The Terrorist Designation: A New Red Line for Ransomware with Cynthia Kaiser
In this episode, host Caleb Tolin explores the battlefield of enterprise defense, which has moved from simple data theft to ultra heinous crimes that put patient outcomes at risk. Guest Cynthia Kaiser shares Battlefield Stories from her time at the FBI and her current work as SVP of the Ransomware Research Center at Halcyon (@halcyonsecurity ) illustrating how the industrialization of cybercrime has reached a tipping point. They dive into the alarming reality of modern dwell times, specifically looking at how groups like Akira move from initial access to full encryption in as little as one hour.
The conversation challenges the industry to face the inconvenient truths of cybercrime and ransomware. Kaiser shares case studies of how modern cybercriminals are adopting multilateral techniques to gain access to and exploit your network. By adopting an Assume Breach mindset, elite defenders can build the defense in depth required to combat malicious threat actors who follow their own rules to cause disruption and destruction.
What You’ll Learn:
- Why designating ransomware as terrorism helps influence adversary target selection.
- The impact of Akira's accelerated dwell time on traditional incident response.
- How AI enables clumsy amateur "wannabes" to conduct messy attacks.
- The critical role of phishing resistant MFA in securing the identity perimeter.
- Why Assume Breach necessitates deep defense in depth strategies.
- The overestimation of readiness among CISOs compared to actual red team performance.
Chapters:
[00:00] The Case for Designating Ransomware as Terrorism
[04:20] Modern Extortion and the Shortening of Dwell Time
[08:30] Ransomware Recovery in Interconnected Cloud Environments
[11:45] The Impact of AI on the "Wannabe" Attacker
[17:45] Three Actionable Steps for Modern Defenders
[21:30] Inconvenient Truths for Government and Private Sector
Episode Resources:
- Caleb Tolin on LinkedIn: https://www.linkedin.com/in/calebtolin/
- Cynthia Kaiser: https://www.linkedin.com/in/cynthia-kaiser-cyber/
- House Homeland Security Committee Testimony: Online Scams, Crypto Fraud, and Digital Extortion (https://homeland.house.gov/hearing/online-scams-crypto-fraud-and-digital-extortion-an-examination-of-how-transnational-criminal-networks-target-americans/)
- Halcyon Analysis: Akira Ransomware Attacks in Under an Hour (https://www.halcyon.ai/ransomware-research-reports/akira-ransomware-attacks-in-under-an-hour)
- Halcyon: Sicarii Ransomware Encryption Key Handling Defect (https://www.halcyon.ai/ransomware-alerts/alert-sicarii-ransomware-encryption-key-handling-defect)
- Previous Episode Referenced: Downtime in Healthcare is Fatal: Achieving Resilience in Health & Life Sciences (https://www.rubrik.com/podcasts/downtime-in-healthcare-is-fatal-achieving-resilience-in-health-life-sciences)