ABIGAIL: HOW SAFE IS THE STATE
OF OKLAHOMA WHEN IT COMES TO
CYBER SECURITY?
IS YOUR PERSONAL INFORMATION
PROTECTED?
LAST WEEK, WE TOLD YOU ABOUT ONE
OF OUR STATE AGENCIES BEING
HACKED.
JOINING US NOW TO TALK ABOUT
THIS, THE DIRECTOR OF CYBER
COMMAND FOR THE STATE OF
OKLAHOMA MARK GOWER.
THANK YOU SO MUCH FOR BEING A
LONG.
I REFERENCE THE STORY ABOUT ONE
OF OUR STATE AGENCIES BEING
HACKED.
CAN YOU TELL US WHAT HAPPENED?
MARK: THERE WAS A FOLLOW-UP ON
THIS STORY AND AN EMPLOYEE HAD
HIS HOME BROKEN INTO AND HE HAD
A STATE DEVICE STOLEN.
WHAT WE ARE TRYING TO DO IS LET
PEOPLE KNOW HOW THE PROCESS
WORKS, HOW WE SECURE THE
INFORMATION.
IN THIS INSTANCE, HE
CONSOLIDATED AGENCY, WHICH MEANS
THEY ARE UNIFIED UNDER THE
STATE'S CONSOLIDATION ACT.
WE MANAGE THOSE DEVICES THROUGH
MOBILE SOFTWARE.
THE AGENCY NOTIFIED US THE NEXT
MORNING THAT THE DEVICE WAS
STOLEN.
WE RESPONDED IN ABOUT ONE
MINUTE.
WE WERE ABLE TO IDENTIFY THAT
THE ASSET WAS ENCRYPTED AND SENT
THE COMMAND.
THAT AFTERNOON WE WERE ABLE TO
CONFIRM THAT THE COMMAND WAS
DONE AND CONTINUE THE
INVESTIGATION AND FOLLOWED UP TO
GET THE DEVICE THAT.
ABIGAIL: WHAT IS A WHITE
COMMAND?
>> IT IS A SIGNAL THAT WE SEND
TO THE DEVICE THAT TELLS IT TO
WIPE ALL THE DATA OFF OF IT SO
THAT IT IS NOT USEFUL TO ANYONE.
ABIGAIL: WE HAD A STORY WHERE A
STATE AGENCY WAS HACKED AND
ANOTHER WHERE A STATE COMPUTER
WAS STOLEN, WHERE DATA MAY HAVE
BEEN STOLEN.
THESE ARE THE SAME STORY?
MARK: CORRECT.
ABIGAIL: CAN YOU TELL US WHAT
AGENCY IT WAS?
MARK: WE KEEP SECURITY EVENTS
CONFIDENTIAL IN THOSE PARTICULAR
CASES.
WHEN WE GET THE CHANCE TO
RECOVER THE DEVICES, WE KNOW
THAT EVERYTHING IS SECURE.
ABIGAIL: WE KNOW THAT TAXPAYER
MONEY MAY HAVE BEEN TURNED INTO
BITCOINS TO PAY THE HACKERS.
IS THAT ACCURATE?
MARK: THAT IS AN ONGOING CASE,
SO WE DON'T COMMENT ON THOSE.
WE HAD A SUSPICON THAT THAT WAS
OCCURRING, AND WE ARE FOLLOWING
UP WITH THAT AGENCY NOW TO MAKE
SURE THAT THAT DID NOT OCCUR.
ABIGAIL: HOW OFTEN DOES
SOMETHING LIKE THIS HAPPEN WHERE
YOU HAVE TO PAY OFF THESE PEOPLE
, TURNING TAXPAYER DOLLARS INTO
BITCOINS, DOES THIS HAPPEN MORE
THAN WE KNOW, OR IS THIS RARE?
MARK: IN 2016, WE HAD 10 CASES
OF RANSOM WARE.
WE HAVE THOUSANDS OF SERVERS
AROUND THE STATE, SO I THINK THE
INCIDENTS ARE PRETTY LOW BASED
ON THE SIZE, BUT WE HAD NOT PAID
ANY OF THE ATTACKERS.
WE HAVE A PLAYBOOK, IF YOU WILL,
WHICH ALLOWS US TO GO THROUGH A
PROCESS TO GET THE DATA BACK.
THE FIRST THING IS AND WE DO NOT
PAY THE ATTACKERS, WE TRY TO
RECOVER THE DATA.
ABIGAIL: YOU SAID EVERY WEEK
THERE ARE THOUSANDS OF CYBER
EVENTS THE STATE THAT YOU HAVE
TO MONITOR.
WHAT KIND OF EVIDENCE ARE YOU
TALKING ABOUT?
MARK: ANYTHING FROM MALWARE
INFECTED WEBSITES THAT EMPLOYEES
VISIT, EMAIL ATTACHMENTS, OR
TARGETED ATTACKS FROM ATTACKERS
TRYING TO PENETRATE OUR DEFENSES
CONSTANTLY ON A DAILY BASIS.
IN 2016, WE HAD 500,000 EVENTS.
ABIGAIL: WHAT IS THE POINT OF
THIS, DO THEY WANT INFORMATION
FOR IDENTITY THEFT?
MARK THE MAIN POINT FOR THE
MAJORITY OF THEM IS TRYING TO
GET CONTROL OF OUR PCS.
IF SOMEBODY TRIES TO INFECT YOUR
MACHINE, THEY WANT TO GET DATA
FROM IT.
IF THEY CAN MAKE YOUR MACHINE
REMOTELY ATTACK SOMEBODY ELSE'S
MACHINE, SO THE WEB IS AN
INNOVATION -- WEAPONIZATION OF
STATE COMPUTER IS SOMETHING WE
ARE LOOKING FOR.
ABIGAIL: DO YOU KNOW WHERE THEY
ARE FROM, ARE THEY FOREIGN,
DOMESTIC?
WE KNOW THAT IN THE ELECTION
RUSSIAN HACKERS MAY HAVE
INFILTRATED.
MARK: THIS IS A GLOBAL PROBLEM.
WE SEE IT FROM ALL OVER THE
WORLD.
WE HAVE TO PLOT REAL-TIME IN THE
STATE CYBER COMMAND WHERE THESE
ATTACKS ARE COMING FROM.
THEY CAN BE ANYWHERE FROM ACROSS
THE GLOBE.
ABIGAIL: YOU HAVE BEEN WITH THE
STATE OF OKLAHOMA FOR MORE THAN
A DECADE.
IS THIS PROBLEM GROWING
EXPONENTIALLY AS PEOPLE ARE
GETTING MORE ACCESS TO
TECHNOLOGY, OR HAS THIS BEEN
GOING ON A WHILE AND WE ARE JUST
NOT HEARING ABOUT IT?
MARK: THIS HAS BEEN GOING ON A
WHILE.
THE WAY THAT ATTACKERS ARE
TRYING TO ATTACK IS CAUSING SOME
PAIN HERE IT IS A NEW FRONTIER
FOR EVERY BUSINESS OUT THERE.
IT IS NOT SOMETHING NEW THAT THE
STATE IS DEALING WITH.
THIS IS SOMETHING THAT WE ARE
ALL TRYING TO BRAVE AND PROTECT
THE STATE SYSTEMS SO THAT
CITIZENS CAN INTERACT ONLINE AND
EMPLOYEES CAN BE MORE MOBILE AND
STILL HAVE THE SAME PROTECTIONS
AS IN THE BRICK-AND-MORTAR
BUILDINGS.
ABIGAIL: WHEN YOU TALK ABOUT
HACKERS GAINING ACCESS -- LET'S
USE ME FOR EXAMPLE.
THEY COULD GET MY TAX
INFORMATION, HEALTH INFORMATION,
IF I HAD ONE, CRIMINAL RECORD.
MARK: THE STATE AND MULTIPLE
AGENCIES DOES HOUSE INFORMATION
ABOUT OUR CITIZENS.
SO IT IS INCUMBENT UPON US TO
MONITOR AND PROTECT THE DATA.
ABIGAIL: DO YOU FEEL A SENSE OF
RESPONSIBILITY FOR THE 3 MILLION
CITIZENS IN OKLAHOMA THAT YOU
HAVE TO PROTECT?
THAT IS A LOT OF PRESSURE.
MARK: ABSOLUTELY.
I HAVE A GREAT STAFF THAT WORKS
FOR ME.
THEY TIRELESSLY STAY AROUND THE
CLOCK.
I HAD SEVERAL EMPLOYEES WORKING
THIS WEEKEND JUST TO MAKE SURE
THAT THE CYBER THREATS WERE
HANDLED.
ABIGAIL: I WANTED TO ASK YOU ONE
LAST THING, IF YOU COULD
PINPOINT THE BIGGEST THREAT,
MAYBE WHAT KEEPS YOU AWAKE AT
NIGHT, WHAT WOULD BE THE BIGGEST
THING FACING OUR SITE SECURITY
RIGHT NOW?
MARK: PEOPLE'S EDUCATION,
UNDERSTANDING WHAT IS IMPORTANT
TO YOU, HOW YOU SECURE YOUR
SYSTEMS.
IT IS ALL INCUMBENT ON THE
PERSON TO DO THIS.
WE CAN PUT THE BEST TECHNOLOGY
IN PLACE BUT IF THEY FOOL YOU,
THEY CAN GET PAST OF OUR
AUTOMATED SYSTEMS.
ABIGAIL: DO YOU HAVE RESOURCES
WERE SOMEBODY CAN GO IF THEY GOT
AN EMAIL OR TEXT MESSAGE THAT
SOUNDS PHONY, DO YOU HAVE
RESOURCES FOR PEOPLE, THE PLACE
THEY CAN GO TO REACH OUT?
MARK: WE HAVE CYBER
SECURITYOK.GOV.
THERE ARE ALSO'S FEDERAL
RESOURCES ON THE FBI WEBSITE,
LOOK FOR PHONE SCAMS, EMAIL
SCANS, THOSE TYPES OF THINGS.
KEEP YOURSELF UPDATED.
ABIGAIL: AND BE CAREFUL WHEN YOU
POST ON SOCIAL MEDIA.
MARK, THANK YOU.
REALLY INSIGHTFUL.
IT IS LIKE THE WILD WEST OUT
THERE WITH THE INTERNET.
WE CERTAINLY APPRECIATE THE
Không có nhận xét nào:
Đăng nhận xét