Making cyber personal: how Canadian companies are painted as targets and what we can do to help them

THE SUMMARYAI-generated

Key Concepts

  • Cyber score: A communication tool to help regular people and small business owners understand their cyber security posture.
  • Dark web breaches: Compromised credentials (usernames and passwords) found on the dark web due to data breaches.
  • Email spoofing/impersonation: Sending emails that appear to originate from a legitimate source (e.g., a colleague or superior) but are actually from a malicious actor.
  • SSL certificate: Encryption protocol (HTTPS) that secures communication between a web browser and a web server.
  • Web application firewall (WAF): A security measure that protects websites from various attacks.
  • Boring Basics: Passwords, Fishing, Patching - the three fundamental cyber security practices.
  • Open Source Intelligence (OSINT): Information that is legally collected from public sources.

Canadian Tech Companies as Targets

  • The Problem: Canadian tech companies that receive government grants are publicly listed, making them targets for cybercriminals. The Canadian government's grants and contributions website discloses which companies receive funding, how much, and when.
  • Data: A study of 60,000 Canadian tech companies that received government grants was conducted using the Cyber score.
  • Findings:
    • 70% of these companies had employee passwords found on the dark web.
    • On average, each company had 20 breached accounts and seven exposed passwords.
    • 88% lacked proper email impersonation protection.
    • 85% had properly encrypted websites (HTTPS).
    • 60% had a web application firewall.
  • Example: A criminal could use the government grants website to identify a company receiving a $100,000 grant, find employee passwords on the dark web, and then impersonate the CEO to instruct the financial controller to transfer funds to a fraudulent bank account.
  • Why Website Protection is Higher: The high percentage of encrypted websites is attributed to Google's search engine ranking algorithm, which favors HTTPS websites.

Email Impersonation: A Major Vulnerability

  • Explanation: Email spoofing allows attackers to send emails that appear to come from a trusted source, making phishing attacks more effective.
  • Technical Details: Preventing email impersonation requires configuring DNS records (SPF, DKIM, DMARC) to specify which servers are authorized to send emails from a domain.
  • Statistics: Only 4% of Canadian tech companies have fully configured email impersonation protection.
  • Impact: Attackers can easily impersonate executives or employees to conduct invoice fraud or steal credentials.
  • Google's Response: Google is penalizing senders of marketing emails who do not have email impersonation settings configured by sending their emails to spam folders.

The "Boring Basics" of Cyber Security

  • Passwords:
    • Use unique passwords for every account.
    • Employ a password manager (e.g., Bitwarden) to generate and store strong passwords.
    • Rationale: If one account is compromised, other accounts remain secure.
  • Fishing:
    • Be aware of phishing emails and scams.
    • Recognize common tactics, such as creating a sense of urgency or using malicious links.
    • Training: Learn how to spot phishing emails through online resources.
  • Patching:
    • Install security updates regularly on all devices (computers, phones, etc.).
    • Set calendar reminders to check for updates monthly.
    • Rationale: Updates address known vulnerabilities and protect against exploits.

Shifting the Mindset: Security as a Marketable Advantage

  • The Problem: Cyber security is often viewed as a cost center rather than a value-added service.
  • The Solution: Frame cyber security as a marketable advantage to attract and retain customers.
  • Examples:
    • Accounting firms can promote their security measures to protect clients' financial information.
    • Law firms can emphasize their data protection practices to safeguard confidential client data.
  • Google's Example: Google's requirement for HTTPS encryption and email impersonation settings demonstrates how security can be tied to marketing and business outcomes.

Recommended Books on Cyber Security

  1. Sandworm by Andy Greenberg: Explores the activities of the Russian hacking group Sandworm, known for attacks on Ukrainian power grids.
  2. How I Rob Banks by Freaky Clown: A penetration tester recounts stories of breaking into banks and other secure facilities.
  3. The Lazarus Heist: Investigative journalism on a North Korean hacking group's attempts to steal nearly $1 billion.
  4. Tracers in the Dark by Andy Greenberg: Follows the use of cryptocurrency by criminals and the efforts to track and apprehend them.

Conclusion

Canadian tech companies are vulnerable to cyber attacks due to the public availability of government grant information and a lack of basic cyber security practices. However, individuals can make a significant difference by adopting the "Boring Basics" (passwords, fishing, patching) and promoting cyber security awareness among their peers. By shifting the mindset from security as a cost to security as a marketable advantage, businesses can improve their security posture and gain a competitive edge.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.