Importance of Cyber Security for your Startups by G. Higgins & S. Kundu in partnership with Ignite

THE SUMMARYAI-generated

Key Concepts

  • CIA Triad: Confidentiality, Integrity, and Availability - the core principles of cyber security.
  • Cyber Threat Intelligence Frameworks: Tools like the Pyramid of Pain and Cyber Kill Chain to understand adversary behavior.
  • MITRE ATT&CK: A globally accessible knowledge base of adversarial tactics, techniques, and common knowledge.
  • Tactics, Techniques, and Procedures (TTPs): High-level strategies (tactics), specific methods (techniques), and established routines (procedures) used by attackers.
  • Indicators of Compromise (IOCs): Artifacts observed on a network or in a system that indicate a potential intrusion or malicious activity.
  • Spear Phishing Attachment: A targeted phishing attack using malicious attachments.
  • Ransomware: A type of malware that encrypts a victim's files and demands a ransom to restore access.
  • Multi-Factor Authentication (MFA): An authentication method that requires the user to provide two or more verification factors.
  • Incident Response Plan: A documented set of procedures to detect, respond to, and recover from security incidents.
  • Cyber Security Insurance: Insurance coverage designed to mitigate financial losses resulting from cyber security incidents.

Why Cyber Security is Important for Startups

  • Statistics:
    • 43% of all data breaches occur in small businesses.
    • 84% of Canadians are unlikely to do business with a company that has suffered a data breach.
    • 70% of Canadian organizations believe cyber security is a competitive advantage.

What is Cyber Security?

  • Analogy to Fire Safety: Just as fire safety requires balancing oxygen, heat, and fuel, cyber security requires balancing confidentiality, integrity, and availability (CIA Triad).
  • CIA Triad Explained:
    • Confidentiality: Protecting information from unauthorized access (e.g., using encryption).
    • Integrity: Ensuring data is accurate and unaltered (e.g., using hashing).
    • Availability: Guaranteeing reliable access to information and services (e.g., ensuring website uptime).
  • Reversal of Roles: Attackers only need to compromise one element of the CIA Triad, while defenders must maintain all three.

Impact of Cyber Security on Small Businesses: Case Studies

Case Study 1: Code Spaces

  • Background: Cloud hosting and project management service startup founded in 2009. Gained popularity due to interactive user base, flexible pricing, and offering an alternative to GitHub.
  • Attack: On June 17, 2014, attackers gained access to Code Spaces' AWS control panel. The company's attempt to regain control aggravated the attackers, leading to the deletion of the core infrastructure, including EBS snapshots, S3 buckets, and machine instances.
  • Aftermath: On June 18, 2014, Code Spaces announced its closure due to the catastrophic data loss.
  • Key Mistakes:
    • Single Point of Storage: Insufficient backups and lack of redundancy.
    • Reactive Approach: Lack of proactive cyber security measures, such as staff training and a comprehensive incident response plan.
    • No Cyber Security Insurance: Inability to financially recover and reconstruct the platform.
  • Lessons Learned:
    • Implement multiple backups.
    • Develop and maintain a comprehensive incident response plan.
    • Obtain cyber security insurance.

Case Study 2: City of Saint John

  • Background: A municipality with close to 1,000 employees, responsible for services to 67,000 people and managing a budget of $166 million.
  • Attack: In November 2020, the city's systems, including its website, emails, and payment gateway, were affected by a ransomware attack. Attackers demanded $17-20 million.
  • Response: The city decided to rebuild its platform from scratch instead of paying the ransom.
  • Outcome: Reconstruction cost $2.9 million, with approximately 85% covered by insurance and $400,000 paid by citizens.
  • Key Mistakes:
    • Lack of Preparedness: Insufficient backups and absence of a proper incident response plan.
    • Outdated Systems: Lack of system upgrades, multi-factor authentication, and real-time anomaly detection.
  • Lessons Learned:
    • Invest in cyber security training for employees.
    • Treat cyber security as a functional department.
    • Implement access management controls.
    • Ensure vendors have good cyber security practices.
  • Positive Change: The city now has a comprehensive cyber security training plan.

Gaining Perspective and Understanding of Threats

Cyber Threat Intelligence Frameworks

  • Pyramid of Pain: Illustrates the difficulty for attackers to change different types of indicators, with TTPs being the most difficult and valuable to defend against.
  • Cyber Kill Chain: Outlines the stages of a cyber attack, from reconnaissance to exfiltration.

MITRE ATT&CK Framework

  • Definition: A globally accessible knowledge base of adversarial tactics, techniques, and common knowledge (ATT&CK).
  • Purpose: To understand and categorize the behaviors of threat actors in real-world attacks.
  • Components:
    • Adversary Groups: Known threat actors and their associated behaviors.
    • Tactics: High-level goals of attackers (e.g., initial access, execution).
    • Techniques: Specific methods used to achieve tactics (e.g., spear phishing attachment).
    • Mitigations: Recommended security measures to prevent or reduce the impact of attacks.
    • Detections: Methods to identify malicious activity.
  • Attack Matrix: A grid that maps tactics to techniques, providing a comprehensive view of potential attack vectors.
  • Visualization Tool (Developed as part of Master's Capstone Project):
    • Aggregates threat actor behaviors to identify common attack patterns.
    • Highlights the most frequently used techniques, such as spear phishing attachments.
    • Allows filtering by industry or threat group to tailor the analysis.
  • Key Takeaway: Focus on defending against the most common and impactful threats to maximize the return on investment in cyber security.

Membership Models at the Canadian Institute for Cyber Security (CIC)

  • Student/Researcher Membership: Free access to data sets, newsletters, and knowledge sharing opportunities.
  • Corporate Membership:
    • Basic (Consulting): 48 hours of CIC expertise over 12 months.
    • Strategic & R&D: For problems requiring more extensive support.
  • Benefits:
    • Opportunity to define research projects aligned with specific cyber security needs.
    • Access to expertise from professionals with experience in various domains (banking, tech, government).
  • Partners: CIC works with private companies and government organizations, including the City of Saint John and G&B.

Conclusion

Cyber security is crucial for startups and small businesses. Understanding the CIA Triad, learning from past incidents, and leveraging frameworks like MITRE ATT&CK can help organizations prioritize their security investments and mitigate risks effectively. Engaging with organizations like the Canadian Institute for Cyber Security can provide access to expertise and resources to enhance cyber security posture.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.