Kaspersky Incident Communications
#1
Exclamation 
Quote:
[Image: Kaspersky-speaking.jpg]

I remember that day like it was yesterday: Our CEO called me into his office, asking me to leave my smartphone and laptop at my desk.

“We’ve been hacked,” he said bluntly. “The investigation is still ongoing, but we can confirm that we have an active, extremely sophisticated, nation-state sponsored attacker inside our perimeter.”

To be honest, this wasn’t totally unexpected. Our specialists had been dealing with our clients’ security breaches for quite a while already, and as a security company, we were a particular target. Yet, it was an unpleasant surprise: Someone had penetrated an information security company’s cyberdefenses. You can read about it here. Today, I want to talk about one of the key questions that arose immediately: “How do we communicate about it?”

Five stages of learning to live with it: Denial, anger, bargaining, depression, and acceptance

As it happened, pre-GDPR, every organization actually had a choice — whether to communicate publicly or deny an incident had even occurred. The latter wasn’t an option for Kaspersky, a transparent cybersecurity company that promotes responsible disclosure. We had consensus throughout the C-suite and started preparing for the public announcement. Full steam ahead.

It was the right thing to do, too, particularly as we watched the widening geopolitical rift and saw clearly that the mighty powers behind the cyberattack would definitely use the breach against us — the only unknown elements were how and when. By proactively communicating the breach, we not only deprived them of this opportunity, but we also used the case in our favor.

They say there are two types of organizations — those that have been hacked and those that don’t even know they were hacked. In this realm, the paradigm is simple: A company shouldn’t hide a breach. The only shame is in keeping a breach from the public and thus threatening customers’ and partners’ cybersecurity.

Back to our case. Once we established the involved parties — legal and information security teams versus communications, sales, marketing, and technical support — we began the tedious work of preparing the official messaging and Q&A. We did that simultaneously with the ongoing investigation by Kaspersky’s GReAT (Global Research and Analysis Team) experts; involved team members conducted all communications over encrypted channels to exclude the possibility of compromising the investigation. Only when we had most of the A’s covered in the Q&A doc did we feel ready to come out.

As a result, various media outlets published almost 2,000 pieces based on a news break we initiated ourselves. Most (95%) were neutral, and we saw a remarkably small amount of negative coverage (less than 3%). The balance of coverage is understandable; the media had learned the story from us, our partners, and other security researchers all working with the right information. I don’t have the exact stats, but from the way the media reacted to the story of a ransomware attack against Norwegian aluminum giant Hydro earlier this year, it seems the handling of those news stories was suboptimal. The moral of the story is, never keep skeletons in the closet.
...
Continue Reading
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Adobe Acrobat Reader DC 2026.001.21529
Adobe Acrobat Read...harlan4096 — 09:58
AxCrypt 3.0.0.90
AxCrypt 3.0.0.90: ...harlan4096 — 06:27
Microsoft Edge 147.0.3912.98
Version 147.0.3912...harlan4096 — 06:26
Google Chrome 147.0.7727.137/138
Google Chrome 147....harlan4096 — 06:22
Rufus 4.14
Rufus 4.14 (stable...harlan4096 — 06:19

[-]
Birthdays
Today's Birthdays
avatar (74)divinenews
avatar (51)plajhunTat
Upcoming Birthdays
avatar (28)akiratoriyama
avatar (48)Jerrycix
avatar (40)awedoli
avatar (82)WinRARHowTo
avatar (38)owysykan
avatar (49)beautgok
avatar (39)axuben
avatar (45)talsmanthago
avatar (31)mocetor
avatar (46)piomaibhaict
avatar (51)kingbfef
avatar (38)izenesiq
avatar (45)centfootadoni
avatar (40)ihijudu
avatar (45)tiojusop
avatar (42)Damiennug
avatar (40)acoraxe
avatar (49)contjrat
avatar (41)axylisyb
avatar (44)tukrublape
avatar (41)iruqi
avatar (42)saitetib
avatar (36)ypasodiny
avatar (39)omapek
avatar (48)Geraldtuh
avatar (44)knigiJow
avatar (46)1stOnecal
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (45)xclubDum
avatar (41)Stewartanilm
avatar (44)nikitaxople
avatar (40)GregoryRog
avatar (45)mediumog
avatar (40)odukoromu
avatar (46)Joanna4589
avatar (28)Honor6

[-]
Online Staff
There are no staff members currently online.

>