Digital Forensics, Incident Response & Attribution

Cybercrime investigations are similar in nature to fraud and financial crime investigations. Today, a great deal of financial crime is in fact cyber-crimes and cybercrimes, just like financial crimes, are frequently difficult to spot.

In the case of financial crimes, it might take something like a quarterly financial audit to reveal that something suspect is going on. Some cyber-crimes are subtle like this, too. 

For instance, in the case of a hidden attacker maintaining persistence on a corporate network for purposes of long-term data exfiltration, the intrusion might only be revealed during a network sweep, as part of periodic threat assessment process, or via a newly installed intrusion detection system.  

Not all cybercrimes are difficult to spot. Some cybercrimes reveal themselves as part of the operation, an attacker will contact the victim organisation and will attempt to extort a ransom, or an attacker will leak data to the public, and the victim company will find out about it.

It’s interesting to note that several high-profile breaches during the past few years were discovered when a cyber security vendor installed their technology stack on the victim’s network as part of a pre-sales demo or trial period.

Regardless of how it’s discovered, once a company suspects that they’re the victim of a financial or cybercrime, they’ll need to collect additional evidence before involving law enforcement. 

Once an investigation is initiated, a variety of third party auditors are usually brought in to help. In the case of suspected fraud or financial crime, insurance companies can provide some of those services. 

In the case of a cybercrime, a cyber security firm specialised in digital forensics and incident response will be called in.

The victim organisation pays for such services out of their own pocket. Why? Because incident response isn’t just about forensics. It’s about cleaning up affected systems, restoring the network to a non-compromised state, restoring lost data, and often it’s also about providing assistance to the victim organisation in adjusting security practices and risk management plans to avoid future incidents. 

As part of the incident response process, law enforcement is involved once enough evidence has been collected to determine when and how the crime was committed.

Once involved, law enforcement agencies utilise the forensic data collected by privately run incident response operations as a starting point for their own investigations. Remember that the police have access to additional sources of evidence that private investigators don’t. 

For instance, law enforcement agencies can subpoena logs from additional private sources (such as Internet Service Providers), and can correlate data from other investigations they’ve run. In our experience, law enforcement will often continue to cooperate with third party first-responders during an ongoing criminal investigation.

Attribution is more of an art than a science. When it comes to cyber-crimes, private incident responders perform educated guesswork. This usually involves correlating the tactics, techniques, and procedures (TTPs) found at the crime scene with previous casework or open source threat intelligence. 

This guesswork includes analysing samples, such as custom tools or malware, found at the scene, language and content patterns found in phishing emails, the locations of C&C servers and phishing sites, techniques used for persistence or lateral movement, IP addresses associated with the attacks, and any other metadata uncovered during the investigation. The motives of suspected criminal groups may also factor into attribution guesswork. 

It’s not uncommon for private cyber security companies to work with law enforcement when determining attribution. However, due to the confidential nature of ongoing law enforcement work, evidence collected by or provided by law enforcement agencies isn’t normally made public as part of a third-party’s attribution conclusions.

There are a lot fewer cyber security companies in the world than there are insurance and financial services companies. Because of that, the demand for cyber security services companies is high. So high, in fact, that security-conscious organizations will often pay a yearly fee to keep a cyber security firm on retainer. By doing this, they ensure that help will be at hand as soon as an incident happens, and that prices for incident response work are charged at agreed upon rates. 

This is not unlike keeping law firms or financial services firms on retainer (for emergencies) or having certain special corporate agreements with insurance partners in place. Organizations that don’t have a cyber security firm on retainer typically have difficulty securing incident response and forensics services when they’re needed, and may end up paying rather high prices when they finally find someone who can help.

Incident response work isn’t just about reacting to breaches and cyber-crimes. Companies are now able to purchase cyber insurance policies. Here’s how forensics work comes into play in the case of an insurance settlement related to a cyber security incident. 

Insurance firms employ claims adjusters whose job it is to investigate insurance claims and determine the extent of a company’s liability when the claim is filed. In a traditional sense, claims adjusters gather data in a variety of ways, including interviewing claimants and witnesses, consulting police and hospital records and inspecting property damage. In the case of a cyber-crime, cyber claims adjusters, are brought in to run forensics in a similar way to how incident response is carried out. 

Compensation is awarded to the claimant based on the findings of the cyber claims adjuster. If the cyber claims adjuster were to, for instance, determine that a network was breached via a known vulnerability that should have been patched long ago, the claimant may receive a low amount of compensation. This is completely analogous to how an individual claimant would receive a low amount of compensation if they were burgled and it was later determined that they’d left their front door open.

With cyber security incidents becoming more and more widespread, businesses are learning that they need to adapt. This includes setting aside budget to keep cyber security services on retainer, paying for periodic trainings, threat assessments, and risk assessments, and even bringing experts onto their payroll to properly manage their cyber security practices. 

The cost of not taking cyber security seriously today is akin to the cost of not having your business properly insured. And yet there are plenty of businesses out there who don’t think they’ll become the victim of the next breach, and who clearly don’t take these costs into account. And they’re most likely going to end up paying through the nose in the long term.

fSecure:                  Cultural Strategies For Data Security (£):
 

« Artificial Intelligence, Self-driving Cars & Cyberwar In 2017
Company Boards Need To Get A Grip. »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Homeland Security Investigations (HSI)

Homeland Security Investigations (HSI)

Homeland Security Investigations (HSI) is a premier federal law enforcement agency within the Department of Homeland Security (DHS).

Alarum Technologies

Alarum Technologies

Alarum Technologies (formerly Safe-T) is a global provider of cyber security and privacy solutions to consumers and enterprises.

CSO GmbH

CSO GmbH

CSO GmbH provide specialist consultancy services in the area of IT security.

TitanHQ

TitanHQ

TitanHQ offers ultimate protection from internet based threats and powerful Web filtering functionalities to SMBs, Service Providers and Education sectors around the World.

GrrCON

GrrCON

GrrCON is an information security and hacking conference that provides the Midwest InfoSec community with a fun atmosphere to come together and engage with like minded people.

Enterprise Ethereum Alliance (EEA)

Enterprise Ethereum Alliance (EEA)

EEA is a member-led industry organization whose objective is to drive the use of Ethereum blockchain technology as an open-standard to empower ALL enterprises.

TechRate

TechRate

Techrate is an analytics agency focused on blockchain technology and engineering. Or expertise includes security and technical audits of projects.

DataCloak

DataCloak

DataCloak is an innovation company that focus on providing enterprise data-in-motion security solutions based on zero-trust security technology.

Greenberg Traurig (GT)

Greenberg Traurig (GT)

Greenberg Traurig, LLP (GT) is a global law firm with offices in 40 locations in the United States, Latin America, Europe, Asia, and the Middle East.

Byos

Byos

Byos provides visibility of devices across all networks, regardless of location, integrating with your existing security stack.

Ekco

Ekco

Ekco is one of Europe’s leading managed cloud providers. With a network of infrastructure and security specialists across Europe, we’ve perfected our approach to supporting digital transformation.

Deutsche Gesellschaft für Cybersicherheit (DGC)

Deutsche Gesellschaft für Cybersicherheit (DGC)

As a leading provider of cyber security, DGC supports companies in taking advantage of the opportunities offered by the digital transformation – and in minimizing the associated risks.

Zigrin Security

Zigrin Security

Zigrin Security offer comprehensive, hands-on security testing of internal networks, applications, cloud-based solutions, e-commerce applications and mobile devices.

Synagex

Synagex

Synagex Modern IT is a simple IT and cybersecurity solution for businesses.

AI Security Institute (AISI)

AI Security Institute (AISI)

The AI Security Institute’s mission is to minimise surprise to the UK and humanity from rapid and unexpected advances in AI.

Fernao Group

Fernao Group

Fernao offer you all solutions from a single source - from cyber security, business resilience and digital infrastructure to cloud technologies and pentesting.