Copyright © Sullivan Wright All Rights Reserved
War and Cybersecurity
Prior to World War II, most wars took place on battlefields. Opposing forces lined up and tried to overwhelm each other with the technology of the day. Those opposing forces also kept the other side from encroaching into their home territory.
The advent of long-range bomber aircraft just prior to World War II transformed warfare by making it possible to bypass enemy lines and take the war to the enemy's home. While the US started the war focused on military supply chain, we eventually hit whole cities in an attempt to wear down the populace's will to fight. The UK spent most of the war area bombing German cities as retribution for the German's bombing of civilian population centers in and around London. For the first time in modern history, military forces could easily bypass enemy land forces and strike at the heart of the populace.
With our massively interconnected modern world, the ability to disrupt everyday life far from the battlefield is even easier. While we may lump all cyber attacks under the umbrella of cyber crime, a statistically significant portion of those cyber attacks are related to war or, at the least, an adversarial relationship between nation states.
Most recently, we've seen this with Iranian attacks on public water systems in Minnesota. We've also seen spillover from the Russia-Ukraine war for years. In the past, we'd attribute these cyber attacks to "assymetric warfare" or the less-militarily-capable side grasping at straws attempting to damage the more capable side. Now, they are just a part of standard warfare.
This change is difficult for Americans to accept as we've mostly been insulated from the effects of war. Most of us have never had a tank roll down our street or a missile slam into our neighborhood. Our infrastructure has been safe, we've continued to have food to eat, and have generally lived comfortably through most wars.
Now we have at least a little worry that we'll turn on the water and nothing will come out, that we'll try to pay for groceries and the credit card system will be down, or that we'll be watching a streaming TV show and the Internet connection dies. Okay, the last one is probably more the fault of weather or provider negligence than anything else, but you get the idea.
As business owners and decision makers, you should take this to heart. We still hear it all the time: "I'm too small to be a target." No one is too small. Everyone is a target. You may not be directly targeted, but you are at risk of being captured in the wide net of an adversary trying to make the US hurt for one reason or another.
The good news is that you don't have to build Fort Knox. You do need to understand your threats, though. From there, you can build a program that protects where possible, monitors for the inevitable threat that slips through (because catching it early limits damage), and prescribes a response and recovery to get you back to 100%, efficiently and effectively.
We are well past the days of "set it and forget it" type security. That firewall and antivirus just aren't cutting it any longer. You can design something that works within your resources, though. It doesn't need to be expensive. If you're curious, ask me how.
References:
https://www.darkreading.com/cybersecurity-operations/businesses-wartime-cybersecurity-gameplans
https://cybernews.com/security/minnesota-water-systems-cyberattack-iranian-hackers/
