775-591-8633 INFO@factualytix.com

Case Studies

CLIENT 229: A small business (less than 100 employees) suffered a ransomware attack. The company was inconsistent in backup policies when it came to locations and privileged access accounts. The hackers encrypted the company’s data and all backups. There were no certified viable backups that were not within reach of the hackers. The company found out that all backups were encrypted by the hackers so as to render them useless. The company paid the ransom but the hackers never bothered to give them the decryption key. The sales team for the security software maker responded by promoting a suite of products with some boasting ‘Next Generation / Artificial Intelligence’ and a mandatory migration to the Cloud using the CASB suite (Cloud Access Security Broker) the software maker positioned as the ‘game changer’ of the industry.

FACTUALYTIX: We ascertained the root cause. The lone IT resource had clicked on an email which then successfully delivered a package of social engineering (plain old tricks) and common technical exploits. The basic problem was that the IT resource had been fooled into ‘updating’ his password and user accounts by an email he received. This resource was unaware of the concept of Least Privilege. This resource was unaware of the concept of never clicking on links in emails and certainly knew nothing about disabling links in emails to eliminate any risk. The resource held the single account that made, archived, encrypted and restored all backups. That one account’s password was also the same on all admin accounts which were left with the nameĀ  ‘admin’ so the single IT resource could access them most easily. Our recommendation had nothing to do with software purchases, implementations and next generation artificial intelligence. When it comes to intelligence, we recommend using the real thing. Ultimately, the client decided a Managed Services agreement was better than hoping they would learn and quickly become expert in what we taught them. They kept the IT resource as an employee but with severely limited privileges, of course.

CLIENT 77: A large payments processing subsidiary of a major bank pursued a complete overhaul of their security posture both Cyber and Identity & Access Management. The most pressing issues were in teh area of Identity and Access control. This was necessitated because they had a home grown sort of Identity & Access Management solution that was neither effective nor easy to use which they had contorted to suit all requests from the business side no matter what they demanded. This was regardless of conflicts or failures in regulatory compliance. They tolerated the situation behind closed doors but were surprised to find themselves on the losing end of arguments with federal regulators.

FACTUALYTIX: Engaging twice, we lost our appeals to reason on our first round with the company contact provided to us as the program lead. We established that regulators were getting ready to shut them down for myriad issues of non-compliance. We established that the exotic and preposterously complicated nature of their IAM solution rendered it useless. We got one auditor to explicitly declare that they would not approve a system that was like nothing they had seen before or that required them studying the system for months to determine if it fulfilled any regulatory requirements. Our company program lead was adamant that he was building a ‘star ship’ that would be ‘like nothing ever seen before’ despite our recommendation that IAM demands adherence to basic rules regarding work flows and procedures. We held fast that regulators don’t want to study company systems for new features and process flows that are unknown to them. They are not impressed by outrageous innovation. They prefer vanilla after vanilla installations. Regulators want to compare systems with the ones they know work so they can approve the one in front of them at the time. We were released by the company appointed program lead because we didn’t share his brilliant vision. Four months later the client called us back to the program after terminating the employee they appointed as program lead. Apparently, the regulatory staff performing the audits threatened to shut down operations if a major paradigm shift did not occur and took their concerns straight to the C Suite to make it clear they meant business. Our second round was much more fruitful. We created work flows with full participation of all managing directors running their separate lines of business. Although substantial at times, our modifications to existing business processes were minimized as much as possible while we made it clear to the government employees that the client sought only regulator happiness as our goal. We slashed the software and development budget by 67%, minimized redesign of business processes, hardened business processes and avoided any ordered shutdowns.