Time For 'Culture Of Security'

By Ray Birch

RANCHO CUCAMONGA, Calif.—The WannaCry ransomware attack is sending a strong message to credit unions that they need to further bolster cyber defenses, most especially in staying current on all security patches, understanding the threat extends to ATMs, and creating a “culture of security” within their offices.

That is the opinion of several security analysts who shared their insights following the massive ransomware attack that recently struck companies across the globe and which continues to be an issue.

Ransomware is a type of malicious software designed to block access to a computer system until a sum of money is paid. Crooks first use the malware to encrypt the contents of a victim’s computer and then extract a ransom, in bitcoins, in exchange for decrypting the data and allowing the victim to regain access. Losses to ransomware across the globe are in the hundreds of millions of dollars, experts say.

The WannaCry ransomware takes advantage of a security vulnerability in the Windows XP operating system, for which Microsoft created a patch in March. More than 300,000 computers have been affected, sources indicate, and victims have been offered the choice of losing all their data or paying roughly $300 in ransom via Bitcoin.

Expect More Attacks

KrebsOnSecurity last week said the Bitcoin data associated with the ransomware attack shows criminals have only received approximately $26,000 so far from the scam. Krebs noted that cybercrime frequently causes damage disproportionate to the amount of money obtained.
Financial institutions should expect the crime to continue, if not pick up speed, experts told CUToday.info. Ransomware has become popular with criminals because of how quickly they can get their money and how easy it is to pull off a ransomware attack, even by novice criminals. Inexpensive ransomware kits are available on the dark web.

Paul Love

“Ransomware has been around for years, although the general public has not been as involved,” noted Paul Love, chief information security officer at CO-OP Financial Services. “These attacks will continue because of the high success rate and the ability of the attackers to monetize quickly and move on. Companies will need to consider their strategies for data recovery very closely and take ransomware into consideration when developing their business continuity and disaster recovery strategies.”

While the WannaCry ransomware leveraged a vulnerability that Microsoft had patched in March, Josh Gatka, security evangelist at Hyland in Westlake, Ohio, said that a recent leak resulted in attackers discovering that they could use tools to exploit this vulnerability on older, unsupported operating systems.

“Unfortunately, there are still many PCs running old, unsupported operating systems. In many cases businesses do not commit the budget necessary to upgrade systems that are still perceivably working fine,” Gatka said. “The results of this particular attack were severe enough that Microsoft actually issued patches for Windows 8, Windows Server 2003, and Windows XP in an effort to stop the WannaCry ransomware. It is important for businesses to realize that the life preserver thrown by Microsoft should not serve as an excuse to continue to put their data at risk by opting not to upgrade systems. An attack of this size and impact could happen again, and most likely will.”

Josh Gatka

Gatka emphasized that the WannaCry ransomware attack should be alarming sign to the financial industry.

Outdated ATM Software

“There are ATMs using the same outdated operating systems that were compromised in the attack,” he said. “Financial institutions have been a favorite target of criminals since the days of the famous fraudster Frank Abagnale, and it is logical to assume that attempts will be made to attack financial institutions using the WannaCry ransomware in the future.”

Gatka said that CUs should ensure that their systems are up to date.

“They should ensure that they are using reliable backups, and should test those backups frequently. In the event of a ransomware attack, a good backup policy may mean the difference between a few hours of downtime and being forced to pay tens of thousands of dollars in ransom,” said Gatka. “Lastly, since many ransomware attacks start out as phishing emails, it’s important to train staff on how to recognize suspicious emails, and what to do in the event of receiving one.”

The steps to effectively fight ransomware attacks are basic, insisted Love.

“Credit unions will need to develop strong information security programs that help their IT groups maintain a strong security posture,” Love said. “This includes the basics like keeping up with vendor patching, making users aware of threats and turning off IT systems and IT services that are not needed.”

Shea Lambert

Shea Lambert, chief technology officer at United Solutions, Tallahassee, Fla., said that all CUs should use the “defense in depth” concept for security.

“In this case, a few policies and procedures would have protected an organization. First, have or put in place a good patch management strategy,” said Lambert, noting the Microsoft patch in March. “Second, decommission software and operating systems that are at end-of-support. Microsoft quickly released patches for unsupported systems, this time. That won’t always be the case.”

Third, and perhaps most important, Lambert said to train staff and consider testing them throughout the year with a phishing simulator—a tool that simulates a phishing attack on a computer.

“Lastly, back up your data,” Lambert said. “Credit unions should consider having a backup strategy that includes a secure cloud backup provider”

Noting that the easiest and most common method of getting into a company’s network is through social engineering, Love said credit unions need to maintain a “culture of security.”

“This includes constant security awareness efforts that are actionable and relevant,” Love said. “Sending users a one-page document that says they need complex passwords is not enough. Creating engaging, personally relevant security programs will help develop strong advocacy among the employees who are the front line of any security program. And keep instructions simple, such as ‘Don’t click on links in emails.’”

Another Attack

What’s ahead? As experts said, more ransomware attacks are certain.

And as the cyber security experts were sharing their advice with CUToday.info, last week a second massive computer virus was discovered to have infected hundreds of thousands of computers worldwide.

This second global hack, while not ransomware, exploits the same Microsoft vulnerabilities as the WannaCry attack and it is estimated to have infected more than 200,000 computers, Euro News reported.

CUToday.info late last year ran a two-part series on a credit union that successfully defended two ransomware attacks in a short period. The stories can be found here and here.

Section: Standard
Word Count: 1327
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/Time-For-Culture-Of-Security