I’ll start this Cybersecurity Awareness Month with a story worth being, well, aware of. A medical practice we know lost a laptop in about the strangest way anyone could lose one. A long-tenured administrator, the kind of employee who gets trusted with patient records and payroll, took his work machine home for a weekend. A few days later a family member called the office to say he had perished in a car accident. The practice grieved. Eventually, somebody asked about the laptop, and the family said they couldn’t find it.
The device held protected health information, which put the practice a short distance from a HIPAA breach report and the steep penalties attached to it. Their IT provider had recently deployed our software, so they went looking and found the laptop online. They activated the webcam and saw the administrator alive, parked in a trailer in the desert, watching YouTube. He had faked his death, kept the laptop and taken an RV along with it. Police found him eventually. Stranger than fiction (perhaps other than if in a Breaking Bad episode), yes.
I bring this out during Cybersecurity Awareness Month because of what it says about the shape of the security risk most organizations are carrying. Every alarm that should have fired here didn’t, because nothing looked wrong. The login was real, and the permissions were correct. Encryption was doing precisely what encryption does, which was nothing at all, since the person opening the files was the person authorized to open them.
The credential is the new perimeter (and it’s porous)
Awareness month messaging tends to center on keeping attackers out. Spot the phishing email! Use a password manager! Turn on MFA! All of it is worth doing, of course, but it also describes a threat model where the danger is outside and the inside is safe, and that model alone is incongruent to reality.
Many incidents I hear about now involve someone who got in with a working login. A contractor’s password turns up for sale on a forum, or a laptop gets left unlocked in the back seat of an Uber. An employee gives two weeks’ notice and still has a company machine during the return window. None of these produce an alert, because to the system they still look normal. It’s an uncomfortable realization, since the standard answer to data risk has been encryption, and encryption assumes the wrong adversary. Full-disk encryption protects a powered-off device from a thief, but it does very little against a legitimate session. An attacker who reaches a PC remotely through the network sees files in decrypted form, same as the user would.
Two controls that actually hold up
Businesses that weather these situations tend to have layered encryption managed above the operating system, meaning protection that travels with the data instead of stopping at the disk. Files stay unreadable after they’ve left the building. That matters more every year, because ransomware crews have largely shifted from locking data up to stealing it and threatening to publish (Ransomware 2.0, if you will). Backups solve the first problem, and stolen files nobody can decrypt are worth considerably less (like $0.00) on the second.
The other is the ability to revoke access to data on a device you no longer physically control. It’s the control that saved the medical practice. Their provider quarantined the machine and cut access to the sensitive files while the laptop was several hundred miles away in somebody’s trailer. The same capability handles the boring version of the problem, which is far more common. A departing employee’s access ends the day their employment does, on the hardware itself, whether or not the laptop ever comes back.
There’s a second half to that story. Because those controls had been running continuously rather than being checked once a year, the practice could produce a report showing which protections were in force on that laptop and that nobody had opened the sensitive files after the administrator’s access was cut. That documentation is what kept the incident from becoming a reportable breach. HIPAA asks organizations to demonstrate a low probability that protected information was compromised, and demonstrating anything requires evidence you were already collecting before the trouble started.
Frameworks like HIPAA, CMMC and NIST 800-171 have been describing this for years in the language of least-privilege access and breach risk assessment. Plenty of organizations read those requirements as paperwork. They’re a fairly precise description of what goes wrong when a trusted login stops being trustworthy and nobody can do anything about it from a distance.
Worth asking this month
Here’s a question to put in front of your team during October. If a laptop walked out the door tomorrow with a valid login on it, how long would it take to cut that machine off from anything sensitive, and would you need the device in hand to do it?
If the answer involves waiting for hardware to come back, or a ticket, or a conversation with a vendor, you have the practice’s problem without the practice’s luck. Most organizations never find out where their data went. That one got an answer because somebody could still reach the device and watch it happening.
##
ABOUT THE AUTHOR

Cam Roberson is Vice President at Beachhead Solutions, whose cloud-managed platform provides device encryption, security policy enforcement and remote data access control for compliance with CMMC, HIPAA, PCI DSS, ISO 27001 and other mandates. He began his career in product management at Apple and later built and ran one of the largest advertising agencies by revenue in the San Francisco Bay Area.






