Transcript
Speaker: The COVID -19 pandemic has done more than disrupt operations. It's opened the door to more cybersecurity attacks than before. Find out where they're coming from and what you can do to close that door on the next episode of The Market That Moves America.
Speaker: Welcome to The Market That Moves America, a podcast from the National Center for the Middle Market, which will educate you about the challenges facing mid -sized companies and help you take advantage of new opportunities. As if COVID -19 weren't enough.
Speaker: While they hunker down to wait out the pandemic, middle market companies are facing increased cybersecurity threats. Today's edition of the Market That Moves America explores why that's happening and what executives and companies can do about it. I'm Tom Stewart. I'm the executive director of the National Center for the Middle Market at the Ohio State University Fisher College and Business.
Speaker: We are the nation's leading research outfit studying the mid -sized companies that account for a third of private sector employment and GDP and historically the lion's share of economic growth. It is indeed the market that moves America. The National Center for the Middle Market is a partnership between Ohio State and CHUB.
Speaker: I have a special guest with me today, Emre Cocksall. Emre is a professor of electrical and computer engineering at Ohio State and the CEO of a university -funded spinoff called Data Anchor that is focused on cybersecurity. Professor Cocksall, Emre, welcome to the market that moves America. Thank you very much. It's my pleasure. Thanks for having me. Also, I must mention that I'm impressed with the way you pronounce my last name. That was awesome.
Speaker: I'm glad I got it right. It's K -O -K -S -A -L for those of you following along at home. And we'll be giving you some information about how to contact him and Data Anchor at the end of this discussion. But, Emre, let's start with the headline. Cybersecurity is always important, but it has become even more challenging and vital
Speaker: now in the middle of this pandemic lockdown. Why is that? Oh, absolutely. I mean, overnight, the entire workforce became remote, right? So, you know, the way we used to look at this problem, the security problem was like, confine everybody within your organization's network, put firewalls, put, you know, measures to keep them inside when they're consuming sensitive data.
Speaker: and you'll be 80, 90 % safe. But right now what happened is overnight, everybody set up their own network in a sense. Now I have the problem scaled proportional to the number of users because everybody has their own network and there's absolutely no way for an IT to identify the problems, let alone cover them.
Speaker: So I know people at banks, for example, who literally could not access certain bank applications from home because that was part of the security system for banks. But now they have to be able to. So that's an example. Everybody's left the castle. They're on the other side of the moat and they're now doing sensitive work from their little huts and hovels out in the field.
Speaker: Yeah, exactly. So financial industry, you're right. Many of the applications are designed or the systems are designed in such a way that the access is allowed only from inside. So now there are some hot patches and people are forced to use VPNs. But there are so many different problems occurring associated with that. And, you know, there are more problems than solutions we have right now.
Speaker: I mean, obviously, we've heard a fair amount about Zoom, the conference platform that I've been in three Zoom rooms today alone. But that's an example of a system that people are using a lot that simply hadn't been designed with the kind of robustness needed for this kind of use.
Speaker: First of all, what's your sense about the job they've done? They're a middle market company, although I think they're pretty fast growing, maybe beyond that. But have they done a good job of patching? And what are the lessons and what are the similar issues about working from home, people relying on sort of unhardened systems?
Speaker: Right. I mean, Zoom has been designed to do, you know, fundamentally connect people in, you know, in the form of telecom or video conferencing, and they are doing that job really well.
Speaker: I mean, in any given time, security was an afterthought for them. But now that it became ubiquitous, I mean, almost the entire world, all the organizations started using Zoom in most part. Some of the problems became apparent, like authentication is one example, unauthorized access was another example. Zoom has done a good job to patch up
Speaker: to quickly patch up those seemingly obvious problems. But there are some other problems obviously remaining, such as unauthorized access without an intention of letting the attendees know. I mean, if I lose my credentials, for instance, which is very easy these days, or if somebody captures a valid authentication, they can still capture the communication in a man in the middle fashion
Speaker: and do a bunch of damage without the knowledge of the attendees, without the knowledge of the organization. Just as an example, if you want to exchange files over the Zoom medium, you have to go unencrypted. So they don't do end -to -end encryption properly for file exchange. And the way they used to do encryption had problems, which in some part they have fixed.
Speaker: I don't want to pick on them, but that's almost a symbol of the kinds of things. People are using informal systems. People are trying to do things with an intuitive, easy -to -use system that it wasn't designed for. We're all living
Speaker: more outside the firewall than ever. So there's more vulnerability. Has the number of attacks gone up? Have you seen more people exploiting these vulnerabilities?
Speaker: Oh, absolutely. Just to give you an example, at Data Anchor, we have a client, they're a small to mid -size medical billing organization. So they have highly sensitive data, right? HIPAA compliant data, they need to secure it. We had a conversation with their owner the first week of remote workforce,
Speaker: you know started and you know they have seen just more than 50 attacks only from China originating from China in the first week alone so this has definitely increased and the attackers are now exploiting the vulnerabilities more than ever I mean the numbers are extreme right now so it's definitely increased
Speaker: Have the kinds of attacks changed too? I would suspect that maybe we'd get more phishing attacks and maybe less denial of service attacks. More cybersecurity attacks, but is the composition of the attacking force also changed?
Speaker: Yeah, some of those attacks were like fishing. They were classical attacks. They were going on. But now what happened is, you know, maybe some of the attacks have transformed and are happening in multiple stages as opposed to a single stage. Let me give you an example. For instance, now that everybody
Speaker: is accessing from a router that they just purchased out there. And you don't even know as an IT that they properly set up the, you know, the security or encryption, or you don't even know whether they're sharing their routers with others, right?
Speaker: And furthermore, all these devices and all these networks are being used for personal purposes on top of business. So all the problems that you were facing when you were doing personal transactions now expand to your sensitive data usage as a part of your business.
Speaker: The problems associated with my router, for instance, which I can list 20 of them right now, 20 different attacks to your personal network, now extended and you're potentially exposed indirectly in your business data consumption.
Speaker: And that's interesting I hear that going two ways right on the one hand you're saying, because I'm doing my personal business and my business business over the same router the one that's in the next room beyond me.
Speaker: I think weaknesses in my personal data behavior or action could go over to business. But it also works the other way around, right? I also might actually, my own personal cybersecurity might be negatively affected because it's exposed to attacks on my business. Yeah, it goes both ways. I mean, furthermore, I mean, my daughter is accessing the same device as me and doing certain exchanges.
Speaker: from those vulnerabilities associated as well. So there's no way to control for every single one of them. So why are mid -sized companies especially vulnerable?
Speaker: So that's a great question. So mid -size companies are a bit similar in the sense that they have the same kind of sensitive data problems as enterprises. So they have a significant amount of data that's worth stealing, right? So in that sense, they're not that different from an enterprise. They're also compliant in most part, like financial, for instance, mid -size banks, healthcare providers,
Speaker: They need to be compliant, and they have similar data as enterprises, as large organizations. However, if you look at the resources in terms of IT, they don't have enough dedicated resources to, quote -unquote, micromanage the user behavior in this day and age, in this remote workforce era. So, what happens is, you know, some of the
Speaker: problems remain unaddressed, unmonitored, undetected, and, you know, there are, I bet, a bunch of losses that go undetected and unrealized as a result. A lot of marginalized, yeah, that makes sense. The other thing I'm thinking about, and tell me how this works, our experience and our research
Speaker: show that a lot of middle market companies recognizing that they can't field a world -class cybersecurity force.
Speaker: on a $100 million revenue base have put a lot of their IT resources and perhaps some of their cybersecurity resources in the cloud. So let those guys handle it because we can't. As companies have more remote work, I mean, I guess in normal times, that might be a good security measure, assuming your cloud service provider is secure.
Speaker: But if I've got everybody dispersed at home, does that cloud solution become less secure than it was?
Speaker: Yeah, it is the same. So cloud, you can view cloud as the store that is sitting there with much higher resources to protect. However, I need to access the cloud, right? So it all starts from my end user device. And what is the first hop from my device to the cloud? It's that router there and my own personal device there. I may meet all sorts of credentials. I may have
Speaker: multi -factor authentication, which is great. But this doesn't eliminate from an attacker to capture it and run all sorts of attacks that would damage that first off, because there are so many vulnerabilities. And the problem is, if I have 500 employees on the mid -size organization, there's no way for the IT to check and keep in balance all 500 users' infrastructure.
Speaker: So there's still the same problem with the cloud. So more people are dispersed. My defenses are less good. More people are attacking. I've got valuable data. I also have a real desire, a real need to try to be as responsive as possible in this time because I'm trying to keep my business going. Under these circumstances,
Speaker: Where do I start? How should a company, what ideas can you give me about how a company can start sort of protecting itself in this particularly vulnerable time from cyber attacks? Right. That's a great question. That's the key question, actually. What should we do?
Speaker: One of the things that we have observed interestingly is that because all of these companies, they have enough stuff to do. They always have their calendars filled up. So they keep this as an afterthought, the security, which is necessary, yet it's kept afterthought. I mean, to the extent that
Speaker: When you want to inform them about the risks that they have, we have interacted with companies who do not want to know about it, because if they know about it, they need to take action. So ignorance is bliss in that sense.
Speaker: So, this is, again, based on this old -fashioned notion that security is difficult, security has to be hard, I need to spend much resources to keep myself secure, and on top of it, I need to manage it, and furthermore, there is this infamous trade -off between security and performance. I need to kill efficiencies and
Speaker: workflow impediments are going to be there because of security. But the thing is that need not be true. There are many elegant solutions, for instance, in terms of security data -centric, rather than network -centric security solutions, which are making life easier for the IT and organizations of that source. So such solutions have
Speaker: very simple integration, they are very basic in the sense that, you know, go back to basics, right? I mean, encrypt your data in a simple fashion, keep it secure such that security travels with data, those notions start to get out there. And, you know, the thing is, first, keep in mind that security need not be difficult. You know, it can be simple, it can be integrated, you don't have to think about it after that.
Speaker: and it can be maintained in a simple fashion. So that is the starting point. So if I can't keep the network as secure as, so let's say my network was 95 % secure and now it's 85, whatever it is, I can't keep the network as secure as it was, but I should spend a little more time encrypting everything, all the documents on it. Yeah, I mean. That's what I thought, yeah. Right, whatever, either sensitive documents or all of the documents in such a way that, again, you know,
Speaker: The notorious notion with encryptions, people think it's difficult, but it's not. It's very simple. It's very basic. And there are solutions out there that can keep all data encrypted in a fashion that it doesn't necessarily make the workflows inefficient or change in that regard. So you can keep the exact same workflows and keep your data encrypted at the same time.
Speaker: So, and I would think also would be a good idea to do some, you know, I know a lot of companies, including Ohio State, are sending out fake phishing messages to see whether we catch them right. And so far as I know I've been pretty good. But but I would imagine that that would be another defense would be sort of do the double down on those things that remind people about security, particularly because I'm at home, I may have a
Speaker: you know, a kid needing an algebra lesson or all kinds of other distractions, but training, reminding the individual of her or his role in security the same way you would at work, but just sort of saying, hey guys, don't forget.
Speaker: That would be another one, I think. Absolutely. Training. I mean, it all starts and ends with training. I mean, training is very important. People need to be educated. But one of the things that organizations should keep in mind is that
Speaker: Trust doesn't scale. I mean, you trust people. They may do the right thing. We all make mistakes. And there may be adversarial, intense insight from the insiders. So you shouldn't assume. I mean, training obviously reduces statistically the vulnerabilities. But you shouldn't assume people will follow the rules.
Speaker: just because they are very careful or necessarily they are not adversarial. That will happen. So you should basically figure out a way in which you're still secure even though those things happen, even though Snowden attack happens, even though my credentials are lost. So that's the way we should look at the problem. I'm almost thinking that there is
Speaker: cyber distancing, just as there's social distancing. That there are things that we can, that almost is an analogies that you can draw. Are you washing your hands? Are you covering your face? Are you taking, are you spraying your shoes? Whatever you need to be doing, are you keeping the right kind of distance and are you keeping the right sort of level of, I guess, distrust?
Speaker: um that that that you need so that we can move forward in as safe as manner as possible until we can come back into the castle absolutely i agree
Speaker: This has been a fantastic conversation. There's just one other question I'd like to ask before we wrap it up is, where can I go for help? What are a couple of places that people can go to now where they can figure out what they can do in this time that will strengthen their cybersecurity capabilities?
Speaker: So, you know, I should offer help from my own institution, Ohio State University. You know, there are multiple resources on the website there on CISO's office. It's all fantastic. Don't view it as necessarily crafted for employees of Ohio State University. The advice provided there is scalable and it applies to everybody.
Speaker: Also, I mean, you have, I think you give our address but www .dataanchor .io
Speaker: We have a questionnaire there which we crafted for people to evaluate their vulnerabilities in this new remote workforce era. We would love to help without an extra cost. We would love to evaluate your existing security openings and what you can do as a result, and we'll give you free evaluation as a result.
Speaker: That's great. And we will capture that. Thank you for that because we will capture that also and share that on our social media things. We have a National Center for the Middle Market has a cybersecurity evaluation questionnaire, but this one is optimized for this moment now with remote work. So we'll find that and we will pass that on to.
Speaker: That is a very important remark. I'm sorry I interrupted you. It's optimized for this remote workforce. You said until we get back to our castle, one thing that I would like to emphasize is that when we get back to our castle, it doesn't end there.
Speaker: you know, there are, you know, you have to be cognizant of the problems, even as people, as you think, are consuming data within the castle. So, security problems still remain to exist. And you know, my own hypothesis is that the post -COVID world will be a world where there is more
Speaker: sort of fluidity between what happens in the office and what happens at home. And some of the things that we've learned about working at home and working in Zoom rooms and all that good stuff is stuff that we're going to try to incorporate in our lives, which means that that footprint of vulnerability or whatever, that vulnerable skin of our organization is probably going to be expanded forever.
Speaker: By this event, all of which is, let me try to wrap this up because first of all, I think it's been a great conversation and Professor Emery Cocksall, thank you so much for joining for joining with us. I mean, what we've heard is that the COVID -19 pandemic
Speaker: environment, working from home, pandemic responses has opened up cybersecurity vulnerabilities, that people are exploiting them, more attacks are going on, that there are a number of things that companies can do to beef up that security even at a time when there are more windows of opportunity for the bad guys to get in. And one place to go to learn more is that the data anchor website, that's www .dataanchor .org.
Speaker: And there's and data anchors D A T A N C H O R. So the two middle A's are compressed into one data anchor .io and you can learn more about about cybersecurity in a remote in a working remotely environment there.
Speaker: And you can learn more about the middle market and about us at the National Center for the Middle Market's website, which is middlemarketcenter .org. Thank you all for listening to The Market That Moves America. Never miss a new episode. You can subscribe to the podcast on iTunes, Stitcher, Google Play, or wherever fine podcasts are found. And as I said, you can subscribe and learn more about us at our website, middlemarketcenter .org. Stay safe, and thank you very much.


