MAT-SU BOROUGH 2018 Cyber Attack
2018 Cyber Attack What Happened Why It Happened The Response Going Forward
The Timeline Victim 210 Zero Day What Happened? Theoretical Exploit Late April eMail phishing Late May heavy activity June dormant July Discovery and Crypto-Locked Zero Day Theoretical Exploit Trojan- Emotet Credential Stealing – Dridex PowerShell Empire Ransom Ware - BitPaymer The Timeline Victim 210
Why it Happened On Our Side What They Wanted Staffing Funding Priorities Complacency Data Gathering Disruption Ransom
Mat-Su Borough Response Public Relations Vendors Volunteers Long hours Emergency funding Incident Response Project Management Minimum Viable Product (MVP) Communication Communication COMMUNICATION Take Care Of Your Users!
Communicate…Communicate…Communicate Going Forward We Can’t Do This Alone Partnering MS-ISAC DHS – US Cert InfraGard CIO Council Smart Community Forum Federal State Local Commercial Communicate…Communicate…Communicate
Security Portfolio
Discussion