terms of Use

You're signed up!

Sign up

By subscribing you agree to our Terms of Use

You're signed up!
Sign up

By subscribing you agree to our Terms of Use

You're signed up!

Sign Up

By subscribing you agree to our Terms of Use

You're signed up!
Sign up

By subscribing you agree to our Terms of Use

You're signed up!
Sign up

By subscribing you agree to our Terms of Use

You're signed up!
BENEFITS READERS PASS PATRIOTS FOUNDERS
Daily and Breaking Newsletters
Daily Caller Shows
Ad Free Experience
Exclusive Articles
Custom Newsletters
Editor Daily Rundown
Behind The Scenes Coverage
Award Winning Documentaries
Patriot War Room
Patriot Live Chat
Exclusive Events
Gold Membership Card
Tucker Mug

What does Founders Club include?

Tucker Mug and Membership Card
Founders

Readers,

Instead of sucking up to the political and corporate powers that dominate America, The Daily Caller is fighting for you — our readers. We humbly ask you to consider joining us in this fight.

Now that millions of readers are rejecting the increasingly biased and even corrupt corporate media and joining us daily, there are powerful forces lined up to stop us: the old guard of the news media hopes to marginalize us; the big corporate ad agencies want to deprive us of revenue and put us out of business; senators threaten to have our reporters arrested for asking simple questions; the big tech platforms want to limit our ability to communicate with you; and the political party establishments feel threatened by our independence.

We don't complain -- we can't stand complainers -- but we do call it how we see it. We have a fight on our hands, and it's intense. We need your help to smash through the big tech, big media and big government blockade.

We're the insurgent outsiders for a reason: our deep-dive investigations hold the powerful to account. Our original videos undermine their narratives on a daily basis. Even our insistence on having fun infuriates them -- because we won’t bend the knee to political correctness.

One reason we stand apart is because we are not afraid to say we love America. We love her with every fiber of our being, and we think she's worth saving from today’s craziness.

Help us save her.

A second reason we stand out is the sheer number of honest responsible reporters we have helped train. We have trained so many solid reporters that they now hold prominent positions at publications across the political spectrum. Hear a rare reasonable voice at a place like CNN? There’s a good chance they were trained at Daily Caller. Same goes for the numerous Daily Caller alumni dominating the news coverage at outlets such as Fox News, Newsmax, Daily Wire and many others.

Simply put, America needs solid reporters fighting to tell the truth or we will never have honest elections or a fair system. We are working tirelessly to make that happen and we are making a difference.

Since 2010, The Daily Caller has grown immensely. We're in the halls of Congress. We're in the Oval Office. And we're in up to 20 million homes every single month. That's 20 million Americans like you who are impossible to ignore.

We can overcome the forces lined up against all of us. This is an important mission but we can’t do it unless you — the everyday Americans forgotten by the establishment — have our back.

Please consider becoming a Daily Caller Patriot today, and help us keep doing work that holds politicians, corporations and other leaders accountable. Help us thumb our noses at political correctness. Help us train a new generation of news reporters who will actually tell the truth. And help us remind Americans everywhere that there are millions of us who remain clear-eyed about our country's greatness.

In return for membership, Daily Caller Patriots will be able to read The Daily Caller without any of the ads that we have long used to support our mission. We know the ads drive you crazy. They drive us crazy too. But we need revenue to keep the fight going. If you join us, we will cut out the ads for you and put every Lincoln-headed cent we earn into amplifying our voice, training even more solid reporters, and giving you the ad-free experience and lightning fast website you deserve.

Patriots will also be eligible for Patriots Only content, newsletters, chats and live events with our reporters and editors. It's simple: welcome us into your lives, and we'll welcome you into ours.

We can save America together.

Become a Daily Caller Patriot today.

Signature

Neil Patel