Live at ELC: Exploring the Realities of Network Security and Cybercrime

Handling network security compromises is a nightmare. Crypsis demonstrates the process of shepherding victims through the digital forensics process toward recovery, and illustrates what safeguards manufacturers can take before the ingress even happens.

Executive Leadership Conference
Executive Leadership Conference

By the time Brendan Rooney, director of the Crypsis Group, gets involved in a cybersecurity matter, it’s often the case that significant damage has already been done. The Crypsis Group is a digital forensic and investigative consultancy that frequently acts as the first responder when financially motivated cyber thieves, organized crime, nation-state threat actors, and hacktivists compromise a victim network. While threats are always evolving, two primary methods of ingress Crypsis encounters, are ransomware or business email compromise (BEC).

That means that first call is a tough one for Rooney. While it’s the start of the process for him, if the brand owner or OEM he’s dealing with isn’t insured against cyber-attacks, the victim may stioll have to incur a big ransom payout out of pocket. Odds are great that the victim company will also experience a disruption in productivity or suffer possible permanent loss of data. In some cases, the victim suffers all of the above.

“Our analysis aims to get answers to three initial questions,” Rooney says. “How did attackers gain access to the system? What did they have access to? And what may have been exfiltrated from the environment?”

The following is geared toward OEMs, but much of the information applies upstream and downstream as well.

Defining terms
Ransomware is a form of malware targeting both human and technical weaknesses in an effort to make critical data/systems inaccessible. Ransomware is delivered through various vectors, including phishing attacks, and also via Remote Desktop Protocols that allow computers to connect to one another across a network.

List: Digitalization Companies From PACK EXPO
Looking for CPG-focused digital transformation solutions? Download our editor-curated list from PACK EXPO featuring top companies offering warehouse management, ERP, digital twin, and MES software with supply chain visibility and analytics capabilities—all tailored specifically for CPG operations.
Download Now
List: Digitalization Companies From PACK EXPO