ServiceNow Federal Tech Talk: FBI Insight on Ransomware Prevention and Defense for Federal Agencies
good afternoon and thank you for joining us today kerasoft technology would like to welcome you to our service now Federal Tech talk FBI insights on ransomware prevention and defense for federal agencies at this time I'd like to hand the floor over to our speakers Jason the floor is all yours thanks Heather and thanks everybody for joining today um I think this is going to be an informative session that hopefully you walk away and you've got a better understanding of the landscape of ransomware um James would you like to provide a brief introduction of kind of your title what your role is at the FBI and and kind of how you're responding to um some cyber security events yes good afternoon everybody and thanks for joining uh my name is supervisory special agent James cheeks and I work here at the Washington field office um in the Washington field office we have multiple cyber squads that work the Cyber threat my group particularly works the the threats from a and what we do is we do a number of things one we have investigations against uh the Cyber nation state threat actors and the role of FBI in this is to pose risk and consequences so we're identifying who the actors are collecting the evidence and then providing that evidence um for ultimately for an indictment and which will allow the US government to then determine what the next steps are for them so on a daily basis we're working these investigations but we're also doing a lot of victim notifications we're notifying victims that we come across in the course of our investigations but also victims that come across in investigations of other cyber investigations across the FBI um because we're in the Washington um area of operation the Washington DC area there's a lot of government agencies in this area which are a big Target um for cyber criminals as well as nation states um so whenever there's a victim from an investigation my team will go out there and be the U person that knocks on on the door and provides the information or makes a phone call and make sure we get in a secure manner um anything to help those victims out whether it's indicators of compromise um tppps or anything that can assist them so that's um what we do on a daily basis Thanks James and so I'm Jason bean I am solution sales executive here at service now I have over 20 years of technical Consulting uh specifically around networking digital forensics and cyber security so I've uh consulted for some of the largest uh Federal and uh commercial agencies out there um so I've seen a lot moved into a sales role over the last 10 years uh so it gives me opportunity to stay current with the the latest Technologies and I I appreciate everybody joining today so as I was doing research for this particular um Tech talk well aware of the ransomware threats out there but um some of the numbers and some of the things that I found are are actually jaw-dropping uh you know so obviously ransomware attacks have been increasing significantly um it's reported that September had the record number of ransomware attacks in 23 2023 and that's significant over just what we saw over the last couple of years um according to the NCC group ransomware groups launched about 514 attacks in September which surpassed the previous high of 459 attacks in March of 2023 and here are some statistics that really opened up my eyes that nearly 50% of the breaches in the first half of 22 uh 2022 had stolen credentials 80% of those who paid victim who paid were victims of a second attack and I think we'll talk a little bit more about that um at the time 500 uh 5.12 million was the total average cost of a ransomware attack um this is from 2021 and then 68% of victims of ransomware attacks who paid once were hit again within less than a month with higher Ransom and then there was a 33% increase in ransomware taxs over 2021 so AI driven ransomware is likely to become more prevalent and the attackers are using machine learning to identify targets and vulnerable items additionally these attackers are more likely to be more sophistic use more sophisticated methods to evade detection such as using multiple layers of ENC uh encryption and observation so we're going to a question and answer session with um agent cheeks um so these are some of the questions that that came up through my colleagues and um some of our customers um James can you provide some examples of recent ransomware attacks that had significant impact on agencies and what lessons were learned from these incidents sure um we had several we had the lockpick and the boup ransomware back in 20221 that was worked out of our field office in Newark New Jersey and these were um we believe were developed by Mel matif and this individual um deployed these along with with the um high ransomware and one of the victims was the MPD the Metropolitan Police Department I'm here in Washington DC um the FBI was able to get an indictment on that individual um in December of 2022 another um big case was the hve ransomware group um they had over 130 million dollars worth of Ransom demands um Target over, 1500 uh victims over 80 countries um and those victims were you know hospitals um governments Financial firms critical infrastructure schools and the FBI was able to penetrate that group in 2022 and um steal the encryption key the sorry the decryption keys so with those decryption Keys we were able to once we identify the victim was quickly give them a call and provide them them Keys the keys before they paid the uh the ransomware that is a best case and a a great success story um but that's not always a case where we're able um to get those keys um so that highlights one of the less learns of notifying the FBI early um you know notifying us early we'll be able to identify is this a ransomware variant that we're familiar with and we have information on that we can in turn share ttps ioc's that can pinpoint the victim to identify where the vector of intrusion was and to um to start working their remediation plan um and then in some cases and Hive isn't the only one where we have able to get the decryption keys right but if we have them we will provide them um so that um the victim avoid paying the ransom wear and can get back online what we see um you brought at the statistics early on it's not going away um ransomware is very lucrative and they're only going to get better at it and what we see is the lesson learn is some of the things are are prevalent is the patching um you know this the basic hygiene and that the first few hours are critical sometimes uh especially the smaller organizations large organizations have a very robust cyber security team where the smaller ones don't and they may have feel that they have a handle on it and then once you know they spend a day on it and then they start reaching out their valuable time um that is lost um another lesson learned is the the backups the backups don't always work so when you have your plan and you're you're working your in response plan and your test plan test the backups to make sure that everything is configured properly um so that when you go back online using the backup they're actually available um for you um to use um another thing is with those lessons is no with on your network know what Legacy systems you still have connected uh make sure that you're inviting the right people to the table when you do reach out to law enforcement that it's not just the figurehead or the CEO or the president or the VP that you actually have your subject matter experts that can speak to your network configuration that can speak to how things are configured what's on your network and then what the plan is um sometimes that stuff gets lost in translations because the higher ups may not be familiar um with the details on how things actually work and that's where the problems need to be solved is at the network level um so those are some of the Lessons Learned U when working those investigations okay that's that's interesting so how I guess how frequently are is the FBI able to get uh the decryption Keys um you said it was rare or it's it's not always something you could do but do you have a high success rate at that and if not what really are the options for an agency or a um organization to rebuild from if they're not willing to pay the ransom if they're not willing to pay the ransom you know their options are using their backups if they have them and if um depending depending on if they had an offline copy because sometimes depending on how you had it configured that could be corrupted as well um so their options are to restore back to their best um copy of what they have um another option for them is to to reach out and see sometimes what a third party remediation company that comes in um they may have information that they learned from another um victim that they that was a customer and sometimes they connect those two after an agreement between the victims to have a discussion um I've seen that happen as well so if they're not paying the ransome you want to make sure that you have your backups and you have you can be able to restore here at the FBI we don't advocate for paying the ransom um because that just encourages plus you you're lining their pockets for them to continue to do so but that's a business decision we won't tell you which way to go that's something that the leaders or organization have to make that decision we just ask if the ransom's going to be paid just reach out and let us know and then from there we can try to whatever information we have based on success or non-success of other victims we can provide that information to you so you have all the information available as you make that decision okay um and from what I understand um sisa Congress passed a law the C law back in 2022 where sisa is going to be taking um if you do pay Ransom you're supposed to report to them is that an agency that you do cross um communication with to to get and share information between the sisa and the FBI uh we do communicate between um agencies and other agencies um but I would suggest is when you're reaching out to reach out to both agencies we have different um missions um for us when you look at um president directive um 41 pbd 41 our responsibilities you know for instant response versus Sizzle which is remediation we're not going to remediate it so that's somebody you want to reach out to is Sia but when it comes to identifying the actors that's somebody you want to do in parallel because we could provide you indicators of compromise ttps um and based off experience when we're talking about ransomware these ransomwares are different variants so they kind of evolve just like a a virus would evolve you know for humans right so as a different variants come out we have we assign it to different field offices so they become the subject matter experts so by calling both you make sure that both are notified and both can get working on the their respective piece of the pie that's going to help your organization sometimes when you just reach out to one there could be a delay or an assumption that the other one knows and then time is lost again you know the critical hours are in the beginning um so you want to reach out to to both contacts no that that's great you know good information and it sounds like time and truly is the enemy in your experience you know what are some of the common vulnerabilities or weak points that cyber criminals are exploiting to execute ransomware attacks and you know how can agencies better Safeguard against them um the top three is RDP remote desktop um email fishing and then software vulnerabilities and just like everything else these are known and it you know it's been like that for years especially in Co you see a spike of people working remotely um so when you're using RP doesn't mean don't use it it's just the company should be aware of what the risk and vulnerabilities are by using RDP and then have mitigations in place you don't have to have every port open just like with everything else got make sure things are configured right and and that applies to everything a lot of times people think they're safe that we have firewalls we have an IDs they have all the equipment the latest ones on the market but if they're not configured properly um that's not going to to protect you the way you think it is um so RDP you know having an account lock out because sometimes a Brute Force um the the actors are trying to get in email fishing you know we're trained to look for spelling errors and mistakes and bad grammar that was really a case um years ago nowadays they Outsource that um that that Duty right so they're they're resourceful um they run a business so the it maybe someone in the US is crafting this for an organization out of Nigeria so don't always expect that you're to find um mistakes with the email fishing and keep training your people not to click and you're when you're you're doing those tests try them all hour because if you send somebody an email 7 o'clock in the morning um they're not going to be as um as Savvy as they are at 9 10 o'clock after they had that cup of coffee so don't just test in the day test at all times on to make sure that the message getting across for email fishing and then software vulnerabilities um patching as soon as possible as you know with zero days there's a time before the zero day where the actors who have discovered the vulnerability are already using it and then once that zero day has been communicated to the world they're now rushing to use it before anybody gets a patch because an IT person may not patch right away they want to test it make sure that it's not going to make their Network unstable so they're they're bad actors are counting on that lag where that Sal vulnerability has been identified and they're going to keep attacking and then a lot of times what we see is the company be compromised by vulnerability that was discovered and a patch was issued six months or a year before so they will go back and check to see who hasn't updated who hasn't patched and so it's not just because of the zero day was communicated on January 1 they'll be January 1 two years later and they'll try the same patch and they'll always find someone okay no that that's great um so it sounds like it's a you know there needs to be a good mix of Technology but then also end user training to make sure that the the the user is not inviting the the bad actor into the organization would you what would you rank as a higher priority training or technology I say go hand inand because why the technology that's a whole different group that's going to be working on that the average user is not going to be part of purchasing that technology um so the user should be going for training and they should be receiving that training reading about it and then it should be reinforced and at the same time in parallel HR should be working with finance and should be working with it folks to make sure that the best equipment is being purchased legal is involved making sure that there's no restrictions there so those teams should be working on purch receiving equipment and those same teams should be working on the the the training scenarios and the security awareness um both in parallel everybody working together it should be talking with HR on who are the right people to hire whether it's the people on the cyber security side the workers it's a it can't be in silal everybody needs to be working together so I say it's important both are very important um both lead to vulnerabilities both can compromise and it's something that could be tackled together and at the same time okay how is the evolution of ransomware tactics and techniques influence the way that the FBI is going to approach combating the threats and what types of advancements have been made by law enforcement to be able to stay ahead of these cyber criminals all right what the FBI has done um because ransomware the actors uh continue to evolve they go from individuals just making ransomware and deployment themselves to r someware as a service where they're making it for other people's and deploying it um they're using it and giving it to other people and one of the ways to the to try to prevent this having the antivirus and anti-malware detection on your system so what that forces the Cyber actors to do is to change the variant um so what that allow it to do is to as they make their different tweaks and change like the hash so that it's not detected um new variants come out so what we did at the FBI was we went to a model where every variant um that is identified is assigned to a specific field office so that they become the subject met expert um to get ahead of this what we do is they'll create each office will create a list of questions a questionnaire so that for example if you're in Cincinnati Ohio and you have a ransomware attack and you call the the Cincinnati uh field office they may not be familiar with that particular variant but they can look and see who is and it could be the um Dallas Texas office so they'll look and see what the questionnaire is and they'll ask like what file types do you see um you know was there a ransomware note where did you find it what did they say so it be a whole list of questions that the Cincinnati office can ask that victim and then package that information and provide that to the office that's working it so that they have all that that information and they can start seeing are there a pattern are there ttps so maybe the first four victims um just provide information but by time the 10th 11th 12 victims calling we're able to give them information to help them get back online um so and if you can help the community that in terms can stop the bleeding and prevent the ransomware attackers from making the income that they expected to and maybe that can kind of stifle that particular group and then also that we can start identifying based on the information we give the different victims who the actors are and if they're another country leverage our our contacts with our foreign Partners uh to an effect an arrest so one of the things we did was besides doing that is looking at the ecosystem you know who's creating the malware um who's doing the ransomware who's providing infrastructure you know sometimes it's a different group that create the infrastructure so we started looking at the ecosystem uh for ransomware and as well as um our approach to how we conduct investigations for ransomware okay um it's that's interesting so when you know an organization is a victim of ransomware and the data includes pii is the automatic assumption that that data is compromised and it needs to be reported uh as a data leak or a data breach um where more communication with the uh the end user needs to be um either communicated or um they need to be contacted let them know that their data has been compromised um we assume that their data has been compromised and we also assume that the thread actor still in that Network and despite efforts by the the organization to remediate in terms of notifying there was legislation that was proposed U multiple times to my knowledge it hasn't been actually passed where um they they have to report that but if we come across it during our course of our investigation we will notify um the victims and then we work with our victim Services we have an obligation um and mandated by the Department of Justice that if we identify victims our victim services U will'll work with them one notifying them of what we know and then also just keeping um I want to say Taz but follow up because sometimes the the victims you know be like okay we're used to Pi with stolen you know some of us in our government we expected was St them with the OPM brief years ago but it doesn't make it any easier for for the victims so we want to make sure that um just like any other crime that the victim is cared for okay um and you know one of the statistics that I I heard or through research was around double or triple extortion as far as the way that um once that bad actors do get hold of that uh data can you explain that a little more detail um yes because originally was ransomware they would encrypt your data um send you a ransom note and tell you how much they wanted and to release that data then they evolv to doing the double ransomware where they would in one encrypt your data and then two xfill it so now they're giving you one rant they're sending you the ransom note demanding payment to release um the the the data on your system so you can get back access and get back online and then once uh they do that the double is now they're they're going to charge you an amount of money uh to keep them from leaking that out to the public um as you know you know companies are in the business you know in um operate to make money and if people lose confidence they can lose customers and then lose money so that is a a viable threat and that's the double extortion comes in where they're now uh threatening to do so and typically does the F how does the FBI address that um the double extortion is there anything to do to there anything that could be done to help prevent that um in terms of preventing it's the goes back to the you know the Cyber hygiene um it goes by goes back to identifying the problem as soon as possible um and you know one of the things that we see when we try to talk to victims is not everybody has logging um right so they don't keep logs or they keep it for a very short amount of time so you're not seeing they're not seeing what's being ex exfilled um they're not creating a baseline of what the normal activity looks like in a network um so what the B without basic hygiene um the actors got to get in any ways but it makes it easier for them because if you make it hard for them they'll pivot and find another victim so may not necessarily prevent it um but it's it's having the the things in place which is the right appliances having logging um in place and being able to ass sift those and those what normal and what's not normal traffic okay and do like if if an agency or organization does pay Ransom and they get their files unlocked do does you do you see an influx of other groups trying to exploit that and and go immediately after the that particular Network and try and see if they can um use either the same exploits or maybe a different exploit uh to hold their data Ransom uh we've seen where um a victim's been hit multiple times um sometimes it's because they know that or they're taking they're predicting that that individual company might not have patched and they're going to test that vulnerability it's not anything that they're doing in they're not working together it's just a bad actor knows that there's a vulnerability out there and he's going to use it and unfortunately sometimes a victim can get hit more than once um by different actors for the same vulnerability again it goes back to how long it takes them to respond um when it comes to patching how long it takes them to remediate and how long it takes them to put in um mitigation um controls in place okay and one of the areas that I'm I'm most concerned with is you know has artificial intelligence or machine learning how's that change the way that hackers are approaching these types of um either malware or ransomware attacks um is this something that is of concern of the FBI um Ai and what can be done as AI is a concern and that's an area like everyone else we're looking into and trying to understand as it's being developed and being used more and more but when it comes to the the actors just like us and anybody else that's curious or researchers they're testing it and and seeing what's the art of the possible with AI in terms of them actually using it you know how would we know that they actually used AI to create that that that message um for that that fishing or for the use it to look at the code and help them build it faster or check for errors I don't know at this point how we will be able to detect that um but I would tell people that that I have that concern um at the end of the day you know maybe it means that they do it faster create malware but if you're not protecting yourself now like what's the difference you know if you're not putting the hygiene and you're worried about AI you know I think just I wouldn't focus on AI if it's definitely a good topic to learn a lot of good books and and blogs and white papers on AI but I would tell people stop you know concerning about Ai and just focus on doing the basic um because they're going to get you you know anyway the easiest way and the easiest way has been working all along which is you know right now the people are getting hit today and got hit yesterday and all that was without AI it was just they didn't patch um or they didn't practice uh basic hygiene hygiene is not the end all Beall but it does make it harder and like I said actors they don't want to work hard they want to make money so if they start running to roadblocks they're just going to Pivot and find an easier [Music] victim okay um you might addressed this a little bit uh earlier but you know what are the typical steps taken by the FBI in investigating ransomware attacks and how can the V victims best cooperate with law enforcement during these investigation processes I know we mentioned a little bit about um you know reporting to FBI and sisa but are there certain things that um an agency or an organization can do in advance as they're waiting for an FBI response to kind of help with the investigation process yes I would say they can help themselves by coming up with an incident response plan um before something happens and those discussions should include their legal councel um you know we mentioned several times that time is critical there's a lot of time spent if this conversation hasn't taken place on you know the the network Defender the person behind the keyboard and the organization they just want to get things back online and things running um but the legal may have other questions and concerns and can put the breaks um on those type of um efforts so it's best to include them early um so that they're familiar with the terms they're familar with what's being what's taking place they are familiar with what is going to be passed to law enforcement so that they're familiar what law law enforement is going to act to the victim and that way if there's any concerns on for example what the FBI is asking for we can hash that out before an intrusion so at the point of an intrusion the the whether it's the sizzle the deputy or someone in that chain of command should already know what can be passed and should be able to pass that immediately to law enforcement whether SZ or the FBI or both versus waiting for approval from from legal so I would say start there um and then soon as they have something immediately pick at the phone and say okay this is what we have these are the roc's we think it's uh a China actor or we know it's a particular it's apt29 we know a specific threat act that would that is very helpful um if there is a a contract with a third party vendor letting us know hey we have a contract with this thirdparty remediation company and you know getting approval to share that information if we can see that report even if it's in the draft allow us to get a better understanding of what occurred and then we can look through our own Holdings to see what information we have that can enrich what the victim is already um seeing or hasn't seen yet so it's a before part of the planning and then during is is sharing being transparent um I can tell you how many times working with companies where they say nothing happened but then you show them like here's your xville and you know all this was XF at this date and this time and they're like then okay yeah it did happen so being just being upfront being honest we're not Regulators um you're not forced to cooperate with us we're here to help um so being honest being transparent um is the best way for us to be able to help you okay so it sounds like a lot of ransomware attacks may be under reported just because it's more of a they don't want to admit that it's happened um do you have any statistics on that I don't have the statistics because you know we we don't know what we don't know um so some don't want to report it because they they don't know it's even going on um so then once there everything is locked out um they they hire a company they feel it resolved and they say okay you know we have insurance so we hired a company we have them on retainer um let's just move on um some don't want to do it because they feel that we you know we're a regulator and we're g report it or they're going to be penalized um for it there so there's several reasons why they don't you know the numbers is under reported um but it's hard to put a finger on exactly what the actual number is but as you can see from the numbers keep growing for the those that are reporting it um it's a lot yeah and the research you know every day I I get email alerts of a new company being hit and that that that attack's probably happened weeks ago but they're just starting to announce it today so it's um it's constantly it's growing exponentially um yeah and the attack could have happened weeks ago but the the intrusion probably happened month or two before because U what we see with some especially the very sophisticated actors they're going to get a foothold inside the network and they're going to take a look and do an inventory and see what's of value you have a pii that they can sell to One customer right they have Trade Secrets another information they can sell to other customer sometimes they sell the same thing to multiple customers so they may spend time in the network looking around to see what's of value and then once they're done with that or they feel that that vulnerability is going to be disclosed and then they enact the ransomware um so the actors could have been in there for for a while okay and then are there developments in ransomware that the agency should be more vilant about I know we talked about uh patching vulnerabilities understanding the assets but there are there other areas that you know that you feel like maybe be is you know a common theme across the the teams that you're investigating you know post breach um I would say well the themes are it's using the victim the I'm sorry user or clicking um or could be where you have you know the pirated connections where somebody wants to play video games at work and and so they create a um they log something into the network to get around whatever security controls are in place um or get around software restrictions I say just categorizing what what's the value um you know viit folks should know what's on the network prioritize it um what they have making sure they have the antimalware and Antivirus disabling the macros doing white listing like it's a defense in depth it's like you have to put everything in place just to to make it harder nothing's foolproof but just to to make it harder um but every victim as we look across is is um usually a common thingses one of the three ways they got in and then you know how they were able to then um lateral through the network especially if it's a flat Network okay so NE Network segmentation would be an important aspect uh to be able to try and keep the lateral movement from uh really propagating across the network yes and having that Network map so if there is an intrusion whoever is doing the remediation and law enforcement we can have a look um goes to knowing what's on network but yes if you can segment it um that's a another way to to create that um the offense in death I'm not seeing a lot because it takes work um and sometimes they don't want to go through it and just they figure that they'll just throw a firewall and then everything it'll be safe okay and then do do you feel like a agencies or organizations that rely too much on the cyber security Insurance side where they they've got you know they know that they're covered for payments if they need to so they can maybe they feel more comfortable without having that that good cyber hygiene um yes I see what they do is the the bare minimum just to satisfy that the requirements for the Cyber insurance and it's a false sense of security what I I realized a few years ago is just started getting fewer calls um from victims and started getting calls from like uh legal representatives and then when I tried to call them back um they wouldn't returned calls so we started seeing is that one of the things was that they had to reach out to law enforcement so they're putting the check mark that they made that phone call and but not providing that information and moving on but with not realizing that it's all in a fine print um cyber insurance is just like any other type of insurance it's you know out there for the company to make money um so they don't pay for everything so you have to really see what it says is there any stipulations on how your stuff was configured did you have to have certain equipment um did you have to have certain protocols in place it's very important you know when they buy the insurance to read the fine print to see what's covered what's not covered and what can keep you from getting coverage on a particular cyber event okay um I I know we're running close to time I believe you have to drop at uh 10 minutes of I've got one last question and then we'll see if there's uh any questions from the audience but is there a time of year that is typically you see more of these attacks know September was one of the higher months in in recent history I'm not sure why SE why September but is there certain times of the year that you start seeing these uh happening more frequently I want to say you know I'm familiar with it this particular time of the year what sticks out to me is March um just because I start seen like the small mom and pop type um firms that provide tax services so it doesn't mean that March and April is a particular High time it just sticks out to me where some of the small organization tied to um tax services are hit um usually it's just tied to the vulnerabilities what you know what's out there um what's the L vulnerability they're testing these vulnerabilities um they're looking at other people researchers that are testing it and to see you know what's out there what's vulnerable and how quick they can can react so yeah again yeah September I don't know why that particular month was High um maybe it's just the reporting um but the threat is ever present is present every day and they focus on um doing what the best they can to protect themselves okay I wasn't sure if it was you know August a lot of people take time off for vacation including security team so maybe there's a you less staff in in that can catch these things as they happen or you know around the holidays where people are you know trying to focus around family so sometimes you can't you just can't uh have this the full staff that you want um so I was just curious if that was uh something that that did come into play they do pay attention to holidays um they know the government work works Monday through Friday um so that is something they're aware of just know that if you discover an intrusion on a weekend call us um it's a 247 job for us um and we will have that conversation okay and then Heather are there any questions from the audience I see one in the chat um it says as AI is learning and becoming more humanlike whereby information for updates or how to fix it may appear sound what is the FBI doing to keep up with AI in the new way that potential actors can abuse networks um we talked briefly about AI so what we're doing is we're trying to stay on top of what the latest developments are with AI and what the capabilities are and when it comes to what they're able to how they able to use that um just continues to communicate to individuals on how to protect their networks having the security awareness briefings um providing that to companies being available for companies for ttxs training exercises um letting know that that's a good way to test the response plan and to make sure that everyone's on the same page and we're happy to to participate in those type of events are there any other questions Jason there's one more in the Q&A I don't know if you want to um scan that in case you want to take it offline or or do it over the line we'll have to I'll have to have um our security team respond to that um appreciate the question so we'll we'll respond to that uh directly um James I really appreciate the time do you have any closing thoughts that you'd like the audience to kind of leave you know with you know just having in the back of their mind as some you know some best practices or some some things to to think about post this Tech talk um keep educating yourselves just like coming on this call um because hearing you know what's out there it reinforces what you're learning with the security awareness training that you're getting from your companies continue to educate yourself on ransomware and the Cyber hygiene you know all that information has been out there for years sza has a great page where you can review that information and their stop ransomware I encourage everybody to take a look at that where you can get the cyber tips um as well as see latest information and see if they have any advisories um reach out to your local FBI field office establish um those contacts so that when you pick up up the phone and call and I leave you that if somebody comes and say hey they're the FBI you can always call the field office and say hey somebody just came by and you know if it's me knocking on your door you can call the Washington field office and we said hey James Cheeks is here he claims he's an FBI and you know they can give you the badge number and you can verify it that way um a lot of times you know I'll send my agents to do notification and we'll spend days of back and forth are you an FBI agent are you really an FBI agent you tell them to call the FBI office time is critical and it's good to be vigilant and watch for imposters but just pick up the phone you don't have to trust us with the number we're giving you you can look online call that FBI office and verify that individual so that we can get you that information um we'll give you a teleporter link where we can send you that information um so we can go out of bank and um so get to know your FBI um office and and have that as part of your your response plan and you know thanks for inviting me um together working amongst yourselves get to know not only the FBI but your peers um in the industry because they may be seeing things they have experts and people that you can talk to bounce ideas and see hey what are you seeing and sharing amongst yourselves is also a better way to to protect yourselves well thank you so much I appreciate the time special agent cheeks uh this was really informative and I'm sure we'll have some additional questions if um if if our participants do have questions specific to this uh webinar can they reach out to you directly um yes I think I don't know if the had the uh email address on there but yes again reach out to me directly um and then we'll see we can get you the answers everybody stay safe and hope everybody has a great Thanksgiving that's coming around the corner thank you so much appreciate it so hopefully special agent CH was able to provide some valuable Insight um we've got a couple of minutes left and I just wanted to go into high level how service now can help uh protect and also plan for you know the post post uh post ransomware attack because it's not a matter of if but it it it's really going to be when um so you know as he mentioned you know assets are a major concern so you can't protect what you don't know or in your environment so having a good understanding of where your assets are what's on them is vitally important um you know also having processes in a plan so you know it comes back down to people processing technology ology but having a a a process that you can follow you know as part of that planning phase is vitally important and that could be you know making sure that you have the contact information for the field office for the FBI hopefully you never need to use it but having that there um is vitally important and then also you know start understanding what you know the your business criticality is and your recovery Point recovery time objectives so if you do uh face a ransom attack you can't decrypt it and and you can't pay the ransom how much data can you afford to lose um what how long can the system be down before it impacts the overall business knowing what those are up front also helps un makes these decisions a little bit easier in advance because you don't want to have to do this when it's already too late um and then when it comes down to protection so you have to have controls uh you know really the controls and then test those controls with you know simulated attacks so you can understand where they're there might be gaps and you can monitor risk indicators to gain Insight on the potential risks give you your data so you can help prioritize and respond to different threats because that they're coming in different ways they're using fishing they're using um you know RDP they're using vulnerabilities having uh you know having a clear picture of which ones uh risk indicators are out there is going to be vitally important um and then you know monitor make sure that you're monitoring everything so you understand uh what anomalies are um and then when it comes to the response side it's really around planning and managing response operations um they these can't happen on the fly so I if if you're trying to put a response plan together post breach it's already too late so have that out have it tested and make sure that you have a a plan and automation is is a great um a a a great way to make sure that you can cut out some of the the noise but then also make sure that you have um the right types of security events bubbling up to the right people um have a communication plan as you know as agent cheeks mentioned you legal might need to be involved you know there may be different groups within the organization that needs to be part of these uh these conversations HR um these are all areas that uh I think all you know some some agencies are are looking at but others may be um may be missing and then you know how do you restore the systems what's the process you know and what type of B you know what is your business continuity plan um and then and very similar to say nist 861 around the adapt so not hopefully you get Lessons Learned so you when you do see an attack or an attempted attack um you're able to take and start identifying what the root cause was was it successful was it not successful if it was successful how can we help Harden our security posture so really being able to have that type of um methodology so you're continuous improving the security posture over time um will certainly make it easier to prevent these attacks there's nothing that can there there's no foolproof or or silver bullet that can stop a ransomware attack but if you could be as proactive and make sure you have the good clean cyber hygiene understand your assets and test and find where you're weak that will will go a long way um and then for those in the government and even a commercial space it really ties back down to zero trust um architecture because you're looking at you know identity making sure the right people are on the network that the right devices are on the network you know where they are the network itself making sure that that's secure um all your applications and then the data um all these things come into place you know and as agent chica mentioned Network segmentation that's a key component for for zero trust um asset Discovery is a key component for zero trust so a lot of the the zero trust methodologies and pillars can help with the mitigation or the reduction of risk for uh zero day ransomware just good clean cyber hygiene um so these are areas that I think are very vitally important and um the service now platform can kind of help bring all that information information in so you can make more informed decisions um so in conclusion are there any other questions I think for the service now team I think that's a no um so thank you so much for attending this hopefully you learned something uh hopefully it opens up conversation and dialogues uh back uh with your uh with your teams and you know if you have questions for special agent cheeks his contact information is here it'll also go out in a email that we send out post uh post Tech talk and then my contact information is here as well too um but as agenc she said you know wish you ha Happy Thanksgiving hope everything um goes well but you make sure that you're you're planning and hopefully um you know you're able to to stay ahead of these types of attackers uh again appreciate the time if there's no last questions I think we can end this Tech talk
https://www.youtube.com/watch?v=1yyWCxYhTZw