Localities are turning to zero trust, multi-factor authentication & cyber hygiene training as the push to remote work coupled with an increase in ransomware shift the threat landscape.

The cyber threat landscape is constantly evolving as technologies and capabilities advance. The pandemic also widened the attack surface as entire workforces accessed networks remotely. State and local governments had to act fast to defend their systems and implement new security protocols.

Seven cybersecurity experts from the state and local governments and industry gathered at FedInsider’s recent Cyber Threats 2021 webinar to discuss the new technologies and tactics they’ve adopted to thwart cyber threats.

The following are some of the most important aspects of those efforts.

Featured Experts:

Mike Watson, Chief Information Security Officer, Commonwealth of Virginia
Mike Watson
Chief Information Security Officer,
Commonwealth of Virginia
Solomon Adote, Chief Security Officer, State of Delaware
Solomon Adote
Chief Security Officer,
State of Delaware
Tony Lauro, Director of Security Technology & Strategy, Akamai
Tony Lauro
Director of Security Technology & Strategy,
Akamai
Chris Beal, CISO, MCNC
Chris Beal
CISO,
MCNC
Drew Reinders, Director, Solutions Engineering, Akamai Technologies
Drew Reinders
Director, Solutions Engineering,
Akamai Technologies
Ashley Ewing, Chief Information Security Officer, University of Alabama
Ashley Ewing
Chief Information Security Officer,
University of Alabama
Douglas Holland, Senior Solutions Engineer, Akamai Technologies
Douglas Holland
Senior Solutions Engineer,
Akamai Technologies

State & Local Governments are Experiencing a New Threat Landscape

Mike Watson, chief information security officer for the Commonwealth of Virginia, said the threat environment is changing rapidly. “The last six months have been a completely wild ride, cyber-wise,” Watson said.

The commonwealth’s biggest concern is critical infrastructure threats like the Colonial Pipeline ransomware attack that caused the company to shut down its operations and freeze IT systems. An example of such a threat against government would be if an attack would strike an emergency response network during a natural disaster. Such an attack would prevent the state and its citizens from accessing emergency services.

Watson is also seeing an increase in ransomware attacks due to the high profit margins for attackers. In Virginia, ransomware attacks are largely targeting localities and the school systems, which can be defended with zero trust strategies, access management components and critical controls.

“All of those things are really effective in preventing ransomware and keeping us safe, but it is very difficult to get the technology and resources in place at government levels to implement those across the board,” Watson said.

The pandemic also put a lot of pressure on the state’s security personnel. There wasn’t much time to completely ensure security when everybody began working remotely, and new technology and systems were being implemented quickly. The state had to take on more risk, and is now assessing how to readjust its security posture to facilitate a more hybrid working environment with zero trust and strong identity and access management in mind.

A Pandemic Push to Digital Tools

States remain concerned about the increase in ransomware attacks and the consequences of losing critical data. The pandemic led to an even greater attack surface area to manage. Local and state governments were forced to digitally transform in accommodating remote workforces and digital citizen services.

“A lot of decisions have been stood up very quickly and with that comes a lot of potential for vulnerabilities and exploitation of those vulnerabilities,” said Tony Lauro, director of security technology and strategy at Akamai.

Phishing and ransomware attacks are on the rise because the security ecosystem originally built to protect localities didn’t necessarily extend to home offices. Home networks and connections don’t have the same security protocols as the state, so governments are working to gain more visibility into remote employees’ network activity as they access data from home.

For Delaware, maintaining a cybersecurity profile became more of a challenge due to the pandemic, according to the state’s Chief Security Officer Solomon Adote. Users at home could be visiting other sites while connected to the work server, and if a bad actor were to find a way in, they’d have access to the state’s network.

“We have to evolve how we do remote access and look at the threat landscape in terms of the amount of communication that is allowed with access to our network,” Adote said. Delaware is looking to isolate controls from the network and extend intrusion prevention and other internal security to remote endpoints, plus implement identity management and zero trust.

Ransomware is on the Rise

Chris Beal, chief information security officer of the Microelectronics Center of North Carolina (MCNC), said ransomware is the primary threat in the education sector, “due to a number of attacks that transferred into incidents that we ha d to help the community deal with over the past three or four years,” Beal said.

Considering that education institutions have largely moved to digital and online platforms, these attacks can be debilitating.

Plus, there are more students and teachers working remotely than ever before on systems not originally meant to be used in that manner. If firewalls are opened to allow inbound traffic to a remote desktop, attackers can find a way in, he said.

Akamai Technologies’ Director of Solutions Engineering Drew Reinders noted that the pandemic has also drawn increasing attention to ransomware attacks, especially with more systems online. Sectors like retail, education, local government and healthcare have always been heavily targeted, however, and it has a lot to do with profit.

“It is a numbers game,” Reinders said. “The more people they attack, the more people they will get monetary compensation from.” Plus, bad actors can still sell the data even if the ransom isn’t met.

To help these high-risk sectors, Beal said MCNC is helping localities understand better cyber hygiene practices, implement multi-factor authentication and zero trust, stay up to date with security patches and continuously identify vulnerability configurations. “The reality is attackers adapt every day. You need something that evolves with it,” Beal said. “This will provide a dynamic security posture.”

Protecting Education Data

Education data spans from housing and food services to personally identifiable information and financial aid. “There is a lot there to deal with, and then a very, very wide range of research data covering just about any kind of restricted or sensitive information you can think of that needs to be protected as well,” said Ashley Ewing, CISO at the University of Alabama.

Plus, students and faculty at universities are using multiple devices to access the campus’ network. Ewing said the university will see around 150,000 unique devices on its network, and this isn’t unusual for higher education environments.

Douglas Holland, senior solutions engineer at Akamai, said this poses significant security challenges for universities around the country, especially regarding controlling access to network data.

“You have no control over those devices, so you have no concept of what state those devices are in,” Holland said. He recommends increasing security awareness among employees, and implementing necessary programs to train the workforce.

Nation state actors are also targeting research-rich data. Ewing said there are about 44,000 attack attempts made against University of Alabama systems every hour, but the rush to facilitate remote education has led to “more emphasis in functionality and operability than security.”

To address the heightened risk, the University of Alabama increased VPN capacity, added more security tools and implemented multi-factor authentication within a year. “Build a basic cyber foundation with network security, endpoint security, monitoring and logging that has that zero trust in mind,” Ewing said.

The cybersecurity challenges in education, like for state and local governments, is complex and never ending. But best practices like zero trust networking, identity management and good cyber hygiene can keep those threats at bay and give the advantage back to the defenders despite the challenging threat environment that they face.

akamai-logo-color