The Ukraine war is nothing more than a click away, and the sooner corporations, schools and universities, and other organizations realize this, the safer they will be.
And the threats are real.
Russia has a long history of hacking the internet systems of organizations and entire countries. These hacks and cyberattacks can impact our national security, steal vital information from companies and organizations, or simply shut everything down.
Imagine for a second the recent truck blockade on bridges in Canada. Those are crucial roadways, used for delivering oil, food supplies, products, and components to and from Canada and the U.S. In many ways, the truckers shut everything down. Nothing moved during the blockades.
Now picture the same thing happening – but electronically. A hack from Russia can close down entire internet systems needed by critical infrastructures such as banks, stock exchanges, credit card providers, and more. Nothing can move.
In the past, Russian cyberattacks have traditionally included such things as:
Spear phishing. This is the practice of sending emails from a known or trusted sender asking for personal information.
Brute force. A brute force cyberattack makes repeated and ongoing trial and error attempts to log into an organization’s database and uncover confidential information.
Exploitation. Instead of seeking information, cyber exploitation attacks disrupt online services, deny access to, alter, destroy, or release confidential information.
With Ukraine war, even more detrimental attacks could be in the making from Russia.
And don’t think just because yours is a small university in the Midwest or a charitable organization, you are safe from a Russian cyberattack.
Russian hackers have gotten into small and often little-known schools and universities and stolen vital data. And here’s the catch. Many times, they do this just to test their expertise and see if their hacks work. As to charities, in the Netherlands, Russian hackers have infiltrated worthy charitable organizations along with public service watchdog agencies, often just to embarrass them.
If they have done things like this in the past, and because the Ukraine war is turning them into an international pariah, we need to be more on guard than ever before, protecting ourselves – our people, property, and information – from an entire array of threats and attacks. Here is what we are advising our clients to do due to the Ukraine war:
Conduct cyber security audits. The cyber security audit looks for weaknesses and vulnerabilities in internet systems and suggests ways to eliminate them. This is similar to a risk assessment, but its focus is entirely on internet-based technologies in your organization.
Encourage robust logging in. Many staffers log into an organization’s internet infrastructure only once or twice per day. Encourage staffers to log in and out frequently. It is often during the authentication process that an organization first learns something might be amiss.
Realize threats can be internal. Several years ago, a person that was later identified as connected to a terrorist organization managed to get a job at a financial services organization in Canada. However, his real job was to obtain access to the company’s customer data and transactional information. In this case, astute administrators were concerned about this person’s behavior and expressed those concerns to Canadian police authorities. The police were able to step in just as the attack was to begin and arrested the individual.
Conduct a risk assessment. The goal of a risk assessment is to look for weaknesses, vulnerabilities, and hazards throughout an organization, all in an attempt to eliminate them.
A risk assessment often does include the cyber security audit mentioned earlier but it is far more extensive. It would also involve analyzing such hazards as vulnerabilities in the facility and its location, workplace violence, the potential for fires or explosions in a facility, mechanical systems failure, internal threats and terrorism, even risks to an organization’s reputation.
The Ukraine war is unlike anything most of us have ever seen before.
Such a brazen invasion has not occurred in decades. Because of this, and with the many uncertainties in the world today, a risk assessment is no longer something organizations may want to do – it’s something they have to do.
Johnathan Tal is Chief Executive Officer of TAL Global Corporation, an international investigative and security-consulting firm. He served as a Military Field Intelligence Officer for the Israeli Armed Forces during the 1970s. As an intelligence specialist, Tal supervised and initiated behind-enemy-lines intelligence gathering relying on both hardware systems and personnel. Tal has also served as an anti-terrorism security specialist. He is a licensed investigator, former President of World Association of Detectives (2000-2001) and holds a Bachelor of Science degree. He can be reached through his company website at www.talglobal.com










