The security risks of taking a stand
ORGANISATIONS face increasing internal and external pressure to take public stands on issues unrelated to their core business. Examples include a broad range of social, political, and global events, which seldom involve the business directly. While the merits or flaws of organisations engaging in sociopolitical discourse are arguable, the fact that doing so creates security risks is undebatable. The question is, how should chief information security officers (CISOs), chief information officers (CIOs), and other security leadership deal with the inevitable risks that arise from their company taking a public stand?
When an organisation chooses one side of a divisive topic, it inevitably alienates those who strongly disagree. Segments of the organisation’s customer base, employee pool, and professional connections will become disenfranchised.
Their disappointment with the organisation, when expressed in a healthy manner, may lead to people berating the company on social media, employee resignations, or calls for boycotts. When expressed in an unhealthy way, there is a risk that individuals or external organisations may decide to take direct action against the company through many means, including data exfiltration, denial of service, spamming or voice phishing. In fact, in 2019, The Times of India reported that ideological cyberattacks were outpacing physical attacks.
Most cybersecurity measures focus on external threats, making them relatively well-positioned to handle an increase in normal threat activity. Insider threats, however, can cause considerable damage to a company, largely due to the perpetrator’s access to internal resources. Sudish Ramesh, a disgruntled former employee of Cisco, shut down 16,000 Webex accounts and deleted 456 virtual machines of his former employer. The total damages from his retributory strike: US$2.4 million.
In addition, the ransomware group Conti pledged to attack anyone who aggressively acted against Russia during the early stages of the conflict in Ukraine. This stance resulted in 60,000 internal messages of the threat group being publicly leaked, crippling their operations and sending members on the run.
Government agencies, in particular, seem to have a number of high-profile cases where former employees have used their positions to leak data. Of course, insider threats are not the only source of cyberattacks arising from ideological tensions. External actors attacked GiveSendGo during the Canadian Trucker protests of 2021, leaking the personal information of supporting donors. Ideologues are increasingly turning to cyberattacks as a means for retaliation, forcing CISOs to consider the security ramifications of their organisation’s position on divisive issues.
Preparing for post-announcement cyber risks
In building an organisation’s overall threat profile, start assessing potential cyber risks through identifying areas that might be particularly appealing to ideologically-driven threat actors. The attacker’s motivation may be more focused on reputation damage rather than financial gain. This means CISOs should look at other high risk assets aside from the standard “crown jewels” – which include the organisation’s website, third-party and vendor access points, and C-level email accounts, to name a few.
Once it is clear what may be used to cause reputational damage to the organisation, it is time to consider which actors might be motivated to harm the organisation. Knowing this information can help a CISO adjust security parameters, processes and controls to better protect the company as it moves towards making its announcement.
Of course, there are still many problems to tackle after the initial threat assessment is complete. Suppose some employees are likely to be angered by the company’s position and have direct access to sensitive assets. If these resources are critical to the employee’s workflow, then removing access is not feasible. Should access be constrained, or more tightly monitored – or would doing so simply offend the employees and increase tensions?
These kinds of questions need to be considered on a case-by-case basis, and weighed carefully before any changes take place. Ultimately, the right answer will be the one that keeps organisational resources the safest. Have a pre-defined approval process agreed with HR and other business stakeholders that can initiate an additional monitoring process of high risk individuals if the approvals and criteria are met.
If the assessment must be presented, CISOs must work hard to maintain the appearance of neutrality while covering the information. Divisive topics bring out heightened emotions among participants, and some may view the threat assessment as an attempt to derail their efforts. For this reason, CISOs should emphasise that the assessment is part of normal security protocol, and not intended to change minds. Care should be taken to present the report as something important to all involved parties, and unrelated to the company’s ideological position.
Cybersecurity is a tough field, and successfully navigating through divisive topics and emotionally charged conversations without compromising its effectiveness is a challenge. However, with the right approach in place, it is not an impossible task for CISOs to tackle.
The writer is chief information security officer for Asia-Pacific and Japan at cloud security company Zscaler.
TRENDING NOW
He built the Vingroup empire. Now South-east Asia’s richest man is handing some key roles to his sons
Grab CEO’s wife Chloe Tong on life with Anthony Tan and finding her purpose
What role can Japan play in Asean’s future?
From folding clothes to factory work: Why China is sending humanoid robots to school