The FBI issued a stern warning in February 2019. They witnessed multiple Managed Service Providers successfully attacked by advanced hacking tools and organizations. This article details what’s happened since then.
On Oct. 18th, 2018 the US-Computer Emergency Response Team (US-CERT) issued an advisory. It warned Managed Service Providers (MSP) that they were being targeted by Advanced Persistent Threat (APT) actors. APT’s use to only include nation states, however, other bad actors are entering this arena too now. APT’s recognize the enormous rewards of breaking into an MSP: hack one company with access to many companies. The FBI underscored the US-CERT warning by releasing its own warning in Feb. 2019. The FBI gave identical warnings and urged the following protection strategies for MSP’s. Use a VPN to access your clients. Enable two-factor authentication on those VPN’s and everything else of value. Improve and ensure strong password hygiene. Attacks on MSP’s since Feb. have been fast and furious. Here are a few articles detailing some of them:
MSP’s are beginning to recognize they’re being targeted by APT’s with Phishing, Password, and social engineering attacks. MSP’s need to be perfect 100% of the time while an APT only needs to succeed once. These events can put an MSP out of business from the reputational damage and costs of recovering all their clients, at the same time. If you’re an MSP, you need to immediately begin bolstering your cybersecurity program. Identify your weaknesses and follow the advice of the FBI by adopting:
CyberHoot works with multiple MSP’s to Train, Govern, and Assess their Cybersecurity maturity. CyberHoot is FREE for MSP’s to use for themselves helping them Walk the Walk and Talk the Talk. The only way to protect yourself is to proactively engage on Cybersecurity. Begin preparing today by taking the critical steps to avoid a breach. All too often a breach puts the compromised company out of business.
Visit CyberHoot.com today for a free 30-Day trial. Managed Service Providers who enroll at CyberHoot will receive a free Cyber Risk Assessment of their organization to help jumpstart their Cybersecurity preparations. Act now before its too late.
Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.
Spoiler alert: If you’re still using “password123” or “iloveyou” for your login… it’s time for an...
Read moreStop tricking employees. Start training them. Take Control of Your Security Awareness Training with a Platform...
Read moreGet sharper eyes on human risks, with the positive approach that beats traditional phish testing.