All posts by kristie@shejumpsintocyber.com

Why risk management IS important to an organization

Image by <a href="https://pixabay.com/users/geralt-9301/?utm_source=link-attribution&utm_medium=referral&utm_campaign=image&utm_content=909710">Gerd Altmann</a> from <a href="https://pixabay.com/?utm_source=link-attribution&utm_medium=referral&utm_campaign=image&utm_content=909710">Pixabay</a>

Without the management of risk, business functions become in jeopardy. Especially when those functions have been identified as critical to achieving the strategic mission of the organization.  Ensuring that financial data is backed up, for example, can keep a business functioning via maintaining sales data, paying its employees, and could be a component of a law that the organization must follow to stay in business. However, if the backup mechanism fails and there is no “Plan B,” the organization is in serious detriment. By knowing how business functions are prioritized, risk management activities can be implemented to protect them.

Within the video communications industry, Zoom was affected by a security breach in 2020. Hackers took advantage of the fact that more people were using the application during the early part of the pandemic and that the application itself had poor programming and security measures. They used a brute force-type of attack, called credential stuffing to gain access to login credentials, email addresses, and personal URLs of meetings of over 500,000 users. The harvested data was given away for free or sold on the dark web for a penny.

The hackers collected databases of usernames and passwords from a variety of attacks from 2013 through 2020. Then they wrote a “…configuration file for an application stress testing tool” (Winder, 2020). The configuration file aimed the stress tool at Zoom. To avoid being discovered as a DoS attack, the configuration file enabled multiple bots to carry out the attempted logins and also varied the time between login attempts to make the logins seem normal. All the password and usernames were then vetted to make sure they worked and collected into one database that was then sold in online forums on the dark web.

Ironically, Zoom’s mission statement is to “…make video communications frictionless” (Zoom, 2019). Unfortunately that has not been the case as the hackers. This incident resulted in privacy lawsuits backed up by California’s Consumer Privacy Act and a huge downturn in the value of its stock.

Network Security Design

 
SIMULATION PARAMETERS
The existing network is physically isolated from the internet and any other networks. It has the following components: 

  • 50 workstations 
  • 1 database server 
  • 1 application server 
  • 1 print server 
  • 1 file server 
  • multiple switches 

With the new network, the fictitious company wants to: 

  • Have a web-facing web server to host the company website 
  • Setup an in-house Microsoft Exchange Email server 
  • Setup a secure FTP server for external client access 
  • Give remote users VPN access to the LAN 
  • Provide a wireless connectivity option for internal laptops 
  • Have internet access to the workstations and laptops 

In order to achieve this, the new network will require the following additional components: 

  • 1 web server 
  • 1 email server 
  • 1 web-facing secure FTP server 
  • 1 vpn server 
  • 1 internal wireless switch 
  • 20 laptops to be connected via wireless switch 

PROBLEM
Create a new network design utilizing any additional switches, firewalls, or other security equipment might be needed to secure it. In addition, develop a network threat analysis strategy to identify any security threats and their possible countermeasures. 

SOLUTION