You’ve seen bits and pieces of the SolarWinds story in the news, but what actually happened (to the best of our knowledge) and what can CISOs learn from it? On this episode of Cyber Security Inside, Tom and Camille invite Dr. Eric Cole, CEO and founder of Secure Anchor Consulting, onto the show to talk about the SolarWinds hack.

Plus, during Fun Facts:

• What’s an early sign of Alzheimer’s or dementia?

• What did people believe would kill you in 1954?

• Why was a donkey-less game named Donkey Kong?

Tune in to find out. This is one you can’t miss!

Here are some key take-aways:

• Large-scale data breaches all share one commonality: a lack of awareness about unprotected data.

• When it comes to asset inventory and patching configuration management, automation is key. Businesses can’t rely solely on humans to get the job done. There’s technology available that can recognize when a new asset appears, so businesses only have to respond when there’s a problem. They don’t have to be looking 24/7.

• The SolarWinds attack was a two component attack. First was the attack against SolarWinds to modify their source code for their Orion product. Second, was the distribution of a malicious update to all of their clients (which then created a back door).

• Unlike attacks in the past where a specific company is targeted, with the SolarWinds attack, it’s more likely that a list of companies was compiled. From there, the hackers looked for common denominators between those companies in search of a way in.

• There wasn’t a single point of failure with the SolarWinds attack. Source code shouldn’t have been directly accessible on Internet facing systems; checks and validations should have been done before sending out updates; and checking and testing should have been done in-house.

• If you have servers or software from a third-party vendor, that needs to be isolated on a separate segment and going through a firewall.

• Businesses should always be watching outbound traffic for anomalies.

• The SolarWinds hackers knew that it’s not uncommon for vendors to push out patches for software. So, they made their malicious code look like a patch update.

• Not all SolarWinds customers were affected. With this attack, you had to be running a specific version of SolarWinds in order to be affected.

• These types of attacks aren’t typically spotted by security departments. They are usually caught as a result of performance issues with IT equipment. The reason is the attackers are clever enough to fly under the radar with security, but they don’t understand the thresholds of the hardware.

• Even if you’re not a customer of SolarWinds, you need to work with your suppliers to ensure that they weren’t attacked through SolarWinds.

• What else do you need to do now? Design as if you were compromised and it will happen again.

Some interesting quotes from today’s episode:

“When you're looking at any of the large-scale data breaches over the last five years, anytime you're seeing more than 50 million records compromised, it's pretty much the same exact playbook. There is a server visible from the Internet that the organization isn't aware of. It's missing a patch. It contains critical data. And that data is not properly encrypted or protected.”

“The real big problem is companies don't have a hundred percent asset inventory and therefore they don't know what's out there and they can't patch it, protect it, or secure their data.”

“Anything that's based on a human is eventually going to fail. But computers are systematic and can be programmed.”

“In the past, if I wanted to target Company X, I break into company X. If I want to break into Company Y, I target them individually. But in this case, they went in and said, ‘Okay, we want to break into all these companies. How do we go after it?’”

“I will tell you how I would have done this attack when I was on the offensive side. I would have put together a list of the companies and government entities that I wanted to break into. I would then start looking at what is the common denominator?”

“They got access to one of those computers. They used that computer to set up what we call a pivot point. They did lateral movement into the network and ultimately found the source code computers. Then from there, they were able to upload malicious code into that source code…They then push that update out to all of the clients. And then all of those systems got infected, installed malware, and then set up outbound command and control channels to communicate with the adversary.”

“Now whether they broke into other vendors is yet to be seen. Remember, most organizations don't detect attacks for two to three years.”

“What they were going after on the source code is the ability to take control of the client computers that ran the SolarWinds software. So essentially what they wanted to do is have a command and control piece of code that, once it was installed on the system, would then be able to take control, make outbound connections, and give somebody access to those networks.”

“I believe they had a long list and they had specific reasons and goals for each of those. Because the malicious code that got distributed with the SolarWinds software, it didn't specifically gather data, exfiltrate data, or delete data. What it did is create access paths for the adversary. So all we know is that the adversary wanted to gain access to this list of networks.”

“That's the interesting thing with not only SolarWinds, but most of these other attacks that we've seen over the last three years. It's typically the IT department that catches it. It's not the security department.”

“At some point they make the false conclusion, ‘Oh, no one's going to catch us. We've been doing it for two years.’ And then they start cranking it up and they inadvertently go in and overload the computer systems. Because these attackers know how to bypass the security equipment, but they don't know the thresholds of the IT equipment.”

“It's often ‘Let's get access and maintain the access to see what we can do, so we can use it at a later point in time.’ Sometimes it's the cell access. Sometimes it's to ransom it back to the company. Sometimes it's to sell to a third party. But the name of the game now is whoever has access wins the game. And that definitely looks like what they were after with the SolarWinds attack.”

“The best bet is to assume that you were compromised and use this as a lesson learned. It will happen to you. You have software vendors, you have components. SolarWinds was not the first and they won't be the last. So you need to go in and assume that you were compromised. Be proactive. And then whatever you would have done to respond to an actual compromise, those are the things you need to put in place today.”