Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Louisiana Declares Cybersecurity State of Emergency
Newest First  |  Oldest First  |  Threaded View
tdsan
tdsan,
User Rank: Ninja
7/25/2019 | 9:48:39 PM
Sounds like the state did not think enough of the schools to address this impending problem

"The state was made aware of a malware attack on a few north Louisiana school systems and we have been coordinating a response ever since," Gov. Edwards said. "This is exactly why we established the Cyber Security Commission, focused on preparing for, responding to and preventing cybersecurity attacks, and we are well-positioned to assist local governments as they battle this current threat."

Since this 2017 commission was created and now it is 2019, why didn't the government institute a proxy and email filtering system that identifies the type of traffic going in and out of their network? The traffic should go to a SOC or central distribution center, from there, traffic should be filtered in and out of the network using NGFW, Proxies and NAC devices. If they centralized this traffic, then the threat would have been identified ahead of time due to well-trained professionals reviewing those external threats or so you hope.



"While there are problems with system connectivity, we have no reason to believe there is any public safety issue. We also have no indication that there was any unauthorized access of sensitive or private information. We also believe that full connectivity will be restored in the near future."

According to a news release from the governor's office, the declaration makes available state resources and allows for assistance from cybersecurity experts from the Louisiana National Guard, Louisiana State Police, the Office of Technology Services and others to assist local governments in responding to and preventing future data loss. The state is in contact with parish school systems and governments across the state to assess further areas that may be at risk. 

The Governor's Office of Homeland Security and Emergency Preparedness (GOHSEP) has activated its Crisis Action Team and also the Emergency Services Function-17 to coordinate the response to this cybersecurity incident. So far, the state is coordinating with the FBI, state agencies and higher education partners.

This is an interesting comment if the schools think they have not been compromised, then why is the FBI in the building, obviously, there is something because they initiated a "State of Emergency", that means there is a fire (metaphorically speaking).

In 2017, Gov. Edwards established the Louisiana Cybersecurity Commission which is a statewide partnership comprised of key stakeholders, subject matter experts, and cybersecurity professionals from Louisiana's public sector, private industry, academia, and law enforcement.

Also, if Lousiana put together a "Cybersecurity Commission" in 2017, why are we having this discussion because they should have controls in place or at least a framework to address some of these issues (where is the assessment, compliance, and risk management framework)? Also, why didn't the schools have an external group monitoring traffic going in and out of the network (i.e. SOC).

The feds have a forensics division and analysts that will be able to address where the hack originated from, they just have to determine the culprit, where it originated and gather evidence to make their indictment stick.

Only time will tell.

T


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Incorporating a Prevention Mindset into Threat Detection and Response
Threat detection and response systems, by definition, are reactive because they have to wait for damage to be done before finding the attack. With a prevention-mindset, security teams can proactively anticipate the attacker's next move, rather than reacting to specific threats or trying to detect the latest techniques in real-time. The report covers areas enterprises should focus on: What positive response looks like. Improving security hygiene. Combining preventive actions with red team efforts.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-25878
PUBLISHED: 2022-05-27
The package protobufjs before 6.11.3 are vulnerable to Prototype Pollution which can allow an attacker to add/modify properties of the Object.prototype. This vulnerability can occur in multiple ways: 1. by providing untrusted user input to util.setProperty or to ReflectionObject.setParsedOption ...
CVE-2021-27780
PUBLISHED: 2022-05-27
The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.
CVE-2021-27781
PUBLISHED: 2022-05-27
The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.
CVE-2022-1897
PUBLISHED: 2022-05-27
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
CVE-2022-20666
PUBLISHED: 2022-05-27
Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient va...