Economic cybersecurity
In 2009, the US formed its Cyber Command as part of its armed forces – a clear indication that cyber is a military front in every respect. Today, it is clear that it is also a civilian front in every respect, and that cyber presents dangers to the home front no less than to combat forces. Even in peacetime, cyberattacks are a daily occurrence against companies large and small in all sectors, from power companies and hospitals, to banks, to the media. There are attackers who do it for the thrill. Others wish to extort payment for releasing stolen data; and foreign countries also attack commercial companies.
The damage from a cyberattack can be huge, both economic, and to an organization’s image. The right approach to dealing with such attacks is to start from the assumption that any organization can fall victim to them, and therefore every organization must be prepared to face them and must do everything in its power to prevent them, and to minimize the damage they can cause. Barlev Associates offers a broad range of cyber defense services.
Performance of a cyber review to formulate a defense strategy for the organization:
- Construction of relevant scenarios, and periodic updates to them (who is the attacker? what could he threaten? where will he attack from? what weakness will he exploit?) for possible threats to the organization’s data and communications infrastructure.
Development of intra-organizational policies for managing cyber events:
- specifications for the organization’s SOC (Security Operations Center); creation of a procedure in the event of an attack; definition of the responsibilities of the various roles in the organization.
- Development of business continuity plans to ensure that the organization functions even at the time of an attack.
- Organizational practice drills in cyberspace to discover weak points and prevent attacks.
- Investigation of cyber incidents and attacks:
- Quantification of financial damage and assessment of the exposure caused by the event.
- Working out how the attacker operated when the incident is discovered only after it is over.
- Expert opinions for the courts and legal proceedings, with an emphasis on the economic and accounting aspect.
Information systems audit, with an emphasis on financial systems:
- Review of financial systems to determine how well they are adapted to dealing with general and specific threats.
- Examination of the organization’s cyber defense policy to determine compliance with relevant regulation and Israeli standards.
- Examination of the development, procurement, installation and maintenance of information systems within the organization, in relation to cyber threats.
- Installation of dedicated systems for interrogating data and identifying anomalies:
- Systems for interrogating computers using keywords and detecting anomalies.
- System for detecting fraud in an organization.