• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Excelitas Qioptiq banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Subscribe
  • Contact
  • Media Pack 2023

Darwin and Ransomware By James Andrew Lewis

May 22, 2017 by Julian Nettlefold

15 May 17. The most important thing about the cyber “attack” over the weekend is that while thousands of computers were affected, millions were not. This highlights one of the biggest problems in cybersecurity: many people still don’t take it seriously. The 2016 Verizon Data Breach Report, one of the best sources of information on breaches, found once again that the vast majority of successful hacks required only the most basic techniques because defense is too often ignored, something that has been true for years. “WannaCry” is a tribute to negligence.

WannaCry took advantage of a vulnerability in Microsoft software found by the National Security Agency (NSA) and made public by “Shadow Brokers,” an unidentified group of hackers likely backed by Russia. However, Microsoft published a fix to the vulnerability two months ago. Networks that implemented the fix largely escaped harm. The incident is embarrassing for NSA, but culpability rests first with the criminals and second with network owners that did not stay up to date. Blaming NSA, while tempting, is irrelevant. There are an immense number of software vulnerabilities, and social engineering techniques to trick people, like phishing, always work. Taking NSA out of the equation will not change this. Blaming NSA avoids hard questions about operator negligence, buggy software, and the Snowdenistas’ anti-American agenda.

We can have a long debate over whether intelligence agencies should play nice in cyberspace. This is not going to happen for a long time, if ever. Eventually, constraints on cyber espionage may be necessary, but these would only work if everyone observed them, and there is reasonable doubt that China and Russia would go along. There is only one agreement to limit cyber espionage: the Obama-Xi agreement on commercial espionage, tightly written to block only a specific kind of espionage while allowing all other kinds to continue. With the United States challenged around the world, this is not the time to give up something as crucial for defense as cyber espionage unless one favors unilateral disarmament—and it is not possible to force NSA to reveal every exploit they develop without giving Russia and China an intelligence advantage. As a leading Russian dissident put it, “Putin needs an enemy. He wants to be the leader of the anti-American, anti-European world.” In this context, calls for NSA to be more forthcoming are dangerously naïve.

We can also have a long discussion over how to improve law enforcement in cyberspace, something that faces major political obstacles. Countries that are hostile to the United States have no incentive to cooperate, particularly if they support cyber crime as a tool for state power (such as Russia and North Korea). Other countries worry that cooperation would diminish their sovereign control over their citizens’ private data. Like-minded countries (e.g., Western democracies) could agree to cooperate against cyber crime, but it would take time for the United States to develop a new, coherent strategy for cooperation that its sometimes-timid allies would find persuasive.

Cyber criminals are fast and innovative; defenders are too often slow and reactive. Cyberspace will not be safe anytime soon, but in the interim (and it may be a long interim), there are three things organizations, can do to better protect themselves against this kind of incident:

  1. Keep software up to date. This means, at a minimum, stay on top of “patches” released by the vendor to fix vulnerabilities, something that many WannaCry victims did not do.
  2. Encrypt sensitive data. There is no excuse for not encrypting data at places like banks and hospitals. Personally identifiable information (PII) should always be encrypted.
  3. Keep copies of sensitive data on an independent backup system or with a cloud service.

None of these are new ideas, nor do they require advanced degrees to implement, but people who own networks (or make software) must move from a twentieth-century approach to data protection. Cyberspace is a Darwinian environment, replete with predators and victims, but the risk of being eaten in this environment can be managed and reduced. WannaCry should not have worked.

James A. Lewis is a senior vice president at the Center for Strategic and International Studies in Washington, D.C.

Commentary is produced by the Center for Strategic and International Studies (CSIS), a private, tax-exempt institution focusing on international public policy issues. Its research is nonpartisan and nonproprietary. CSIS does not take specific policy positions. Accordingly, all views, positions, and conclusions expressed in this publication should be understood to be solely those of the author(s).

© 2017 by the Center for Strategic and International Studies. All rights reserved.

Filed Under: News Update

Primary Sidebar

Advertisers

  • qioptiq.com
  • Exensor
  • TCI
  • Visit the Oxley website
  • Visit the Viasat website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • businesswire logo
  • ProTEK logo
  • ssafa logo
  • Atkins
  • IEE
  • EXFOR logo
  • DSEi
  • sibylline logo
  • Team Thunder logo
  • Commando Spirit - Blended Scoth Whisy
  • Comtech logo
Hilux Military Raceday Novemeber 2023 Chepstow SOF Week 2023

Contact Us

BATTLESPACE Publications
Old Charlock
Abthorpe Road
Silverstone
Towcester NN12 8TW

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • EXHIBITIONS AND CONFERENCES

    March 24, 2023
    Read more
  • VETERANS UPDATE

    March 24, 2023
    Read more
  • MANAGEMENT ON THE MOVE

    March 24, 2023
    Read more

Copyright BATTLESPACE Publications © 2002–2023.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT