Complete Webinar Transcript:
00:00
Yeah, thank you, Michel, for that nice introduction. My name is Stefan Fries. I have 10 years in the IT and cybersecurity. I work today as a sales engineer and cybersecurity expert at Viber Security Group, and I’ve been here for five years, and I located in Copenhagen, Denmark.
00:17
My daily routine is that I analyze the current and new threats in and around EMEA, both threats that we receive in Viber, and we analyze that, but also threats being worked on currently on the dark web by attackers.
00:30
This knowledge is leveraged by thousands of customers and partners around the world to better understand and protect against these threats coming. And also, one of the main contacts for Denmark’s radio, where I’m often asked to participate in radio programs and help with giving expert insight into current threats happening right now.
00:48
And I’ve been expert on several TV2 news, airings, and articles like, for example, last year when 7-11 were hit by a ransomware attack. I’m fairly active on LinkedIn and Twitter, and I encourage you to link up and follow me.
01:02
If you want to prefer to give me a call or email afterwards, know more about Viber, let me know. I am here for you guys. So, here we are on the verge of having to deal with yet another legislation.
01:18
And what is NIS2? And why do they keep putting out new laws and legislation that keeps making life and job harder for the everyday IT manager? In this session, we’re going to talk about exactly that.
01:32
Deep diving into the reason why NIS2 is a big deal, why it is not the last legislation to come, and why it is happening right now, and how it can become an extremely useful guideline for everyone, also those not required to do any of the things NIS2 is requiring companies to do.
01:50
And I will speak about fresh and general, give you crucial and critical insight into how serious the threat are right now, and how the world is adapting to that. And in the end, I will give you some advisement on how to not only check off the boxes for NIS2, but also provide you with solutions that you can manage, and make sure that you’re protected against these type of threats.
02:12
But first, let’s go down and lay some down on the groundwork, so we need to So the first thing is that the aim to do is it is to improve security and resilience of essential services and critical infrastructure within European Union.
02:31
It’s to harmonize cybersecurity measures across the euro and to reduce risk of cyber incidents that may impact essential services and cause widespread disruption. Ensuring the protection of personal data and privacy of European citizens and to help European companies to do so.
02:52
It is to establishing a framework for cooperation and information sharing among European member states and relevant stakeholders in the event of a cyber incident. And enhance the overall cybersecurity posture of the EU and strengthening the position in the global cybersecurity landscape.
03:14
And that all sounds good and fine. What does it really mean and what does it cover? Let’s break it down into two sectors. So we have NIS1, which came a few years back.
03:27
NIS1 covers, for example, the healthcare sector, the banking sector and the energy sector. NIS2 is an expansion of NIS1 and includes industries within food services and or production providers of public accessible electronic communication networks and public administration among others.
03:47
You can see over you right here. And that’s simple enough, right? Or maybe it’s too simplistic. But how do you find what is covered under, let’s say, transportation and food? Good question.
04:00
Let’s deep dive into that. So NIS2, let’s break it down. Let’s start with the energy sector. So what does that mean? So that means everyone that do business around electricity, central heating and cooling, oil, natural gas and hydrogen.
04:20
Everything in between here, if you have any kind of business in this sector, you are required by NIS2 to follow the certain guidelines. Phew, that’s a lot. So let’s go into transport.
04:32
So everything that has anything to do with air transportation, rail transportation, water transportation or railroad transportation. It’s also covered. Then we have the banking companies and financial market infrastructures, healthcare sectors, water and wastewater, digital infrastructure, management of ICT services, public administration and space.
04:55
Well, not the universe. That’s a little bit too broad and ambitious. But we are talking about the space industry, of course. So everything has to do with anything to do with space, basically.
05:05
And of course, everyone that supplies to this kind of, everyone inside this one. So if you’re supplying anything to the public administration on space, you’re also required to follow NIS2 directive. That also…
05:20
Actually, it’s the case if you’re outside of Europe, so it’s not only European companies, it’s also companies in India, China, Russia, or the United States. So timeline-wise, what is actually the journey here?
05:36
So very early on, in 2015, the global parliament decided to adapt the first NIS directive, which we just spoke about. And along the way, GDPR came as well. It came in May 2018, which was a measure to make sure that personal data were kept secure and you had some rights over your own personal details.
05:59
And along the way, they started having these kind of what to do next kind of sessions. And in 2019, the Europa Commission published a report that says the NIS2 directive needed harmonizing and better cooperation.
06:14
And they kind of said, like, you know, we need to have better protection, we need to have better requirements, it’s not sufficient for the future. So in December 2020, they started to talk about NIS2, which extends the scope of the previous NIS initiative to additional sectors and titles and strength of the cybersecurity requirements overall in Europe.
06:36
And in 2022, the legal content for these two was published by a real parliament for everyone to read through. And yeah, well Denmark, for at least in 2024, we are required to have that international law and it will be enforced.
06:50
So we have not a lot of time to go on now. And if you look closely on this line, there’s a lot of words here, but what you kind of see is kind of the direction.
07:00
You start with NIS2, kind of sets the direction, GDPR comes along and now and it’s not only that. It’s not only in Europe where they’re going nuts with this new legislation. It is happening all over the world and it’s happening right now.
07:14
And this is the direction that is set and this is the direction we are going to go on in the future. Oh, wrong side. So for example, cyber threats are increasing threats and the entire world is right now making new laws, making new legislation to make sure we deal with that in a timely matter.
07:35
For example, in America, they have the Cybersecurity Disclosure Act. Both India and Australia has something coming or has something already. We have spoken about NIS2. Everyone knows NIS2 is coming in Europe.
07:47
On the back of NIS2, something called Cyber Resilience Act is also coming. And not to forget that the UN also is talking about a cybercrime treaty to better prosecute cybercriminals across borders.
08:01
So it is definitely something that NIS2 tends to. You might say that the internet is a little bit of a wild west. So we have caught a lot of ground of NIS2 and how the trend is not only is isolating to Europe now, the entire world is starting to catch up.
08:17
So let’s have a look at the real world observation and why this is happening. So if you look at the facts, we saw last year 1,093 incidents, 307 which confirmed data closure.
08:33
That is a lot. 97% of attacks begin with an email. That’s also a lot. And one thing that’s also very interesting to see is that the motives is almost 80% of the time is financially driven.
08:49
And if you also look into consideration, what kind of data are they compromising? What kind of data are they going for? 86% is either internal documents or secret documents that should never leave your systems.
09:02
So the attackers are purposely attacking documents that you know you don’t want to have out and they want for money for it. So that’s also why ransomware is an increasing threat to threat right now.
09:16
And if you look at the graph on the right, I mapped out 30 colors we want to focus on, the blue, purple, and the yellow. So let’s start with the blue one first, social engineering.
09:27
This is easily available by awareness training of employees, making them aware of threats and pattern from social engineering attacks. We saw a spike in COVID-19 pandemic when the entire world were forced shut down and employees were forced to work from home.
09:46
And the attackers clearly saw a potential here. It was proven quite effectively to actually attack employees who are now working from home isolated. And it’s proven actually that no company really took notice of this.
10:02
No one has really thought about really empowering the employees with basic tools like understanding how phishing mills went and how to prevent these kind of things. And you can see on the same line that the attackers actually took so much notice of this, they actually stopped looking for, didn’t stop, but they downsized their focus on vulnerabilities in programs, which is the yellow one, basic web application attacks covering anything from vulnerabilities within software to gain access to the system itself.
10:34
When you look at this one, there’s also one thing that comes to mind is that you see how quickly things shift. This proves that attackers are extremely quickly and well-prepared to adapt to a new world order, like we saw with Code19.
10:51
Instantaneously, almost, they shifted their focus from attack and internal programs that may run on your computer or in the office to attack the person working from home. And this is exactly why when we speak about cybersecurity, it’s never a good idea to put all eggs in one basket.
11:09
For example, put everything at Google or everything at Microsoft. Ideally, you want to partner up with someone to provide additional security on top of these. The last line, system intrusion, the purple one, is basically covering over attack like ransomware attack where files are taken partially or entirely controlled systems.
11:27
And interesting enough, when you see this one from 2017 to 2021, you see this is an increasing tent. It is something that keeps coming up. It’s an increasing trend that just keeps being more and more used.
11:40
And in 2022, I can tell you that we have seen substantial amount of ransomware attacks in 2022. And even in 2023, we have seen an increase in attacks. So this is something we need to save in the next 5-10 years to come.
11:56
Let’s talk about graphs. That’s interesting enough. Let’s talk about numbers. 96% of organizations were targeted by an email-related phishing attempt in 2022. When you’re compromised, out all compromises that were 12% of hackers had a full access to the internal systems for more than 12 months before activating ransomware, rendering most backups useless.
12:25
75% of the data from worldwide has been attacked by ransomware last year. That is an increase in 61% since 2021. 64% pay to the ransom, yet 4 out of 10 fail to recolor data.
12:38
That is also a scaring amount. And here comes another one. 66% of IT management said they were fully aware of cyber risk. A tester assured that that was not really the case.
12:50
And then another thing, 93% of organizations said that using AI and machine loading technology significantly improve the technology. That kind of stays without reason because you can see that with AI and Machine Learning chances of catching serial threats that just been developed right now drastically increases from 59% to 95.9%.
13:14
That is a big increase in actually leveraging a full portfolio of good and advanced product. The billing breach is never cheap, we can tell that. But how expensive is it really? So the question you need to answer yourself is, and actually ask yourself and answer yourself, is is the cost of doing business or is it the cost of doing bad business?
13:37
With being breached, you have to consider what you need to pay. So, you have to pay for all time for employees. Once they need to roll out that nasty ransomware that’s now playing around in the servers and computers, have to pay for consultants.
13:52
Maybe you want to replace equipment. You have downside business. Maybe you come to a complete stop, like 7-Eleven did last year, and you have substantial reputation damage. And that also may consider you may need to hire PR and marketing personnel to repair that reputation.
14:08
Otherwise, you’re just going to keep losing money. And as I just showed, 12% of all ransomware attacks and breaches were inside the system for more than a year. That’s a scary thought.
14:19
So, let’s look at some other scary thoughts. Average time to identify and contain a data breach is 277 days. That is almost a year. That’s some good news though. It is a 3.5% increase improvement since 2021, which is pretty nice.
14:39
According to the IBM report, a ransomware attack isn’t cheap, and the average cost between, like depending on where you are, $2 million and $5 million, just by adding all the cost up of paying over time to the employees, paying consultants, et cetera, et cetera.
14:57
So, it is not cheap. So, looking over the five years, we have seen a shift in recent time of what attack, attack, detect. We have seen the static primary attacking enterprises as a main target of these attacks.
15:13
And now we’re seeing they are starting to shift their focus to smaller companies. And that kind of makes sense because when you want to test out and make a template for your ransomware and your attack, you want to go against the best.
15:26
And going against enterprise companies, they have substantial, significant, higher cybersecurity budget, meaning they can afford to have more personnel surveying the machines, having better solutions, more expensive solution, covering the solutions. So, if you are able to build a template that’s able to almost breach one of the big ones, you can automate this and hit everyone.
15:52
You can hit all the smaller companies that doesn’t have the counter manpower, doesn’t have the counter budgeting. And this is why we’re seeing an increase in cybersecurity as well, because this shift now focusing away from cybersecurity on the enterprises to shift on the lack of cybersecurity on the mid-size and small company markets.
16:11
So, and it’s far more devastating because a bigger company can survive on ransomware attack. We saw a few years ago that Ape & Miller Mask actually also were hit quite nicely. They’re still shipping around in their container ship.
16:25
I’m not so sure that a smaller company would be able to, in the same kind of way, survive. It will be a devastating impact for sure. So, what can you do about it?
16:35
Well, there’s kind of a lot of things you can do. At Vyral, we have a few solutions I wanna cover you with and why they may be something you need to consider as well, at least have a discussion about.
16:46
So, we have one of the areas we have this endpoint. We have an award-winning EDR system that is proven an effective enemy against ransomware attacks. It comes with patch management, vulnerability scanning, better scan control, and it is very good at detecting if something’s trying to embed within the browser, within the URL.
17:09
And if even Ransom is able to execute a machine, the machine will be isolated and you will be able to, as an IT manager or an IT assistant, be able to remove power shelling into this machine and clean it up without the need of having to unplug every single machine in the organization, which is extremely useful.
17:30
Another side, we have email. Another next-generation software provider solution. Basically, what it has is it has a brand new link isolation, which is able to scan elements on the websites, which has already proven it’s worth.
17:49
We had a few years ago, an incident where one customer of ours reached out to us because there were five colleagues trying to go into a Danish newspaper and one of them couldn’t go in there.
18:02
And we tried, first of all, there was a mistake. There was an error going on. And it turned out that one of the codes, like one of the advertisements, had a malicious code behind it.
18:13
And it turned out that almost all newspapers and almost all news sites that use this kind of advertisement has a third party managing them. So they had no control of what actually went better than this website.
18:25
And it turned out that four of the colleagues went to a website that didn’t have that malicious code in the advertisement. The last one did, however, and that proved to be extremely valuable for them because our solution were able to stop that.
18:40
With link isolation, we’re able to crawl through the website pages that’s underlying there and scan every single element. And put that inside of attachment sandboxing, where you basically take the attachment, whatever it’s on, it could be a document, it could be an Excel sheet, PDF file, or even an encrypted ZIP file.
19:01
What we do is we take that little file, we shove it into a VM machine, Windows machine, it could be, and we just later play around, have fun. And we monitor it and see what actually goes around and what is happening.
19:13
I mean, we provide you with that information, of course. So, and everything is put into the Federal Explorer and the thing like that. So you will be able to kind of see And speaking about threats, we have a very, very big threat network, and I just spoke about sandboxing and link isolation.
19:33
So we have this kind of dynamic forensic analysis sandbox, which we are leveraging both on files and links, both in our EDR solution and our ATP solution on the email side, making sure that when you encounter, it’s not a question about if you encounter.
19:49
A serial threat, we are able to detect to stop that. I’m fairly confident that this is something you would be able to see the benefit in and actually leveraging in a better way.
20:01
We’ve seen other customers having the same kind of issues with serial threats coming in and using a solution and being happy. So it’s something to consider. Last but not least, we have the training element, which go by already, low hanging fruit.
20:14
Providing training to employees is your first god of defense. But that also comes through explore and link analysis, which is in the advanced fresh protection where you can go deep diving in, seeing what is going on, understanding which threat is happening right now.
20:31
Excellent tool and providing valuable information to you in terms of understanding what do you need to do now? What is now attacking you right now? Is it ransomware? Is it malware? What is it that hitting you right now?
20:45
But how can that actually combine with this to help you? So the purpose you solve is like, that’s something here, basically. But right now, by partnering with Wyber, you can have more than half of these two requirements just covered.
21:03
So take the first one, cybersecurity training and education for employees. Is it done? Cybersecurity set product, security awareness training. Our plans for operation, doing the business a after security evidence, that backup, we have archiving.
21:17
So that’s good as well. Next one is advanced threat protection. We have a practice of elementary computer hygiene, that’s EDR. You want to have something to scan that. And what EDR provides you is a capable opponent against ransomware.
21:36
So that’s definitely also a plus to remember. When it comes to encryption, we have in the Nordics, we have secure mail. And in the UK, we have encryption. And rest of all, we have something called encryption.
21:48
And when it comes to have security procedures for employees with access to sensitive information, important data, for example, the secret data you want to have leaked, we have station, a brilliant tool that comes both for the OVA plugin and Outlook plugin.
22:03
Brilliant, just as it, you don’t need any other products to have it to work. And it’s proven very useful for bigger organizations, smaller organizations, banking, financial institution, companies that work with deeply sensitive information, it’s extremely valuable.
22:18
You can have a 42 weeks free trial right now by going to websites. So do that if you want. It’s brilliant. And if you partner up with us, only these need now needs to be addressed, like risk assessment, a plan to handle security events, and etc, etc.
22:34
The last one, although I needed to add this one in, because like, although we do offer a multifactor of vocational solutions, it also covers like you need to cover all of your bases, so all our solutions you have, you need to cover this as well.
22:47
So it kind of needs to be there because we are able to provide a solution that actually covers all of that for you. So that’s basically my kind of talk for the day.
23:02
That means we had the Q&A session, basically. Yes, so thanks, Stefan. That’s certainly a lot of information to take into consideration. Yes. If you’ve got any questions for Stefan at all, if you can please enter them into the questions tool in your webinar and we can answer as many of those as we’ve got available in the time left.
23:23
If you’ve got, if any questions come up that we don’t get time to answer, then Stefan and our product team can get back to anyone whose questions we don’t get to. So let’s see if the big questions coming in.
23:36
Not currently? Any burning questions about NIS2 that we can help? Okay, one question through Stefan. Someone has asked her, a current VIPA customer, what is the best thing for them to do now in terms of getting additional information about this too?
23:55
The next step would be to reach out to your account manager and speak to them about your current needs and your current solutions and ideally set up a meeting with me or one of my brilliant colleagues in Southernering to walk you through the solutions you have right now and what we offer and what would be a good fit for you.
24:15
Excellent, thank you. Another question in, how do I communicate to my business that we need to comply with NIS2 even though we are a US-based organization? It’s a very good question actually because when you are US-based sometimes organization cannot believe that this is a regional problem.
24:41
There’s plenty of law text on the euro parliament website that actually we will be able to get information from in terms of what is required and if you want you can reach out and I will help you identify where this is and how to position that internally for your leadership team but it’s something that definitely is a challenge we have seen previously but it is all accessible, publicly shown, so it is information you can gather yourself.
25:16
Another question is, I know you’ve probably talked through the deadlines already but when is the absolute deadline for implementing NIS2 and can I start now? I would say you should absolutely start now, rather than yesterday and then tomorrow.
25:33
Because even though you’re not obligated to follow these two, it still provides you with a guideline of what you should be doing and why this is important. The absolute deadline is in October 2024.
25:49
That is when they will start having consequences not being under these two requirements. Excellent. One more through. I come from a public school. How relevant is NIS 2 for us? Mainly on the purely legal level.
26:08
A public school, well public schools are under public administration so that is also something you need to consider. You need to, when you charge personal details like you know sensitive information, CPR numbers, personal security numbers, you are required by law to have these kind of things off that also includes to have a cybersecurity training for all employees so they can know what not to click on so these data that you have access to are not compromised or can be compromised by attackers who want to have it so you are also obligated under these two.
26:50
One final question I think we’ll get to today. Security Weather Training, is that provided by Vyper? It is provided by Vyper. We partnered up with our other company in the Vyper security group called Inspire eLearning.
27:07
They have currently the most award-winning content right now, which is also a very important thing because you don’t want to have content that makes employees fall asleep. It’s a very important thing that you partner up with someone who has content like Inspire eLearning, like Vyper provides, because you want them to learn from it, not sleep through it.
27:37
Any more questions from anybody else in the audience? I know that everybody in Europe is probably desperate to head out for the Easter holidays, so, yeah. No, no more questions. So it looks like we will wrap up the session for today.
27:59
Again, thank you so much for taking time today to learn more about Viper and NIS2. If you’d like any more information at all, as Stefan said, please reach out to your Viper rep.
28:08
Or if you don’t know who that Viper rep is or you’re new to Viper, then please send us an email at viper at marketing at viper.com and we will be sure to get that to you.
28:18
Also, remember there will be a really quick survey to take as you leave the session just to help us to improve our webinar programme. Again, thank you so much for your time today and we hope you enjoyed the rest of your day or your evening. Thank you guys.