RSAC Tech Talk - Cyber Hygiene by Trevor Parks and Emily Skahill

RSA Conference 2024 · Tech Talk

Overview

This talk, presented by Emily Scahill and Trevor Parks from the Cybersecurity and Infrastructure Security Agency’s (CISA) Joint Cyber Defense Collaborative (JCDC), delves into the critical need for enhanced cyber hygiene within high-risk communities. Initiated in March of the previous year, the High-Risk Communities Protection effort aims to bolster the cyber defenses of civil society organizations, encompassing nonprofits, activists, human rights defenders, and journalists. These groups, due to the nature of their work and their frequently outspoken positions, are disproportionately targeted by Advanced Persistent Threat (APT) actors, making them highly vulnerable to sophisticated cyberattacks.

Watch on YouTube

Visual summary for RSAC Tech Talk - Cyber Hygiene by Trevor Parks and Emily Skahill
Visual summary for RSAC Tech Talk - Cyber Hygiene by Trevor Parks and Emily Skahill

Key moments

  1. 0:00 Introduction to JCDC's high-risk communities effort
  2. 2:00 Defining the target high-risk communities
  3. 3:15 Importance of cybersecurity for under-resourced groups
  4. 5:20 Case study: Lockbit ransomware attack on Relentless Church
  5. 12:00 Understanding APT goals against civil society
  6. 12:50 Empowering individuals with practical cyber hygiene practices
  7. 14:40 Introducing CISA's High-Risk Communities Protection webpage and Project Upskill

RSAC Tech Talk - Cyber Hygiene

Speakers: Emily Scahill, Cyber Operations Planner, Joint Cyber Defense Collaborative (JCDC), CISA; Trevor Parks, Cyber Operations Planner, Joint Cyber Defense Collaborative (JCDC), CISA

Conference: RSAC 2024

YouTube: https://www.youtube.com/watch?v=bUpf2zlIaeE

Overview

This talk, presented by Emily Scahill and Trevor Parks from the Cybersecurity and Infrastructure Security Agency’s (CISA) Joint Cyber Defense Collaborative (JCDC), delves into the critical need for enhanced cyber hygiene within high-risk communities. Initiated in March of the previous year, the High-Risk Communities Protection effort aims to bolster the cyber defenses of civil society organizations, encompassing nonprofits, activists, human rights defenders, and journalists. These groups, due to the nature of their work and their frequently outspoken positions, are disproportionately targeted by Advanced Persistent Threat (APT) actors, making them highly vulnerable to sophisticated cyberattacks.

A central challenge highlighted by Scahill and Parks is the severe under-resourcing faced by many of these organizations. Unlike large corporations or government entities, civil society groups often lack the financial means to invest significantly in robust cybersecurity infrastructure, nor can they easily attract and retain skilled cybersecurity professionals. Compounding this issue, these communities have historically received insufficient support from government agencies. The JCDC's initiative seeks to bridge this gap through strategic partnerships with industry and civil society, providing accessible, actionable guidance and resources to those most in need.

The presentation underscores the urgency of addressing this vulnerability, emphasizing that effective cyber defense for these communities is not merely a technical challenge but a societal imperative. By empowering under-resourced organizations and individuals with practical cyber hygiene knowledge and tools, the JCDC aims to mitigate the impact of malicious cyber activities that seek to disrupt, discredit, or suppress vital civil society functions. The talk serves as a call to action for both individuals within these communities and the broader cybersecurity ecosystem to contribute to a more secure digital environment for those on the front lines of human rights and social justice.

Background

▶ Watch: Introduction to JCDC's high-risk communities effort (0:00)

The landscape of cyber threats has evolved to target a diverse array of victims, extending far beyond traditional government and corporate entities. As highlighted by Scahill and Parks, civil society organizations, including nonprofits, human rights defenders, activists, and journalists, now represent a particularly vulnerable and frequently exploited segment. These groups are attractive targets for Advanced Persistent Threat (APT) actors for reasons that often transcend mere financial gain. Their work, which frequently involves sensitive political, social, or human rights issues, places them squarely in the crosshairs of state-sponsored groups, cybercriminals, and other malicious entities seeking to monitor, disrupt, or discredit their operations.

A significant contributing factor to their vulnerability is a profound lack of resources. Unlike well-funded corporations, many civil society organizations operate on shoestring budgets, making significant investments in cybersecurity infrastructure or the recruitment of dedicated security professionals an impossible luxury. They often lack the foundational understanding of the complex cybersecurity landscape that professionals take for granted, struggling to grasp the nuances of threat actors, attack vectors, and defensive strategies. This resource disparity means that even readily available cybersecurity controls within common devices and software often remain unconfigured or underutilized, leaving critical gaps in their defenses. The challenge is further exacerbated by a historical lack of tailored government support, leaving these communities to navigate a treacherous digital environment largely on their own.

The motivations of these threat actors are varied and insidious. As Trevor Parks explained, the goals extend beyond financial theft, encompassing objectives such as besmirching or discrediting organizations with opposing political or social beliefs, intimidation, and the suppression of speech. In some cases, threat actors deploy spyware to monitor activities, gather intelligence on members, or identify connections to other organizations of interest. A stark example of this threat was presented with the case of Relentless Church, a faith-based group that fell victim to the notorious Lockbit ransomware group. Beyond the immediate financial impact of the ransomware attack, Lockbit successfully exfiltrated a significant volume of sensitive data. Even after a ransom payment, the APT actors retained this information, leaving the organization exposed to future attacks or the potential for data sale on black markets, illustrating the long-term consequences and multifaceted nature of these attacks. This context underscores the urgent need for accessible, practical, and community-specific cybersecurity guidance to empower these high-risk groups.

Key Findings

▶ Watch: Importance of cybersecurity for under-resourced groups (3:15)

The JCDC's High-Risk Communities Protection effort has yielded several critical findings and contributions aimed at empowering under-resourced civil society organizations against sophisticated cyber threats. A primary discovery is the observation that Advanced Persistent Threat (APT) actors target these communities with a diverse set of objectives, extending far beyond traditional financial gain. Their motives frequently include besmirching, discrediting, intimidation, and the suppression of speech, often leveraging cyber means to undermine organizations whose work conflicts with the aggressors' political or social agendas. This highlights a need for defensive strategies that acknowledge these non-monetary attack motivations.

Another key finding is the pervasive gap in cyber hygiene among these communities, largely due to a lack of resources, technical understanding, and awareness of readily available security controls. Many personal devices and home networks, which are often used for sensitive work by activists and journalists, possess inherent cybersecurity features. However, users frequently lack the knowledge or guidance to properly configure and utilize these existing controls, leaving them unnecessarily vulnerable. This insight directly informed the JCDC's strategy: rather than advocating for costly enterprise-grade solutions, the focus shifted to maximizing the security posture achievable with existing, often free, tools and built-in functionalities.

The central contribution of this initiative is the creation of a dedicated online platform: the High-Risk Communities Protection webpage on cisa.gov (specifically, cisa.gov/high-risk-communities). This "one-stop shop" consolidates vital resources into three main components:

  1. Project Upskill: A series of cyber hygiene guides meticulously designed for individuals without a technical background. These guides translate complex cybersecurity concepts into easy-to-understand, actionable steps, empowering users to implement foundational security practices on their personal devices and networks.
  2. Cybersecurity Resources for High-Risk Communities: A curated collection of tools and services compiled through partnerships with industry and other civil society organizations. This resource aims to provide practical, accessible solutions tailored to the unique needs and budget constraints of these groups.
  3. Cyber Volunteer Resource Center: An initiative to connect under-resourced organizations with cybersecurity professionals and students willing to volunteer their expertise. This center facilitates assessments, provides guidance on improving cyber hygiene, and helps organizations better prepare for and respond to cyber incidents, effectively leveraging external expertise to fill internal resource gaps.

These findings and the resulting resource ecosystem represent a significant step towards democratizing cybersecurity, making essential protections accessible to those who need them most but have historically been overlooked.

Technical Deep Dive

▶ Watch: Case study: Lockbit ransomware attack on Relentless Church (5:20)

The JCDC's approach to bolstering the cybersecurity of high-risk communities is fundamentally rooted in the concept of personal cyber hygiene, recognizing that many individuals within these groups rely on personal devices and home networks for their sensitive work. Unlike enterprise environments with dedicated security teams and budgets, the focus here is on empowering the individual to leverage existing, often underutilized, security capabilities within their everyday technology.

The program identifies common attack surfaces that are prevalent in personal use but critical for organizational security. These include:

  • Personal Phones: Often contain sensitive communications, contact lists, and access to organizational accounts.
  • Personal Laptops: Used for document creation, research, and remote work, making them repositories of critical information.
  • Operating Systems (OS): Windows, macOS, Android, iOS all have inherent security features that, if properly configured, can significantly reduce risk.
  • Software Applications: Web browsers, email clients, communication apps, and productivity suites are frequent targets for exploits and phishing.
  • Home Wi-Fi Networks: Often the weakest link, poorly secured Wi-Fi can provide an easy entry point for adversaries to access devices on the network.

The core technical strategy articulated by Trevor Parks is to identify and explain how to activate and maintain the cybersecurity controls already present within these tools. For instance, modern operating systems offer features like built-in firewalls, disk encryption, automatic software updates, and user account controls. Mobile devices include biometric authentication, app permissions, and remote wipe capabilities. Home Wi-Fi routers typically have options for strong password protection, network segmentation (guest networks), and firmware updates. The challenge, as identified by CISA, is that "a lot of people who don't aren't technologically educated don't necessarily know what these tools do or how to implement the security controls."

Project Upskill directly addresses this by providing "easy actionable steps" for non-technical users. While the talk does not delve into specific code or protocol details, it implies guidance on fundamental practices such as:

  • Strong, Unique Passwords and Multi-Factor Authentication (MFA): Essential for account security across all platforms.
  • Software and OS Updates: Patching vulnerabilities promptly to prevent exploitation.
  • Phishing Awareness: Recognizing and avoiding malicious links, attachments, and fake websites (e.g., "fake site" mentioned in the transcript as an APT tactic).
  • Secure Network Configuration: Changing default router credentials, enabling WPA2/WPA3 encryption, and understanding the risks of public Wi-Fi.
  • Data Backup: Protecting against data loss from ransomware or device failure.
  • Physical Security: Securing devices against unauthorized access (e.g., screen locks, device encryption).

The initiative emphasizes a holistic cyber hygiene defense, encompassing both physical and logical security measures. This means not only securing the software and data but also protecting the hardware itself from theft or tampering. The underlying principle is that by systematically addressing these basic, yet critical, vulnerabilities, high-risk individuals can significantly limit their exposure to Advanced Persistent Threats (APTs), even when faced with sophisticated adversaries whose goals include financial theft (ransomware), discrediting, intimidation, and the deployment of spyware to monitor activities. The Lockbit ransomware example illustrates how even basic lapses can lead to severe consequences, including data exfiltration and long-term compromise. The JCDC's technical deep dive, therefore, is less about developing new security technologies and more about democratizing the knowledge and implementation of existing ones.

Demo / Proof of Concept

▶ Watch: Empowering individuals with practical cyber hygiene practices (12:50)

The RSAC Tech Talk by Emily Scahill and Trevor Parks did not feature a live demonstration or a technical proof of concept in the traditional sense. Instead, the practical output and "demonstration" of their work manifested in the launch and presentation of the High-Risk Communities Protection webpage on cisa.gov.

This webpage, accessible at cisa.gov/high-risk-communities, serves as the tangible embodiment of the JCDC's efforts. While not a dynamic, interactive demo of an exploit or a defensive tool, the website itself acts as the central repository for the resources discussed. It compiles the Project Upskill cyber hygiene guides, the Cybersecurity Resources for High-Risk Communities (a collection of tools from industry partners), and information on the Cyber Volunteer Resource Center. The speakers encouraged attendees, both in-person and virtually, to visit this site, highlighting it as the practical outcome where individuals and organizations can access the actionable steps and support services described during the presentation. This approach underscores the initiative's focus on education and resource provision rather than the showcasing of novel technical exploits.

Defensive Implications

▶ Watch: Introducing CISA's High-Risk Communities Protection webpage and Project Upskill (14:40)

The insights and resources provided by the JCDC's High-Risk Communities Protection effort carry significant defensive implications for several stakeholders, primarily high-risk civil society organizations and the broader cybersecurity industry.

For High-Risk Communities (Nonprofits, Activists, Journalists, Human Rights Defenders):

  • Prioritize Foundational Cyber Hygiene: The most immediate implication is the urgent need to adopt and rigorously implement basic cyber hygiene practices. The talk emphasizes that many vulnerabilities stem from unconfigured or ignored security controls on personal devices (phones, laptops) and home networks. Organizations should direct their members to Project Upskill on cisa.gov/high-risk-communities to access the user-friendly guides for "easy actionable steps" to enhance their security posture.
  • Leverage Existing Resources: Instead of seeking expensive enterprise solutions, these communities should actively utilize the free or low-cost resources compiled on the Cybersecurity Resources for High-Risk Communities webpage. This includes tools and services from industry partners and other civil society groups that are tailored to their unique constraints.
  • Understand Evolving Threat Motivations: Defenders must recognize that Advanced Persistent Threat (APT) actors targeting them are often motivated by ideological goals (discrediting, intimidation, suppression of speech) in addition to financial theft. This understanding should inform their threat modeling and incident response planning, recognizing that data exfiltration, even after a ransom payment (as seen with Lockbit and Relentless Church), can be used for future nefarious activities.
  • Seek External Expertise: The Cyber Volunteer Resource Center offers a crucial avenue for under-resourced organizations to obtain cybersecurity assessments, guidance, and incident response support from skilled professionals. Proactively engaging with such programs can significantly enhance their defensive capabilities without straining limited internal resources.
  • Secure Personal Devices and Networks: Given the prevalence of remote work and the blending of personal and professional digital lives, individuals must secure their personal phones, laptops, operating systems, software, and home Wi-Fi networks. This includes activating built-in security features, maintaining strong, unique passwords, enabling multi-factor authentication (MFA), and regularly updating software and operating systems.

For the Cybersecurity Industry:

  • Design for Security-by-Default: Industry partners are encouraged to develop products and services that are "secure right out of the box." This means designing intuitive security features that require minimal technical expertise to configure and maintain, reducing the burden on non-technical users in high-risk communities. This was a key point highlighted for an upcoming blog post mentioned by Emily Scahill.
  • Offer Accessible Solutions: Companies should consider offering pro-bono services, discounted rates, or tailored versions of their products specifically for under-resourced civil society organizations. Partnerships with initiatives like the JCDC can facilitate the distribution of these resources.
  • Support Volunteerism: Industry leaders can foster a culture of volunteerism among their employees, encouraging participation in programs like the Cyber Volunteer Resource Center to share expertise with vulnerable communities.
  • Collaborate with Government and NGOs: Continued collaboration with government agencies like CISA and non-governmental organizations focused on digital security is vital to identify gaps, develop targeted solutions, and disseminate best practices effectively.

By empowering individuals with practical knowledge and fostering a collaborative ecosystem, the JCDC's initiative seeks to build a more resilient digital environment for those who are often overlooked yet critically important to global civil discourse and human rights.

Key Takeaways

  • Vulnerable Targets, Unique Motivations: Civil society organizations, including nonprofits, activists, human rights defenders, and journalists, are frequent targets of Advanced Persistent Threat (APT) actors, often due to their work and for non-monetary goals such as discrediting, intimidation, and suppression of speech, in addition to financial theft.
  • Resource Disparity is a Critical Gap: These high-risk communities are severely under-resourced, lacking the financial means for robust cybersecurity investments and the ability to attract or retain cybersecurity professionals, making them highly susceptible to attacks.
  • CISA's JCDC Leads Protection Effort: CISA's Joint Cyber Defense Collaborative (JCDC) launched the High-Risk Communities Protection effort to bridge this gap by providing accessible, actionable cyber defense resources and fostering partnerships.
  • Comprehensive Resource Hub: The initiative established the High-Risk Communities Protection webpage (cisa.gov/high-risk-communities), a centralized platform offering Project Upskill cyber hygiene guides, a curated list of Cybersecurity Resources for High-Risk Communities, and a Cyber Volunteer Resource Center.
  • Empowering Through Basic Cyber Hygiene: The core strategy focuses on empowering individuals to implement fundamental cyber hygiene practices by leveraging existing, often underutilized, security controls on personal devices (phones, laptops, operating systems, software) and home Wi-Fi networks.
  • Industry's Role in "Secure by Default": Beyond individual responsibility, there is a strong call for the cybersecurity industry to design products that are inherently "secure right out of the box," reducing the burden on non-technical users and making default configurations safer.

About the Speaker(s)

Emily Scahill is a Cyber Operations Planner within the Joint Cyber Defense Collaborative (JCDC) at the Cybersecurity and Infrastructure Security Agency (CISA). In her role, she focuses on strategic planning and execution of cyber defense initiatives, particularly those aimed at protecting critical sectors and communities. Scahill was instrumental in co-leading the High-Risk Communities Protection effort, leveraging her expertise to support civil society organizations against advanced cyber threats.

Trevor Parks is also a Cyber Operations Planner within the Joint Cyber Defense Collaborative (JCDC) at the Cybersecurity and Infrastructure Security Agency (CISA). Working alongside Emily Scahill, Parks contributes to the development and implementation of cyber defense strategies. His work on the High-Risk Communities Protection effort involved educating these communities on understanding cybersecurity threats and providing guidance on personal cybersecurity strategies and resources.

All talks from RSA Conference 2024