TechOnPurpose Logo

Russia’s Impact on Global Cybersecurity

by | Mar 22, 2022

Who's In Your Cloud?
Who's In Your Cloud?
Russia's Impact on Global Cybersecurity
Loading
/
Welcome back to “Who’s In Your Cloud?” 21 Steps to Secure, Reliable, Trusted Technology. I’m Lauren Lev, Marketing Manager for TechOnPurpose, and today we have a special episode for our viewers: Russia’s Impact on Global Cybersecurity.

Looking back at our previous episode, we considered how the rise of BYOD in the workplace has created new opportunities for malicious actors to exploit your devices- and explained how to keep your environment safe with the use of Mobile Device Management. We were lucky to be joined by a cyber expert cast from Cisco, JumpCloud, and TBI as they provided us with their mobile device management and protection solutions.

For today’s episode, we’ll be discussing the cybersecurity implications of the ongoing Russia/Ukraine conflict. Russia’s involvement in malicious cybersecurity events has been a hot and debated topic for many years, but how should we adjust our attention and priority to these nation-states’ cyber risk given the recent Russian invasion of Ukraine? Our cast of cyber experts from ConnectWise and Independent Cybersecurity Consultant, Jim Bowers are here to break down what we do and don’t know about the bad and the ugly of Russia’s growing impact on global cybersecurity and how to keep yourself cyber-safe. We’re thankful to our partners for joining the “Who’s In Your Cloud?” series as they help us educate our clients and prospects on the road to #secure, reliable, trusted technology

As a reminder, we began releasing a new episode every Tuesday, starting 10/20/21, and will continue to do so through late spring of 2022, with brief time off for holidays with family and friends. We’ll also follow each Tuesday episode release with subsequent Wednesday, Thursday, and Friday posts highlighting our (3) contributing solution partners from that week’s episode. We hope you’ll find this an immersive, hopefully simple, educational and enjoyable experience. So how do you tune in?

To easily follow the journey ahead, we’ve diversified your access options to all (23) of our coming episodes. You can follow along here on our blog or by any of the following methods:

  • Email Newsletter: sign up at techonpurpose.net/blog and have each episode delivered directly to your inbox when released.
  • LinkedIn: follow here
  • YouTube: follow here
  • Facebook: follow here
  • Podcast: follow here

Buckle up – it’s time to hit the road to #secure, reliable, trusted technology!

Read Transcript
Lauren Lev
Welcome back to “Who’s In Your Cloud?” 21 Steps to Secure, Reliable, Trusted Technology. I’m Lauren Lev, Marketing Manager for TechOnPurpose and I’m very excited for this “Who’s In Your Cloud?” special episode today to discuss the cybersecurity implications of the ongoing Russia/Ukraine conflict. Before we get into it, make sure to like and subscribe to our YouTube channel down below. It really helps us out. And while you’re here, check out our entire “Who’s In Your Cloud?” vlog series in our playlist above. We post episodes of this series every Tuesday on LinkedIn, Facebook, Spotify, and of course here on YouTube. And you can get episodes delivered straight to your inbox by signing up at TechOnPurpose.net/blog. From the boardroom to the water cooler, Russia’s involvement in malicious cybersecurity events has been a hot and debated topic for many years. But how should we adjust our attention and priority to these nation states cyber risk given the recent Russia invasion of Ukraine? The Russian government seems no stranger to malicious cyber activities with allegations including suppression of social and political activity to stealing intellectual property and harming regional and international adversaries. Today, our passionate, sassy and savvy cast of cyber experts are here to break down what we do and don’t know about the bad and the ugly of Russia’s growing impact on global cybersecurity. Alright, so first up, I will introduce author and independent cybersecurity contractor, Jim Bowers. Jim, give us the rundown. Why do you care about cybersecurity?

Jim Bowers
Hey, Lauren, first of all, thank you very much for being back. I love being on TechOnPurpose’s TOP21. It’s awesome to be here. So what drives me with cybersecurity? I think cybersecurity- really what drives me and I’m passionate about is simply the fact that it touches every aspect of our lives, not only in a corporate aspect, but our personal aspect, especially due to what the pandemics have done and how we’re working today. We’re working more closely in home environments, working from anywhere, and the ability for the cyberattacks can not only affect businesses, but it can have huge outcomes on us as people in general, such as the Colonial Pipeline. So really glad to be here. Thanks for having me on board and I’m looking forward to this conversation today.

Lauren Lev
Next, we have Jay Ryerse, Vice President of Global Security Sales at ConnectWise. He should be a familiar face because he and his colleagues have had a large presence on the Vlog. But Jay, remind the audience who you are and what your role is at ConnectWise.

Jay Ryerse
Thanks, Lauren and Matt, for having me back again. I must be doing something right. Yeah. I’m Jay Ryerse, I’m VP of Global Security Sales at ConnectWise. We are the world’s leading IT provider of software to the service companies out there. And that does include cybersecurity. I’ve spent a large portion of the last section of my life dedicated to helping secure small businesses, so I’m excited to be here and very much excited to hear probably what we don’t want to know about what’s going on behind the scenes.

Lauren Lev
Speaking of what we don’t want to know, we have ConnectWise’s Threat Intelligence Evangelist and Cyber Researcher Bryson Medlock. I’ve said it before, I’ll say it again: Bryson, I’m very happy to have you here with us today. You can kind of give us a peek behind the curtain of Oz that we probably don’t really want to know. But introduce yourself and tell us more about what you do at ConnectWise.

Bryson Medlock
Thanks. Yeah, I’m really happy to be here today. I’m Bryson. I do security research. I’ve been in the IT and then security industry for like 20 plus years. I like making bad people sad. That’s what motivates me, tracking down what the bad guys are doing and trying to stop it. So yeah, I’m part of ConnectWise’s cyber research unit. So we’re the security researchers at ConnectWise. We mainly focus on some of our security tools and building threat detection around it, as well as threat hunting, and then just gathering intelligence and focusing on what sort of threats that MSPs are facing today.

Lauren Lev
As always, we have TechOnPurpose’s Founder and CEO, Matt Tankersley. We’re twins wearing our matching shirts today.

Matt Tankersley
Man, guys, thanks for having me back. And you guys all make us look good. So we’re so blessed to have you back and Jay and Jim repeat offenders. Glad to have you and Bryson, I think you have the best line yet for introductions that “making bad people sad” man, that’s deep.

Jim Bowers
Clearly, that’s a keeper.

Matt Tankersley
Yeah, we’re going to copy that. Well, welcome back, everybody. We’re excited to talk about Russia/Ukraine today and what that means.

Lauren Lev
Tell us why we are taking a deeper dive into why we decided to have this special feature episode today on Russia’s impact on cybersecurity.

Matt Tankersley
Okay, cool. Thanks, Lauren. And again, thanks, everybody for taking the valuable time to have this very worthy discussion about cyber risk and security best practices in general. And then, you know, what does this Russia Ukraine thing mean? How does that change the environment? Well, I’ve said from the beginning, I wish we didn’t even need to have these conversations about these very real devastating risks of cybersecurity, but it’s clear the topics are not going away. Now, with nation states present and expanding their malicious efforts, right? These things must not go undiscussed or more importantly, adoption of these best practices is clearly an operational priority for nations and organizations everywhere, regardless of your size. So while we as a nation deal with the rising economic pressures of inflation, and even divisions between political parties, friends and family, the enemies at the back door, and I’m afraid, maybe already in the kitchen, and living room, and even likely our bedrooms and cars, as we’ve heard in other episodes, and anywhere in our internet connected devices are present, right? So best cyber practices, right, like never before, that’s not an option. How does the current Russia Ukraine war impact that conversation? Well, let’s turn that over to the real experts. And I’m anxious to see what we learned today from each of your unique perspectives on the problems and solutions that help TechOnPurpose, our peers, and organizations everywhere to achieve the reality of secure, reliable, trusted technology in the face of these ever changing threats. So where would you like to start, Lauren?

Lauren Lev
Jay, over to you first, the Russia Ukraine conflict is merely the beginning of modern warfare being waged online for some time now. So what are your opening thoughts on the elevating risk factors from the current Russia Ukraine conflict?

Jay Ryerse
I hope that we’re overblowing this, and that, you know, right now, it’s not an issue, but it’s going to be an issue at some point. So it’s better we start talking about these things and addressing them. I have confidence, a high degree of confidence based on contacts in the space that NSA, our military, you know, they’re already fully prepared for this type of activity. You know, they know what’s happening. They know what the playbooks are, they know what they would do, and that they’ve got, hopefully, countermeasures in place to protect our most important and critical infrastructure of assets. That does not reach down into business and especially that small medium business. You know, that two person accounting firm that’s, you know, in their second year of business and trying to work through it coming out of COVID and run their operations, all the way to those, you know, two, three or 4000 employee businesses that are really struggling to hire and retain the security talent. You know we’re all challenged with these things. And I think we need to go back to the basics. Pick your framework, assess your environment, follow the 21 recommendations that we’ve been talking about, you know, and understand why they matter, and how they fit your business. And do your best to be prepared with a survivability plan. I’m kind of going beyond even just, you know, backups, but you know, what does it look like to survive a cyber attack these days? And I’d even go so far, I’m opening up a new can of worms that wasn’t on topic for today. But, you know, how do insurance companies-How are they going to look at cyber warfare versus just a cyber attack? You know, someone that falls victim to a ransomware attack is different than if it’s a nation state and its intent is malicious as part of a warfare attempt. I can’t even imagine where that goes. And I’ve been asking the insurance people that I know in the space, you know, what’s happening? What does this mean? How are you looking at it? And they’re throwing their hands up. They don’t have a good answer yet, because it’s something that we’ve not ever encountered. You know, domestic terrorism and those kinds of things where, you know, bad things happen to buildings and people is one thing, but when you start looking at what happens to data, I don’t think they really can grasp that. So if I’m a business owner, I’m thinking okay, what can I do? Right, and again, I’m going back to the TOP21 list that we’ve been talking about for the last- I don’t know how many weeks we’re on now. And make sure that we understand what the impact of those are to our business. And make sure we assess, because at the end of the day, the things we’re about to hear about from Bryson and the team are things that, you know, we can take positive action on now, to avoid paying later and help minimize the impact of a cyber attack.

Matt Tankersley
Well, Lauren, let’s keep going around. Jay, I gotta tell you, man, I’ve been looking forward to this conversation and right if you’re following the TOP21, cyber risk insurance is part of that conversation. But I hadn’t connected those two dots in the way that you just did. And knowing how insurance companies work and knowing how companies want insurance to work and knowing little about how nation states and malicious actors choose to work together in harmony and how all those things connect to impact SMBs, wow.

Jay Ryerse
Yeah, the act of war is a comment in an insurance policy. What does that mean in today’s conversation? And again, I don’t think we have an answer. I think it’s probably another session where we go deeper. You can’t see it right now. But I’ve got goosebumps, because if this were to happen if we were to go wide open cyber war. I don’t know how insurance companies could survive.

Matt Tankersley
Yeah. In the face of that kind of devastating impact. How would they modify their definition of liability and coverage really to acts of war? And how does a third party actor that happens to be from Russia and has no intentional intent of working from a nation state perspective to attack an SMB, but yet the insurance company chooses to interpret it as such? Wow, man, that’s a can of worms I hadn’t even thought about.

Lauren Lev
Very good point. I’m going to take it to Bryson, as our cyber researcher, obviously, this topic has been on your radar probably for quite some time. But it’s now you know, more pertinent than ever. So what new methods of attack are emerging as a result of this Russia Ukraine conflict? And what else should we expect to see as the conflict continues to unfold?

Bryson Medlock
The nation state threat actors are using the same tactics, techniques, procedures that they’ve always used. There hasn’t been a lot of new things that have come up, not a lot of zero days they’ve been sitting on. And the majority of the ways they get in are still just bad password hygiene and phishing attacks. The only thing that was really new per se was they were exploiting some default behavior in MFA. I won’t name the vendor, but there was a MFA attack that they were doing. Essentially, if an account had gone dormant because the user was no longer active, they still had their Active Directory account active, then their account gets disabled when with their MFA provider. But then if they are able to guess the password, they can re-register and re-enable MFA. And so, if the accounts are still active on the back end, then they actually can control the MFA and are able to login and get initial access that way. That’s the only really new technique that we’ve seen and kind of highlighted an exploit in the default behavior of some MFA providers. But otherwise, it’s been the same thing. And it’s mostly been bad password hygiene, it’s been either weak passwords or password reuse and phishing attacks. It’s amazing how many times everything kind of comes back to that. Those and IoT devices that aren’t patched, I would say that’s probably like, you take care of those and it’s 95% of your attack surface as far as what threat actors are actually using. And I just made that statistic up, I don’t have the actual number in front of me, but it’s very, very high. That’s how they’re getting in and that’s still how they’re getting in. The main difference in what we’re actually seeing is the main difference in the tactics that we’re seeing with these threat nation state threat actors, as opposed to like, criminal groups that are you know, after a profit is what they’re after. And they’re after denial of service, they’re after destruction of property, or intelligence, as opposed to your typical criminal group, which is after making money. And so the nation state actors are deploying data wipers instead of ransomware. Several of them have been disguised as ransomware, but they actually just delete the data. So that’s a pretty significant difference, you know, ransomware operators typically want to actually encrypt the data in a way where it can be decrypted. So you know, they can make money. It’s bad business to just wipe the data but the nation states don’t really care about the business side. They just want to destroy the data, disrupt services and just cause problems for their targets.

Matt Tankersley
So I know we’re gonna go to Jim there, but what I heard was interesting, right? We’ve been talking from the beginning about these 21 best practices. And very early in the conversation, we talked about complex passwords. And we talked about unique passwords for every credential. And we talked about, you know, IAM and SSL and all of these very things. And it’s, as you said, Bryson, everything’s kind of coming back to these core, you know, low hanging fruits, when people have bad hygiene when it comes to their passwords. And, you know, we have vendors in the case that you mentioned, that have vulnerabilities in their MFA platforms, right, those sorts of things. And I know we’re all moving a lot. We all talk about a lot of things all day, every day. And obviously, this is a broad topic that we’re trying to simplify and focus on. And this is the first time in this group that I’ve thought about it. And I think if I were to reflect on it, I want to carry this thought forward, maybe even ask a question to the process. But if I reflect on what I am aware of, in recent times of a maybe classified nation state, I think of what I thought I heard of Israel doing to Iran when they were trying to disable their nuclear efforts. And I seem to recall someone saying something about an exploit that literally took down their entire operational systems and their nuclear production facilities, right. I just thought about that, while we’re talking in the context of nation state, and I’m curious Bryson, how were they able to deliver that, right? Is that present in the conversations we’re already having about how Russia might be doing similar things in our national infrastructure? Again, how might that roll over into the business fire?

Bryson Medlock
I think what you’re thinking of is Conficker, I believe that was the one.

Jay Ryerse
Or was it a Stuxnet? Yeah, I think it was Stuxnet. Yeah, that’s, that’s where they delivered a PLC control that altered the speed that they cooled nuclear reactors, the pistons and speed.

Bryson Medlock
Yeah, they specifically targeted that hardware that the Iranians were using in their nuclear plants. Yeah.

Matt Tankersley
Yeah, that’s it. So Stuxnet, and I’m not deeply familiar with it. I mean, how was that delivered? Was it somebody who just walked in the door and stuck a USB in something? Or was it something else?

Jay Ryerse
I’m not sure that’s ever become public knowledge. I think the ongoing joke has always been that it was a USB, you know, stuck in someone’s bag. And they were curious what it was and put it in. But it wouldn’t surprise me because it was a PLC that was impacted. If it wasn’t a circuit chip change in the PLC that got delivered to them to help build the nuclear plant. And they had been in for a long time and no one noticed. So no different than we saw how China was altering circuit boards on equipment that was destined for the US and was identified quickly. But only because some security people had to receive that equipment for their own environments. And they looked at the circuit board mappings and found an extra device on there, which they didn’t expect. I mean, who would check that? I mean when I order my computer from Dell today, I’m not going to look and see if it matches the original, you know, board specs. I trust that it’s right. That’s the problem. So but yeah, back to what happened with Stuxnet, I don’t know that we know. And Bryson, you may have more information, but everything I looked at previously, even when Symantec did an entire report on it, it never actually said how we got in.

Bryson Medlock
Yeah, that was a while ago. I mean, it’s more than a decade ago. So it took me a minute to go back and check my notes. I think it’s generally believed, yeah, that the initial infection was the USB flash drives, but I don’t think that’s been 100% confirmed.

Matt Tankersley
Yeah, old guy. I forget the passage of time sometimes. But you know, I mean, nation state thing, right. I mean, you know, legit or not, right. So clearly it caused some damage. And, you know, we just talked about so many factors that are part of our TOPCyber 21. And we’ve talked about this, and we’re here to talk about how these nation state’s attack. Basically what I’m hearing Lauren so far, and let’s get Jim to get a word in, is that everything we’ve been talking about from day one about this, the best practices that we need to implement are just even more critical to adoption. And we talked about USBs, right? I think that was in the Zero Trust Episode. We talked about the ability to prevent USB connections and yet simultaneously not making it possible for folks to use USB, but have the tools to get real time access. Yeah. All right. I’m going to hush up. Jim, let’s give you a chance to open up on the topic here of Russia Ukraine conflict implications,

Jim Bowers
You know, A) Bryson very great points B) Jay great points. And I think one thing we overlook here is, let’s think about why ransomware is on rise. It’s because of the chaos. The pandemic had a lot of chaos, a lot of content for the threat actors. And let’s think about the war in Ukraine, and how that’s generating content. Yes, nation states may not go after small businesses, but if they’re causing chaos, and they’re causing trepidations in the media, in our societies, then what do you think’s going to happen? These organized crime groups are going to rise up, now they have content, and now they’re going to go in tandem with these guys. So the nation states may not be attacking our small-medium sized businesses, but they will attack, you know, our infrastructure. Like Bryson said, they’ll go after to disrupt, to delete, and not really look at it from a monetary perspective. Like you saw how they did the colonial pipelines, it was actually not Russian initiated. Bryson correct me if I’m wrong, but it was a Russian hacking group that fostered in Russia? So I think what we need to realize is you’re going to see these multi-vector attacks rise out of this. A) they’re getting more content from the war in Ukraine, right? We see the accelerating potential of these cyber attacks, not only in Ukraine, we saw it, we already saw responses from anonymous, right? Anonymous is a geopolitical group, one of the most well organized hacking groups that no one knows who they are, they attacked Russia. So what happens here is, all of these- Also, we got to think about- Jay talked about these SMBs. Think about how many little SMBs support these government entities that are attack vectors. How many of these little mom and pops are providing parts and supplies to water facilities, to electric grids, to all of those pieces. I live in South Carolina, where there’s so many mom and pop shops, small businesses that help BMW and their big plant in Greenville, right outside of Greenville, South Carolina. So I think what we’re going to see is not only do we have to be worried about cyber warfare, but again, it’s generating content, it’s generating distractions, it’s enabling organized crime, the monetary threat actors have more content and more ways to attack us, right? Simply for the fact of it will have a domino effect, right? Nation states probably are never going to attack small, medium sized businesses, but they will attack certain infrastructures that we have, where small and medium sized businesses are supporting, but also organized crimes play off of that chaos and they increase their attacks on the SMB space. So I think we’re in for a world of- I don’t think the Ukraine, I think we’re at the beginning. And I think we’re gonna continue to see this. I think Putin is very angry at the Western world. And I think we are going to absolutely be a target, not to mention the rest of Europe being a target. And that will enable other threat actors to generate content and accelerate their attacks on companies and commercial entities.

Matt Tankersley
That’s brilliant, Jim. I mean, I had a million thoughts when you’re talking about and one of the things that I’m reminded of is the sanctions, right, that the US and the West and others have placed against Russia? There’s no question these are impacting Russian business owners and billionaires and all those kinds of things, right? There’s no question that those guys could, and perhaps in reciprocity, how they have the same impact on businesses, you know, their peers in the United States, right? So I think what I’m hearing is there’s an obvious trickle down effect, right? And if we’re as a nation saying, we’re going to bring harm upon industries in these countries, why would we not expect those industries to want to do the same thing to our industries? Whether it’s the nation state, or it’s the industries out of reciprocity.

Jay Ryerse
Matt, it was interesting, because when you start thinking about what’s happening, we haven’t seen as Bryson said, any direct, you know, volume of attacks coming our way yet, but we have seen a whole bunch of reconnaissance work done and “prep work” done for what this could look like. And I’m curious, Bryson, if you want to share, you know, two or three or four things that have happened in the last few months that kind of set the stage for what’s coming, because well, that ties back together in that conversation.

Jim Bowers
Yeah, Bryson, scare the hell out of us.

Lauren Lev
Well, Jim already did that.

Jim Bowers
Yeah, I know, you’re so welcome. But Bryson’s really gonna scare us.

Bryson Medlock
Well, if we just look at what’s been going over the past few months, I mean, really kind of saw some things ramping up back in like q4 of last year. There was a significant increase in Dark Web sales of Ukrainian leaked databases and user credentials. We saw an increase in phishing attacks against Ukraine. And then in January there was, you know, whisper gate, which was one of those disc wipers that was released, as well as some defacement of websites. So that’s one of the tactics that they’ve used a lot of. There were about 70 Ukrainian government websites that were targeted, only 10 of them were actually compromised, but they had several sorts of messages that were designed to sort of stir the pot as far as some racial issues that are going on in Ukraine, as well as messages that said things such as wait for the worst. There’s also large scale DDoS attacks. So there’s was right around January, the 14th 15th, all these things happen at once. There were some indicators at the time that their attack might have begun around then and some of this might have been a precursor to that, this might have been a test leading up to it. But the actual effect, of course, got delayed for a while. There’s been a lot of social media bot farms that have been discovered. February 9th, there was a bot farm that was found inside Ukraine that was shut down that had about 18,000 social media accounts that were just constantly posting, like, you know, disinformation and things that were all designed to increase tension in the area. And then, of course, on February 23rd when I think we saw more DDoS attacks, the hermetic wiper, and then which was another disk wiper. And that’s also the day that the US and UK released information on Sandworm which was an IoT botnet, something they actually had known about since 2019, but they decided to share the information in light of the actual attack. And then since then, there’s been, you know, a number of DDoS and wipers and just that’s been a lot of what’s been going on. Tons of disinformation actually on both sides. There’s people who are doing this information. We’re starting to see some deep fake videos. I saw a video earlier today of the Ukrainian president saying things he hadn’t actually said. And then there are just so many different quote unquote hacktivist groups, or even cybercrime groups that are coming in on one side or another, you know, I’ve got a list here with like 30 or 40 different groups that have come out and declared for Ukraine or Russia and they’re actively fighting each other. And yeah, back to Jim’s point, it’s not just the nation states that we have to worry about. A lot of the Cybercrime operators are specifically doing things to hurt people that they think are either directly involved with the conflict or you know, they’re blaming the US for well, they blame us for everything. So there’s some of that going on. Conti was a big one that was in the news. So the Conti is a ransomware group. They were one of the first ones to like, come out and publicly declare for Russia, they released a statement on their data leak site, saying that they supported Russia, and they would come after anyone who attacked Russians infrastructure, they would attack your infrastructure back. And then a couple of days later, someone- so Conti has a very large organization. And someone who had the inside scoop- many people believe it was a Ukrainian researcher who had infiltrated Conti, but we don’t know exactly who this person was, but they actually had a year’s worth of chat logs and data on Conti and they leaked it publicly. So we know a lot more about Conti now than we did a month ago. We’ve learned how large they are, how well organized, I mean, reading a lot of them- they’ve got like meeting notes and you can go through and it just sounds like a business. You know, you’ve got managers, you’ve got a full infrastructure as far as you know, an HR organization. There’s an org chart you can look at. It’s amazing how organized they are. There’s been some source code that’s released. So that’s, I mean, that’s kind of been a big thing is Conti and they’ve also apparently have some ties to the Russian government, which is no real, real big surprise. But it’s been- there’s been a lot going on.
Other things that have gone on, so Revil was another pretty well known ransomware group, responsible for the big ransomware attack back in July, July 4 weekend last year that targeted like 40 Plus MSPs. And there are 1500 Plus clients ransomed all one day that was Revil who’s responsible for that. They were actually arrested by the Russian law enforcement back in January, and many people believe that was really more of just a PR move. As tensions were heating up around the globe. And there were a lot of you know, a lot of people who were disdainful of Russia and the things that they’re doing and a lot of criticism they’re receiving about their stance on cyber warfare. So there were a few weeks in January where they just really started cracking down and arresting a number of groups. So Revil was one that got arrested, there were a few different carding forums and sites that got kind of taken down. Again, I think most of us believe that to be really a PR move on Russia’s side, not really cracking down on anything because then we see large groups like Conti that have direct interactions with Russian law enforcement, they’re still very active. So if anything they might have been taking down some of their competitors. That’s just some of the things going on, but yeah, it’s just constant. There’s so much right now, especially when you bring in all these vigilante groups. There’s so much vigilantism going on. Anonymous is one that a lot of people are hearing about, and they make a lot of the big news just because they’ve been around for a long time. And we’ve all heard of them, but they’re not the only group out there. Like I said, I’ve got a list here. of something like 40 different groups, a lot of them I never heard of before, you know, some of them have just appeared, some of them have been around for a while. And actually, you know, Ukraine’s actually been recruiting volunteers- their cyber army, they call them or the IT army of Ukraine, where volunteers are, you know, they’re doing DDoS. And they’re trying to hack into Russian systems. It’s really just we’ve never seen this scale of specific targeted vigilantism in the cyber world before.

Lauren Lev
It’s like guerrilla warfare on the web.

Jay Ryerse
What happens when all those turn their attention on the US or other potential Ukraine allies. I know that we haven’t taken a position, but for the most part I think we have. And what’s that going to mean for businesses, because they’re going to get swept up in the net of attacks, whether we like it or not. And Matt, which really goes back to you know, why you’re doing this whole series, as you know, what can we do? And how can we take steps to protect ourselves?

Matt Tankersley
Man I mean, Bryson, you said so much. I took a lot of notes. And there’s probably about a dozen questions I could ask, but I think I’ll pause and say here was the summation for me. In the world where we have such realistic deep fake videos, one of the things I took away was, how do we know that this Conti IM link, is it in and of itself a huge, deep fake? And I think the point for me was, how do we as individuals and organizations and managed service providers and cyber experts, how the heck in this new changing world do we know what’s really real?

Jim Bowers
That’s right. And matter of fact, Matt, I’ve got a good deep fake- a new one of you that if you have time, I’ll be glad to show.

Lauren Lev
I knew it was coming. As soon as they said deep fake, I was like Jim!

Matt Tankersley
I think Lauren’s due for one, come on.

Jim Bowers
No, it’s all Tank, it’s Will Ferrel also. So you know, I’l be glad to show it when there’s time.

Matt Tankersley
Done deal. Well, now let me ask a specific question and let’s keep going around the room Lauren. I know we’re running out of time, but I do want to ask this one question. I think I heard you say that these bot farms that you were talking about were in Ukraine. And they were doing disinformation campaigns via social media, if I’m not mistaken, right? Now, is that Russian, pro Russian people that have put those things inside of Ukraine to do this? Or do we know?

Bryson Medlock
Yes.

Matt Tankersley
Okay. Yeah, wow. So they literally have infiltrated nationally and injected all of this disinformation campaign into that environment to accomplish-

Jim Bowers
Well, you know, think about it here. This information, these bot farms, that during all the turmoil we’ve been going through, they were here in the US, because you gotta make it look like it was posted from a geopolitical geography perspective. So yeah.

Matt Tankersley
Wow, all right. Well, Lauren, we got nine minutes. What did we not talk about? And I guess, let’s all think about asking ourselves in the closing question, what is it that people really need to know, then we’d like to believe that we know that answer, and how does this issue really escalate what we’ve been talking about all along? And maybe even just reprioritize the topic.

Lauren Lev
Bryson, what do you believe listeners should do to better protect themselves during this time of uncertainty?

Bryson Medlock
Well, I’ll go back to if you look at the most common ways that all these groups are getting initial access, it’s phishing and bad password hygiene. And honestly, those have been around for as long as we’ve had computers and had email. And we have fixes for those. So you know, come on, guys clean it up. We know what these problems are and we’ve got controls, we’ve got solutions to these. You don’t don’t use the same password on every site. And that’s it’s not even just weak passwords, but it’s the password reuse. That is a big problem. Password spraying, I think Microsoft did a report last year of all the compromised accounts that they had, a third of them were just from passwords spraying the attacks, which is where they already have a username and password and they’re just trying them out. So because somebody reused that password on some other, you know, you go to some random website, some forum or whatever it may be, use the same username and password. It’s a hobby site that somebody set up and they don’t maintain it. It gets compromised, passwords get leaked. Now you’ve got a list of usernames and passwords, you try them everywhere. That is so common. And use a password manager, that’s a big one, so you have a unique password for every site and then MFA everywhere. And you know, if you really want to do it well, just avoid SMS if you can, because that’s a lot easier to hack and then you know, get a YubiKey. You know, something that you actually have a physical device on you, so even if your MFA account gets compromised, they actually have to have this physical thing on them to access it. You know, there’s a little extra level of security, those things exist. They’ve been around for a long time, and it’s easy to fix. I keep saying that everywhere I go, because it is still a major problem and is the most common method that the threat actors use for initial access, and we have fixes for them. So it’s time to get those things fixed.

Matt Tankersley
Yeah, I love it. That was exactly what I said. Lauren, without knowing it Bryson just endorsed episode three on complex password management, episode four on identity access management, episode eight on phishing protection, and then dark web monitoring. Guys, how are you gonna know when this is happening? Right. But we monitor that dark web for those credentials when they show up. So I had a feeling we might end up basically saying that everything we’ve been talking about is as critical as it’s ever been. But let’s keep the ball rolling in closing out the conversation.

Lauren Lev
Jay, with this warfare on the web, what should we in small businesses be doing to better protect ourselves during this time?

Jay Ryerse
So there’s too much to know. I mean, I’m guessing if we actually let Bryson really talk, and he shared what he has been doing for the last several months, the amount of data that his team and he actually looks at on a daily basis, like the tools that he uses ingests 56 billion events a day. And they’re having to sort through that information. So cybersecurity is a team sport. We need the researchers to give the tools, the knowledge and understanding of what’s happening, and that needs to be shared out to all of us, which is really where, you know, Matt, you and I spend a lot of our time; Working with companies like ConnectWise, working with consultants like Jim, to help understand what’s going on so we can help our clients make the best decision possible. And if you lose any one piece of that equation, you’re lacking the knowledge you need. But at the end of the day, if I’m a small business owner, I care about a small number of things in my business. Can I get to my financial systems? Can I pay my bills? Can I receive money? Can I pay my employees? Because if you can’t do that, you don’t have a business. So look closer at the security on those things. Look at your business line tools, you know, what do you do for a living? Now, if you’re a doctor, it’s your medical data and the work that you do for patients. If you’re a dentist, it’s their health records. If you’re a lawyer, it’s your client. Look at the data that makes your business work, and then look at the controls around how those things are secured. And the best way to do all of this is to start with an assessment. Again, just have somebody look in, take a view, who has access to the researchers, the teams doing all this work, and bring it back and say, okay, these six things could cause you harm. Let’s go tackle those six things. And you’re going to get back to MFA password hygiene and some of the tools that we talked about. But if you don’t know why those tools matter, then you’ve got to have the assessment to help identify what the risk is to your business. And it’s not as hard as we make it. And it’s not as scary as we make it. And I think that’s probably important to keep in mind too.

Lauren Lev
Quoting TechOnPurposes founder and CEO, Matt Tankersley: You can’t know where you’re going if you don’t know where you are, which is why we have our cybersecurity risk assessment, which you can sign up for at WhosInYour.Cloud. Thank you for queuing that up for me, Jay, it’s perfect.

Matt Tankersley
Yeah. And for clarity, and all the right reasons, right? It is ConnectWise that empowers us with that technology, guys, to deliver you these reasonable to free risk assessments. So definitely take advantage of that. And for those that didn’t hear it already, we created one through 21, and Jay, one of the things that Lauren and I realized is that we’re trying to tell you about the 21 so that you’ll get a risk assessment. And what we realize is the risk assessment is the most important part. We should have made that number one, we put the cart before the horse a little bit, so we’re gonna we’re gonna shuffle that around a little bit.

Jay Ryerse
Oh, turn your paper upside down. Yeah, start at 21 and work your way up to one. So you know, you need to assess though, that’s very important.

Matt Tankersley
Yeah, thanks for the great tools that you guys give us. You guys are one of our most important critical partners in all that we do. And so, Jim sounds like you’ve got final words on Russia, Ukraine and motivating viewers to take this whole cybersecurity topic seriously. Don’t wait.

Jim Bowers
I think Bryson nailed it. I think we overcomplicate this at the end of the day. We’re the weakest link in this whole piece and I can’t stress enough I’ve said this before, Matt on some of your episodes. Employee awareness, cybersecurity awareness and training and phishing should be part of the culture, shouldn’t be something done every month. If we never click it, if we never open it, we never go to the malicious site, none of this goes anywhere, right? So I can’t stress enough, continue with the employee education and phishing, make it an everyday part of your culture of the organization, and then the other TOP21 layers are critical components within protecting organizations. And as we continue with these environments, as we continue with chaos, threat actors love chaos and make their phishing emails a lot better, a lot more realistic. They play off the emotions of humans. When we drive them and base decisions off of emotions they are typically not the best decisions we make at that time. So having this relevant content enables them to make your business very insecure. So keep us protected. And, you know, I’m gonna have to come back up to the deep fake, because I am going to throw this in there at you, Matt. That’s the next big phishing I think is a deep fake. And I’ll be glad to share that with the team before we end, because it’s a good one, I think.

Matt Tankersley
Absolutely. So look, guys, here’s the summary for our viewers, right? We’ve been telling you from day one, this is not an option. Right? And because you want to do what you do all day, every day, you’d love to not think about any of this stuff, but the reality is it takes the risk vectors are so many they’re coming at you whether you want them or not. The Russia Ukraine thing is only advancing and escalating. And what I heard some of today is that there’s an increased collaboration that is possible and likely already happening between nations and criminal organizations. This stuff isn’t going to slow down guys. Get on top of your security practices, reach out to a service provider, like tech on purpose, or whoever’s in your backyard. Take these practices. Really, if you want to know how to start, go look at the TOP21 because we broke it down for your network priority.

Lauren Lev
Thank you for joining us for our special episode on Russia’s Impact on Global Cybersecurity. We hope you took away a lot from today’s episode, but most importantly, learned more about how to protect yourself in this ever increasing threat landscape. We’ve said it before and we’ll say it again. It’s not a matter of if, but when you and your business will face a malicious cybersecurity attack. Next week, we resume our regularly scheduled “Who’s In Your Cloud?” vlog series with episode 13 on network security. Remember to watch, listen, like and subscribe. Catch up on all of our episodes on LinkedIn, YouTube, Facebook, and Spotify. And get episodes delivered straight to your inbox by signing up at TechOnPurpose.net/blog. And finally, I will close this out with the biggest takeaway of today is sign up for our free cybersecurity risk assessment at WhosInYour.Cloud.

Ready for your free cybersecurity survey?

Discover potential vulnerabilities for your business and get a copy of our #TOPcyber21 Best Security Practices to help get you started on the road to #secure, reliable, trusted technology! Subscribe to our blog to get episodes of “Who’s In Your Cloud?” delivered direct to your inbox weekly.

Claim Your Free Cybersecurity Sruvey
Protecting your Blindside. Your Team is Your 1st Line of Defense

Protecting your Blindside. Your Team is Your 1st Line of Defense

Cyberattacks are on the rise, with phishing, ransomware, and social engineering attacks becoming more prevalent and harder to detect. A recent report from the Anti-Phishing Working Group (APWG) shows a significant increase in phishing attacks, with attackers becoming more sophisticated in their tactics.

View Next

Diagram showing how Texas cybersecurity law applies to every business, with two outcome paths — documented before a breach leads to safe harbor, documented after leads to full legal exposure

Texas Cybersecurity Law: What Every Business Must Know

⏱ 6 min readKey Takeaways Texas cybersecurity law already requires every business, regardless of size, to protect sensitive personal information and report breaches within 60 days of discovery. SB 2610 offers a safe harbor from punitive damages — but only if you can...
CVE dashboard showing NIST's "Not Scheduled" status replacing CVSS scores — patch prioritization without a score

NIST Just Derailed Patch Prioritization — Here’s Your Fix

⏱ 3 min readKey Takeaways NIST stopped automatic CVSS scoring for most CVEs on April 15 — the patch prioritization signal most organizations relied on just changed permanently. Only CVEs on CISA's KEV list, federal software, and EO 14028 critical software receive...
AI-Enabled Device Code Phishing — TechOnPurpose Identity & Access Management MFA Bypass Prevention

AI-Enabled Device Code Phishing Is Bypassing MFA — What Your Microsoft 365 Users Are Up Against

⏱ 4 min readKey Takeaways Device code phishing abuses a legitimate Microsoft OAuth flow — no passwords stolen, no MFA prompt triggered, full M365 access granted. AI-generated lures are now role-specific and hyper-personalized — standard phishing training won't catch...
Chrome Zero-Day Patch — TechOnPurpose TC21-05 Endpoint Patch Management Urgency

Chrome Zero Day Patch: Update Now

⏱ 4 min readKey Takeaways This chrome zero day patch isn’t routine maintenance — it covers two vulnerabilities already being weaponized. CVE-2026-5289 scored a 9.6 CVSS — a full sandbox escape. If exploited, an attacker owns the endpoint. CISA added CVE-2026-5281 to...
Russian CTRL Toolkit remote desktop hijacking — TechOnPurpose TC21-15 secure remote access defense

Russian Malware CTRL: Remote Desktop Hijacking Undetected

⏱ 4 min readKey Takeaways Newly disclosed Russian remote access toolkit called CTRL is enabling remote desktop hijacking attacks that bypass all known threat intelligence platforms — including VirusTotal CTRL is a newly disclosed Russian-origin remote access toolkit...
Old vulnerabilities cyber risk — TechOnPurpose patch management defense-in-depth

#CYBERinsanity: The Vulnerabilities Attacking You Today Were Published a Decade Ago

⏱ 5 min readKey Takeaways 32% of the most active exploits are old vulnerabilities, more than ten years old — patches exist, they're just not being applied. Attackers start with the low-hanging fruit: automated scans for known, unpatched flaws before deploying anything...
Defense in depth strategy — TechOnPurpose TOPCYBER21 cybersecurity framework protects your organization from vulnerability exploits

Why Patching Alone Won’t Stop 40% of Cyberattacks

⏱ 4 min readKey Takeaways A defense in depth strategy is no longer optional — it's the only architecture that holds when patching alone fails. Nearly 40% of all intrusions in Q4 2025 were caused by exploited vulnerabilities — not phishing, not credential theft. Some...
2026 National Cyber Strategy Blog Post image

2026 National Cybersecurity Strategy: What It Means for You

⏱ 5 min readKey Takeaways The White House's 2026 national cybersecurity strategy introduces six strategic pillars — the clearest federal signal yet that passive cyber defense is no longer acceptable. All six pillars align directly to the TOPCYBER21™ framework — if...
TechOnPurpose achieves MSSP Alert's prestigious 2025 Top 250 Managed Security Service Providers (MSSPs) list, ranking #159 globally—a significant jump of 32 positions from last year's #191.

TechOnPurpose Named to MSSP Alert’s 2025 List of Top 250 MSSPs – Climbs 32 Spots Year-Over-Year

TechOnPurpose is proud to announce its inclusion in MSSP Alert's prestigious 2025 Top 250 Managed Security Service Providers (MSSPs) list, ranking #159 globally - a significant jump of 32 positions from last year's #191. This marks the second consecutive year...
#STOPtheCYBERinsanity image - Is Pen Testing a Dollars-Before-Defense Mistake

#CYBERinsanity: When Pen Testing Becomes a Dollars-Before-Defense Mistake

The Fallacy of Pen Testing as a Priority in Cybersecurity If you’ve been following our STOP the #CYBERinsanity series, you already know this uncomfortable truth: Most cybersecurity failures aren’t caused by brilliant hackers or exotic zero-day exploits. They’re caused...
en_US