Organizations face a lot of unknowns raised by Russia's invasion of Ukraine, and cybersecurity analysts are weighing in to help.
“CISOs and their teams in Europe and worldwide are either already experiencing cybersecurity impacts from the war in Ukraine and the sanctions imposed on Russian and Belarusian actors — or they soon will,” Forrester analysts wrote in a blog post.
“Their biggest concern is the unknown,” Gartner Research VP Katell Thielemann told SDxCentral, referring to the firm’s enterprise clients. “The situation is very fluid, and reports of cyberattacks don’t come with a lot of details.”
U.S.-based enterprises with employees and operations in Ukraine are concerned about their safety and the threat of cyberattacks spreading to other locations. Meanwhile, companies using vendors based in Ukraine or Russia are concerned with ngoing support and potential impacts to their technology supply chain. Finally, businesses operating in critical infrastructure sectors should pay close attention to government security bulletins, “because cyber retaliation to sanctions is a distinct possibility,” she explained.
Forrester Principal Analyst Paul McKay echoed that sentiment, adding that businesses operating in the affected region expressed concerns with the “spillover effect” and operation continuity.
Enterprises that have “taken a public and critical stance to the war and to Russia in particular, they might find themselves targeted as a result as a form of retaliation,” he said. “It's just a reality that clearly if you put your head up in the middle of something like this, and you make a statement criticizing one side or the other, you're going to be potentially a target of some of those groups that vowed to help one side versus the other.”
That being said, McKay agrees that early indications suggest the use of cyberattacks within this conflict has not been as widespread as perhaps feared.
Organizations should not attempt to predict what nation states will do, but instead focus on preparation and improving cyber resilience, the analysts said. “I don't think there's actually any way in which we can really predict what's going to happen in this situation that is so fast moving, dynamic,” McKay said.
Enterprise leaders mustn't add to the fear, uncertainty and doubt. "Focus on what you can control," Thielemann said.
“Increase awareness and vigilance to detect and prevent potential increased threats, but be mindful of the increased stress and pressure,” she wrote in a recent research report. “A human error due to these forces may have a greater impact on your organization than an actual cyberattack.”
Organizations Should Take Extra Precautionary MeasuresThis fluid cyber landscape is uncharted territory for most organizations, so it's helpful to understand the first protectionary steps businesses can take.
“Following the advice from the national authorities and specific hygiene, best practices is really the best thing that people can do to prepare themselves,” McKay suggested.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently warned through its Shields Up initiative that “every organization — large and small — must be prepared to respond to disruptive cyber activity” in the wake of Russia's invasion of Ukraine.
Organizations in the critical infrastructure sector should maintain stable contact with the governments, McKay added.
Other immediate responses should include improved communications and strengthened channels with security and IT departments, stakeholders, employees, and supply chain providers. Finally, businesses need to demand detailed intelligence from their threat intelligence vendors and collaborate with their security vendors, according to Thielemann and McKay.
Recommendations for CISOs, Security LeadersSo, what questions should security leaders ask their threat intelligence and security vendors?
McKay suggested posing questions around specific threat actors; the tactics, techniques, and procedures used by those groups; threat risk assessments by location; and how to prepare for changes resulting from the rapidly evolving conflict.
CISOs should also make sure they understand the companies’ business footprint and vertical industry, he said, adding that threat intelligence information should be specific to the organizations instead of a generic assessment.
Finally, “use that threat intelligence to get ahead of the news cycle,” McKay said. Understanding the threat landscape and how it impacts the organization can also inform senior executives and board members in a manner that goes deeper than news reports, the analysts said.
Comments