Ransomware Attacks: Who You Gonna Call? – CISO Talk EP 35
Every CISO knows it’s not a matter of ‘if’ a cybersecurity incident will occur, but ‘when.’ Fortunately, there’s one name at the top of every CISO’s incident response list: Stephen Reynolds, partner in Baker McKenzie’s Intellectual Property & Technology Practice. Reynolds built a well-deserved reputation as a bulwark between organizations and the cybercriminals who attack them, and he is rightly seen as the man who can make the difference between an organization living on to fight another day and total devastation. In this episode of CISO Talk, Stephen shares his experience responding to cybersecurity threats with hosts Mitch Ashley and JJ and talks about how decisions made early on can have a significant impact later in a security incident, when to call your cyberinsurance provider, when to involve law enforcement, what to communicate and what to keep to yourself and how to successfully negotiate with cybercriminals in ransomware situations.
Transcript
Hey everybody, welcome back to another episode of siso talk. I'm joined by Mike and I partner my co-host JJ. How are you doing today?
JJ, Manila? Hello Mitch and peoples. I am great.
It's a wonderful. I don't know what day it is, but it's a wonderful whatever day wait, you know, the weather's getting better and seems like people are getting out and now we got to do with their yards and all that fun kind of stuff, but that's that's the gardening show. We're not doing that show today, but we've got a great guest.
You know, I haven't been a CIO I've had security incidents that I've had to deal with nothing major like not not really serious. I'm sure JJ you've worked with companies that of course have dealt with some pretty serious security cyber incidents. But I think our guest today Stephen Reynolds.
Will be able to give us kind of an Insider view because he's known as the person first person Fortune 500 companies call when they're under attack. He's the he's the first fire person in the building right things burning down. So, um, Steven introduced yourself.
We'd love to hear a little bit about you and tell us about where you work what you what the company does Sarah so Steven Reynolds. I'm a partner at a law firm Baker McKenzie based out of their Chicago office, but work remotely my practice is helping clients. Like I said when they're going through a serious cyber security incident and then I also help companies with regulation regulatory investigations and litigation that may fall in the cyber security incident.
Wow, okay, that's a lot. Yeah, this is kind of a second career for me. I was a software developer before becoming an attorney.
So that's how I ended up in the space interesting too late. Yeah, I got to jump in because I saw your profile. I was like Leo gotta talk to this guy.
But yeah, so that was my first question is are you where are you in the in the legal ecosystem? Are you a lawyer? Did you go to Lawrence?
Because I saw a lot of your background was actually technical. So how did you get there? Yeah, so I started off this is actually really in school.
I started doing software development actually one of the first started by building websites for local businesses and I was in high school and actually in the first websites I built was for an attorney and my hometown and Sebastian Florida and of course, I have no idea. I got a law school at that time, but no my practices is legal. I work as a partner to Law Firm.
So I'm helping with the legal aspects, but I get very involved with the computer forensics people who often come in outside. Already incident. I joke that a lot of my job is just helping translate between the attorneys and the information security people at executive because they kind of all speak different languages.
That's interesting that. So tell us about this the move from thinking of the world as a software engineer and thinking of the world as in the world that you're playing now, how do you look at things differently now? Yeah, I I do miss sometimes the software engineer world because I felt like I was more creating things oftentimes now, I'm just coming in when something's already gone wrong.
And I I main goal is to give legally advice to clients. A lot of what I'm doing is really just helping people solve problems or make a solution or or help them come up with a solution to a problem or a tricky situation. So and a lot of respects it's similar, you know, you're coming in and you know, when as a software developer like, you know, one of my first projects for building an online store and how do we integrate shipping and calculate how much the price for orders and do credit card processing and mapping that out.
Now, I'm coming into you know, something's already gone wrong. How do we work with the computer forensics folks? How do we involved?
You know public relations people for messaging and media inquiries. So part of it still is just problem solving its core but under a little more stressed as an attorney than it was under the software developer. So I'm curious.
I have so many questions, but let me start with this one. Because I think one of the things you know we hear and we tell people in this space is you know, when you've had an incident. The first thing you have to do is is call your insurance company if if you've engaged in cyber insurance, and they're going to direct you to that.
So, where do you guys fit in to that? Do you work with you know as it's kind of approved provider through some of the insurance companies do work directly with the organizations? And is that through and I'm kind of more just broadly asking how this field works.
Are you guys kind of on retainer because swooping in After an incident, of course when you have no relationship with somebody is certainly challenging. So how does that model work? First a different law firms are different.
So and you're right to pick on hit on Cyber Insurance. That's a big part of what we do a lot of companies have cyber liability insurance that helped them through an incident and that is often. One of the first things you need to do is contact your insurance just a quick and a free tidbit of some insurance companies won't pay what they call pre-notification costs.
So anybody retained to help any cost to incur before notice may not get paid. So you definitely want to do notice very early on but you also want to make sure you do notice correct. So I would suggest working with your attorneys to make sure that notice is done to maximize your potential to get insurance coverage under your policy different law firms handle this differently.
Some are like you described on panels so they actually have agreements with the insurance companies and when you notify your insurer, they will say here's Law Firm that we recommend as your data call it like your data breach coach to help you through the incident other law firms make it pre-approved by the carrier. So, you know if you are a company Going purchasing cyber Insurance during the purchase or during your renewal Fades. You can say here's who we want to work with if we have a data security incident and get them pre-approved by your insurer for my permanent particular at Baker McKenzie.
We often come in more in that role or the client has cyber insurance and we're getting approval by the carrier during the incident or the carrier gives our client the ability to hire whoever they want, but we're typically not on an insurance panel, but there are other law firms that do that. So out of like the hundred percent what percentage would you say? Of the clients that you guys in your firm already have relationships with prior to an incident versus that is when the relationship initiates that's a typically we already have a relationship with the client.
You want to call someone, you know, and you trust and have worked with before sometimes I may not work with them, you know in particular. So like I said, I usually come in when things have gone wrong so they may have worked with some of our privacy people before or done like a tabletop exercise with us before or maybe you know, in an ideal situation. We actually help them draft their incident response plans and policies.
So we are familiar with what they are procedures are in the event of an incident and then they give us that call. Thanks, I'm curious about so that that sounds like I mean, alright a great situation where you know what their process is as you helped shape and create it. Is that one of the first questions well, tell us what do you ask?
You know, hi. This is Mitch from ABC company and we have a whole lot of whip ass can coming out as and we need them some help over here. Can you help me?
Come on over Stephen? What's what do you do first? Yeah, so I'll borrow an allergy for the medical field and a lot of my first ransomware matters were for hospital hospital clients or people in healthcare.
So it's almost like a triage process. So I want to First assess where they are in the process. Like is it a broken arm to where you know, and the triage analogy, you know, it's a bad situation, but it's not that time critical, you know, fixing a broken arm and 30 minutes versus two hours.
You may be in some pain, but it's not a life or death issue. Typically are they not breathing? You know, that's an immediate issue.
We need people immediate on the phone, so I'm often times trying to assess. Have already done and where they are. So sometimes a client is calling saying email is down.
We can't print we can't communicate. We're basically blind and we don't even know how to contact, you know, orange a lot of times on the insurance note. I will tell clients when we're doing their incident response plans.
Send me a copy of your insurance policy because oftentimes during a ransomware incident. They can't access the files that have to contact information of the insurance person or even an insurance policy or or the insurance brokers information. So I'm usually trying to assess where the client is in the situation and then a lot of it is bringing in or determining what resources they need brought in.
So sometimes it will call and say we're already working with the forensics provider like Mandy and our crowds Frank or or kivu or one of these companies that come in and assist the information security folks other times. It will say we don't know what to do or we don't know who to call and that I'm you know, suggesting or bringing in someone to help them with that situation. So a lot of it's kind of an initial assessment of where they are.
Different companies will be a different levels of sophistication. What a lot of this involves to be honest is kind of project management. You've got multiple different work streams and things going on.
So part of it is eradication on file for my Hospital analogy. So stopping the bleeding is kind of one of the key things. So making sure the attackers are out of their system.
So I've had incidents especially early on when people are less familiar where they're emailing me and one of the from their company emails and one of the first things I'll ask I'll pick up the phone and call. Do you know if your email system secure because I don't want the attack or 3D my emails back to them and they'll say oh I didn't think about that, you know sometimes and so we'll switch to an out-of-band Communications method like signal or Whatsapp or just iMessage on phones. So a lot of it is figuring out who we need to bring in and what needs to be done first.
And like I said, it's it's really a lot of project management coupled with, you know, letting them know potential legal risk. I hate to like sounds scary, but little DEC That companies make at the outset of information security incidents can have profound consequences when you go through a legal process and litigation or regulatory investigations things that companies may think aren't that important of decisions or you know, you're stressed you're Panic to the moment and making, you know, the best decision you can oftentimes as humans. We make incorrect decisions in panic situations.
And so a lot of what I'm doing is actually trying to keep people from making mistakes early on that's one of the things I think, you know having an incident response plan and I think we I know I hear a lot of questions around this regularly, but I think a lot of organizations are. They know they need to do something but they don't know what to do when or how you know, but trying to respond to an incident. I mean, there's a there's a whole subset of products out there now for you kind of described, you know out of band communication because you may not have access to email or any of the corporate resources you anything right your your corporate phone your laptop your email applications Etc.
So there's there's entire subsets of products built on pre-planning for incident response with those out of ban, you know, getting your base unit personal email text messages Etc. And then the you know, you mentioned some of those snap decisions is you know, I know even clients I've worked with because I want you know, I don't work in incident response so we don't I don't do that service for them. But I find out after the fact what they've done is.
Basically destroyed any opportunity for forensics evidence in their attempt to just stop what was happening because they didn't know ahead of time what they what they should or shouldn't be doing. So I'm curious about, you know, do you have any War Stories? Around some of that absolutely.
So so, you know, this is general advice of you know, not the technical person coming into these but generally if you're going through answer incident Don't Unplug and turn off computers, you want the encryption, you know, what ransomware does, you know encrypts files on your computer and servers you wanted to either fully run or don't run but you don't want to catch it in between because then you just get corrupted files. So even if you pay the ransom, there's no way to decrypt those files. So you want to disconnect computers from the network manually or however, you can do that through Hardware, but you don't want to generally, you know, unplug them, you know from Power turn them off because that can actually make things worse or even seeing JJ that what you describe people say.
Oh, let's just start wiping, you know computers or servers and that destroys some of the forensics we actually need it or kind of used to restore files. So yeah, you're absolutely right. There's some key mistakes you can make from a technical perspective at the outset and are there non?
Technical things decisions that companies make early on in that it's their process that have profound consequences. Yeah. Absolutely.
I think on the non-technical it's usually Communications. So like I like to say when there's a lawsuit over an information security incident when there's a regulator or a plaintiff suing a company for an incident that occurred. It's a little bit difficult and maybe really difficult to prove that that company had bad information procedures or policies or practices.
You may have to bring in an expert and talk about, you know, they should have multi-factor authentication but they didn't here's what the industry standard is. That's a more complex case a much easier case is to say this company said they were doing X, but they were actually doing why they made a misrepresentation or maybe fraud or they stated something incorrectly and I like to think a lot of our clients. Like I said during a data security incidents.
Usually the worst possible time. They often have been on holidays and weekends. I just had one come in on Easter Sunday.
The recently so there's always happens like that. So I don't think clients try to mislead or make representations. But I think what may happen is you're putting out information or you're getting incomplete and possibly interactive information.
And if you start repeating that information, it may look, you know, a year later or two years later when there's a lawsuit like you said something that was untrue. So the kind of short answer makes your question is one of the biggest states I see companies make is a rush to put out Communications. You may have customers asking questions why your systems down you may have reporters asking questions.
Yeah. They're they're bloggers and people you may be familiar with that that look for data reaches and you know, look on the dark websites that these ransomware groups use and we'll see your company's name in the last questions and clients oftentimes made put out information that they have like, yes, we're aware of a Cyber attack but no credit cards or financial information is impacted. Do we really know that that's what we know.
Right. Now if that may prove to be, you know inaccurate later, it looks like a misrepresentation. So one of the key kind of things we work with clients on is to make sure the communications are accurate or we you know, say we don't have information Sometimes.
The best answer is actually I don't know or we don't know yet, but it's kind of a difficult thing to coach people to say, I think we like to be able to say here's what we know right now. And sometimes we really don't need to say anything or say we're still investigated. yeah, and those those I feel like the where we you know in the past six months we've seen some.
Relatively high profile things including including LastPass. Right and I think and I'm just picking on them because that was pretty visible. But there's so many others and I feel like the information that comes out is we currently have no evidence indicating the attackers were able to access X Y and Z and of course most of us are going well.
You don't have any evidence that they weren't you just say you don't know and then come back when you've got something a little more actionable for us. Yes. That's exactly right.
That's a great example of we we have seen no evidence of XYZ. It's like well, it's maybe better honestly, we're investigating and you know, we're going to be diligent and thorough when when do you involve law enforcement in this what's to decide? Like what's the logic chain of when and whether to bring law enforcement?
And yeah, so working in a global law firm with clients that have Global presences. This really has there a lot of issues involved as you may be familiar with under privacy laws in some country. Just you know, you can kind of open sometimes he's may not like, you know involvement with us law enforcement as much as others too.
So it's a it can be a tricky decision and there's some legal aspects involved with that too. But I will say in the event for for example ransomware incidents which are a lot of the incidents. I work.
I oftentimes try to get us law enforcement involved sooner than later when I first started doing these types of incidents, I would say that US law enforcement was less. Knowledgeable and prepared for ransomware now. I think they are really really going to be really helpful either.
Sometimes the FBI or sometimes working with the US Secret Service in particular for financial crimes with the US secret service for example, and often one of the attacks. We see a lot of is business email compromise. So I pretend to be someone in your organization and convince someone to wire out two million dollars to a malicious party, you know, it's the classic the emails will say something like hey just closed the business deal in Hong Kong need to wire this money confidential transaction.
Don't tell anyone about it and make sure at some poor person and actually sending the money out if that gives caught in detected within usually 72 hours or so and we report it to us law enforcement. They have waves of actually being able to stop that transfer or reverse it and get that money back. So in those types of situations, that's one of the first calls I would make and then Insurance of course because there may be insurance if you aren't able to recover the money in a ransomware situation, not as Urgent is the fun transfer fraud situation.
The FBI or Secret Service aren't usually able to come in and you know shut down the bad guy and decrypt your files, but there are some instances high in particular. There's a ransomware threat actor group where law enforcement was able to basically dismantle this group and was able to get some decryptors for companies that were victims of five. So I would put that higher up on the list of priorities but a lot of times, you know, there's some immediate concerns of you know, we're using the medical analogy stopping the bleeding if we're using a fire kind of putting out the fire first before, you know calling calling the law enforcement to come in You guys keep saying firefighters, but I'm imagining Ghostbusters.
Are you? That's interested like some of the business email compromise. So I've you know, I've seen some of these that are really tricky.
I know one of my clients the The attacker if you would had registered a domain that was exactly the same as the company's domain except for there was an i in the domain so they used a lowercase l so when you look at it, it looks exactly like the domain so they recreated the, you know, most of the the user and for structure from that they somehow still don't know how scraped an entire email signature like exactly, you know, not recreated one that was similar, but the exact email signature that was used for this Persona that handled accounting inside the organization. So it was you know, this is right before a lot of the product started adding that Banner that's like this is from outside your organization, but there's some tricking stuff that they do. Yeah, yeah that one I see a lot.
Oh, sorry that I know. I want to hear more. I want to hear some of the stuff that you That's a common tactic the registering a domain close to yours.
So instead of an M you register to ends, you know on phones in particular those things just kind of blend together and they look very similar if I could share one of my kind of you know, I wouldn't say one of my favorite attacks, but when I thought wow, that was pretty tricky that was yeah, I got to give it to the backers. I had one where the attackers got into a company's payroll system and they changed all of the the banking information for only the high earning employees, which I don't know if this is because they thought those people would be less likely to notice or they were kind of maybe that they were Robin Hood, but for the very high earners at this organization make change all of their banking information for their payroll for direct deposit. Um, what they did though, the the third party system that the company is for payroll sends alerts to users saying hey you're banking information has been updated.
So hopefully, you know, they would notify the company and they know that someone will trade their system what the attackers did too was send out an email from a Name not similar to my clients domain name but similar to the payroll company domain name and said hey, we're doing Network Updates this weekend. You may get these parent emails about your banking information being changed, please disregard about. Wow, that's pretty clever.
They've got a lot of fun and planning into this attack fortunately. This company was able to for most of these stop the the payroll distribution from going out to the attackers, but I thought you know, they're pretty clever with these tricks and like you said, they didn't really have to get inside the company's Network to do this attack. They just did this by, you know, creating a, you know, domain similar to another one and then we're able to access an account on a third party payroll system.
Yeah, the sprawl we have and the footprint is just absolutely amazing at this point. Ever reminds me of the the being one of the ingenious things you mentioned about them going after the people of the high Financial Learners. It's like well it reminds me the old joke.
Why do they keep right robbing banks? Because it always seems like they get caught. Well, that's where the money is.
Yeah, which is which is sort of an adage for me of Follow the money, I mean and look for the easiest path to it. It doesn't have to be complicated right now for sure. That's why I think the fun transfer fraud stuff is so prevalent because the old days the model that the attackers used when I you know, the old days not too long ago was to steal beta and then sell it.
Basically they would steal, you know credit card number credit card information social security number is to come in identity after driver's license numbers and then sell that to people who then used it Friday night that and monetize that the new model is really just trying to take money directly either through fund transfer fraud like we described or through ransomware where you're starting it or some other extortion. So the attackers have kind of figured out I think well, two things one. Once you've stolen everyone Social Security numbers, they're not worth anything anymore.
I think that's almost what has happened. They already took them. You can't really feel those twice and so they're not worth as much anymore to steal and in the second thing is it's more profitable.
Beneficial for them to steal money directly or get money directly rather than stealing something and then having to turn around and sell it even the threat of elevating and the crime to a wire fraud or a financial fraud. That's not a deterrent. You would think so, but unfortunately, I think what they use is foreign Banks where it's you know, they're they're less likely to be a cop.
There's a whole kind of ecosystem of you know, people involved my understanding from law enforcement is some of the people involved maybe I'm knowingly involved like they will sell someone. Hey, you're you're doing this work from home and we're going to wire you money. And then once you get this liar, we need you to do the steps.
And so some of the people involved in these transactions may not even understand. They're part of a from Enterprise. But yeah, I think that's how they they work and unfortunately with the Advent of cryptocurrency, I think that's also help the the attackers better hide resources, but some of them do get caught and unfortunately working with law enforcement as a way to you know, increase the chances that they do get out branded.
Even have you worked directly like during a ransomware negotiation. With sure. Okay.
Yeah, those are interesting. I just tell smart typically and we always clients not to do the negotiation themselves. There are third-party companies that can help you with these negotiations not to plug any but companies like kivu Cove where is one irritate where these people have people who are maybe some former law enforcement, but they have experience in dealing with the different thread actor groups and they help you through these negotiations.
So yeah, those are interesting. So what oftentimes happens is they will make a demand. It's really a business to them.
So let me back up ransomware is kind of an affiliate model. It's it's almost like think of it as bright eyes. So let's say JJ.
You want to start doing ransomware? So you may Reach Out break into a company is network and then reach out to a threat group. Let's say locked in or high or whatever group and say hey I got in this company's environment.
Give me the tools. An employee of the ransomware and then they will tell you you'll get 80% of whatever Ransom we collect and the main group will collect 20% And literally when you know, I've helped clients with making those payments they will give you two separate Bitcoin while it's until you 20% goes to this one in 80% goes to other so it's really a ransomware as a service or an affiliate model. I would think of it almost like a franchise kind of model.
So very K malware use that one. Basically that's it. So anyone can be involved.
So when you're really good week weeks makes which is why that's important because when you're doing these threat negotiations, it's important to realize that there are multiple people involved. So what can happen when you're negotiating with the threat actor group is let's say they're initial demand. They may say it's five million dollars.
I usually you can talk them down on that demand depending on a threat actor group, but you may get like a side Channel communication. These are these are organizations and this is a business, but they're loosely. Elated right?
So you make it aside communication. Like let's say you say we're never gonna pay you five million dollars. The most will ever pay is one million in use your your company stands to that and says, we're not going to go not going to bugs or any we're never going to get to five million.
Someone else may reach out to you and say hey, I actually have access to the description key. I'll take the one million, you know instead and so it gets very complicated. So you have a lot of things the side of whether you're willing to trust this person or not.
I would say not but these negotiations can be Complicated by the factors of kind of the relationships between the entities that are doing the attacks on the other thing. I'll say I'm the negotiations with these groups is some are very professional, you know, someone like apologize some I've had one say we're sorry. This is our business some think of themselves.
Like they're very Noble they'll say like we're well one called themself host paid penetration testers and they'll say like we'll even give you a report of how we Into your environment after you pay us I'm security tips. Yeah, like like they're doing the world of service. They're all very different.
But the negotiations can get very interesting with these groups. Yeah for any aspiring ethical hackers and Pen testers out there. This is not the model to follow you're not testing or infiltration of somebody's Network or encryption of their data without their written approval.
We're once yeah, I'm curious. I've heard a lot of so I think first of all Stephen this model of almost kind of the middle the multi-level marketing malware screen here that's for as much as I try to learn and listen to stay up to speed with what's going on. That's actually a new A new model for me to understand so that's really interesting.
And the other thing I heard that's very conflicting is how often and the likelihood of actually getting the decryption keys. So I hear from one side, you know, you hear oh, it's usually 80% because this is their business and if they get the reputation of they're not providing the keys, then that word's gonna get around and people will stop paying a ransom because why would they and then, you know, the other side of that coin is no the the actual percentage of you know, remediation with the decryption keys and getting the decryption keys that will work is closer to 20% because these are criminals and then somewhere in the middle we hear stuff like you'll probably get the key, but it's not straightforward to use the decryption key. So what let's Tell us about all that.
Yeah, so kind of a combination of all of those things. So I wasn't just personally have done a lot of these incidents every time I've had a client pay Ransom. We've always gotten the keys.
They may not always work on 100% There may be technical issues and errors like corrupted files, but this is a business to the people who do these attacks. So absolutely most of the time you get the keys the group side ascribe that help you with the negotiation. They will give you actual statistics by threat actor and say Here's the percentage that got keys.
Here's the percentage where they worked the FBI can give you that type of information as well for the different threat groups, but generally speaking I'd say if you pay it's a business you do get the keys in terms of you raise a good point and it's it's not as simple as you get one key in Lots you will get a file back from them you then need to check that file and make sure there's not additional malware on that file. So you don't want to take the file from the attackers and run that on your system. So all takes a Of time and it may not work.
You may get several different keys. They may give you thousands of different keys and you may have to work with a company to actually use those keys to restore files. So it's not as straightforward as here's the key you get your stuff back.
It usually takes quite a bit of work and some time even once you pay and get the keys. I do want to tell it kind of a quick answer note on you know, the giving you the keys they may use you. If you pay your ransomware kind of that they reference it's on a client ones pay Ransom and then months later the CEO called me and said we actually got a call from a competitor competitor to see called me and so they got hit with this ransomware attack.
And the threat actor said hey you'll vouch for if we pay we'll get the key so they will say hey we hit this other organization. You can call them they paid and they got the key. So I've had that happen before so I have to ask do the threat groups do they provide support?
Hey, we're having trouble with the keys you said. Can you help? That they provide support they will provide support in the sense typically on will help you obtain Bitcoin instead of a Bitcoin wallet.
They actually have call centers that do this which is kind of you know crazy but they do have support for these things. They will work with clients, especially now with the model of not just encrypting files. They also will excel trade files.
So copy files off of your network threaten to publish those. So even if you're able to restore from backups, they still have something else they can get you with. Well, we're going to release these sensitive files unless you pay us so often times they'll Provide support in that, you know, we'll help you prove to who have never that we deleted these files so it's support but not the kind of tech support you think in the classic things, but they absolutely will help you set up a Bitcoin wallet and walk you through the process of how to fund it and get money to them Steven.
I have a question about you know, how well I guess it's a two-part question. The first part is what what are your thoughts as is a you know, prior technical professional and a legal professional now on and there's a lot of kind of Regulation being considered that would ban here in the US as paying Ransom. So I'm curious about your thoughts about that and whether you participate in those conversations where those are heading pros and cons and then the kind of this second piece of that is You know, it is a decision to pay ransomware or not.
And I know there's you know time factors money factors reputation factors and a lot of public sector feels like they have to be stewards of the Public's money. And so some some of them have, you know internal Maybe prohibitions on paying Ransom. So I'm just curious on you know, your thoughts on whether you know, that that potentially being banned and what that you know the pros and cons around that and then What are some of the decision factors that you would talk a client through when determining whether they're going to pay Ransom?
Yeah, so you're absolutely right there as pending legislation in some jurisdictions on just Banning the payment of Ransom letting Australia maybe a company that's considering that in some others. There's also with the United States in the United Kingdom has something similar there's a guidance from ofac the office of foreign. I'm going to forget what it stands rested.
They're under the Department of Treasury of we're getting foreign asset control I think is what it is, but they're under the US Treasury Department and they've issued some guidances on warning companies that you know, there are people that are whatever they call sdns or special designated persons where you're not allowed to pay these people people like terrorists who are on a list. So you're supposed to do in the US tragic department wants you to do some level of due diligence to make sure you're not paying someone on one of these lists because there is on the Civil liability side strict liability meaning even if you didn't know they were on the list if you pay them you can be liable for Sanctions and and you know monetary consequences and then on criminal side if you knowingly pay someone who's on one of those lists that can be actual jail time. You could be you know, you know indicted and you know subject to actual prison time for making a payment to someone who's on one of those lists if you need a work so because of that that's actually a huge consideration in paying one of these threat actors is the possibility of sanctions or whether the payment is actually illegal in the jurisdiction you're in so the there I am involved in a lot of discussions on that I think in terms of factors when companies are evaluating whether to make around for a payment or not, it has a lot to do with Kim they keep their business up and running and the severity and how quickly so if I'm working that they can't just Center our hospital and patient lives are at stake and we're unable to restore from backups and restoring backups quickly that may weigh more in favor of paying a ransom than a company that may be A manufacturer and yeah, this is slowed us down on you know, making a product or delivering things but will eventually be able to rebuild our Network and get back.
So maybe they're less likely to pay the other category. I would see where you know, there's a lot of pressure on companies to pay is if you're holding a third party's data. So if you are, you know a service provider and you have data on hundreds of different clients that may be sensitive data and you've had a ransomware attack and there's the threat of excellation you may be more likely to say.
Hey, we're going to get judged by our customers. If we don't pay you may have customers calling and saying hey you pay this Ransom. So I think those are situations where we typically call that the double or triple extortion because the threat actors they may look at the data and say oh you do business with XYZ company and if they're not liking how the negotiations are going, they will reach out to that company directly and say, hey we attack this, you know business that you that has your data and they're refusing to pay.
Going to lead your file that they don't pay or you don't pay as someone needs to pay us. So in those situations in particular our clients are under a lot of pressure to pay a ransom and curious to go a little bit of a different direction talk about the emotional Factor emotions in this because I could you know, some people are going to be pissed off angry something people are gonna be scared that you're gonna find out. We don't have the security controls.
We should have had he I would imagine just having a third party helping you with that. But how do you keep the Motions in check to make the right decisions going to yeah, that's a great question during these incidents and I'm not joking. He's always happen kind of during the worst possible time.
So and I think the attackers do this intentionally so it will happen while the CEO is on vacation in Alaska or during holiday or during a weekend or having an attack happened during for a US company during the Super Bowl. I won't forget that what about like, I'm not expecting that one. That was a little creative there.
So they happen during awful times. People are humans and have emotions and so it can be stressful. You have people who are working around the clock, you know, working diligently and then also they may feel some sense of am I going to get fired or am I going to get held responsible for this?
So I like to tell people to work when they keep that in mind when you're interfacing with the company's information security people is maybe worried about their own jobs. Whether payroll is actually working like whether they will get paid that's the question that employees often asked and they're just under a lot of stress and worried. Am I going to get blamed?
So oftentimes I'll tell people, you know, my not job, you know, there are other lawyers who are employment lawyers who make come in and assess whether people should get fired and who's in trouble internally for this that's not my role. We're just getting through this incident and then we'll figure out later. You know, we're not looking to assess blame during the incident.
We're looking just to get through it and they'll be plenty of time later for people to evaluate what is done, but the human aspect of this is very real the attacker is no and understand that human aspect. That's why you know firewall. Don't care if it's Easter or not.
You know, they're making these attacks based on when they think people are most vulnerable and so it's a big part of this. This makes us how to deal with the human aspect and literally had you know incidents where I'm an employee like, you know, I'm going to quit like that people tell me that I like that, you know or something like this or start blaming someone else or say I've been warning of this so a lot of times often, you know, Communications become very important in these and what people say, but let's just stick to facts and stick to getting through the incident. It's not the time yet to figure out you know, who's responsible or what should have been done different what plenty of time to to assess that later, but it's a big factor.
This is just, you know, dealing with humans. I remember sitting at RSA several years ago at this point and I don't know if I don't care if it was in the morning and we were having coffee or it was night and we were drinking whiskey but I was sitting around with several friends who happened to work and it cisos and in the security organizations at various large Banks and financial organizations. And I remember, you know, we're just sitting there chatting away and then the phone start going off and you what one person and then the next person the next person they all start looking at each other and there was there was one that was one of the major attacks across several of our financial organizations that they plan during RSA when they knew all the Security Professionals, we're gonna be and so they found a private room I excuse myself and it was a not a fun week for the rest of them, but they they all managed to handle it.
But I'm gonna tell you guys this Stephen and Mitch You know on that kind of emotional response being an outside party. I was at a healthcare client. Probably a couple months ago at this point.
Walking through doing something with with my contact there and I suddenly see all of this nursing staff running around with papers, you know, like they're carrying paper charts everywhere. There's no tablets. The computers are all Etc and I turn around and look at my you know, my client I said, well what But what's happening here?
Let's go, you know because this is one of the secured Network infrastructures, we've done where everything's connected and I know it's connected and it works. And they were doing an instant response exercise. Hmm and I tell you what, you know, it doesn't matter who you are.
if you've ever been in a hospital or you've had a family member in a hospital the crushing fear of suddenly not having access to everything in the in the Healthcare System the patient records the connected Ivy all of these things that are so so hyper connected now and everything. That's so digital. That is I mean, I still get chills because I mean when you're standing in there watching it happening around you and again it was an exercise.
It wasn't real. That's some scary s***. That did not make me feel good very sir.
Yeah. It's a scary situation and then like you mentioned, you know part of this. I was just on a call where the client actually one of their leaders was doing a good job of he was asking questions.
Like hey, did you guys sleep last night like this person seems like they've been working. I've been getting emails or messages from them, you know, 24/7. Let's give this person a break and have someone else take over and that's an important part of the management as well because you know, we will make more errors thinking hospitals people are not At people are not eating and people are you know under too much pressure, they will make other mistakes and so part of managing it.
Is that aspect as well. Yeah, I always joke that we have to keep everybody fed and watered you do it projects. So I feel like this I'll do this as a last question JJ.
We're just about a time. I feel like we could do a whole another show on this is ransomware just a fact of life or is there are other things on the horizon that is going to help. Combat it real that's a great question.
If I had looking kind of the crystal ball, I would hope that eventually we are able to better mitigate against this. I think they have been examples a borrow from fire. Like if you would think of, you know, the years and decades and maybe centuries ago.
It was a common, you know, not so uncommon for entire cities to burn down because the fires like someone, you know think about many cities have had to be rebuilt because a big kind of fire Chicago and I think Boston has some lots of cities around the world. This is a it was kind of a common phenomenon. Now when you build a building, you know, one of the primary aspects, is there fire control surprising systems and everything.
It's an everything you do. I'll buildings are lay it out. There's inspectors.
There's all sorts of things. You know, we don't typically have now entire Cities Burn Down The Fire And so I look at ransomware a lot like this because it's similar to Fire and that you could be doing great yourself, you're building could be fantastic. But if your neighbor is not and they catch on fire it's going to affect you too.
And that's really how ransomware is our. These are so interconnected that I don't have to attack, you know, a particular organization. I can attack someone that they do business with or so when that anybody does business with to get to them.
So it really will take is just kind of improvement across the board. Everyone's information security improving and some better practices. I think we could really reduce the amount of ransomware and the severity of it but I think it's possible.
I'm not suggesting we go to a model where you have to have an inspector every time really is a piece of software or deploy a server, but I think they're you know, we all raise our information security system. I think we could make it to where ransomware is is less of a threat. And it comes back to our firefighting analogy.
Then everyone's got a role of this you do JJ parting thought anything you want to wrap us up with? Oh, this is just been such a fun conversation Stephen. I hope we see you again.
I think there's a lot of takeaways for professionals and organizations that are I mean really, this is something that applies to to every size organization and every technical professional and business owner. Even, you know, all the way down to small businesses that don't have cisos. So this is really interesting and I think we we have a lot of actual takeaways from this.
Well, thank you so much for having me. I'd love to chat with you all again. Well, you know one of the I'm sure things are going well for you at Baker McKenzie, but you also have now a parallel career appearing on Tech strong panels.
It's been a great great conversation. We really appreciate your time today Stephen Stephen Reynolds, who is a partner with Baker McKenzie intell. Property and Technology practice again.
We'd love to have you back. Thanks for joining us Stephen. All right.
Thank you.



