Thu, Apr 15, 2021
A A A
Welcome Guest
Free Trial RSS
Get FREE trial access to our award winning publications
Horizons: Family Office & Investor Magazine

Cybersecurity – Expert entreats: Do NOT use the same password

Tuesday, March 05, 2019

Cyber security expert Cyrill Brunschwiler gives some advice on cyber security for family offices ranging from passwords, non-computer devices, the right cloud solutions to the weakest links.Brunschwiler is managing director at Compass Security, a cyber security firm with offices throughout Switzerland and in Berlin.

Opalesque: What recommendations would you make to family offices regarding cyber security?

Cyrill Brunschwiler: If you consider the business case of a family office, it does not differ much from an investment company or trust. However, contact in a family office is very personal and this is of course a good prerequisite for recognizing social engineering attacks. Basically, one can say that families that are in the public eye have an increased risk.

But in most cases, family offices hardly differ from other service providers in terms of their IT infrastructure and are therefore also susceptible to the same threats such as infiltration by Trojan horses or against encryption of documents by Ransomware.

Opalesque: Anything they should not do?

Cyrill Brunschwiler: People often use the same password everywhere. That is a severe problem. Some time ago, a Swiss online merchant was accused of losing usernames and passwords after it was found that many valid login attempts were made for Swiss accounts from foreign locations. It then turned out that the same several thousand accounts had been lost at another company. Obviously, the users had the same username (email address) and password. For the hacker, it is clear as daylight that if you have an email address ending in “ch”, you probably also have an account with the major Swiss online shops. For this reason, you should use different passwords.

Opalesque: What about security when using multiple devices?

Cyrill Brunschwiler:Smartphones and tablets are very different from standard computers. Each application is isolated in itself. This is also called a sandbox. Therefore, the apps cannot easily access files from other apps. It is safer to do your online banking on the iPad than on your laptop because it is much more difficult to infect such a device with malware.

Zerodium, a company that specializes in dealing with vulnerabilities, buys information on identified vulnerabilities and on how to exploit them. Subscribers to Zerodium’s feed get that information to tailor defence and offense tactics. Currently, $0.5 million is claimed to be paid for a vulnerability that allows full control over the Windows operating system. In comparison, $1.5 million is offered for the same functionality on the Apple iOS platform. The amount of these bounties confirms the claim and give an idea of how difficult it really is to remotely control a mobile device without user intervention.

Opalesque: Cloud solutions, how secure are they?

Cyrill Brunschwiler: The term cloud is ambiguous. I understand “cloud” to mean that you no longer know exactly where the service is running; it could be in an Irish data center in the morning, then in the room next door in the afternoon and in a Japanese data center at night.

Since the services are partly operated in foreign jurisdictions, data protection laws are a central issue. Maybe you do not want your data to be in a foreign location. Luckily, large cloud providers have started to set up Swiss data centers - where the cloud data is then stored in Switzerland.

I recommend every small business to opt for cloud-based services at one of the mayor players like Amazon, Microsoft, Google or Alibaba, if data protection and privacy requirements permits. The big ones employ very reputable cyber security teams that are responsible for the entire infrastructure on a permanent basis. You will never get such service from a niche or local provider.

Access regulations are the most important things to consider when using cloud services. Cloud services can be used from anywhere in the world. Following that, corporate data can be accessed with a username and password from outside the company. It is therefore a good idea to protect access with a second factor (e.g. SMS or app) as is the case with e-banking. In addition, you should keep a watchful eye on those who leave your company. It is imperative that the permissions of resigned employees are immediately revoked.

Opalesque: Business and outsourcing partners: what security risks do they pose?

Cyrill Brunschwiler: Business partners are often imitated in social engineering attacks. This means forging documents with the CI/CD of the business partner or sending forged emails with the sender for example.

“Keep a simple rule in mind. The attacker takes the path of least resistance. So, all elements in the chain have to be secured.”

Currently, attackers use cracked email accounts to send fake invoices or money orders to the accounts’ business partners. It even happens that hackers delete an invoice from the inbox, modify the PDF such as providing it with a different IBAN (International Bank Account Number) and put the forged invoice back into the inbox. We have observed and analyzed quite a number of such cases this year. We are talking large 6-digit amounts. The ROI of such an attack is both absolutely fantastic and totally scary.

Whenever you consider investments into measures, keep a simple rule in mind. The attacker takes the path of least resistance. If a company is difficult to attack, then perhaps the IT service provider poses an easy gateway to the company. So, all elements in the chain have to be secured - because a chain is only as b as its weakest element. Thus, do not put all your money on a single bet.


Opalesque: Could you give us an example of a past family office cybercrime that can serve as a warning?

Cyrill Brunschwiler: We worked on a case this spring where the company’s core database was encrypted by a standard Ransomware. A decryption of the data was not possible as the backup got encrypted too. As a result, the external IT service provider did not have any hope of recovering the data and started formatting the system. Fortunately, one of the hard disks was corrupt and we were able to reconstruct the database from shadow data over the weekend. On top of that, my colleagues had to restore the application, because the manufacturer did not have that specific version anymore. This example shows the potential that certain companies have when it comes to cyber security.


 
Today's Exclusives Today's Other Voices More Exclusives
Previous Opalesque Exclusives                                  
More Other Voices
Previous Other Voices                                               
Access Alternative Market Briefing


  • Top Forwarded
  • Top Tracked
  • Top Searched
  1. New Launches: Atlas Holdings closes fourth PE fund at $3.1bn, Zigg Capital nabs $225m to invest in proptech startups, Canvas Ventures raises $350m to help bring intentionality back to early-stage investing, BlackRock and Fidelity launch first green bond ETFs[more]

    Atlas Holdings closes fourth PE fund at $3.1bn From PE Insights: Atlas Holdings has held the first and final close of its fourth private equity investment fund, Atlas Capital Resources IV LP (ACR IV) at its hard cap of $3.1 billion. The latest fundraising, which began in Novembe

  2. SPACs: UK stock market to lure SPACs with rules overhaul, Nuvation Bio flounders after EcoR1 SPAC merger, Singapore Exchange may launch regulatory framework for SPACs by mid-2021, SPAC listings slow to a crawl with bankers buried in paperwork[more]

    UK stock market to lure SPACs with rules overhaul From Yahoo Finance: Britain's financial watchdog has fired the starting gun on plans to overhaul stock market rules in a bid to lure more SPACs to the London market. The Financial Conduct Authority (FCA) on Wednesday said it woul

  3. New Launches: Amundi launches Just Transition for Climate fund, Index Ventures launches $200m seed fund, China's Hosen Capital hits $800m hard cap for third US dollar fundraise, Shackleton launches fifth venture secondaries fund[more]

    Amundi launches Just Transition for Climate fund From Bloomberg: Amundi has launched a European fixed income fund that will support energy transition. The Just Transition for Climate fund is managed by Alban de Fa?, head of fixed income ESG investing, and Dany da Fonseca, credit portfo

  4. SPACs: Investors see $90bn SPAC craze fizzling in the next year, US regulator turns spotlight on rosy SPAC projections, SPACs drive March M&A record, but other infotech players are still buying, Blank-check ETFs keep coming even as SPAC fever cools down[more]

    Investors see $90bn SPAC craze fizzling in the next year From PE News: Investors overseeing almost $13tn in assets say the frenzy around Spac listings will slow over the coming 12 months, predicting a spate of high profile failures will suppress appetite for so-called blank-cheque comp

  5. PE/VC: 'Frustrated' limited partners are questioning PE-sponsored SPACs, European venture reaches all-time high in the first quarter of 2021[more]

    'Frustrated' limited partners are questioning PE-sponsored SPACs From Institutional Investor: It's hard to imagine that private equity firms would have stayed out of the booming business of special-purpose acquisition companies. But private-equity-sponsored SPACs could lead to conflicts