Opens in a new tab
vmblog logo 2024 wht (updated)

Summer Cyberattacks Are Heating Up (Again): Cool Them Off with These Pre-Vacation Security Tips

Share: 

David Marshall | Published: July 24, 2024

By Corey Nachreiner, CSO, WatchGuard Technologies

For the IT and security professionals among us setting out on vacation during the back-half of a summer (barring another flight-grounding global IT outage, of course), you must not forget to account for what should be at the top of your pre-PTO checklist – bolstering your organization’s attack surface and solidifying a cybersecurity incident plan.

That’s because cybercriminals are counting on it. Throughout the summer months, security teams at organizations across the Northern Hemisphere are often short-handed during a time when most will take time off from the daily grind – CISOs included.

From AT&T, Ticketmaster and CDK Global, this summer – like many of the recent summers before it – has been red-hot cybercrime activity.

From the Los Angeles Unified School District ransomware attack over the 2022 Labor Day weekend, the massive MOVEit SQL injection vulnerability that dominated the 2023 Memorial Day weekend and later that summer, perhaps most notorious cyberattacks of them all, the REvil ransomware group’s breach of Kaseya on the eve of the July 4th holiday weekend that left scores of organizations vulnerable to supply-chain attacks. 

Taking these historical cybersecurity events into consideration should remind us of the critical necessity for organizations to bolster their security measures ahead of the summer months. Here are a handful of actionable tips for security leaders to keep their out-of-office plans on-track and thwart malicious actors’ attempts to gain access into your systems.

  • Enable MFA on Accounts & Devices: Integrating Multi-Factor Authentication (MFA) into your organization’s cybersecurity framework creates a formidable initial barrier against unauthorized network access. This strategy should be a top priority, considering a majority of breaches stem from successful spear-phishing attacks on staff members.

The infamous celebrity Twitter hack in July 2020, for instance, was found to be the result of a spear-phishing attack on Twitter employees. This could have likely been prevented with MFA’s multifaceted verification process that significantly enhances security by requiring passwords in addition to actions like generating temporary access codes or the user providing biometric verification. Ideally, MFA should have been part of your security controls long before this summer and if not, make it your top priority before going out-of-office.

  • Create (or Update) Cyber Incident Response Plans: Creating robust cybersecurity contingency plans is a crucial practice for effectively responding to cyber threats and minimizing their potential impact on the organization. This plan, at a minimum, should establish clear communication channels and response procedures for security incidents such as malware or ransomware attacks, the detection of a previous data breach or attempted distributed denial-of-service attacks.

Case in-point: In August 2021, the IT director for the Jackson Hospital in Florida,  discovered that ransomware had infected the hospital’s software used for patient charting, which was maintained by a third-party. Rather than wait for assistance from the software vendor, the IT Director immediately enacted his ‘downtime procedures’ contingency plan designed to respond to such events and quickly shut the hospital’s systems, which was key in successfully fending off the attack.

Taking a lesson from this example, your plan should ensure both internal teams and any third-party that is responsible for managing or maintaining your business-critical software and systems are properly staffed, scheduled and provided with the necessary access to the platforms or solutions in your security stack. If your vacation will take you completely off the grid for longer than a few days, take extra time beforehand to align these plans with your organization’s legal and executive teams. This ensures that responsibilities for the absolute worst-case scenarios are covered,  – such as complying with data breach notification laws – even if you are unreachable. 

  • Use Strong Passwords & Implement a Password Manager: First, it is crucial to drive an organization-wide effort aimed at eliminating users’ passwords that are easy to guess or have been leaked on the Dark Web through a previous data breach. Then, require each staff member to use stronger, more effective passwords – preferably at least 16 random characters or in the form of passphrases. Better yet, rather than put your front line of defense in the hands of busy and sometimes, digitally-gullible employees, consider adopting an enterprise-level password manager or Identity Access Management solution to streamline their login process without compromising on security. By rolling out one of these solutions across the business, users only need to remember one password to access all the systems and software they need, while security teams benefit from minimizing the risk of a malicious actor obtaining active credentials. 
  • Consider Working with an MSP: Partnering with a trusted Managed Service Provider (MSP) or Managed Security Services Provider (MSSP) – particularly those offering around-the-clock monitoring and maintenance – significant eases the burden on internal IT and security teams and ensure systems continue running safely and smoothly. Working with a reputable MSP or MSSP, especially organizations with leaner internal security teams, often results in fewer business disruptions and a vigilant partner in monitoring for malicious activity. According to CompTIA’s 2024 MSP Outlook, companies working with an MSP reduced their annual IT costs up to25 percent.

By incorporating these proactive measures into your pre-summer vacation checklist, IT and security leaders will not only foster a culture of cyber agility, resilience and readiness, but also help give themselves peace of mind during what has become the most dangerous time of year for falling victim to cyberattacks.

##

ABOUT THE AUTHOR

Corey Nachreiner 

Corey Nachreiner is the Chief Security Officer at WatchGuard Technologies. Nachreiner has operated at the frontline of cyber security for 16 years, and for nearly a decade has been evaluating and making accurate predictions about information security trends. He is also a regular contributor to leading publications including CNET, Dark Reading, eWeek, Help Net Security, Information Week, and Infosecurity, and delivers WatchGuard’s “Daily Security Byte” video on Facebook.