Cybersecurity expert: You’ve been hacked and probably don’t even know it

Mark Schiefelbein / AP

In this May 13, 2017, photo, a screenshot of the warning screen from a purported ransomware attack, as captured by a computer user in Taiwan, is seen on laptop in Beijing.

There is no such thing as a computer network that has not been hacked or compromised, a leading expert said this week on “Nevada Newsmakers.”

There are only two types of computer networks, said Ira Victor, digital forensic analyst for DiscoveryTechnician.com:

• Compromised networks with owners who know where they have been compromised, how extensive it is and what data is breached.

• Compromised networks with owners who aren’t aware of the attack or its consequences.

"With the experts, that is pretty much consensus," Victor said. "All networks are compromised and it’s just how much you know about it and how much you don't."

Businesses and other entities with computer networks may not be aware of the hack but can still be compromised, Victor added.

"Cybercriminals are breaking into networks with such frequency and such ease that they don't always exploit that network right away," Victor said. "Or they do other types of techniques that are exploiting the networks but they keep a low profile so that the people who are running the business or working the business have no idea."

Firewalls and other computer security services are not security blankets for computer systems, Victor said. "You want to have anti-virus (programs) and firewalls, but they only offer very minimal protection," he said. "They do not keep the bad guys out of your network."

Victor, who testified about cybersecurity at the Nevada Legislature in April, said the state of Nevada (and many businesses) can't afford to secure every bit of information in their systems. Entities should focus efforts on the most important data to be protected, he said.

"If the bad guys are in your network — and they are — and if they are there persistently — and many times they are — then it is often not cost-effective to protect everything, every little shred of information and every single communication in your network,” he said.

“So we need to rank them and say, 'What is our most valuable asset? What are our crown jewels? And then, concentrate our resources on protecting our most valuable assets," Victor said.

Businesses and governments don't earmark a lot of money toward cyber-security, Victor said. Information technology (IT) is not the same as information security, Victor said.

The culture of IT employees teaches them to deliver services on time and on budget, Victor said. "So if we have less than $10,000 to spend, we figure out a way ... so we've got to 'stand up' those systems, as we like to say, and deploy them and do the best we can with the $10,000 we have over the next three years. That is the culture of IT.”

The culture of information-security employees is about assessing risk, he said. "What is the data we have? What are the risks? How do we mitigate those risks? And then we go to our decision-makers and say, 'Here are the risks. Here are the liabilities. If you want protect that data, here are the steps that need to be taken.'"

When government agencies or businesses attempt to protect all cyber information, that is a good thing for the cybercriminals Victor said.

"Bad guys are having a field day because we're saying, 'Well, all of our information is valuable.’And then none of it gets well-protected, or not enough of it gets well-protected."

Ray Hagar is a retired political journalist from the Reno Gazette-Journal and current reporter/columnist for the Nevada Newsmakers podcast and website, nevadanewsmakers.com. Follow Ray on Twitter at @RayHagarNV.

Business

Share