The Illusion of Control: What the Second Line Gets Wrong—and What Regulators and Failures Reveal

By Jeremy Swenson

Thirty-one. That is how many unaddressed safety-and-soundness supervisory warnings Silicon Valley Bank was sitting on when it collapsed in March 2023—roughly triple the number carried by comparable banks. The warnings existed. Examiners had written them down. Committees had reviewed them. And the bank failed anyway, in 36 hours, taking $209 billion in assets down with it.[1]

This figure isn’t really just about Silicon Valley Bank; it’s a broader story about how governance can falter right when it was meant to prevent failure. Across modern sectors like finance, healthcare, insurance, and tech—especially under heavy regulation—the structure is quite similar: a First Line managing risks, a Third Line (Internal Audit) independently evaluating effectiveness, and a Second Line acting as an oversight layer to challenge and ensure risk remains within boundaries before issues arise.

The uncomfortable pattern across nearly every major governance failure of the last fifteen years is not that the second line was absent. It was there, busy, and documented—and it still didn’t work.

That is the uncomfortable pattern across nearly every major governance failure of the last fifteen years: the second line of defense (2LOD) was rarely absent. It was there, it was busy, and it was thoroughly documented. JPMorgan’s Chief Investment Office had risk managers. Credit Suisse’s Prime Services division had a dedicated risk team. Wells Fargo had a corporate risk function, a legal department, and an audit group that all reviewed the Community Bank. Danske Bank’s Estonian branch had internal audit and a chief risk officer. In each case, the paperwork existed. The risk did not go away.

This raises the question at the center of this piece, and one that boards, regulators, and chief risk officers are increasingly asking out loud: is the modern second line of defense actually reducing risk—or is it primarily producing evidence that governance activities occurred? The two are not the same thing, and the gap between them is where some of the costliest failures in recent corporate history have lived.

What the Second Line Is Supposed to Do

The three-lines model that underpins risk governance at virtually every large regulated institution was formalized by the Institute of Internal Auditors in 2013 and substantially updated in 2020. The first line is operational management—the traders, lenders, engineers, and business unit leaders who own risk because they create it in the course of doing their jobs. The third line is internal audit, an independent function that reports to the board and periodically tests whether the first two lines are actually working. The second line sits in the middle: risk management, compliance, information security, and similar functions that provide, in the Institute’s own language, “complementary expertise, support, monitoring, and challenge” to the business.[2]

In U.S. banking specifically, this structure is not just best practice—it is regulatory expectation with teeth. The Office of the Comptroller of the Currency’s (OCC) 2014 heightened standards for large national banks explicitly require an independent risk management function, organizationally and financially separate from the business lines it oversees. The Federal Reserve’s 2011 guidance on model risk management, SR 11-7, assigns the second line an independent validation role specifically because business lines have an inherent incentive to trust their own models.[3]

Notably, when the Institute of Internal Auditors rewrote its guidance in 2020, it deliberately dropped the word “defense” from the model’s name, worried that the martial framing had encouraged organizations to treat risk management as purely defensive—blocking and reviewing—rather than as a function that helps an organization take the right risks well. That single word change is a useful preview of this piece’s argument: a second line built entirely around defense metrics—how many reviews were completed, how many policies exist, how many attestations were signed—can satisfy every requirement on paper while missing the actual point.[4]

Where the Model Breaks Down

Strip away the acronyms, and the recurring failure modes of the second line reduce to a short, uncomfortable list. Each one, on its own, sounds like a minor process gap. Together, and when combined with real money and real institutions, they have produced some of the largest corporate governance failures on record.

Documentation Instead of Risk Reduction

The clearest symptom is a second line that measures itself by volume: reviews completed, policies published, attestations collected, meetings held. Every one of those activities can be running at full capacity while the underlying risk grows untouched, because none of them require anyone to verify that a control actually works—only that someone said it does.

Self-Attestation Over Independent Verification

Much of traditional second-line practice depends on the first line telling the second line the truth: attestations, self-assessments, and point-in-time control tests that sample a narrow window and assume it represents the whole. When Danske Bank’s Estonian branch was later examined, the bank’s own lawyers conceded that “major deficiencies in controls and governance made it possible to use Danske Bank’s branch in Estonia for criminal activities such as money laundering,” and that internal reporting simply never reached the people positioned to stop it.[5]

Individual Exceptions Over Systemic Patterns

Second lines are often organized to catch one broken control at a time—a missed reconciliation, a late report, an expired certificate—rather than to notice that dozens of small, individually explainable exceptions are actually one large, systemic problem wearing different clothes.

Compliance Treated as a Proxy for Safety

Perhaps the most persistent conflation in second-line practice is the assumption that a control environment which satisfies a regulation is therefore a control environment that manages the underlying risk. The two frequently travel together. They are not the same claim, and treating them as interchangeable is exactly how organizations end up technically compliant and substantively exposed at once.

A Challenge Function That Doesn’t Actually Challenge

Effective second-line challenge requires two things that are hard to combine: enough independence to say no to a profitable business line, and enough technical and commercial fluency to know when “no” is actually warranted. Many second lines have one without the other—independent enough to be disliked, but not fluent enough in the actual business to be heeded, or so embedded in the business that independence quietly erodes.

Struggling to Govern What It Doesn’t Understand

Every one of the weaknesses above compounds sharply the moment the underlying risk is technical: artificial intelligence models, cloud migrations, third-party data pipelines, or novel cyber threats. A second line built to review loan files and sales scripts is not automatically equipped to evaluate a machine learning model’s training data lineage or a cloud vendor’s shared-responsibility boundary—and regulators are now saying so explicitly. NIST’s AI Risk Management Framework (RMF) and the broader push toward AI-specific governance exist precisely because traditional control catalogs were not written with adaptive, probabilistic systems in mind.[6]

Five Failures, One Pattern

These are not abstractions. They are the documented findings of regulators, board-appointed investigators, and congressional committees—and read together, they describe the same failure recurring in different industries, different countries, and different decades.

1. JPMorgan’s “London Whale” (2012)—When Risk Managers Don’t Know What the Business Is Doing

In 2012, JPMorgan Chase’s Chief Investment Office lost more than $6.2 billion on a series of synthetic credit derivative trades that came to be known as the “London Whale.” The U.S. Senate Permanent Subcommittee on Investigations spent nine months and reviewed more than 90,000 documents before concluding that the unit had mismarked its trading book to hide losses, disregarded multiple indicators of increasing risk, manipulated its own risk models, and evaded regulatory oversight.[7]

The Subcommittee’s report found that JPMorgan’s firm-wide risk managers—the second line—“knew little about” the trading strategy and had no role in approving the positions that produced the loss, even as the bank’s own public statements insisted the trades were consistent with firm-wide risk management. This was a second line that existed on the org chart and was functionally absent from the transaction that mattered most.[8]

2. Wells Fargo’s Sales Practices Scandal (2011–2016)—When Egos and Tenure Silence the Second Line

Between 2011 and 2016, Wells Fargo employees opened millions of unauthorized accounts to meet aggressive sales quotas, ultimately leading to the termination of roughly 5,300 employees and $185 million in regulatory penalties. When the bank’s independent directors released their own 110-page investigation in 2017, the findings went well beyond a rogue sales culture.[9]

The report found that Carrie Tolstedt, the long-tenured head of the Community Bank, and other Community Bank leaders “resisted and impeded scrutiny or oversight from corporate risk management and the Board,” and “minimized the scale and nature of problems” when they were forced to report them. Then-CEO John Stumpf, the report found, relied on “the Bank’s decades of success” and was “too slow to investigate or critically challenge” the sales model—a textbook description of tenure-driven bias, where years of past success become evidence against present-day concerns rather than a reason to look harder.[10]

Just as tellingly, the report found that Wells Fargo’s control functions were structurally weakened by internal politics: risk, legal, HR, and audit were “decentralized” and had “parallel units” embedded inside the Community Bank itself, reporting up through business-aligned structures that deferred to the business rather than challenging it. Audit reviewed the relevant controls and largely found them effective—but, the report notes pointedly, “it did not view its role to include analyzing more broadly the root cause of the improper conduct.” That is the governance-activity trap in a single sentence: the review happened, the box was checked, and the actual problem sailed through untouched.[11]

3. Credit Suisse and Archegos (2021)—When the Second Line Is Afraid to Say No

In March 2021, the collapse of Archegos Capital Management, a lightly regulated family office, cost Credit Suisse $5.5 billion—more than any other bank exposed to the same client. The board-commissioned investigation by Paul, Weiss found no fraud and no missing risk architecture. The controls existed. What failed was the willingness to use them.[12]

The investigation found a “persistent failure” to manage and remediate known risks connected to Archegos, and, more specifically, that Credit Suisse’s risk managers had intended to demand additional margin from Archegos to reflect its mounting credit risk—but were prevented from doing so because the business “deemed” it not to be in the bank’s commercial interest to upset the relationship. One outside review summarized the underlying dynamic bluntly: this was “a business more scared of losing a client than addressing the risks that client was bringing to the bank.” The report also found the Prime Services risk team itself was understaffed, had failed to replace departing senior risk staff, and lacked leadership experience—the second line, quite literally, hollowed out from within.[13]

4. Danske Bank Estonia (2007–2018)—When the Second Line Covers Its Own Mistakes

Danske Bank’s Estonian branch moved an estimated $230 billion in suspicious transactions, much of it linked to Russia, between 2007 and 2015—one of the largest money-laundering cases in European history. It might never have come to light if not for Howard Wilkinson, a British trader who filed four internal whistleblower reports to the bank’s audit unit and Copenhagen management between 2013 and 2014.[14]

Wilkinson later testified before the Danish and European Parliaments that the bank had “deliberately ignored” his warnings and that an Estonia branch executive told him the bank was “not the police.” An internal Danske audit team eventually validated the substance of his concerns, yet the bank still failed to take meaningful action until the money-laundering scandal became public in 2018—four years later. As Wilkinson departed the bank, he was reportedly presented with a nondisclosure agreement. This is the sharpest version of the pattern this piece was asked to examine directly: not a second line that failed to notice a problem, but one that noticed, confirmed it internally, and chose containment over correction—protecting the institution’s narrative rather than fixing the underlying failure.[15]

5. Silicon Valley Bank (2023)—When Periodic Reviews Can’t Keep Up With Real-Time Risk

SVB failed in 36 hours following a bank run, but the vulnerabilities behind it built for years. The Federal Reserve’s own review, led by Vice Chair for Supervision Michael Barr, is remarkable for how directly a regulator indicted its own supervisory process: SVB’s board and management “failed to manage their risks,” Federal Reserve supervisors “did not fully appreciate the extent of the vulnerabilities” as the bank grew, and—critically—even when supervisors did identify problems, they “did not take sufficient steps to ensure that Silicon Valley Bank fixed those problems quickly enough.”[16]

The report also found that SVB itself had changed its own risk-management assumptions specifically to reduce how its interest rate risk was measured, rather than managing the underlying exposure—a second-line control quietly redefined until it stopped producing uncomfortable answers. Barr’s report is also a rare admission that periodic, point-in-time supervisory cycles are structurally too slow for a risk that can move at deposit-run speed; a regulator reaching the same conclusion this piece reaches about the second line more broadly.[17]

What Regulators Learned—And Where Their Own Findings Converge

The most useful evidence that this is a systemic problem, not a string of unrelated scandals, comes from the regulators themselves. On April 28, 2023, the Federal Reserve and the Federal Deposit Insurance Corporation (FDIC) each released their own self-critical report on the same weekend of bank failures—an unusually candid coincidence that let the two reports be read side by side.

The Fed’s report on SVB, discussed above, found that supervisors identified real vulnerabilities but did not escalate forcefully enough once they had. The FDIC’s own report on Signature Bank reached a strikingly similar structural conclusion through a completely separate investigation: the bank’s failure was rooted in poor management, but the report also found that FDIC examiners had downgraded Signature’s liquidity rating as early as 2017 while its overall composite rating stayed at a healthy “2-Satisfactory” for six more years—a gap between what examiners were seeing and what the supervisory rating actually communicated.[18]

The U.S. Government Accountability Office (GAO) took a further step by reviewing both agencies together rather than separately. It concluded that this supports the main argument of this piece concerning federal banking regulation: the Federal Reserve and FDIC “identified numerous concerns at the banks as early as 2018, but did not issue enforcement actions.” Additionally, the GAO pointed out that the Federal Reserve’s “procedures for moving from a lower-level concern to an enforcement action often weren’t clear or specific.” This indicates that a regulator, assessing itself, independently recognizes the same core idea discussed here: identifying a risk is not the same as forcing a change. An institution can recognize risks on a large scale for years without reliably enforcing change.[19]

Read together with the NIST AI Risk Management Framework’s push for governance built around measurable, continuous risk assessment rather than static control catalogs, and the IIA’s 2020 shift away from purely defensive framing, a consistent regulatory direction emerges across otherwise unrelated bodies: less faith in point-in-time review, more emphasis on forcing identified risk into actual remediation, and explicit skepticism that documentation volume is a reliable proxy for safety. None of these bodies coordinated with each other. They arrived at overlapping conclusions anyway, because they were all looking at the same underlying failure pattern from different angles.[20],[21]

Figure 1. Most second-line functions do not lack activity—they sit in the high-activity, low-reduction quadrant, producing evidence of governance without changing risk outcomes.

The 2LOD governance trap and its four related boxes.

The Part Nobody Puts in the Org Chart: Tenure, Ego, and Internal Turf Wars

Every case above shares a dynamic that rarely appears in a governance framework diagram but shows up in nearly every post-mortem: the people closest to a mistake are often the ones best positioned to prevent its discovery, and organizational tenure tends to make that worse rather than better.

Long-tenured leaders accumulate something more dangerous than complacency—they accumulate authorship. A risk model, a sales program, a client relationship built over a decade is not just a business asset to the person who built it; it is proof of their own judgment. Wells Fargo’s Board Report describes exactly this pattern in Carrie Tolstedt, who had run the Community Bank for years and treated challenges to the sales model as challenges to her track record, not as useful information. John Stumpf’s decades at the company produced the same effect at the top: reliance on “decades of success” became a reason to discount new evidence rather than investigate it.[22]

Ego compounds this in a specific and predictable way inside the second line itself: once a risk function has signed off on something—approved a model, cleared a client, blessed a control—reversing that judgment later means admitting the earlier review was wrong. The Credit Suisse-Archegos investigation found that risk staff who wanted to tighten margin requirements were overruled by colleagues managing the client relationship, who prioritized the commercial relationship over the escalation. That is not a hypothetical about incentives; it is a documented instance of one part of the organization protecting a prior decision instead of correcting course.[23]

The most direct evidence of internal fighting to cover mistakes is Danske Bank. Wilkinson’s own account describes a bank that did not simply fail to notice a problem—it received internal confirmation that the problem was real, from its own audit function, and chose a non-disclosure agreement and years of silence over disclosure and remediation. That is not a control gap. It is a second line, or the executives who supervise it, actively managing the appearance of the problem rather than the problem itself—the containment instinct that shows up whenever an admission of error threatens a career, a bonus cycle, or a carefully maintained reputation.[24]

A second line that cannot survive telling the truth about its own prior mistakes will eventually stop looking for them.

None of this requires malice to be dangerous. Most of the people in these stories were not villains; they were professionals whose incentives, tenure, and self-image quietly bent the direction of ambiguous judgment calls toward “this is probably fine.” A modern second line has to be designed with the explicit assumption that this bending will happen—through rotation of long-tenured reviewers, external validation of internally cleared decisions, and protected channels for escalation that do not depend on the goodwill of the person whose earlier judgment is being questioned.

Governance Activity Is Not the Same as Risk Reduction

Every case study mentioned earlier successfully passed a compliance test before turning into a scandal. This is the key point repeatedly emphasized here: governance that merely shows evidence of compliance is different from governance that genuinely reduces risk. An organization can generate a lot of documentation proving compliance but still fall short in actually altering risk outcomes.

Evidence-of-compliance governance is legible, defensible in an exam, and relatively cheap to produce: a signed attestation, a completed checklist, a policy that has been “reviewed and approved.” Outcome-based governance is harder and more expensive: independently tested controls, risk metrics tied to actual loss experience, escalation paths that get used even when the news is bad. The first kind of governance protects the organization in an audit. The second kind protects the organization in a crisis. Wells Fargo, Credit Suisse, and Danske Bank all had abundant supplies of the first and a critical shortage of the second.

Figure 2. Modernizing the second line means shifting the underlying operating model, not just increasing the volume of existing activity.

Two columns showing the legacy model of checkbox compliance and the new model of continuous risk governance.

What a Modern Second Line Actually Looks Like

None of this argues for a weaker second line—every case study here shows the cost of that. It argues for a fundamentally different operating model, one that a growing body of regulatory guidance and industry practice is already pointing toward.

Risk-Based, Not Checklist-Based

Oversight intensity should scale with actual risk and complexity, not with how many items happen to be on a standard control list. A stable, well-understood process and a novel AI model deployed into a regulated decision workflow should never receive the same depth of review simply because both appear as line items on the same checklist.

Continuous Monitoring, Not Periodic Snapshots

The Barr report on SVB is itself an argument for this shift: point-in-time exams cannot keep pace with risks—interest rate exposure, deposit concentration, model drift—that can move materially between review cycles. Where technology allows it, continuous, automated monitoring should replace calendar-driven review as the default, with periodic deep-dives reserved for the risks continuous monitoring cannot yet see.

Evidence Over Attestation

Self-reported control effectiveness should be treated as a starting hypothesis, not a conclusion. Independent data validation—sampling actual transactions, actual model outputs, actual system logs—is more expensive than collecting a signature, and it is the only version of assurance that would have caught what self-attestation missed at Danske Bank.

Genuine Business and Technology Fluency

A second line cannot challenge what it does not understand. This means recruiting and developing risk professionals with real technical depth—in derivatives, in cloud architecture, in machine learning—rather than treating the second line as a generalist compliance career track. JPMorgan’s risk managers not knowing what the CIO’s synthetic credit portfolio actually did is the clearest cautionary tale on this point.

Escalation That Survives Internal Politics

Escalation paths need to be structurally protected from the relationship dynamics that killed escalation at Credit Suisse and Danske Bank—which means routing serious concerns to a level of the organization with no commercial stake in the outcome, and protecting the people who raise them, not just on paper but in how the organization actually treats them afterward.

Outcome-Based Metrics

A second line’s effectiveness should be measured by risk events avoided, losses prevented, and issues resolved before they compound—not by the number of reviews completed, policies published, or meetings held. Volume metrics are easy to game and easy to satisfy without changing anything; outcome metrics are harder to fake.

Real Oversight of AI, Cloud, and Third Parties

Emerging-technology governance needs its own competency track within the second line, built around frameworks purpose-designed for these risks—NIST’s AI Risk Management Framework, cloud shared-responsibility models, and structured third-party risk programs—rather than an attempt to stretch legacy control catalogs over technology they were never built to evaluate.[25]

Clear Accountability Between the First and Second Lines

Wells Fargo’s decentralized risk structure, with control functions embedded inside and reporting up through the business they were meant to oversee, shows what happens when the line between “owns the risk” and “challenges the risk” blurs. Modern governance requires those roles to remain organizationally and, where possible, financially distinct—precisely what the OCC’s heightened standards were written to enforce.[26]

Constructive Challenge, Not a Permanent Bottleneck

None of the above is a case for more friction everywhere. A second line that slows every decision equally will be resented, routed around, and eventually ignored—which is its own form of failure. The goal is targeted friction: fast, low-touch review for well-understood, lower-risk activity, and genuinely rigorous, well-resourced challenge concentrated on the decisions that could actually sink the institution.

Conclusion: Measuring the Right Thing

Return to Silicon Valley Bank’s 31 unaddressed supervisory warnings. Every one of them was, in a narrow sense, evidence that governance was happening: someone had identified a risk, written it down, and tracked it. And every one of them failed to change what actually happened to the bank. That is the second line’s central modern challenge, in miniature.

None of this is solvable by better metrics alone. Every case study in this piece also involved someone for whom the honest answer was personally expensive—a bonus, a reputation, a decade of authorship over a program now under question. A second line rebuilt around outcome-based measurement but layered on top of the same career incentives that rewarded Carrie Tolstedt’s silence and cost Howard Wilkinson his job will simply produce more sophisticated versions of the same evasions. The measurement has to change. So does the price of telling the truth.

It is also worth taking seriously what the regulators’ own convergence implies about where this is heading. The Federal Reserve, the FDIC, the GAO, NIST, and the IIA did not coordinate their findings—they arrived at the same conclusion independently, from different mandates, within the same few years. Convergence without coordination is usually a sign that a standard is hardening, not that a moment is passing. Institutions that treat this argument as a post-SVB overreaction, rather than the new baseline expectation, are likely to be rereading their own supervisory letters in a few years and wondering how they missed it.

The stakes of getting this right are also rising, not leveling off. Every failure examined here involved a risk that a sufficiently empowered reviewer could, in principle, still understand—a trading book, a sales incentive, a margin call. The AI models now moving into underwriting, claims, and credit decisions will not extend that same courtesy; their behavior can shift with a single retraining cycle in ways no annual attestation was ever built to catch. A second line that could not reliably catch a mismarked trading book will not reliably catch a model that has quietly drifted—not without first becoming the kind of second line this piece has been describing.

The organizations in this piece did not fail because nobody was watching. They failed because watching, on its own, was mistaken for managing. A modern second line has to be judged by a harder, more honest standard than whether the reviews got done: whether the risks that mattered actually got smaller. Everything else—the frameworks, the dashboards, the attestations—is only useful to the extent it serves that one outcome. Where it doesn’t, it is not governance. It is just paperwork with better branding.

Endnotes


[1]  Board of Governors of the Federal Reserve System, Review of the Federal Reserve’s Supervision and Regulation of Silicon Valley Bank (Washington, DC: Federal Reserve, April 28, 2023), https://www.federalreserve.gov/publications/files/svb-review-20230428.pdf; “Fed’s Barr: ‘Weaknesses in Supervision and Regulation Must Be Fixed,’” American Banker, April 28, 2023, https://www.americanbanker.com/news/feds-barr-weaknesses-in-supervision-and-regulation-must-be-fixed.

[2] The Institute of Internal Auditors, The IIA’s Three Lines Model: An Update of the Three Lines of Defense (Lake Mary, FL: IIA, July 2020), https://www.theiia.org/globalassets/documents/resources/the-iias-three-lines-model-an-update-of-the-three-lines-of-defense-july-2020/three-lines-model-updated-english.pdf.

[3]  Office of the Comptroller of the Currency, OCC Guidelines Establishing Heightened Standards for Certain Large Insured National Banks, Insured Federal Savings Associations, and Insured Federal Branches, 12 C.F.R. Part 30, Appendix D (2014); Board of Governors of the Federal Reserve System, “Supervisory Guidance on Model Risk Management,” SR Letter 11-7 (Washington, DC: Federal Reserve, April 4, 2011).

[4]  “IIA Unveils New Three Lines Model,” Radical Compliance, July 22, 2020, https://www.radicalcompliance.com/2020/07/22/iia-unveils-new-three-lines-model/.

[5]  “Howard Wilkinson,” Kohn, Kohn & Colapinto Whistleblower Case Archive, accessed August 2026, https://kkc.com/whistleblower-case-archive/howard-wilkinson/.

[6]  National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0) (Gaithersburg, MD: U.S. Department of Commerce, January 26, 2023), https://doi.org/10.6028/NIST.AI.100-1.

[7]  U.S. Senate Permanent Subcommittee on Investigations, Committee on Homeland Security and Governmental Affairs, JPMorgan Chase Whale Trades: A Case History of Derivatives Risks and Abuses (Washington, DC: U.S. Senate, March 15, 2013), https://www.hsgac.senate.gov/subcommittees/investigations/library/files/report-jpmorgan-chase-whale-trades-a-case-history-of-derivatives-risks-and-abuses-march-15-2013/.

[8]  JP Morgan Chase Whale Trades: A Case History of Derivatives Risks and Abuses, summarized in Demos, https://www.demos.org/research/jp-morgan-chase-whale-trades-case-history-derivatives-risks-and-abuses.

[9]  Independent Directors of the Board of Wells Fargo & Company, Sales Practices Investigation Report (San Francisco: Wells Fargo & Company, April 10, 2017), https://lowellmilkeninstitute.law.ucla.edu/wp-content/uploads/2018/01/WF-Board-Report.pdf.

[10]  Wells Fargo Newsroom, “Wells Fargo Board Releases Findings of Independent Investigation of Retail Banking Sales Practices and Related Matters,” press release, April 10, 2017, https://newsroom.wf.com/news-releases/news-details/2017/Wells-Fargo-Board-Releases-Findings-of-Independent-Investigation-of-Retail-Banking-Sales-Practices-and-Related-Matters/default.aspx.

[11]  “Summary of the Report of the Independent Directors of Wells Fargo & Company into Sales Practices,” Lexology, October 11, 2017, https://www.lexology.com/library/detail.aspx?g=9b82dbcc-146d-4921-847c-526ccbf505a2; Brad S. Karp, Roberto J. Gonzalez, and Vikas Desai, “Lessons Learned from the Wells Fargo Sales Practices Investigation Report,” Harvard Law School Forum on Corporate Governance, April 22, 2017, https://corpgov.law.harvard.edu/2017/04/22/lessons-learned-from-the-wells-fargo-sales-practices-investigation-report/.

[12]  Credit Suisse Group AG, Report of the Special Committee of the Board of Directors of Credit Suisse Group Regarding Archegos Capital Management, prepared by Paul, Weiss, Rifkind, Wharton & Garrison LLP (July 29, 2021), as reported in “Credit Suisse Publishes Independent Review of Archegos Losses,” Paul, Weiss news release, July 29, 2021, https://www.paulweiss.com/practices/litigation/internal-investigations/news/credit-suisse-publishes-independent-review-of-archegos-losses.

[13]  “Unpacking the Report on Credit Suisse’s Archegos Disaster,” Euromoney, July 29, 2021, https://www.euromoney.com/article/28usrfe6tdwq9fkpayosg/capital-markets/unpacking-the-report-on-credit-suisses-archegos-disaster/; “Credit Suisse and the Archegos Collapse – Lessons in Risk Management and Governance for All,” BDO, February 21, 2025, https://www.bdo.co.uk/en-gb/insights/industries/financial-services/credit-suisse-and-the-archegos-collapse-lessons-in-risk-management-and-governance.

[14]  “Whistleblower in Danish Banking Scandal: Bank Ignored Me,” Associated Press via Seattle Times, November 19, 2018, https://www.seattletimes.com/business/whistleblower-in-danish-banking-scandal-bank-ignored-me/; “Danske Bank Money Laundering Scandal – Tip of the Icebergs,” National Law Review, accessed August 2026, https://natlawreview.com/article/danske-bank-money-laundering-scandal-tip-icebergs.

[15]  “Howard Wilkinson,” Kohn, Kohn & Colapinto Whistleblower Case Archive, accessed August 2026, https://kkc.com/whistleblower-case-archive/howard-wilkinson/; “Thanks to Danske Bank Whistleblower, SEC Sets Aside $178 Million for Harmed Investors,” Whistleblower Blog, April 4, 2023, https://whistleblowersblog.org/corporate-whistleblowers/sec-whistleblowers/thanks-to-danske-bank-whistleblower-sec-sets-aside-178-million-for-harmed-investors/.

[16]  Board of Governors of the Federal Reserve System, Review of the Federal Reserve’s Supervision and Regulation of Silicon Valley Bank, i-iii; “Federal Reserve Board Announces the Results from the Review of the Supervision and Regulation of Silicon Valley Bank,” press release, April 28, 2023, https://www.federalreserve.gov/newsevents/pressreleases/bcreg20230428a.htm.

[17]  Board of Governors of the Federal Reserve System, Review of the Federal Reserve’s Supervision and Regulation of Silicon Valley Bank, 3.

[18]  Federal Deposit Insurance Corporation, FDIC’s Supervision of Signature Bank (Washington, DC: FDIC, April 28, 2023), https://www.fdic.gov/news/press-releases/2023/pr23033a.pdf; “FDIC Signature Bank Report Summary,” prepared for the U.S. House Committee on Financial Services, May 2, 2023, https://financialservices.house.gov/uploadedfiles/2023.05.02_-_fdic_signature_bank_report_summary_final.pdf.

[19]  U.S. Government Accountability Office, Bank Supervision: More Timely Escalation of Supervisory Action Needed, GAO-24-106974 (Washington, DC: GAO, 2024), https://www.gao.gov/products/gao-24-106974.

[20]  National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0) (Gaithersburg, MD: U.S. Department of Commerce, January 26, 2023), https://doi.org/10.6028/NIST.AI.100-1.

[21]  The Institute of Internal Auditors, The IIA’s Three Lines Model: An Update of the Three Lines of Defense (Lake Mary, FL: IIA, July 2020), https://www.theiia.org/globalassets/documents/resources/the-iias-three-lines-model-an-update-of-the-three-lines-of-defense-july-2020/three-lines-model-updated-english.pdf.

[22]  Independent Directors of the Board of Wells Fargo & Company, Sales Practices Investigation Report.

[23]  “Credit Suisse and the Archegos Collapse,” BDO; “Unpacking the Report on Credit Suisse’s Archegos Disaster,” Euromoney.

[24]  “Whistleblower in Danish Banking Scandal: Bank Ignored Me,” Seattle Times; “Howard Wilkinson,” Kohn, Kohn & Colapinto.

[25]  National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0).

[26]  Office of the Comptroller of the Currency, OCC Guidelines Establishing Heightened Standards, 12 C.F.R. Part 30, Appendix D; Independent Directors of the Board of Wells Fargo & Company, Sales Practices Investigation Report.

Crypto, Conflict, and Capital Flight: What Iran’s On-Chain Shock Signals for Middle East Economics and U.S. Markets


In late February 2026, shortly after coordinated U.S.–Israeli airstrikes struck targets in Tehran, blockchain analytics firms observed an abrupt spike in cryptocurrency withdrawals from Iran’s largest digital asset exchange. Within minutes of the strikes, Nobitex reportedly experienced a roughly 700 percent surge in withdrawals, with millions of dollars in crypto leaving the platform in a compressed time window.¹ This episode, while modest in absolute global market terms, offers a revealing case study in how digital assets function during geopolitical stress—and what that may signal for Middle East economics and U.S. financial markets over the next year.

A Rapid Withdrawal Shock:

Reporting indicates that nearly $3 million exited Nobitex in a single hour following the strikes, with approximately $10 million leaving Iranian exchanges over several days.² Such flows are small relative to global crypto trading volumes but significant within the Iranian financial context, where capital controls, sanctions, and currency instability already shape economic behavior.

Iran’s domestic currency, the rial, has faced long-standing pressure from inflation, sanctions, and restricted access to global banking networks. In that environment, cryptocurrencies—particularly Bitcoin and dollar-denominated stablecoins—have increasingly served as alternative stores of value and channels for cross-border transfers.³ The surge in withdrawals appears consistent with crisis-driven capital preservation behavior rather than speculative trading alone.

Crypto as a Financial “Pressure Valve”:

The events underscore crypto’s evolving role as a decentralized financial “pressure valve” in sanctioned or conflict-affected economies. When traditional banking rails are constrained or politically vulnerable, digital assets offer relative portability and censorship resistance.¹

Internet blackouts and temporary exchange disruptions complicate interpretation. Outages can cluster transactions when connectivity resumes, making withdrawal spikes appear sharper than underlying demand alone would suggest.³ Nonetheless, the pattern aligns with prior episodes in emerging markets where digital assets gained traction during currency stress.

The lesson is not that crypto replaces sovereign financial systems, but that it increasingly supplements them under strain.

Economic Implications for the Middle East (Next 12 Months):

Looking forward, several dynamics are likely to shape regional economics:

1. Expanded Informal Dollarization via Digital Assets. Sanctioned or financially constrained economies may see broader retail and institutional adoption of dollar-linked stablecoins as parallel monetary tools.

2. Heightened Regulatory and Surveillance Pressure. As crypto flows intersect with sanctions regimes, U.S. and allied regulators are likely to intensify scrutiny of exchanges, custodians, and cross-border blockchain activity.¹

3. Persistent Capital Flight Incentives. Geopolitical volatility increases incentives for households and firms to diversify outside domestic banking systems.

4. Infrastructure Fragility Risks. Internet shutdowns and exchange outages remain structural vulnerabilities in crisis environments.³

Collectively, these forces suggest that digital asset adoption in parts of the Middle East will continue—not as ideological endorsement of crypto, but as pragmatic economic hedging.

What This Means for U.S. Markets:

For U.S. investors and policymakers, the implications extend beyond regional headlines.

Oil and Energy Sensitivity. Any escalation involving Iran carries oil supply risk implications. Even absent sustained disruption, perceived risk premiums can lift energy prices.

Safe-Haven Flows and Dollar Strength. Periods of geopolitical tension historically reinforce demand for U.S. Treasuries and dollar-denominated assets. Concurrently, Bitcoin and gold often experience volatility tied to risk sentiment shifts.⁴

Regulatory Spillover. If crypto is increasingly viewed as a sanctions-adjacent vector, U.S. enforcement posture may tighten, affecting exchanges and institutional investors.

Systemic Interconnectedness. Crypto is no longer a siloed asset class. It is embedded within global liquidity networks. Geopolitical events can trigger rapid on-chain responses that ripple into equities, commodities, and foreign exchange markets.

Forecast—A Converging Risk Landscape:

Over the next year, expect three converging trends:

  1. Greater integration between geopolitical risk modeling and digital asset analytics.
  2. Increased compliance burdens on global crypto infrastructure providers.
  3. Continued volatility transmission across oil, crypto, emerging market currencies, and U.S. equities during regional escalations.

The Iranian withdrawal spike may have involved only millions of dollars—but its significance lies in what it signals: digital capital now moves at the speed of conflict.

For U.S. markets, that means geopolitical shocks increasingly transmit through hybrid financial rails—traditional and decentralized alike. Outside of economic considerations, peace is desirable for the benefit of all.


Bibliography:

  1. Yahoo Finance. “Millions of Dollars in Crypto Left Iranian Exchanges After Airstrikes.” February 2026.
  2. Economic Times. “Why Did Iran’s Largest Crypto Exchange See a 700% Withdrawal Spike Minutes After US–Israel Airstrikes Hit Tehran?” February 2026.
  3. Bitget News. “Iranian Crypto Exchange Records Surge in Withdrawals Following Tehran Strikes.” February 2026.
  4. Forbes. “Iran War, an Oil Crisis, a Crypto Stress Test.” March 2026.

Apple’s Carrier-Level Location Privacy: Strategy, Law, and the Future of Data Control

Fig. 1. Apple’s Carrier-Level Location Privacy Infographic. Jeremy Swenson and Open AI Chat GPT. 2026.

In January 2026, Apple quietly introduced a new privacy control in iOS 26.3 that allows users to limit the precision of location data shared with cellular carriers. While the feature’s initial rollout was narrow—restricted to select devices and carriers—it represents a significant shift in how location data is governed at the network level, with implications for legal investigations, platform competition, and data marketing strategies.1

Unlike app-level location permissions, which have been a focal point of mobile privacy debates for more than a decade, this control targets a less visible layer of the data stack: the information that cellular networks inherently collect as devices connect to towers. By allowing users to reduce carrier access to neighborhood-level rather than precise location data, Apple is challenging long-standing assumptions about the inevitability of carrier-side surveillance.

How the Feature Works—and Why It Matters

The new “Limit Precise Location” setting is found within Cellular Data Options on supported devices running iOS 26.3. When enabled, it reduces the granularity of location data available to participating carriers without degrading network performance or interfering with emergency services.2 Apple has emphasized that precise location data remains available to emergency responders and to apps that users have explicitly authorized, underscoring that the control is designed to limit passive collection rather than eliminate functionality.

At launch, the feature applies only to devices equipped with Apple’s newer C-series modems and is supported by a limited number of carriers, including Boost Mobile in the United States and select providers in Europe and Asia.2 This constrained availability reflects Apple’s vertically integrated approach to privacy: by controlling hardware, operating system, and key software layers, Apple can implement privacy protections that are difficult to standardize across more fragmented ecosystems.

Legal Investigation and Carrier Data: A Shifting Boundary

Carrier-level location data has long been a cornerstone of law-enforcement investigations. Historical cell-tower records can be used to infer a person’s movements, corroborate timelines, or establish proximity to crime scenes. As a result, carriers are frequent recipients of subpoenas and lawful data requests.

By limiting the precision of location data available at the carrier level, Apple’s new feature introduces friction into this investigative model. While it does not prevent lawful access to available data, it may reduce the specificity of records in cases where users have enabled the setting. This development raises important legal questions: if a platform offers a user-controlled mechanism that technically limits data collection, what obligations do carriers retain to preserve or disclose information that no longer exists in high-resolution form?

Security researchers and privacy advocates have framed the feature as a defensive response to the growing misuse of carrier data, including cases where location information has been sold, leaked, or exploited by criminal actors.3 From this perspective, the control is less about obstructing legitimate investigations and more about narrowing the attack surface of sensitive personal data.

Platform Strategy: Apple Versus Android

The contrast with Android is instructive. Android has made substantial progress in recent years with fine-grained app permissions, background location alerts, and transparency dashboards. However, it does not currently offer a system-level control that restricts the precision of location data shared directly with carriers.

This difference reflects deeper architectural realities. Android’s ecosystem spans multiple hardware manufacturers, modem vendors, and carrier customizations, making uniform carrier-level privacy controls difficult to deploy. Apple’s ability to design proprietary modems and tightly integrate them with iOS enables a level of privacy enforcement that is harder to replicate in a more open, modular platform.

From a strategic standpoint, this gives Apple a competitive narrative advantage: privacy not merely as policy, but as product design. While Android remains dominant globally in market share, Apple’s approach positions privacy as a premium feature tied to hardware, reinforcing brand trust among users who are increasingly sensitive to data misuse.

Privacy, Data Marketing, and Consumer Trust

Location data is among the most valuable assets in the data economy. It fuels targeted advertising, behavioral analytics, and predictive modeling across industries. Limiting carrier-level access does not eliminate these practices, but it does alter where and how data is collected.

Apple has been careful to frame this feature as part of a broader philosophy of data minimization rather than an absolute shield. App-level data collection, Wi-Fi triangulation, Bluetooth beacons, and other signals can still reveal detailed location information when users grant permission. The new control instead constrains a historically opaque channel of data flow that users rarely considered or understood.1

For consumers, this reinforces a key reality of modern privacy: meaningful control requires layered defenses. Carrier-level protections, app permissions, and informed usage patterns must work together. For data marketers and brokers, the shift signals a gradual tightening of default access to passive location data, encouraging greater reliance on consent-driven and aggregated sources.

Conclusion: Implications and Best Practices

Apple’s decision to limit precise location data shared with carriers marks an incremental but meaningful evolution in mobile privacy architecture. It highlights the growing tension between user autonomy, lawful access, and commercial data practices, while underscoring the strategic power of vertically integrated platforms.

Looking ahead, several implications stand out:

  1. Legal frameworks may need to adapt to scenarios where high-resolution location data is no longer uniformly available at the carrier level.
  2. Platform competition will increasingly hinge on architectural control, not just policy promises.
  3. Data markets will continue shifting toward explicit consent and diversified data sources as passive collection channels narrow.

Best practices for consumers remain straightforward but essential:

  • Regularly review system-level and app-level privacy settings.
  • Understand the scope and limits of each control.
  • Grant precise location access only when it is necessary for functionality.
  • Stay informed about how platforms and carriers handle personal data.

Ultimately, Apple’s new feature does not end location tracking, nor does it resolve every privacy concern. What it does accomplish is more subtle—and more consequential: it redraws the boundary of what is considered acceptable default data collection in the mobile ecosystem, setting a precedent that others will be pressured to follow.


Endnotes

  1. Apple Inc., “Limit precise location from cellular networks,” Apple Support, accessed January 2026, https://support.apple.com/en-euro/126101.
  2. Chance Miller, “iOS 26.3 Adds New Feature to Limit Location Data Shared With Your Carrier,” 9to5Mac, January 26, 2026, https://9to5mac.com/2026/01/26/ios-26-3-adds-new-feature-to-limit-location-data-shared-with-your-carrier/.
  3. Suzanne Smalley, “New Apple Feature Will Block Cell Networks From Capturing Precise Location Data,” The Record from Recorded Future News, January 29, 2026, https://therecord.media/new-apple-feature-block-location-data-cell-networks.

🛡️ Cyberattack on St. Paul Disrupts Systems, Triggers National Guard Response: A Wake-Up Call for City Infrastructure and Public-Private Security

Fig. 1. St. Paul Cyber Attack, St. Paul, 2025.

A major cyberattack brought critical systems across the City of St. Paul to a halt this week, prompting Governor Tim Walz to take the rare step of activating the Minnesota National Guard’s 177th Cyber Protection Team through Executive Order 24-25. The breach, which has yet to be fully disclosed in technical detail, forced the shutdown of municipal networks, libraries, payment systems, and internal applications—raising alarms about the fragility of local government infrastructure in the digital age.

This crisis has not only impacted operations but also exposed deeper vulnerabilities—from disruption of city services to potential legal and evidentiary breakdowns, especially concerning the chain of custody for digital evidence and sensitive case management platforms used by law enforcement and legal teams.

“The cyberattack… has resulted in a disruption of city services and operations, and the city has requested assistance from the State of Minnesota in the form of technical expertise and personnel,” Gov. Walz stated in the executive order. “The incident poses a threat to the delivery of critical government services.” (Walz, 2025)


Legal and Infrastructure Ramifications:

One often overlooked consequence of cyberattacks on public systems is the risk to legal integrity. City governments often store digital evidence for court cases, police body cam footage, and case records within networked systems. When such systems are compromised or taken offline, the chain of custody—a legal requirement for maintaining the integrity of evidence—may be broken. This could lead to dismissed charges, delayed court proceedings, or contested verdicts.

Beyond the courts, St. Paul’s systems underpin essential infrastructure. From 911 backend operations to building permits, utility management, and emergency communications, these disruptions ripple into residents’ lives and civic trust. Any delay in fire dispatch systems, real-time weather alerts, or even payroll processing for emergency responders can escalate into broader crisis.


Why Public-Private Partnerships Are Essential:

The attack illustrates the need for stronger collaboration between public entities and private cybersecurity firms. Municipalities often operate with limited budgets, aging infrastructure, and insufficient security staff. In contrast, private-sector vendors—ranging from cloud security providers to endpoint monitoring specialists—offer scalable defenses and expertise that cities can’t always sustain in-house.

Governor Walz’s executive order underscores this reality, stating:

“Cooperation between the Minnesota Department of Information Technology Services (MNIT), the National Guard, and other partners is necessary to protect public assets and respond to cybersecurity threats.” (Walz, 2025)

This partnership must also extend beyond technical vendors. Insurance carriers, legal risk consultants, and incident response firms should be part of proactive city planning, not just post-breach triage.


The Human Factor: Employee Training Matters:

While technical systems are critical, human error remains the top vector for cyberattacks, especially through phishing and social engineering. A well-crafted phishing email clicked by a single city employee can introduce malware into core systems.

St. Paul’s situation shows how cybersecurity education is no longer optional. Ongoing staff training—including:

  • Simulated phishing attacks
  • Clear escalation protocols
  • “Stop and verify” culture for email attachments and access requests

…is essential. Cities should treat their staff as the first line of defense, not just passive users.


The Road Ahead: What Cities Must Do Now:

The cyberattack on St. Paul should serve as a regional and national inflection point. Other cities must take this as a cue to reassess their cyber posture through the following:

Strategic Priorities:

  1. Zero Trust Implementation Limit internal access and require constant authentication, even for trusted users.
  2. Third-Party Risk Audits Review vendors, contractors, and outsourced services for security gaps.
  3. Resilient Backup and Recovery Ensure data is stored offsite and tested regularly for recovery readiness.
  4. Legal and Digital Forensics Planning Build frameworks for protecting the chain of custody in case of breach.
  5. Integrated Public-Private Playbooks Define shared roles between city staff, Guard units, and private partners in cyber response drills.
  6. Community Transparency Proactively inform the public about risks, responses, and what’s being done to rebuild digital trust.

Final Thoughts:

The breach in St. Paul is not just a local IT issue—it is a civic security event that affects courts, emergency services, legal integrity, and public confidence. Governor Walz’s activation of the National Guard is a bold signal that digital defense is now a matter of public safety.

“Immediate action is necessary to provide technical support and ensure continuity of operations,” reads Executive Order 24-25 (Walz, 2025).

Moving forward, public-private partnerships, cybersecurity training, and legal readiness must become foundational to how cities govern in the digital era. The stakes are no longer theoretical—they are real, operational, and deeply human.


References:

  1. FOX 9. (2025, July 29). Gov. Walz activates National Guard after cyberattack on city of St. Paul. https://www.fox9.com/news/gov-walz-activates-national-guard-after-cyberattack-st-paul
  2. KSTP. (2025, July 29). City of St. Paul experiencing unplanned technology disruptions. https://kstp.com/kstp-news/top-news/city-of-st-paul-experiencing-unplanned-technology-disruptions/
  3. League of Minnesota Cities. (2024, October). Cybersecurity Incident Reporting Requirements for Cities. https://www.lmc.org/news-publications/news/all/fonl-cybersecurity-incident-reporting-requirements/
  4. Reddit. (2025, July 29). Minnesota National Guard activated after city cyberattack [Discussion threads]. https://www.reddit.com/r/minnesota
  5. Walz, T. (2025, July 29). Executive Order 24-25: Activating the Minnesota National Guard Cyber Protection Team. Office of the Governor, State of Minnesota. https://mn.gov/governor/assets/EO-24-25_tcm1055-621842.pdf

About the Author:

Jeremy Swenson is a disruptive-thinking security entrepreneur, futurist/researcher, and senior management tech risk consultant. Over 17 years, he has held progressive roles at many banks, insurance companies, retailers, healthcare organizations, and even government entities. Organizations appreciate his talent for bridging gaps, uncovering hidden risk management solutions, and simultaneously enhancing processes. He is a frequent speaker, podcaster, and a published writer – CISA Magazine and the ISSA Journal, among others. He holds a certificate in Media Technology from Oxford University’s Media Policy Summer Institute, an MBA from Saint Mary’s University of MN, an MSST (Master of Science in Security Technologies) degree from the University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire. He is an alum of the Cyber Security Summit Think Tank , the Federal Reserve Secure Payment Task Force, the Crystal, Robbinsdale and New Hope Citizens Police Academy, and the Minneapolis FBI Citizens Academy. He also has certifications from Intel and the Department of Homeland Security.

Interview and Update on Ransomware Leader LockbitSupp

#lockbit #ransomware #cybersecurity #fraud #cyberextortion

Fig. 1. Dmitry Yuryevich Khoroshev, aka LockBitSupp.[1]

Law enforcement agencies spanning the United States, United Kingdom, and Australia have collectively pinpointed Russian national Dmitry Yuryevich Khoroshev as the suspected architect behind the infamous LockBit ransomware crime gang, operating under the moniker LockBitSupp. The government asserts LockBit victims span a wide array of entities, including individuals, small businesses, multinational corporations, hospitals, schools, nonprofit organizations, critical infrastructure, and government and law enforcement agencies. They and their 194 affiliates are responsible for draining an estimated $500 million from their victims over an extensive hacking spree, including [2]:

  • 148 built attacks, meaning they may or may not have attacked.
  • 119 engaged in negotiations with victims, meaning they definitely deployed attacks.
  • Of the 119 who began negotiations, there are 39 who appear not to have obtained a ransom payment.
  • 75 did not engage in any negotiation and thus did not receive any ransom payments.

The group has long evaded identification, with LockBitSupp shrouded in online anonymity due to multiple VPNs, VMs, and fake pass-through names and entities. He was so bold that he even offered a $10 million reward to anyone that could reveal his identity.[3]

This revelation comes in the wake of a substantial operation by UK law enforcement, which infiltrated LockBit’s systems, executed multiple arrests, dismantled its infrastructure, and intercepted internal communications, effectively reducing LockBit’s criminal operations but not stopping or deterring them. This was dubbed Operation Cronos and initiated in February 2024.[4]

Details disclosed by the United States Office of Foreign Assets Control (OFAC) reveal Khoroshev, aged 31 and residing in Russia, is under sanction, with his designation including various email and cryptocurrency addresses, alongside details from his Russian passport. Furthermore, the United States has filed a comprehensive indictment against him.[5] He also faces 26 criminal charges, including extortion and hacking, carrying a cumulative maximum penalty of 185 years in prison. The Justice Department has also issued a $10 million bounty for information leading to his arrest.

‘”This identification and charging of Khoroshev mark a significant milestone,” remarked Principal Deputy Assistant Attorney General Nicole Argentieri in a statement on Tuesday. “Through the meticulous efforts of our investigators and prosecutors, we have unveiled the individual behind LockBitSupp.”’[6]

According to the indictment, Khoroshev is alleged to have served as the developer and administrator of the LockBit ransomware group from its inception in September 2019 through May 2024, typically receiving a 20 percent share of each ransom payment extorted from LockBit victims.

Federal authorities utilized LockBit’s existing victim shaming website layout to disseminate press releases and provide free decryption tools. Following the FBI’s intervention, LockBitSupp reassured partners and affiliates via Russian cybercrime forums that the ransomware operation remained fully operational. Additional darknet websites were launched, promising the release of data stolen from several LockBit victims prior to the FBI’s intervention.

Despite LockBitSupp’s claims of invincibility, law enforcement efforts have made strides. The group’s modus operandi included “double extortion,” demanding separate ransom payments for both unlocking hijacked systems and promising to delete stolen data. However, the Justice Department asserts LockBit never followed through on deleting victim data, regardless of ransom payments made — all the more reason why you should not pay or trust these types.

Khoroshev marks the sixth individual indicted as an active member of LockBit. Among those indicted are Russian nationals Artur Sungatov and Ivan Gennadievich Kondratyev, alias “Bassterlord,” charged with deploying LockBit against targets in various industries across multiple countries.[7]

Lastly, leading threat intel consultancy Recorded Future facilitated an interview with LockbitSupp over an encrypted app via the dark web, where he said they got the wrong guy, among other things.[8] The interview is linked here thanks to hard work of The Record from Recorded Future News and Dmitry Smilyanets!

Disclaimer:

All citations and statements are from publicly available reports. No private info was disclosed in this article. Feedback is welcome. Attempts to retaliate against or censor my research and/or writing will be reported (you will be blocked). This was drafted with the current info, and future info could change things.

About the Author:

Jeremy Swenson is a disruptive-thinking security entrepreneur, futurist/researcher, and senior management tech risk consultant. He is a frequent speaker, published writer, podcaster, and even does some pro bono consulting in these areas. He holds an MBA from St. Mary’s University of MN, an MSST (Master of Science in Security Technologies) degree from the University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire. He is an alum of the Federal Reserve Secure Payment Task Force, the Crystal, Robbinsdale and New Hope Citizens Police Academy, and the Minneapolis FBI Citizens Academy.

References:


[1] Goodin, Dan. “Ransomware mastermind LockBitSupp reveled in his anonymity—now he’s been ID’d.” Ars Technica. 05/07/24. https://arstechnica.com/security/2024/05/the-mastermind-of-the-prolific-ransomware-group-lockbit-has-finally-been-unmasked/

[2] National Crime Agency (NCA). “LockBit leader unmasked and sanctioned.” Viewed 05/10/24. https://www.nationalcrimeagency.gov.uk/news/lockbit-leader-unmasked-and-sanctioned

[3] Burgess, Matt. “The Alleged LockBit Ransomware Mastermind Has Been Identified.” Wired. 05/07/24. https://www.wired.com/story/lockbitsupp-lockbit-ransomware/

[4] Boyton, Christopher. “Unveiling the Fallout: Operation Cronos’ Impact on LockBit Following Landmark Disruption.” Trend Micro. 04/03/24. https://www.trendmicro.com/en_us/research/24/d/operation-cronos-aftermath.html

[5] US Attorneys Office: NJ. “U.S. Charges Russian National with Developing and Operating Lockbit Ransomware.” 05/07/24. https://www.justice.gov/usao-nj/pr/us-charges-russian-national-developing-and-operating-lockbit-ransomware

[6] Sean Powers, Sean; Abdul-Malik, Jade; Temple Raston, Dina. “In interview, LockbitSupp says authorities outed the wrong guy.” The Record by Recorded Future. 05/09/24. https://therecord.media/lockbitsupp-interview-ransomware-cybercrime-lockbit  

[7] FlashPoint. “Indictment-USA-v.-Ivan-Kondratyev.” 05/17/22. https://flashpoint.io/wp-content/uploads/Indictment-USA-v.-Ivan-Kondratyev.pdf

[8] Sean Powers, Sean; Abdul-Malik, Jade; Temple Raston, Dina. “In interview, LockbitSupp says authorities outed the wrong guy.” The Record by Recorded Future. 05/09/24. https://therecord.media/lockbitsupp-interview-ransomware-cybercrime-lockbit

AT&T Faces Massive Data Breach Impacting 73 Million and Negligence Lawsuits

Fig 1. AT&T Data Breach Infographic, WLBT3, 2024.

After weeks of denials, AT&T Inc. (NYSE:T), a leading player in the telecommunications sector, has recently unveiled a substantial data breach originating from 2019, leading to the compromise of sensitive information belonging to 73 million users [1]. This data breach has since surfaced on the dark web, exposing a trove of personal data including Social Security numbers, email addresses, phone numbers, and dates of birth, impacting both current and past account holders. The compromised information encompasses names, addresses, phone numbers, and for numerous individuals, highly sensitive data such as Social Security numbers, dates of birth, and AT&T passcodes.

How can you determine if you were impacted by the AT&T data breach? Firstly, ask yourself if you ever were a customer, and do not rely solely on AT&T to notify you. By utilizing services like Have I Been Pwned, you can ascertain if your data has been compromised. Additionally, Google’s Password Checkup tool can notify you if your account details are exposed, especially if you store password information in a Google account. For enhanced security, the premium edition of Bitwarden, a top-rated recommended password manager, offers the capability to scan for compromised passwords across the internet.

One prevalent issue concerning data breaches is the tendency for individuals to overlook safeguarding their data until it’s too late. It’s a common scenario – we often don’t anticipate our personal information falling into the hands of hackers who then sell it to malicious entities online. Regrettably, given the frequency and magnitude of cyber-attacks, the likelihood of your data being exposed has shifted from an “if” to a “when” scenario.

Given this reality, it’s imperative to adopt measures to safeguard your identity and data online, including [2]:

  1. Implementing multi-factor authentication – a crucial step in thwarting hackers’ attempts to infiltrate your accounts, even if your email address is publicly available.
  2. Avoiding password reuse and promptly changing passwords if they are compromised in a data breach – this practice ensures that even if your login credentials are exposed, hackers cannot infiltrate other accounts you utilize, including the one that has experienced a breach.
  3. Investing in identity protection services, either as standalone solutions or as part of comprehensive internet security suites – identity protection software can actively monitor the web for data breaches involving you, enabling you to take proactive measures to safeguard your identity.

AT&T defines a customer’s passcode as a numeric Personal Identification Number (PIN), typically consisting of four digits. Distinguishing it from a password, a passcode is necessary for finalizing an AT&T installation, conducting personal account activities over the phone, or reaching out to technical support, according to AT&T.

How to reset your AT&T passcode:

AT&T has taken steps to reset passcodes for active accounts affected by the data breach. However, as a precautionary measure, AT&T advises users who haven’t altered their passcodes within the last year to do so. Below are the steps to change your AT&T passcode:

  1. Navigate to your myAT&T Profile.
  2. Sign in when prompted. (If additional security measures are in place and sign-in isn’t possible, AT&T suggests opting for “Get a new passcode.”)
  3. Locate “My linked accounts” and select “Edit” for the passcode you wish to update.
  4. Follow the provided prompts to complete the process.

Here is AT&T’s official statement on the matter from 03/03/24 [3]:

“Based on our preliminary analysis, the data set appears to be from 2019 or earlier, impacting approximately 7.6 million current AT&T account holders and approximately 65.4 million former account holders. Currently, AT&T does not have evidence of unauthorized access to its systems resulting in exfiltration of the data set. The company is communicating proactively with those impacted and will be offering credit monitoring at our expense where applicable. We encourage current and former customers with questions to visit http://www.att.com/accountsafety for more information.”

The hackers behind this, allegedly ShiningHacker, endeavored to profit from the pilfered data by listing it for sale on the RaidForums data theft forum, initiating the bidding at $200,000 and entertaining additional offers in increments of $30,000 [4]. Moreover, they demonstrated readiness to promptly sell the data for $1 million, highlighting the gravity and boldness of the cyber offense.

Not surprisingly, AT&T is currently confronting numerous class-action lawsuits subsequent to the company’s acknowledgment of this data breach, which compromised the sensitive information of 73 million existing and former customers [5]. Among the ten lawsuits filed, one is being handled by Morgan & Morgan, representing plaintiff Patricia Dean and individuals in similar circumstances.

The lawsuit levels allegations of negligence, breach of implied contract, and unjust enrichment against AT&T, contending that the company’s deficient security measures and failure to promptly provide adequate notification about the data breach exposed customers to significant risks, including identity theft and various forms of fraud. It seeks compensatory damages, restitution, injunctive relief, enhancements to AT&T’s data security protocols, future audits, credit monitoring services funded by the company, and a trial by jury [6].


About the Author:

Jeremy Swenson is a disruptive-thinking security entrepreneur, futurist/researcher, and senior management tech risk consultant. He is a frequent speaker, published writer, podcaster, and even does some pro bono consulting in these areas. He holds an MBA from St. Mary’s University of MN, an MSST (Master of Science in Security Technologies) degree from the University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire. He is an alum of the Federal Reserve Secure Payment Task Force, the Crystal, Robbinsdale and New Hope Citizens Police Academy, and the Minneapolis FBI Citizens Academy.

References:


[1] AT&T. “AT&T Addresses Recent Data Set Released on the Dark Web.” 03/30/24: https://about.att.com/story/2024/addressing-data-set-released-on-dark-web.html

[2] Colby, Clifford, Combs, Mary-Elisabeth; “Data From 73 Million AT&T Accounts Stolen: How You Can Protect Yourself.” CNET. 04/02/24: https://www.cnet.com/tech/mobile/data-from-73-million-at-t-accounts-stolen-how-you-can-protect-yourself/

[3] AT&T. “AT&T Addresses Recent Data Set Released on the Dark Web.” 03/30/24: https://about.att.com/story/2024/addressing-data-set-released-on-dark-web.html

[4] Naysmith, Caleb. “73 Million AT&T Users’ Data Leaked As Hacker Said, ‘I Don’t Care If They Don’t Admit. I’m Just Selling’ Auctioned At Starting Price Of $200K”. https://finance.yahoo.com/news/73-million-t-users-data-173015617.html

[5] Kan, Michael. “AT&T Faces Class-Action Lawsuit Over Leak of Data on 73M Customers.” PC Mag. 04/02/24: https://www.pcmag.com/news/att-faces-class-action-lawsuit-over-leak-of-data-on-73m-customers

[6] Kan, Michael. “AT&T Faces Class-Action Lawsuit Over Leak of Data on 73M Customers.” PC Mag. 04/02/24: https://www.pcmag.com/news/att-faces-class-action-lawsuit-over-leak-of-data-on-73m-customers

Four Key Emerging Considerations with Artificial Intelligence (AI) in Cyber Security

#cryptonews #cyberrisk #techrisk #techinnovation #techyearinreview #infosec #musktwitter #disinformation #cio #ciso #cto #chatgpt #openai #airisk #iam #rbac #artificialintelligence #samaltman #aiethics #nistai #futurereadybusiness #futureofai

By Jeremy Swenson

Fig. 1. Zero Trust Components to Orchestration AI Mashup; Microsoft, 09/17/21; and Swenson, Jeremy, 03/29/24.

1. The Zero-Trust Security Model Becomes More Orchestrated via Artificial Intelligence (AI):

The zero-trust model represents a paradigm shift in cybersecurity, advocating for the premise that no user or system, irrespective of their position within the corporate network, should be automatically trusted. This approach entails stringent enforcement of access controls and continual verification processes to validate the legitimacy of users and devices. By adopting a need-to-know-only access philosophy, often referred to as the principle of least privilege, organizations operate under the assumption of compromise, necessitating robust security measures at every level.

Implementing a zero-trust framework involves a comprehensive overhaul of traditional security practices. It entails the adoption of single sign-on functionalities at the individual device level and the enhancement of multifactor authentication protocols. Additionally, it requires the implementation of advanced role-based access controls (RBAC), fortified network firewalls, and the formulation of refined need-to-know policies. Effective application whitelisting and blacklisting mechanisms, along with regular group membership reviews, play pivotal roles in bolstering security posture. Moreover, deploying state-of-the-art privileged access management (PAM) tools, such as CyberArk for password check out and vaulting, enables organizations to enhance toxic combination monitoring and reporting capabilities.

App-to-app orchestration refers to the process of coordinating and managing interactions between different applications within a software ecosystem to achieve specific business objectives or workflows. It involves the seamless integration and synchronization of multiple applications to automate complex tasks or processes, facilitating efficient data flow and communication between them. Moreover, it aims to streamline and optimize various operational workflows by orchestrating interactions between disparate applications in a cohesive manner. This orchestration process typically involves defining the sequence of actions, dependencies, and data exchanges required to execute a particular task or workflow across multiple applications.

However, while the concept of zero-trust offers a compelling vision for fortifying cybersecurity, its effective implementation relies on selecting and integrating the right technological components seamlessly within the existing infrastructure stack. This necessitates careful consideration to ensure that these components complement rather than undermine the orchestration of security measures. Nonetheless, there is optimism that the rapid development and deployment of AI-based custom middleware can mitigate potential complexities inherent in orchestrating zero-trust capabilities. Through automation and orchestration, these technologies aim to streamline security operations, ensuring that the pursuit of heightened security does not inadvertently introduce operational bottlenecks or obscure visibility through complexity.

2. Artificial Intelligence (AI) Powered Threat Detection Has Improved Analytics:

The utilization of artificial intelligence (AI) is on the rise to bolster threat detection capabilities. Through machine learning algorithms, extensive datasets are scrutinized to discern patterns suggestive of potential security risks. This facilitates swifter and more precise identification of malicious activities. Enhanced with refined machine learning algorithms, security information and event management (SIEM) systems are adept at pinpointing anomalies in network traffic, application logs, and data flow, thereby expediting the identification of potential security incidents for organizations.

There will be reduced false positives which has been a sustained issue in the past with large overconfident companies repeatedly wasting millions of dollars per year fine tuning useless data security lakes that mostly produce garbage anomaly detection reports [1], [2]. Literally the kind good artificial intelligence (AI) laughs at – we are getting there. All the while, the technology vendors try to solve this via better SIEM functionality for an increased price at present. Yet we expect prices to drop really low as the automation matures.  

With enhanced natural language processing (NLP) methodologies, artificial intelligence (AI) systems possess the capability to analyze unstructured data originating from various sources such as social media feeds, images, videos, and news articles. This proficiency enables organizations to compile valuable threat intelligence, staying abreast of indicators of compromise (IOCs) and emerging attack strategies. Notable vendors offering such services include Darktrace, IBM, CrowdStrike, and numerous startups poised to enter the market. The landscape presents ample opportunities for innovation, necessitating the abandonment of past biases. Young, innovative minds well-versed in web 3.0 technologies hold significant value in this domain. Consequently, in the future, more companies are likely to opt for building their tailored threat detection tools, leveraging advancements in AI platform technology, rather than purchasing pre-existing solutions.

3. Artificial Intelligence (AI) Driven Threat Response Ability Advances:

Artificial intelligence (AI) isn’t just confined to threat detection; it’s increasingly playing a pivotal role in automating response actions within cybersecurity operations. This encompasses a range of tasks, including the automatic isolation of compromised systems, the blocking of malicious internet protocol (IP) addresses, the adjustment of firewall configurations, and the coordination of responses to cyber incidents—all achieved with greater efficiency and cost-effectiveness. By harnessing AI-driven algorithms, security orchestration, automation, and response (SOAR) platforms empower organizations to analyze and address security incidents swiftly and intelligently.

SOAR platforms capitalize on AI capabilities to streamline incident response processes, enabling security teams to automate repetitive tasks and promptly react to evolving threats. These platforms leverage AI not only to detect anomalies but also to craft tailored responses, thereby enhancing the overall resilience of cybersecurity infrastructures. Leading examples of such platforms include Microsoft Sentinel, Rapid7 InsightConnect, and FortiSOAR, each exemplifying the fusion of AI-driven automation with comprehensive security orchestration capabilities.

Microsoft Sentinel, for instance, utilizes AI algorithms to sift through vast volumes of security data, identifying potential threats and anomalies in real-time. It then orchestrates response actions, such as isolating compromised systems or blocking suspicious IP addresses, with precision and speed. Similarly, Rapid7 InsightConnect integrates AI-driven automation to streamline incident response workflows, enabling security teams to mitigate risks more effectively. FortiSOAR, on the other hand, offers a comprehensive suite of AI-powered tools for incident analysis, response automation, and threat intelligence correlation, empowering organizations to proactively defend against cyber threats. Basically, AI tools will help SOAR tools mature so security operations centers (SOCs) can catch the low hanging fruit; thus, they will have more time for analysis of more complex threats. These AI tools will employ the observe, orient, decide, act (OODA) Loop methodology [3]. This will allow them to stay up to date, customized, and informed of many zero-day exploits. At the same time, threat actors will constantly try to avert this with the same AI but with no governance.

4. Artificial Intelligence (AI) Streamlines Cloud Security Posture Management (CSPM):

With the escalating migration of organizations to cloud environments, safeguarding the security of cloud assets emerges as a paramount concern. While industry giants like Microsoft, Oracle, and Amazon Web Services (AWS) dominate this landscape with their comprehensive cloud offerings, numerous large organizations opt to establish and maintain their own cloud infrastructures to retain greater control over their data and operations. In response to the evolving security landscape, the adoption of cloud security posture management (CSPM) tools has become imperative for organizations seeking to effectively manage and fortify their cloud environments.

CSPM tools play a pivotal role in enhancing the security posture of cloud infrastructures by facilitating continuous monitoring of configurations and swiftly identifying any misconfigurations that could potentially expose vulnerabilities. These tools operate by autonomously assessing cloud configurations against established security best practices, ensuring adherence to stringent compliance standards. Key facets of their functionality include the automatic identification of unnecessary open ports and the verification of proper encryption configurations, thereby mitigating the risk of unauthorized access and data breaches. “Keeping data safe in the cloud requires a layered defense that gives organizations clear visibility into the state of their data. This includes enabling organizations to monitor how each storage bucket is configured across all their storage services to ensure their data is not inadvertently exposed to unauthorized applications or users” [4]. This has considerations at both the cloud user and provider level especially considering artificial intelligence (AI) applications can be built and run inside the cloud for a variety of reasons. Importantly, these build designs often use approved plug ins from different vendors making it all the more complex.

Furthermore, CSPM solutions enable organizations to proactively address security gaps and bolster their resilience against emerging threats in the dynamic cloud landscape. By providing real-time insights into the security status of cloud assets, these tools empower security teams to swiftly remediate vulnerabilities and enforce robust security controls. Additionally, CSPM platforms facilitate comprehensive compliance management by generating detailed reports and audit trails, facilitating adherence to regulatory requirements and industry standards.

In essence, as organizations navigate the complexities of cloud adoption and seek to safeguard their digital assets, CSPM tools serve as indispensable allies in fortifying cloud security postures. By offering automated monitoring, proactive threat detection, and compliance management capabilities, these solutions empower organizations to embrace the transformative potential of cloud technologies while effectively mitigating associated security risks.

About the Author:

Jeremy Swenson is a disruptive-thinking security entrepreneur, futurist / researcher, and senior management tech risk consultant. He is a frequent speaker, published writer, podcaster, and even does some pro bono consulting in these areas. He holds an MBA from St. Mary’s University of MN, an MSST (Master of Science in Security Technologies) degree from the University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire. He is an alum of the Federal Reserve Secure Payment Task Force, the Crystal, Robbinsdale and New Hope Citizens Police Academy, and the Minneapolis FBI Citizens Academy.

References:


[1] Tobin, Donal; “What Challenges Are Hindering the Success of Your Data Lake Initiative?” Integrate.io. 10/05/22: https://www.integrate.io/blog/data-lake-initiative/

[2] Chuvakin, Anton; “Why Your Security Data Lake Project Will … Well, Actually …” Medium. 10/22/22. https://medium.com/anton-on-security/why-your-security-data-lake-project-will-well-actually-78e0e360c292

[3] Michael, Katina, Abbas, Roba, and Roussos, George; “AI in Cybersecurity: The Paradox.” IEEE Transactions on Technology and Society. Vol. 4, no. 2: pg. 104-109. 2023: https://ieeexplore.ieee.org/abstract/document/10153442

[4] Rosencrance, Linda; “How to choose the best cloud security posture management tools.” CSO Online. 10/30/23: https://www.csoonline.com/article/657138/how-to-choose-the-best-cloud-security-posture-management-tools.html

Seven Cyber-Tech Observations of 2022 and What it Means for 2023.

Minneapolis 01/17/23

cryptonews #cyberrisk #techrisk #techinnovation #techyearinreview #ftxfraud #googlemandiant #infosec #musktwitter #twitterfiles #disinformation #cio #ciso #cto

By Jeremy Swenson

Summary:

Fig. 1. 2022 Cyber Year in Review Mashup; Stock, 2023.

The pandemic continues to be a big part of the catalyst for digital transformation in tech automation, identity and access management (IAM), big data, collaboration tools, artificial intelligence (AI), and increasingly the supply chain. Disinformation efforts morphed and grew last year with stronger crypto tie ins challenging data and culture; Twitter hype pump and dumps for example. Additionally, cryptocurrency-based money laundering, fraud, and Ponzi schemes increased partly due to weaknesses in the fintech ecosystem around compliance, coin splitting/mixing fog, and IAM complexity. This requires better blacklisting by crypto exchanges and banks to stop these illicit transactions erroring on the side of compliance, and it requires us to pay more attention to knowing and monitoring our own social media baselines.

The Costa Rican Government was forced to declare a national emergency on 05/08/22 because the Conti Ransomware intrusion had extended to most of its governmental entities. This was a more advanced and persistent ransomware with Russian gang ties (Associated Press; NBC News, 06/17/22). This highlights the need for smaller countries to better partner with private infrastructure providers and to test for worst-case scenarios.

We no longer have the same office due to mass work from home (WFH) and the mass resignation/gig economy. This infers increased automated zero-trust policies and tools for IAM with less physical badge access required. The security perimeter is now more defined by data analytics than physical/digital boundaries. Education and awareness around the review and removal of non-essential mobile apps grows as a top priority as mobile apps multiply. All the while, data breaches, and ransomware reach an all-time high while costing more to mitigate. Lastly, all these things make the Google acquisition of Mandiant more relevant and plausibly one of the most powerful security analytics and digital investigation entities in the world rivaling nation-state intelligence agencies.

Intro:

Every year I like to research and commentate on the most impactful security technology and business happenings from the prior year. This year is unique since crypto money laundering via splitting/mixing, disinformation, the pandemic, and mass resignation/gig economy continue to be a large part of the catalyst for most of these trends. All these trends are likely to significantly impact small businesses, government, education, high-tech, and large enterprise in big and small ways.

1) The Main Purpose of Cryptocurrency Mixer and/or Splitter Services is Fraud and Money Laundering.

Cryptocurrency mixer and/or splitter services serve no valid “real-world” ethical business use case considering the relevant fintech and legal options open. Even in the very rare case when you are a refugee fleeing a financially abusive government regime or a terrorist organization is seeking to steal your assets while the national currency is failing, like in Venezuela, which I wrote about in my 2014 article, “Thought$ On The Future of Digital Curren¢y For A Better World” – that is about political revolution and your personal safety more than anything else. Although cases like this give a valid reason why you might want to mix and/or split your crypto assets, that is not fully the same use case we’re talking about here with the recent uptick of ill-intended crypto mixer and/or splitter service use. Therefore, it’s only fair that we discuss the most likely and common use case, which is trending up, and not the few rare edge cases. This use case would be fraud, Ponzi schemes, and money laundering.

The evidence does not support that a regular crypto exchange is the same thing as a mixer and/or splitter service. For definition’s sake, I am not defining mixing and/or splitting cryptocurrency as the same thing as selling, buying, or converting it – all of this can be done on one or more of the crypto exchanges which is why they are called exchanges. If they are the same or even considerably similar, then why are people and orgs using the mixer and/or splitter services at all? They use them because they offer a considerably different service. Using a mixer and/or splitter service assumes you have gotten some crypto beforehand, from a separate exchange – a step or more before in the daisy chain. This can be done via legal or illegal means. Moreover, why are people paying repeated and hugely excessive fees for these services? The fees are out of line with anything possibly comparable because there is higher compliance and legal risk for the operators of them in that they could get sanctioned like Blender-IO, FTX, Coinbase, Gemini, and others.

You can still have privacy if that is what you are seeking via a semblance of legal moves such as a trust tied to a separate legal entity, family office entity, converting to real estate, and marriage entity – if you have time to do the paperwork. Legally savvy people have anonymity over their assets often to avoid fraudsters, sales reps, and just privacy for privacy’s sake – but again still not the same use case. Even when people/orgs use these legal instruments for privacy, they still have compliance reporting and tax obligations – some disclosure. Keep in mind some disclosure serves to protect you, that you in fact own the assets you say you own. Using these legal instruments with the right technical security including an encrypted VPN and multifactor authentication serves to sustain privacy, and you will then not need a crypto mixer and/or splitter.

Yet if you had cryptocurrency and wanted strong privacy to protect your assets, why would you not at least use some of the aforementioned legal instruments or the like? Mostly because any attorney worth anything would be obligated to report this blatant suspected fraud, and would not want to tarnish their name on the filings, etc. Specifically, the attorney would have to see and know where and what entities the crypto was coming from and going to, under what contexts, and that could trigger them to report or refuse to work with them – a fraudster would want to avoid getting detected.

Specifically, the use of multiple legal entities in different countries in a daisy chain of crypto coin mixing and/or splitting tends to be the pattern for persistent fraud and money laundering. That was the case in the $4.5-billion-dollar crypto theft out of NY (Crocodile of Wall Street), the Blender mixing fraud, and many other cases.

A recent May 2022 U.S. Treasury press release concerning mixer service money laundering described it this way (Dept of Treasury; Press Release, 05/06/22):

“Blended.io (Blender) is a virtual currency mixer that operates on the Bitcoin blockchain and indiscriminately facilitates illicit transactions by obfuscating their origin, destination, and counterparties. Blender receives a variety of transactions and mixes them together before transmitting them to their ultimate destinations. While the purported purpose is to increase privacy, mixers like Blender are commonly used by illicit actors. Blender has helped transfer more than $500 million worth of Bitcoin since its creation in 2017. Blender was used in the laundering process for DPRK’s Axie Infinity heist, processing over $20.5 million in illicit proceeds.”

Fig 2. U.S. Treasury Dept; Blener.io Crypto Mixer Fraud, 2022.

The question we as a society should be thinking about is tech ethics. What design feature crosses the line to enable fraud too much such that it is not pursued? For example, Silk Road crossed the line, selling illegal drugs, extortion, and other crime. Hacker networks cross the line when they breach companies and steal their credit card data and put it for sale on the dark web. Facebook crossed the line when it enabled bias and undue favor to impact policy outcomes.

Crypto mixer and/or splitter services (not mere crypto exchanges) are about as close to “money laundering as a service” as it gets – relative to anything else technically available excluding the dark web where there are far worse things available technically. Obviously, the developers, product owners, and project managers behind the crypto mixer and/or splitter services like this are serving the fraud and money laundering use case more than anything else. Some semblance of the organized crime rings is very likely giving them money and direction to this end.

If you are for and use mixer and/or splitter services then you run the risk of having your digital assets mixed with dirty digital assets, you have extortion high fees, you have zero customer service, no regulatory protection, no decedent Terms of Service and/or Privacy Policy if any, and you have no guarantee that it will even work the way you think it will.

In fact, you have so much decentralized “so-called” privacy that it could work against you. For example, imagine you pay the high fees to mix and split your crypto multiple times, and then your crypto is stolen by one of the mixing and/or splitting services. This is likely because they know many of their customers are committing fraud and money laundering; yet even if they are not these platforms are associated with that. Therefore, if the platform operators steal their crypto in this process, the victims have little incentive to speak up. Moreover, the mixing and/or splitting service companies have a nice cover to steal it, privacy. They won’t admit that they stole it but will say something like “everything is private and so we can’t see or know but you are responsible for what private assets you have or don’t have”. They will say something like “stealing it is impossible” which of course is a complete lie.

In sum, what reason do you have to trust a crypto mixing and/or splitting service with your digital assets as outlined above as they are hardly incentivized to protect them or you and operate in the shadows of antiquated non-western fintech regulation. So what really do you get besides likely fraud? What is the business rationale behind using these services as outlined above considering no solid argument or evidence can support it is privacy alone, and what net benefit do you get besides business-enabling money laundering and fraud?

Now there are valid use cases for crypto and blockchain technology generally and here are five of them:

1.      Innovative tech removing the central bank for peer-to-peer exchange that is faster and more global, especially helping the underbanked countries.

2.      Smart contracts can be built on blockchain.

3.      Blockchain can be used for crowdfunding.

4.      Blockchain can be used for decentralized storage.

5.      The traditional cash and coin supply chain is burdensomely wasteful, costly, dirty, and counterfeiting is a real issue. Why do you need to carry ten dollars in quarters or a wad of twenty-dollar bills or even have that be a nation’s economic backing in today’s tech world?

Here are six tips to identify crypto-related scams:

1.      With most businesses, it should be easy to find out who the key operators are. If you can’t find out who is running a cryptocurrency or exchange via LinkedIn, Medium, Twitter, a website, or the like be very cautious.

2.      Whether in cash or cryptocurrency, any business opportunity promising free money is likely to be fake. If it sounds too good to be true it likely is. Multi-level marketing is one old example of this scam.

3.      Never mix online dating and investment/financial advice. If you meet someone on a dating site or social media app, and then they want to show you how to invest in crypto or they ask you to send them crypto. No matter what sob story and huge return they are claiming it’s a scam (FTC).

4.      Watch out for scammers who pretend to be celebrities who can multiply any cryptocurrency you send them. If you click on an unexpected link they send or send cryptocurrency to a so-called celebrity’s QR code, that money will go straight to a scammer, and it’ll be gone. Celebrities don’t have time to contact random people on social media, but they are easily impersonated (FTC).

5.      Celebrities are however used to pump crypto prices via social media, so they get a windfall, and everyone else takes a hit. Watch out for crypto like Dogecoin which is heavily tied to celebrity pumps with no real-world business value. If you are lucky enough to get ahead, get out then.

6.      Watch out for scammers who make big claims without details, white papers, filings, or explanations at all. No matter what the investment, find out how it works and ask questions about where your money is going. Honest investment managers or advisors want to share that information and will back it up with details in many documents and filings (FTC). 

2) Disinformation Efforts Are Further Exposed:

Disinformation has not slowed down any in 2022 due to sustained advancements in communications technologies, the growth of large social media networks, and the “appification” of everything thereby increasing the ease and capability of disinformation. Disinformation is defined as incorrect information intended to mislead or disrupt, especially propaganda issued by a government organization to a rival power or the media. For example, governments creating digital hate mobs to smear key activists or journalists, suppress dissent, undermine political opponents, spread lies, and control public opinion (Shelly Banjo; Bloomberg, 05/18/2019).

Today’s disinformation war is largely digital via platforms like Facebook, Twitter, Instagram, Reddit, WhatsApp, Yelp, Tik-tok, SMS text messages, and many other lesser-known apps. Yet even state-sponsored and private news organizations are increasingly the weapon of choice, creating a false sense of validity. Undeniably, the battlefield is wherever many followers reside. 

Bots and botnets are often behind the spread of disinformation, complicating efforts to trace and stop it. Further complicating this phenomenon is the number of app-to-app permissions. For example, the CNN and Twitter apps having permission to post to Facebook and then Facebook having permission to post to WordPress and then WordPress posting to Reddit, or any combination like this. Not only does this make it hard to identify the chain of custody and original source, but it also weakens privacy and security due to the many authentication permissions involved. The copied data is duplicated at each of these layers, which is an additional consideration.

We all know that false news spreads faster than real news most of the time, largely because it is sensationalized. Since most disinformation draws in viewers which drives clicks and ad revenues; it is a money-making machine. If you can significantly control what’s trending in the news and/or social media, it impacts how many people will believe it. This in turn impacts how many people will act on that belief, good or bad. This is exacerbated when combined with human bias or irrational emotion.

In 2022 there were many cases of fake crypto initial coin offerings (ICOs) and related scams including the Titanium Blockchain where investors lost at least $21 million (Dept of Justice; Press Release, 07/25/22). The Celsius’ crypto lending platform also came tumbling down largely because it was a social media-hyped Ponzi scheme (CNBC; Arjun Kharpal, 07/08/22). This negatively impacts culture by setting a misguided example of what is acceptable.

Elon Musk’s controversial purchase of Twitter for $44 billion in October 2022 resulted in a big management shakeup and strategy change (New York Times; Kate Conger and Lauren Hirsch, 10/27/22). The goal was to reduce bias and misinformation in the name of free and fair speech. To this end, the new Twitter under Musk’s direction produced “The Twitter Files” which are a set of internal Twitter, Inc documents made public beginning in December 2022. This was done with the help of independent journalists Matt Taibbi, Bari Weiss, Lee Fang, and authors Michael Shellenberger, David Zweig and Alex Berenson.

The sixth release of the Twitter Files was on 12/12/22 and revealed (Real Clear Politics; Kalev Leetaru, 12/20/22):

“Twitter granted great deference to government agencies and select outside organizations. While any Twitter user can report a tweet for removal, officials at the platform provided more direct and expedited channels for select organizations, raising obvious ethical questions about the government’s non-public efforts at censorship. It also captured the degree to which law enforcement requested information – from the physical location of users to foreign influence – from social platforms outside of formal court orders, raising important questions of due process and accountability.”

Fig. 3. Elon Musk Twitter Freedom of Speech Mash Up; Stock / Getty, 2022.

With the help of Twitter’s misinformation, huge swaths of confused voters and activists aligned more with speculation and emotion/hype than unbiased facts, and/or project themselves as fake commentators. This dirtied the data in terms of the election process and only begs the question – which parts of the election information process are broken? This normalizes petty policy fights, emotional reasoning, lack of unbiased intellectualism – negatively impacting western culture. All to the threat actor’s delight. Increased public-to-private partnerships, more educational rigor, and enhanced privacy protections for election and voter data are needed to combat this disinformation.

3) Identity and Access Management (IAM) Scrutiny Drives Zero Trust Orchestration:

The pandemic and mass resignation/gig economy has pushed most organizations to amass work from home (WFH) posture. Generally, this improves productivity making it likely to become the new norm. Albeit with new rules and controls. To support this, 51% of business leaders started speeding up the deployment of zero trust capabilities in 2020 (Andrew Conway; Microsoft, 08/19/20) and there is no evidence to suggest this is slowing down in 2022 but rather it is likely increasing to support zero trust orchestration.

Orchestration is enhanced automation between partner zero trust applications and data, while leaving next to no blind spots. This reduces risk and increases visibility and infrastructure control in an agile way. The quantified benefit of deploying mature zero trust capabilities including orchestration is on average $ 1.51 million dollars less in breach response costs when compared to an organization who has not rolled out zero trust capabilities (IBM Security; Cost of A Data Breach Report, 2022). 

Fig. 4. Zero Trust Components to Orchestration; Microsoft, 09/17/21

Zero trust moves organizations to a need-to-know-only access mindset with inherent deny rules, all the while assuming you are compromised. This infers single sign-on at the personal device level and improved multifactor authentication. It also infers better role-based access controls (RBAC), firewalled networks, improved need-to-know policies, effective whitelisting and blacking listing of apps, group membership reviews, and state of the art privileged access management (PAM) tools for the next year. In the future more of this is likely to better automate and orchestrate (Fig. 4.) zero trust abilities so that one part does not hinder another part via complexity fog.

4) Security Perimeter is Now More Defined by Data Analytics than Physical/Digital Boundaries:

This increased WFH posture blurs the security perimeter physically and digitally. New IP addresses, internet volume, routing, geolocation, and virtual machines (VMs) exacerbate this blur. This raises the criticality of good data analytics and dashboarding to define the digital boundaries in real time. Therefore, prior audits, security controls, and policies may be ineffective. For instance, empty corporate offices are the physical byproduct of mass WFH, requiring organizations to set default disable for badge access. Extra security in or near server rooms is also required. The pandemic has also made vendor interactions more digital, so digital vendor connection points should be reduced and monitored in real time, and the related exception policies should be re-evaluated.

New data lakes and machine learning informed patterns can better define security perimeter baselines. One example of this includes knowing what percent of your remote workforce is on what internet providers and what type? For example, Google fiber, Comcast cable, CenturyLink DSL, ATT 5G, etc. There are only certain modems that can go with each of these networks and that leaves a data trail. Of course, it could be any type of router. What type of device do they connect with MAC, Apple, VM, or other, and if it is healthy – all can be determined in relation to security perimeter analytics.

5) Cyber Firm Mandiant Was Purchased by Google Spawning Private Sector Security Innovation.

Google completed its acquisition of security and incident response firm Mandiant for $5.4 billion dollars in Sept 2022 (Google Cloud; Thomas Kurian CEO – Google Cloud, 09/12/22). This acquisition positions the search and advertising leader with better cloud security infrastructure, better market appeal, and more diversification. With a more advanced and integrated security foundation, Google Cloud can compete better against market leader Amazon Web Services (AWS) and runner-up Microsoft Azure. They will do this on more than price because features will likely grow to leverage their differentiating machine learning and analytical abilities via clients throughout the industry.

Other benefits of integrating Mandiant include improved automated breach response logic. This is because security teams can now gather the required data and then share it across Google customers to help analyze ransomware threat variants. Many of Google’s security related products will also be enhanced by Mandiant’s threat intelligence and incident response capabilities. Some of these products include Google’s security orchestration, automation and response (SOAR) tool which is described this way, “Part of Chronicle Security Operations, Chronicle SOAR enables modern, fast and effective response to cyber threats by combining playbook automation, case management and integrated threat intelligence in one cloud-native, intuitive experience” (Google; Google Cloud, 01/16/23).

According to Dave Cundiff, CISO at Cyvatar, “if Google, as one of the leaders in data science, can progress and move forward the ability to prevent the unknown vectors of attack before they happen based upon the mountains of data available from previous breaches investigated by Mandiant, there could truly be a significant advancement in cybersecurity for its cloud customers” (SC Media; Steve Zurier, 04/15/22). This results in a strong focus on prevention vs. response, which is greatly needed. Lastly, since AWS and Microsoft will be unlikely to hire Mandiant directly because Google owns them, they will likely look to acquire another security services player soon.

6) Data Breaches Have Increased in Number and Cost but Are Generally Identified Faster.

The pandemic has continued to be a part of the catalyst for increased lawlessness including fraud, ransomware, data theft, and other types of profitable hacking. Cybercriminals are more aggressively taking advantage of geopolitical conflict and legal standing gaps. For example, almost all hacking operations are in countries that do not have friendly geopolitical relations with the United States or its allies – and all their many proxy hops would stay consistent with this. These proxy hops are how they hide their true location and identity.

Moreover, with local police departments extremely overworked and understaffed with their number one priority being responding to the huge uptick in violent crime in most major cities, white-collar cybercrimes remain a low priority. Additionally, local police departments have few cyber response capabilities depending on the size of their precinct. Often, they must sheepishly defer to the FBI, CISA, and the Secret Service, or their delegates for help. Yet not unsurprisingly, there is a backlog for that as well with preference going to large companies of national concern that fall clearly into one of the 16 critical infrastructures. That is if turf fights and bureaucratic roadblocks don’t make things worse. Thus, many mid and small-sized businesses are left in the cold to fend for themselves which often results in them paying ransomware, and then being a victim a second time all the while their insurance carrier denes their claims, raises their rate, and/or drops them.

Further complicating this is lack of clarity on data breach and business interruption insurance coverage and terms. Keep in mind most general business liability insurance policies and terms were drafted before hacking was invented so they are by default behind the technology. Most often general liability business insurance covers bodily injuries and property damage resulting from your products, services, or operations. Please see my related article “10 Things IT Executives Must Know About Cyber Insurance” to understand incident response and to reduce the risk of inadequate coverage and/or claims denials.

Data breaches are more expensive than ever. IBM’s 2022 Annual Cost of a Date Breach Report revealed increased costs associated with the average data breach at an estimated $4.35 million per organization. This is a $110,000 year-over-year increase at 2.6% and the highest in the reports history (Fig. 5). However, the average time to identify and contain a data breach decreased both decreased by 5 days (Fig 6). This is a total decrease of 10 days or 3.5%. Yet this is for general data breaches and not ransomware attacks.

Fig 5. Cost of A Data Breach Increases 2021 to 2022 (IBM Security, 2022).
Fig. 6. Average Time To Identify and Contain a Data Breaches Decreases 2021 to 2022, (IBM Security, 2022).

Lastly, this is a lot of money for an organization to spend on a breach. Yet this amount could be higher when you factor in other long-term consequence costs such as increased risk of a second breach, brand damage, and/or delayed regulatory penalties that were below the surface – all of which differs by industry. In sum, it is cheaper and more risk prudent to spend even $4.35 million or a relative percentage at your organization on preventative zero trust capabilities than to deal with the cluster of a data breach.

7) The Costa Rican Government was Heavily Hacked and Encrypted by the Conti Ransomware.

The Costa Rican Government was forced to declare a national emergency on 05/08/22 because the Conti Ransomware intrusion had extended to most of its governmental entities. Conti is an advanced and persistent ransomware as a service attack platform. The attackers are believed to the Russian cybercrime gang Wizard Spider (Associated Press; NBC News, 06/17/22). “The threat actor entry point was a system belonging to Costa Rica’s Ministry of Finance, to which a member of the group referred to as ‘MemberX’ gained access over a VPN connection using compromised credentials” (Bleeping Computer; Ionut Ilascu, 07/21/22). Phishing is a common way to get in to monitor for said credentials but in this case it was done “Using the Mimikatz post-exploitation tool for exfiltrating credentials, the adversary collected the logon passwords and NTDS hashes for the local users, thus getting “plaintext and bruteable local admin, domain and enterprise administrator hashes” (Bleeping Computer; Ionut Ilascu, 07/21/22).

Fig. 7. Costa Rica Conti Ransomware Attack Architecture; AdvIntel via (Bleeping Computer; Ionut Ilascu, 07/21/22).

This resulted in 672GB of data leaked and dumped or 97% of what was stolen (Bleeping Computer; Ionut Ilascu, 07/21/22). Some believe Costa Rica was targeted because they supported Ukraine against Russia. This highlights the need for smaller countries to better partner with private infrastructure providers and to test for worst-case scenarios.

Take-Aways:

The pandemic remains a catalyst for digital transformation in tech automation, IAM, big data, collaboration tools, and AI. We no longer have the same office and thus less badge access is needed. The growth and acceptability of mass WFH combined with the mass resignation/gig economy remind employers that great pay and culture alone are not enough to keep top talent. Signing bonuses and personalized treatment are likely needed. Single sign-on (SSO) will expand to personal devices and smartphones/watches. Geolocation-based authentication is here to stay with double biometrics likely. The security perimeter is now more defined by data analytics than physical/digital boundaries, and we should dashboard this with machine learning and AI tools.

Education and awareness around the review and removal of non-essential mobile apps is a top priority. Especially for mobile devices used separately or jointly for work purposes. This requires a better understanding of geolocation, QR code scanning, couponing, digital signage, in-text ads, micropayments, Bluetooth, geofencing, e-readers, HTML5, etc. A bring your own device (BYOD) policy needs to be written, followed, and updated often informed by need-to-know and role-based access (RBAC) principles. Organizations should consider forming a mobile ecosystem security committee to make sure this unique risk is not overlooked or overly merged with traditional web/IT risk. Mapping the mobile ecosystem components in detail is a must.

IT and security professionals need to realize that alleviating disinformation is about security before politics. We should not be afraid to talk about it because if we are then our organizations will stay weak and insecure and we will be plied by the same political bias that we fear confronting. As security professionals, we are patriots and defenders of wherever we live and work. We need to know what our social media baseline is across platforms. More social media training is needed as many security professionals still think it is mostly an external marketing thing. Public-to-private partnerships need to improve and app to app permissions need to be scrutinized. Enhanced privacy protections for election and voter data are needed. Everyone does not need to be a journalist, but everyone can have the common sense to identify malware-inspired fake news. We must report undue bias in big tech from an IT, compliance, media, and a security perspective.

Cloud infra will continue to grow fast creating perimeter and compliance complexity/fog. Organizations should preconfigure cloud-scale options and spend more on cloud-trained staff. They should also make sure that they are selecting more than two or three cloud providers, all separate from one another. This helps staff get cross-trained on different cloud platforms and add-ons. It also mitigates risk and makes vendors bid more competitively. 

In regard to cryptocurrency, NFTs, ICOs, and related exchanges – watch out for scammers who make big claims without details, white papers, filings, or explanations at all. No matter what the investment, find out how it works and ask questions about where your money is going. Honest investment managers or advisors want to share that information and will back it up with details in many documents and filings (FTC).

Moreover, better blacklisting by crypto exchanges and banks is needed to stop these illicit transactions erroring on the side of compliance, and it requires us to pay more attention to knowing and monitoring our own social media baselines. If you are for and use crypto mixer and/or splitter services then you run the risk of having your digital assets mixed with dirty digital assets, you have extortion high fees, you have zero customer service, no regulatory protection, no decent Terms of Service and/or Privacy Policy if any, and you have no guarantee that it will even work the way you think it will.

About the Author:

Jeremy Swenson is a disruptive-thinking security entrepreneur, futurist/researcher, and senior management tech risk consultant. Over 17 years he has held progressive roles at many banks, insurance companies, retailers, healthcare orgs, and even governments including being a member of the Federal Reserve Secure Payment Task Force. Organizations relish in his ability to bridge gaps and flesh out hidden risk management solutions while at the same time improving processes. He is a frequent speaker, published writer, podcaster, and even does some pro bono consulting in these areas. As a futurist, his writings on digital currency, the Target data breach, and Google combining Google + video chat with Google Hangouts video chat have been validated by many. He holds an MBA from St. Mary’s University of MN, an MSST (Master of Science in Security Technologies) degree from the University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire.

Five Things Small to Medium Businesses Can Do To Mitigate Cyber Risk

Small to medium businesses should evaluate their operational resilience and cyber-security practices quarterly. A good start is the US-CERT’s Cyber Resilience Review (CRR), which helps organizations assess enterprise programs and practices across 10 domains including risk management, incident management, service continuity, and more (SBA, 2018).

b7.contentThey can also use the CSET (Cyber Security Evaluation Tool), which is a free customizable multi-framework DHS created general cyber security assessment. A 2017 report published by Keeper Security and the Ponemon Institute found more than 50% of small and medium business had been breached in the past 12 months, but only 14% of them rated their ability to defend against cyber-threats as “highly effective” (Keeper / Ponemon, 2017). Here are five steps you can take to shield your small business from cyber-attacks:

1) Train Staff Often

Most cyber-attacks take the form of phishing and spear phishing which is hackers targeting individuals rather than computer systems – typically with the help of good social engineering (IT Governance Blog, 2017). Therefore, employees need to be educated to roll back what they share on social media and to opt out of data harvesting when they can. Training needs to be ongoing today because the threat landscape and technology change so fast. For example, ransomware was not a serious attack vector 6 years ago, but it is front and center today. Additionally, crypto-currency mining networks is an exploit vector that is arguably less than 2 years old and growing rapidly. Lastly, training more often improves the company security culture and that’s directly related to keeping their business reputation and core customer base. Here are a few more training necessities:

  1. Follow cyber security best practices and conduct audits on a regular basis – based on your selected one or two frameworks (Cobit 5, ISO 2700, etc)
  2. Use games contest and prizes to teach cyber safety – leadership must do this as well.
  3. Notify and educate staff of any current cyber-attacks – have a newsletter.
  4. Teach them how to handle and protect sensitive data – do lunch and learns.

2) Secure Wireless Networks

Wireless networks can be easily exploited by cyber attackers, unknowing guests, and even angry customers. Your network is not like a coffee shop community room but rather it’s like a bank vault with many segmented areas – map the segments and know their rank order value. To harden your wireless network, avoid WEP (Wired Equivalent Privacy) encryption (which can be cracked in minutes) and use only WPA2, which uses AES-based encryption and provides better security than WPA.

Fig 1. (WPA2 Selection Screen Clip).

wpa_top

If you have a Wi-Fi network, be sure access to the router is secured by a password and hidden so that it does not broadcast the network name. To hide your Wi-Fi network, set up your wireless access point or router so it does not broadcast the network name, known as the Service Set Identifier (SSID). Also, remember to password-protect access to the router. Additionally, for protection against brute-force attacks, protect your network with a complex passphrase containing at least 25 characters and including a mix of letters, upper and lower case and numerals and symbols. Use a firewall and encryption to safeguard your internet connection.

3) Control Access / IAM and Audit Access Often

Administrative access to your systems should only be granted on a need-to-know basis – least privilege principle. The correct job roles should be in the correct windows access groups. Keep sensitive data – such as payroll – out of the hands of anyone who doesn’t need it to do their job, marketing for example. Remove unused, stale, or unnecessary IAM users/credentials. Also, consider decommissioning old systems for risk reduction and cost savings – with the appropriate project analysis done. Use a secure strong password especially for single sign on interfaces – two factor authentication. Organizations should audit their IAM user activity to see which users haven’t logged into AWS for at least 90 days and revoke their permissions. Monitor user activity in all cloud services (including IAM user activity) to identify abnormal activity indicative of threats arising from a compromised account, or malicious/negligent internal employee – when corroborated with event logs and related intelligence.

4) Back up and Secure Your Systems and Data but Don’t Over Retain

Ransomware, or viruses used by hackers to encrypt an organization’s computer files and detain them until a ransom is paid, has emerged as a serious and growing threat to businesses worldwide, according to the FBI (FBI CISO Report 2018). Whether data is stored in the cloud, on-premises, or in a hybrid data center, businesses should back up all files to hard drives stored in a safe place outside the reach of cyberthieves. These are some key data backup subpoints.

  1. Limit access to sensitive data to only a few authorized employees.
  2. Encrypt all your sensitive data – do not over-classify.
  3. Backup your data periodically and store it in an offsite location.
  4. Protect all devices with access to your data – third party vendor implications.
  5. If you accept credit cards transactions, secure each point of sale.

5) Create a Guidebook for Mobile Security

While mobile devices allow for work anywhere, anytime, they create significant security challenges. The FCC suggests requiring users to password-protect their devices, encrypt data, and install security apps to prevent criminals from stealing information while the phone is on public networks (FCC, Feb 2018). Plus, set reporting procedures for lost or stolen mobile devices. Draft a BYOD policy that separates personal vs. corporate data and covers the below points.

  1. Ensure your equipment has the latest security software and run anti-virus/malware scans. regularly. If you don’t have anti-virus software installed, buy, and install it.
  2. Install all software updates as soon as they are available, including all web browsers.
  3. Have the latest operating systems on your devices with access to regular updates.
  4. Make sure your internet connect is protected with firewall security.
  5. Make sure your Wi-Fi network is encrypted, hidden, as well as password protected.

For more information reach out to Abstract Forward Consulting here.

Three Unique Tech Trends in 2017 and Implications for 2018

Minneapolis – 12/24/2017

Each year we like to review and commentate on the most impactful technology and business concepts that are likely to significantly impact the coming year. Although this list is incomplete, these are three items worth dissecting.

3. The Hyper Expansion of Cloud Services Will Spur Competition and Innovation:
Cloud computing is a utility that relies on shared resources to achieve a coherent economy of scales benefit – with high-powered services that are rapidly provisioned with minimal management effort via the internet (Fig. 1). It presently consists of these main areas: SaaS (software as a service), PaaS (platform as a service), and IaaS (infrastructure as a service). It is typically used for technology tool diversification, redundancy, disaster recovery, storage, cost reduction, high powered computer tests and models, and even as a globalization strategy. Cloud computing generated about $127 billion in 2017 and is projected to hit $500 billion by the year 2020. At this rate, we can expect many more product startups and consulting services firms to grow and consolidate in 2018 as they are forced to be more competitive thus bringing costs down.

The line between local and cloud computing is blurry because the cloud is part of almost all computer functions. Consumer-facing examples include: Microsoft OneDrive, Google Drive, GMAIL, and the iPhone infrastructure. Apple’s cloud services are primarily used for online storage, backups and synchronization of your mail, calendar, and contacts – all the data is available on iOS, Mac OS, and even on Windows devices via the iCloud control panel.

Fig. 1. Linked Use Cases for Cloud Computing.
Cloud Infra

More business sided examples include: Salesforce, SAP, IBM CRM, Oracle, Workday, VMware, Service Now, and Amazon Web Services. Amazon Cloud Drive offers storage for music, images purchased through Amazon Prime, as well as corporate level storages that extends services for anything digital. Amazon’s widespread adoption of hardware virtualization, service-oriented architecture with automated utilization will sustain the growth of cloud computing. With the cloud, companies of all sizes can get their applications up and running faster with less IT management involved and with much lower costs. Thus, they can focus on their core-business and market competition.

The big question for 2018 is what new services and twists will cloud computing offer the market and how will it change our lives. In tackling this question, we should try to imagine the unimaginable. Perhaps in 2018 the cloud will be the platform where combined supercomputers can use quantum computing and machine learning to make key breakthroughs in aerospace engineering and medical science.  Additionally, virtual reality as a service sounds like the next big thing; we will coin it (VRAAS).

2. The Reversal of Net Neutrality is Awful for Privacy, Democracy, and Economics:
Before it was rolled back, net neutrality required service providers to treat all internet traffic equally. This is morally and logically correct because a free and open internet is just as important as freedom of the press, freedom of speech, and the free market concept. The internet should be able to enable startups, big companies, opposing media outlets, and legitimate governments in the same way and without favor. The internet is like air to all these sects of the economy and to the world.

Rolling back net neutrality is something the U.S. will regret in coming months. Although the implications of it are not fully known, it may mean that fewer data centers will be built in the U.S. and it may mean that smaller companies will be bullied out of business due to gamified imbalances of cost in internet bandwidth. Netflix and most tech companies dissented via social media resulting in viral support (Fig 2).

Fig 2. Viral Netflix Opposition to Rolling Back Net Neutrality.
Netflix Twitter

Lastly, it exacerbates the gap between the rich and the poor and it enables the government to have a stronger hand in influencing the tenor of news media, social norms, and worst of all political bias. As fiber optic internet connectivity expands, and innovative companies like Google, Twitter, and Facebook turn into hybrid news sources, a fully free internet is the best thing to expose their own excesses, biases, and that there are legitimate conflicting viewpoints that can be easily found.

1. Amazon’s Purchase of Whole Foods Tells Us the Gap Between Retailer and Tech Service Company is Closing:

For quite a long time I have been a fan of Amazon because they were anti-retail establishment. In fact, in Amazon’s early days, it was the retail establishment that laughed at them suggesting they would flounder and fail. “How dare you sell used books by mail out of a garage”. Yet their business model has turned more into a technology and logistics platform than a product-oriented one. Many large and small retailers and companies of all types – employ their selling, shipping, and infrastructure platform to the degree that they are, in essence, married to Amazon.

Magazine Business Insider said, “The most important deal of the year was Amazon’s $13.7 billion-dollar acquisition of Whole Foods. In one swoop, Amazon totally disrupted groceries, retail delivery, and even the enterprise IT market” (Weinberger, 12/17/17). The basis for this acquisition was that grocery delivery is underserved and has huge potential in the U.S. as the population grows, less people own cars, and people value not wasting time walking around a retail store so much (getting socialized to a new level of service) (Fig 3).

Fig. 3. How Amazon Can Use Whole Foods to Serve High Potential Grocery Delivery.
Amazon Whole Foods

By Jeremy Swenson and Angish Mebrahtu

Mr. Swenson and Mr. Mebrahtu meet in graduate business school where they collaborated on global business projects concerning leadership, team dynamics, and strategic innovation. They have had many consulting stints at leading technology companies and presently work together indirectly at Optum / UHG. Mr. Swenson is a Sr. consultant, writer, and speaker in: business analysis, project management, cyber-security, process improvement, leadership, and abstract thinking.  Mr. Mebrahtu is a Sr. developer, database consultant, agile specialist, application design and test consultant, and Sr. quality manager of database development.