Packetlabs CEO Richard Rogerson on Avoiding Ransomware

Transcription

hi I'm James Maguire and on today's e speaks we're talking about ransomware and ransomware attacks how to handle them how to not handle them and what about ransomware insurance what's the deal with that to discuss all that I'm joined by a major industry expert with me is Richard Rogerson Chief Executive Officer of packet Labs Richard very good to have with us today thanks for having me really appreciate the opportunity sure so I I know a lot of people know what packet Labs does can you explain to us what what does your company do briefly sure so um I had up a company called packet labs and what we do is we deliver on penetration testing and what that is is we get hired by companies to attempt to break into them and understand where they're weak so what we'll do is we'll actually launch cyber attacks against the companies who hire us to help outline where they're weak and what vulnerabilities are in their networks and of course the priority which they should remediate them that's really interesting I'm sure obviously there's a huge market for that and I thought it was interesting when you and I talked before you you talk about hiring hiring personnel and you put them through quite a rigorous hiring process can you talk a little about that and and why that's important absolutely so the hiring process that we have we actually put our staff through a rigorous 24-hour evaluation and what that is is it's a a lab environment where they Connect into over a VPN and they're given 24 hours to to demonstrate can they break into systems and this is really you know the rubber meing the road of what can you do and how far can you get you know a lot of times what happens in pentesting is you can find certain discover certain vulnerabilities but to actually drill deeper into them you need to have the passion and those who are willing and you know excited by the the concept of a 24-hour challenge um they're the ones who finding those vulnerabilities that may have gone unnoticed the ones that you know keep us up at night or land in the newspaper they're the vulnerabilities that cause the critical data breaches and um we find that having a certain threshold of a caliber of Staff having a designation that is the 24-hour exam it really helps us you know stay up with the attackers and the motivations they have as well it helps us V and make sure that the people we have on staff are incredibly passionate about what they do because it's so easy to throw in the towel and say you know I ran whatever vulnerability scan and here's the results but it's the folks that are willing to grind through a 24-hour Challenge from 7 a.m. to 7: a.m. in which sleep is completely optional to be able to demonstrate what vulnerabilities they can find in client networks and that really has a a tremendous differentiator from you know a reporting perspective we find things and we ask we ask these questions all the time from our clients how in the world did you find us you know we've had other firms that have come in and done assessments but they miss that finding why did you find it they didn't and it comes down to the passion and making sure that we're evaluating stats at that level and one of the other pieces that very critical is we have this uh core value on our team it's no egos ever and it's it's very hard in our industry because you can get you know very far with you know um having an infla value of you know what you think you can find but what it comes down to is the people who are willing to ask the questions to learn more and dig deeper they find way more vulnerabilities versus the ones that come to the door and say there's nothing more to find I know what I know they're not going to learn any more they're not going to be to keep up you can't rest on your La rals especially in this type of an industry it's ever changing every single day there's a new vulnerability that comes up and we need to constantly be looking and exploring and learning more about those things because they're constantly changing you just can't stay up with them if you don't sure I mean totally understand that because there's so much at stake and some of the you know confidential information and the cyber security you know wall so to speak that's it's it's really sacred to many companies of course because they're protecting their re really the the corporate the corporate Jewel what about the issue of of of ransomware and obviously we hear so much about ransomware these these past few years so many headlines uh what do you advise companies in particular and what about the idea of insurance because I know that that the providers will will offer ransomware insurance but it's a very difficult thing what what what are what are your advice here yeah so the question of insurance or not insurance is always a difficult one but I think it all comes down to you know understanding that security is really made up of layers and it's really looking at things from different perspectives and making sure you have coverage so having insurance coverage it used to be is you know the simple question of have you been breached and how many employees do you have and that's how the Cyber insurance providers were kind of doing that check well now it's a five-page double-sided question and answer multiple choice and it just keeps going there's a lot of controls they're looking at and the the problem with it is that in cyber they don't have Actuarial data as if they were an auto insurance you know the auto insurance industry they know a haa Civic will get a collision a certain amount of frequency the passengers will have certain frequency is that Decades of data some of that stuff sure yeah absolutely whereas in cyber it was almost like they were writing the blank check know how many employees do you have and have you ever been breached and we've kind of got into the sticky situation where the insurance providers not all of them but some of them were actually preferring to pay out the ransom than to restore from backup or to restore otherwise because it's more expensive to do the full rebuild from the ground up than it would be to pay uh The Ransom and The ransomware Operators know this so they're setting their prices almost like an appraisal when they get into a client Network this is how much it's worth to restore versus this is how much we can get off this particular individual so they kind of do that check and the insurance providers they used to do that check to say what's what's more affordable are we going to pay with the ransom or are we going to pay to restore and this this question is obviously it's fueled a ra a wave of ransomware we've had an enormous um ramp of ransomware where you pay a ransom you're basically allowing or funding the next wave the next attacker that's targeting the next business um and I think a lot of companies they struggle with how do you solve this problem do you wait to get hit or do you buy insurance and it's always a tricky thing but what it comes down to is you have to drill into your network and understand your network from an attacker's perspective you have to think like an attacker in order to understand what they'll be doing in your network to know what controls you should have in place back to the kind of the onion concept MH what about um you also men something me about sometimes that the the attackers themselves will will threaten to tell the SEC about about a breach and it's really a very exploited very cynical strategy what are the details on that one yeah so basically there's been some Evolution over the last little while where you know there used to be this concept of to pay the ransom or to not now the FBI has come out and said don't pay the ransom and if you do let us know now this keeps going and the ransom or operators saying well if I don't have a guaranteed payout how do I how can I ensure that they're going to pay well now they're getting to the next level of extortion in the initial stages what they were doing is they would get into a client Network and they would say these are your crown jewels so they send them back to the the company that was compromised and say I have copy of this I'm going to leak it on the web and you get the timer that ticks down that really induces Stress and Anxiety and a whole bunch of other things right um now if that doesn't work the other angle is now the SEC has imposed this mandatory breach obligation so within a short period of time you have to notify the SEC that a breach has occurred and if you don't do it well obviously it opens the window for the attackers and what we've seen recently in the news is the attackers have actually filed a submission to the SEC notifying them of a data breach sharing the breached clients information and triggering the process for the to do the investigation and that comes with findes of its own so they're almost playing this game of you know cat and mouse you know what are the things that I can do to get money out of you and there's obviously different approaches they can take and this is just one of them that is a that is nasty business no doubt we need to protect our souls from those folks no doubt about it um well all right so so regarding ransomware Packa Labs does offer a ransomware protection product right what what how does that serve customers really yeah absolutely so what we offer is is called a ransomware pentest and what that is is we'll actually trying to break into the client Network who hires us not just random on the internet and at that once we get into that client we're going to then follow the same steps that a ransomware operator would follow so it's not to say that we would go and encrypt the client's Network that's not the case but we we want to do is demonstrate fishing email into the company getting onto a end user device laptop workstation server what have you and then how do you move laterally to the other systems to get to what we would call the crown jewels at that point what we'll actually do is demonstrate on on the desktop we'll create a folder put a bunch of fake files because there's files on there and demonstrate that we can encrypt those with um our own malware so the purpose of this is to demonstrate that we're hooking an encryption routine to encrypt the drive or the folder the antivirus itself the actual controls that are on that server should be catching some of those things so what we're doing along the way is we're trying to trip all of the little alarm bells along the way to get to the final um trigger where you would pull and and deploy ransomware and what we're doing is we're showing them all of the different opportunities that they could have detected us moreover we're actually Drilling in to say these are the different types of ransomware and how they move laterally throughout in your network and the different tactics they would employ how do you measure up against those do you have the right controls are the gaps what are the things you should be considering because a lot of it professionals and Security Professionals they love tools and we deploy all these tools and they're they're great and they they they have their purpose but it's the processes that we really need to drive home we need to make sure that we're doing the right things and we have the Technologies can figure the right way but it's not just technology silver bullets anymore like we don't have that that's not in our back pocket we definitely have to do a whole lot of things at once and when you go through and test yourself with a pent test you get to demonstrate whether or not someone could break in and you get to learn what they did and how they did it and as well compare to your security operations team what should we have seen that would have detected this type of a breach what were the alarm bells along the way that should have been triggered and how quick was our response and that definitely helps the client understand how vulnerable are we to an attack what is the impact of a breach and what should we do be doing in in the next couple of years to really Shore up in our defenses well so that really means that when you start to work with a client uh they may be pretty surprised because you in essence are saying here's how an anonymous hacker could get into your network could could penetrate your perimeter so I would imagine some of the clients are pretty surprised oh we had no idea we're that vulnerable to an attack absolutely and we've had several clients that we've been in their networks for weeks before they've detected us and then we have it where we'll actually escalate our actions to make it so we get noisy enough to get caught and then what we'll do is we'll share backwards all of the things that we did and as well the detection opportunities that they would have had to be able to catch us much quicker so we do want to get caught eventually in our assessments because we're doing this you know to help improve security and as well we're trying to outline all of the potential gaps that may exist because we all go and deploy Technologies but again we don't know if they're enough unless we get breached or we bring in someone to simulate a breach which is what a pent delivers on right well I think the big question is the future of cyber security and ransomware because many companies want to be doing what they can now to get ready for that in the future so as close as you are to the market and what do you see what do you predict for the future of ransomware cyber security a couple years out two three four years out what what what's going to be going on and how could companies get ready for that now yeah great question so the future of ransomware I think it's definitely going to be on the rise you know we're already seeing remarkable uptick in ransomware in the amount of attacks that we're seeing as well as amount of clients who are being impacted by ransomware and I think that's that trend is going to continue the whole uh you know cash for data kind of thing um it's going to continue to uh persist but what clients need or which customers really need to be looking at is how do we make sure that our our network is secure how do we test but verify that we have the right controls in place and a lot of that comes down to you know going through a simulated exercise to understand what you would do in a breach sometimes it ends up being a tabletop exercise sometimes it ends up being like a red team style exercise to demonstrate hands on keyboard how far could you get could you get to the crown jewels how would that happen what should we have done answering a lot of those questions um and I think that's going to continue um to build um and we're still going to have this cat Mouse game of is our antivirus capable of detecting but you always need to test and verify and I think a lot of the attacks what we've seen over the past few years as well to forecast the future they all pry on the human element we're all humans by Nature we all have um you know the the desire to do the right thing to help the Urgent case that comes up over email the boss that needs the gift cards and all these sorts of things right but what it comes down to we have to train our people that's going to continue to be a common theme is the people end up being the weakest link isn't isn't that the TR the people who put their password on a sticky and and and and tape it to their their PC that they might be V of the problem problem but at any rate I mean do you think there'll come a time where ransomware is is largely obsolete because companies of a certain stature companies that can really afford it can at least really get to a level of cyber security where ransomware is a thing of the past or or not necessarily I don't know like I I kind of look at some of the the data breaches that we've seen you know if you look back at MGM MGM has a tremendous security budget and there they um they were breached through someone calling into the call center so it comes down to the human element you have a number of security controls but if you're not testing and verifying and having all of these other processes in place it's it's very easy to continue to have those mistakes happen even with the most secure companies the human element is still there um one of the operators called lapsis what they were doing is actually offering a significant bounty to anybody who would give them keys to the the Kingdom right like if anybody can give them VPN access or credentials into a network you know pay to play you think about you know the opportunities they may have there well here's 10 20 $330,000 if you just give me your your password right who knows how you got it so it ends up being quite brutal um from that perspective but you know we're going to continue to have the human element as far as the vulnerabilities go as well as in the technical landscape there's going to continue to be vulnerabilities over there so I don't know that um there's any anything outside of very like going through an exercise consistently to really um prepare your team for this type of an incident it's going to continue to be a common theme that everybody needs to always test but verify sort of like the whole fire drill thing like in the early days when we didn't have a or run a fire drill to make sure that everybody gathers in the right plate so the parking lot it was chaos we didn't know what doors to go out we didn't you know know what to do but when you go through the process and you go through the structure of making sure that everybody does know and running simulated drills to see what they do and make sure they're doing the right thing then you have an opportunity to help reduce the potential for anything like this happening and that's what you know pentest would do as well important stuff to be sure uh Richard I think you said it a lot of good material I definitely learned quite a bit uh thank you so much for sharing expertise and please come back and talk with us again sometime thank you it be my pleasure

This transcript was generated automatically from the video's captions and may contain errors.

Written By
James Maguire
James Maguire
Published: Feb 2, 2024
Updated: Oct 17, 2024
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

I spoke with Packetlabs CEO Richard Rogerson about one of the most challenging cybersecurity issues of our time: ransomware.

James Maguire

James Maguire has been reporting on emerging technology for more than 15 years. He has won two ASBPE Awards of Excellence for in-depth feature articles about cloud computing and artificial intelligence. He has covered the gamut of enterprise and consumer technology, and regularly communicates with leading IT newsmakers, vendors and analysts.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.