By Ray Birch
SAN DIEGO—It’s time C-Suite executives give up some of the keys to their company’s data systems, as crooks are going after those at the top–or more specifically, their broad administration rights.
Security expert Jim Stickley told CUToday.info company executives, particularly CEOs, should only accept access to data systems they truly need, as widespread access to the enterprise easily provides crooks the “keys to the kingdom.”
Compounding the problem, added Stickly, is very often executives lack what’s necessary to have such a high level of security access, and typically aren’t paying sufficient attention to how they handle such great responsibility.
“Oftentimes, the C-Suite executives will insist on having the same access as system administrators—the same priorities, the same privileges, and the same access rights—with no real specific need other than other than they feel they should have this level of access,” said the CEO of Stickley on Security and a frequently cited expert on security-related issues. “Oftentimes, they don't have the security training that goes along with that access and responsibility.”
Stickley’s comments come at a time when Verizon has released its 2019 Data Breach Investigations Report, which reveals senior executives are 12 times more likely to be the target of social engineering incidents, and nine times more likely to be the target of social breaches than in previous years.
High on the List
But while the findings are new, the trend isn’t. Stickley stressed senior executives have always been a big target for crooks and will continue to be high on fraudsters’ attack lists, for the obvious reason.
“The C-Suite executives have always been the ones everybody wants to go after,” said Stickley. “It's them and system administrators, the two top criminal targets within any organization. It’s like getting to the crown jewels because these people have access to everything.”
Perhaps the biggest threat to crooks gaining access to high-level executives’ PC and access rights lies in the fradster’s ability to “become that person,” said Stickley.
“I gain access to your credentials, your systems and now I have the same power as you. I can close out access to information I don’t want people to see,” said Stickley. “I can learn about your life. I can literally become you, the CEO, and then wreak havoc throughout the corporation.”
An Old Tactic That Still Works
Stickley said a common—yet effective—strategy used by crooks is to create emails that are then sent to accounting staff that appear to be coming from the boss and which request funds be wired outside the credit union.
“That's the big one, and it happens a lot,” said Stickley. “The fake emails often say, ‘I want this wire transfer done immediately.’ And the employee says, ‘Oh my gosh, this is from the CEO,’ and just reacts. Those attacks have been happening for a while.”
Stickley acknowledged many companies have improved staff training to help employees spot fake emails.
“I have been hearing less about these attacks than I have in the past,” he said.
The bigger issue, asserts Stickley, is many C-Suite executives work in a “bubble” in which they don’t think they will ever be victimized.
“They often have a mindset that they are not being targeted like their staff, because they are not part of the routine, day-to-day operations of the company.” Stickley said. “They think since they are not managing customer or member information, they are not a target, and that's wrong.
More Training Needed
Stickley emphasized that a different, higher level of security training should be provided to executives.
“And they’re not getting it,” he said. “They need security training closer to what a system administrator gets. The bosses really should not have this level of authentication if they are not getting the high level of training that goes with it. Just for the sake of comparison, it takes years to get to the level of training of administrator—that’s a top security guy who’s gone through a lot of training and certification and earned the right to have all that access.”
Stickley said C-Suite execs, particularly CEOs, are not being arrogant about their demands to have security access that equals that of system administrators. He said often they simply believe that since they are the boss they should have the authority, not only due to their position, but to also serve as a control, to let staff know they have the ability to see all the data in the company and know what everyone is doing.
“Plus, they want to have someone else inside the company with the keys to the kingdom if anything were to happen to the system administrator,” explained Stickley.
Limits Needed
While Stickley said those are legitimate reasons for an executive to want such power, what needs to happen in many companies, in addition to more training, is determining just what security access the boss absolutely needs on a daily basis and limit it to that.
Moreover, executives need manage their access rights in better ways, he suggests.
“Oftentimes, CEOs will use the default account that they log into every day as the place to store their security access details,” Stickley said. “It’s one thing to have alternate accounts that you have somewhere there are available in case they're needed, and people know where they are and they're stored safely, like in the virtual strongbox. It’s another thing to have these in a personal account right on the CEO's desktop. Have your day-to-day account you use, but then have another account you use for administrative-type things.”
Mind Is Elsewhere
Stickley added executives can also be prone to fraudster attacks, because they may not be giving the same level of attention to proper data security as the rank and file.
“What I mean is that if I am an employee who is not in management, I know if I screw up and cause a data breach there’s a good chance I could lose my job,” said Stickley. “But the boss, the CEO, is not thinking about that specifically. He’s thinking about everything else. The possibility of causing a data breach, I think, just doesn't cross their mind as much as it does other staff. It's not arrogance, it’s literally it's just not on their minds.”
