Criminal Actions and Motivations, the ROI of Cybercrime

Symantec just released its 2019 Internet Security Threat Report (ISTR). It is largely a comparison of malware trends and cybercriminal activity over the last 1-3 years. A quick look into the data reveals that many of the report’s findings are aimed at the end user or environments with a small IT footprint. Despite this, there are valuable insights can be taken from it about enterprise IT governance and IT risk modeling. This two-part series talks about the economic motivations of cybercriminals and how their actions change as a result. It then talks about how these should influence your IT risk modeling efforts.

The ISTR focuses on two types of cybercrime, that done by the average cybercriminal trying to monetize their efforts by simple means, and that done by the “targeted attack group” (economic and political espionage actors). The two have different motivations and levels of discipline, but they are largely working from the same toolbox. The first group often seems faceless and inscrutable. Representations that model the cybercriminal attack as a random event characterized only by the rate of attack can be used as a first approximation, but more insight can be derived by seeing them as economic actors. They attempt to obtain the most valuable cyber resources possible with the least possible investment. While the expected return varies from criminal to criminal, each has a minimum expected ROI required before they undertake a given attack. They are therefore not random forces of destruction, but, instead, are tractably predictable and influenceable. Factoring their reactive behavior into your allocation decisions and IT governance strategies makes those strategies and decisions even more effective.

Let’s look at three examples of cybercriminals as economic actors that are covered in the ISTR report. First case is about the correlation between the frequency of cryptojacking attacks and the price of monero, a common cryptocurrency that cryptojackers mine. As the value of the monero fell by a factor of seven over the course of a year, the total cryptojacking events rate fell by a factor of two (1). This is a clear case of cybercriminals having a distribution of acceptable ROIs for launching attacks. Incentives decreased, a smaller percentage of the criminals were willing to launch this sort of attack (the number of monero mined per hour was largely a constant). Complicating this picture is the fact that once the cryptojacking infrastructure is developed, there is less of a cost to launch additional attacks. Nevertheless, a simple economic model can be used to make sense of the cybercriminal’s strategy.

As a second example, cybercriminals, after cutting their teeth on ransomware for consumer computers, moved to enterprise computer ransomware. The barrier for entry for consumer ransomware is lower and it takes less planning, so it makes sense that it was the first place it became a threat. Once the tools were developed, however, they could be used against the enterprise in coordinated attacks. The inelastic pricing of the ransom of enterprise ransomware drove the price up and hence increased the motivation for enterprise malware attacks. This is seen in the data because even though general ransomware decreased by 20%, enterprise ransomware frequency increased by 12% (1).

A third example of the economics of cybercriminals is their adoption of powershell as an attack vector. Recently browsers, operating systems, and anti-malware software have improved so that the yield of a brute force “through the front door” attack has become prohibitive. The response is to “live off the land” with native OS utilities instead of breaking down the front door. This is seen by a 1000% increase in the use of powershell in attacks (1). FYI, the standard vector is an office document with a macro that calls powershell to load the malware payload (1). Macro limiting strategies may be useful in some cases.

In each of these three examples, a simple economic model could be developed to understand how cybercrime attacks rose or fell based on optimizing the ROI to the cybercriminal.

Managing Reputational Risk in an Era of the Unthinkable: Brand Implications of Major Breaches

We live in an era of sometimes unfathomable risk. From the November 2015 attacks in Paris that left 130 victims dead to the deep breach at Equifax that exposed 145 million consumers’ most intimate data, people, places, and companies are dealing with the unexpected every day, and one of the primary repercussions is to the integrity of their brands.
It’s common to assume that many of these events have a short lived impact. In the aftermath of the October 2017 massacre in Las Vegas, stocks dipped and investment banks estimated up to 6 months of reduced demand, but tourism was expected to rebound to levels seen before the event within a year.

The repercussions of such events live on far longer in the ongoing calculus of risk, expense, and operations that they so strongly influence. Risk managers for the Las Vegas Police, MGM International and other hospitality companies have to balance the costs of security enhancements with the broader expense and risk landscape of their business. No amount of spending can reduce risk to zero and too much spending can threaten the integrity of the bottom line

All of these high profile security events have not only operational implications but also reputational ones – bottom line impacts on the brand and the ways the brand influences revenue, market valuations, credit worthiness, regulation, and operations themselves. Reputational risk surfaces in surprisingly diverse ways and one of the major ways risk managers can benefit the bottom line is by demonstrating the organization’s flexibility and resilience in the face of brand damage.

This is a comprehensive look on understanding reputational risk as an enterprise-wide concern requiring an enterprise risk management approach. Reputational risk goes far beyond considerations of physical or cyber-security. Let’s talk about all the ways brand damage is likely to materialize.

The first portion will focus on understanding and mitigating the first-order, bottom line impacts of reputational risk – revenue and valuation. In the latter half we’ll focus on the second-order but equally important impacts on credit worthiness and operating costs.

Revenue & Reputation: Securing the Bottom Line When Bad Stuff Happens.

Often the easiest cost to imagine is loss of customers during a brand impacting event. However, some risk managers find it difficult to quantify impacts on future revenue in the aftermath of these incidents. Consider the horrific attacks in Paris in 2015 – Tourism rebounded quickly to pre-attack levels but the attacks undoubtedly reduced the share of international travelers who would otherwise have come to the city. While this impact can be difficult to quantify, it’s not impossible. By focusing on the primary stakeholder for this cost (in this case tourism consumers) we can go a long way toward modeling the impact of brand damaging events. Maintaining information not only on the sentiments of your customers but acquiring data on the average consumer in your sector is key for calibrating risk models. Further, true brand recovery in the aftermath of a high profile event can only be evaluated when you know what potential as well as loyal customers are looking for or are concerned about.

Reputation & the Markets: The Real Risks of Devaluation

After a brand impacting incident companies almost immediately see effects on stock. Stock prices plummet and there are subsequent losses stemming from these initial dips. Given the herd mentality of investors it is critical to reassure savvy shareholders that the risks to the company are being well managed. Here a strong enterprise risk management approach can provide executives with the right information at the right time to convey to the market that the root causes are known and being addressed. A robust culture of risk management can provide hard evidence of the actions the company is taking to ameliorate the costs of the incident in question. In some cases there is little that can be done to prevent an immediate reputational hit, but demonstrating an awareness of all the ways the costs of the incident have and will materialize goes a long way toward demonstrating resilience to investors.

Reputation and the Cost of Money

In some cases lenders may determine that reputational damage has impacted revenues, operational costs or the overall financial health of an organization so much that the costs to borrow increase. For organizations with low debt levels this financial risk can be managed to drastically reduce these costs. For others it may become extremely costly. No matter where your organization sits on the debt spectrum, resilience is crucial in all areas of the business so you can strengthen lenders’ view as they re-evaluate the health of your business. An enterprise-wide response is ideal to mitigate the often expensive effects of increased borrowing costs. Make sure you’ve built that risk resilience into cash flow, operational costs, and the impact of big events on overall market value.

Reputation and Operations

Like revenue, the impact to operational costs is easy to see in the short term. Increased spending on response efforts, outside counsel, security experts, and more are easy to quantify. However, long after the brand impacting event organizations continue to feel further effects on operations.

Three common areas with ongoing operational cost implications are risk mitigation, compliance spending and the cost of personnel. Often firms respond to brand damaging incidents by throwing money at the problem. Stakeholders and executives get comfort from the immediate spending, but that spending is rarely commensurate with the risks involved. Rather than spending boatloads of money on beefed up compliance and audit or unfettered cybersecurity spending, organizations need to ensure that new spending is matched to the amount of risk reduction needed.

The costs of increased turn-over or retention after a big event are harder to quantify. Just as reputational damage impacts customers’ views of an organization, employees may require more compensation or be easier to lure away if your brand suffers. Focusing on employee sentiment may seem unnecessary in the immediate aftermath of a brand damaging event but it may save you in turnover and talent acquisition costs down the road.

Reputation and Regulation

Depending on the type of incident, regulators might have cause to step in. While fines and legal fees may be unavoidable, a strong risk management program can be critical to avoiding more onerous regulatory oversight. The right kind of program goes well beyond demonstrating large, active programs in compliance or audit. True risk management means that organizations demonstrate, on an ongoing basis, how they manage risks effectively, including how they can detect and respond to failures. Furthermore, showing regulators how your organization protects customers through enhanced resiliency efforts can also give the regulators good cause for not taking their most restrictive actions.

Big Reputational Risk Means Big Action

Given the diverse ways big reputational risks can drive up costs, organizations should take a broad approach when managing such risks. Since no part of the enterprise is safe from brand damage, risk management against this damage needs to be undertaken at enterprise scale. Companies need to look broadly at the value of preventative risk mitigation before a major incident occurs, and consider investing in resiliency to limit the eventual costs to the brand and organization of such incidents. In today’s high risk environment, risk managers need to provide executives with prospective information about the enterprise-wide risks they face and then dive in fully to help with both the response to extreme incidents, and with reassuring all those with a stake in recovering from these traumatic events.

Author