TMCnet News
COVID-19: Is Coronavirus Leaving Canada's Back Door Open to Cyberattacks? Canadian Ethical Hackers Cite Australian Cyberattack as an Early WarningTORONTO, June 23, 2020 /CNW/ - With the bulk of Canadian Government resources focussed on addressing the COVID crisis, Canada may be unintentionally leaving the back door open to serious state-sponsored cyberattacks. According to Richard Rogerson, Managing Partner of Packetlabs, a collective of ethical hackers specializing in real-world simulated cyber-attacks to protect governments, businesses and organizations, the real danger of cyberattacks has increased exponentially due to remote working during COVID-19. "We just saw a very serious, active cautionary tale play out in Australia after they announced a massive and successful cyber-attack last week," said Rogerson. "Australia was targeted by a state-sponsored cyber-attack across several industries and all levels of Government. In the wake of the attack, the Australian PM urged businesses to shore their defences, stating that the "malicious activity" was also seen globally. Canada clearly needs to take that warning seriously and get our house in order." According to Rogerson, the unsettling truth is that COVID-19 has forced several companies to cut corners for quick remote access and opened exposure to insecure applications that often make use of weak credentials. This gives a tempting opening for cyberattacks. Packetlabs is sounding an early warning, hoping that the Canadian Government and businesses step up to reduce the risk of a successful cyberattack. What Canada and Canadian businesses can do now: 1) Consider themselves a target (even if they are far removed from the Government or sensitive information) 2) Actively test weaknesses and schedule a penetration test: A penetration test is basically a cybersecurity fire drill. Generally, Packetlabs run such assessments blind, meaning that limited staff (CISOs, CIOs, VPs) know that an attack is coming to monitor and assess their incident response efforts. 3) Don't assume your IT guy is on top of it: 4) Educate your staff about phishing: 5) Embrace two factor authentication: "Our job is to make the attacker's job more difficult," added Rogerson. "We work to isolate outdated legacy applications, find all missing critical security patches, and provide recommendations to improve overall security." Rogerson points out that the easiest way for Governments and businesses to protect against a cyberattack is to keep their computer systems up to date with easily available security patches. Australian authorities have identified their attacks as being 'copy-paste compromises,' meaning that the attacks took advantage of programs in the public domain. This also shows that because commonly available programs can be compromised for a major cyberattack, the attackers don't even need the persistence or funding of a state actor to be successful. "The Canadian Government and Canadian businesses need to get serious about their cybersecurity, or we could see a real shutdown through weak remote worker systems, phishing, copy-paste compromises or other proven tactics. The good news is that if we learn from the Australia attack, we can start plugging the holes in our systems today." About Packetlabs Their clients occupy multiple industries including government, technology, media, retail, healthcare, financial, consulting, law enforcement, and more. Packetlabs mandates each of their consultants with the most advanced penetration testing training available in the industry. SOURCE Packetlabs
|
