Talos Takes
Every two weeks, host Amy Ciminnisi brings on a new guest from Talos or the broader Cisco Security world to break down a complicated security topic. We cover everything from breaking news to attacker trends and emerging threats.
Talos Takes
Back-to-school cybersecurity: Protecting education networks from ransomware and threats
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
As the new academic year begins, school districts face a surge in cybersecurity threats, from phishing attacks and ransomware to student experimentation with network devices. In this episode, Amy sits down with Cisco Talos expert Pierre Cadieux to discuss practical strategies for IT practitioners.
How do you strengthen your defenses while managing the delicate balance between security and classroom usability? Here are the most high-priority steps to keep your district safe this semester.
Prioritizing patches episode: https://www.buzzsprout.com/2018149/episodes/19360999
Welcome to the Talos Takes podcast, where we discuss Talos' latest research and security news. This podcast is for everyone, from the C suite to the frontline.
Amy CiminnisiHello everyone, and welcome to another episode. My name is Amy Ciminnisi, and today we're talking about something that we see year after year after year, and it's very timely. Happy back to school, everyone, especially if you have kids! But with that brings an absolute phishing frenzy, honestly. So today we have Pierre Cadieux here, who is quite experienced in helping both K- 12 schools and universities secure their networks and respond to incidents. Today we're mainly going to focus on K-12 schools, but we'll be sure to have an episode in the future about universities, especially research universities as well. So Pierre, how are you doing through all this?
Pierre CadieuxI'm doing great. Thanks. Thanks for having me back.
Amy CiminnisiYeah, so happy to have you back on. I think this is going to be a really valuable episode for a lot of people. So back to school is in full swing. Um, especially every, you know, late August, early September through October-ish. Um, we always see a spike in phishing. Why does the specific window of time create such a spike and an opportunity for attackers compared to other times of the year?
Pierre CadieuxIt's definitely a time where folks are doing something either they haven't done for a few months or doing something for the first time, moving to a new educational facility, moving to a university, changing schools. And the bad guys like change. They love to be able to get in there and try and insert themselves in the change however they can, whether that be a phishing attack and then trying to then uh make themselves part of the relationship for how you authenticate something or for you to share your credentials to. Maybe they um are able to compromise your system with an info stealer and steal your passwords or steal information about how you use your accounts. Or maybe they're um actually uh you know gonna uh attack the facility you're going to. They have uh either ransomware uh or some other type of uh situation where they have uh embedded software in an environment and they're gonna misuse it somehow. So lots of risks out there and lots of opportunities for defenders to hopefully do good stuff.
Amy CiminnisiYeah, yeah. And it's like clockwork. And then you were talking about how we see ransomware at least, you know, one school district a month through Talos Incident Response. Um, so we we often talk about kind of the influx of new students and faculty and staff as the primary challenge that defenders are facing. Because when you're dealing with like thousands of different identities that you're provisioning, um I'm curious what the most common pitfalls you see are. Um, and also like how can teams manage this huge surge without, you know, compromising on something that's going to cost them later.
Pierre CadieuxYeah. There are a lot of risks, and it really goes back to some of the basics, which we'll hit on in just a minute, but it kind of depends on the defender's um type of school district or school situation that a defender is trying to work in. So we'll start from ground up elementary schools, uh K-12 kind of school districts. The biggest risk that they have, uh honestly, is probably at this point in time ransomware. Very likely to be uh vulnerable to ransomware. They don't have a very uh robust monitoring environment, likely. They have some of the basic security controls, hopefully, but adversaries are well trained on how to bypass those and how to leverage those for their own gain. So one of the biggest things from the defender on the K-12 side, I think, is making sure you have some sort of an offline backup so you know how to restore your environment so you don't end up becoming a victim repeatedly to ransomware where you have to pay uh to try and recover your data. Even if you do pay, the data you get back may not be, or data you're able to recover may not be comprehensive. You also lose trust with your students and with your district and with your constituents if it's a public school. Um, there's a lot of other exposure of possibly of private information as well. So it's something you want to prevent if you can help it and have a backup so you can restore it back and not have to rely on the adversary's goodwill and or the money convincing them to do the right thing. That only goes so far. And we've seen a number of districts who have been compromised in the past, who've have then gotten compromised again because an adversary knows that once they compromise you and you're encrypted, they're uh very likely to be able to get paid out. So um remember, adversaries are financially motivated, and if they know where they're gonna be able to get reliable money from, they're gonna keep coming back to it. That's on the K-12 side. As we go up into like the high school, uh middle school, high school part of that. One thing to remember is that your students are also going to be part of your own threat model because they're gonna experiment. They're gonna experiment with things, they're gonna have uh hey, uh dare say, Hey, I bet you couldn't put this USB stick into the uh shared screen we have, or whatever like that, with a device or whatever like that. Or I, you know, let's try and change our grades or whatever it may be. We've seen some of these uh come across as incidents uh in the past. We saw one recently where the high school students had malware on a USB drive and then plugged it into a um like a whiteboard...
Amy CiminnisiA SmartBoard or something like that.
Pierre CadieuxExactly. Either way, it had a USB port, they plugged it in. Yep, that caused problems because then it spread throughout the network and then compromised uh part of the um the administrative system because the way that the system networks. Yeah, exactly. So but and so you think USB drives, that's like you know, what year are we in exactly? But people still use it. I mean, and students have to move files around and often they use cloud-based services for that, of course, but there also are still uh reasons for and access to USB drives, and a lot of devices still have USB ports, and it's not something where I'm I'm gonna suggest that you should always like gum up your USB ports and block them. That's a little bit extreme, but be mindful of the fact that that's a threat and make sure that you're uh managing your devices as best you can uh and also some guidance to students, maybe you know, have a lab where they can mess around with stuff and have an actual educational process for like, hey, let's let's do um uh computer tinkering, let's you know, play around with that sort of stuff. There's definitely programs out there for that sort of thing for students, which help them to hopefully channel that energy in a positive direction. Um it's curiosity is great, and we want uh folks to be curious, we want students to be curious, but not on production devices.
Amy CiminnisiAbsolutely not. And I- I remember as a kid, like SmartBoards were just starting to roll out. And you know, if your classroom got one, it was it was the shit. Um but like beyond human identities, many more privileged classrooms are effectively, you know, in their internet of things environments. You know, there are the smart boards, there's the lab equipment, there's other ed tech integrations and stuff. For the security practitioners listening, how do you get better visibility and control over this huge web of connected devices without grinding you know academic experience to a halt?
Pierre CadieuxYeah, it's difficult. And one of the things I spent some time uh as a consultant helping with uh network segmentation. And and I don't want to necessarily say it's a solution to everything, but it it does help a lot with both the ability to restrict access across network segments and prevent things talking from one network to another, and then it also gives you visibility of which devices are connected to these networks. Say, hey, I know which devices are connected right now, which ones are supposed to be here, and I can say there's one device on here that doesn't match my normal user uh uh provisioned uh systems, and I can then investigate that or that I can create an alert or something like that. That is it's super helpful from an asset management perspective because especially if you're looking at a dynamic network like a student network where you're gonna have people to and students plugging in devices. If we think about like the university uh type of threat model, where we're dealing with a student dorm, possibly a student network, student labs, and all those networks are intended to be kind of plug and play, and people are gonna be connecting to those, students can be connecting to those with devices that are maybe untrusted or unmanaged. So you definitely want to partition that off from your administrative network and from your services network and from your classroom network. So you want to have a little bubble where it's preventing that data from traversing the networks into there. Maybe it has access to the internet on some with some restrictions and some filters, but mostly it's gonna be talking to each other. And so you want to be able to allow that and allow it to access the services that it needs without uh exposing those. So maybe you allow uh certain types of protocols and traffic to go through, but you're not gonna allow um logins, for instance, from that network to your administrative network. Um, and that can be restricted both on the egress and ingress side of things and each of those network enclaves. And so you can also monitor for that when someone's trying to do that. You can say, hey, someone's trying to authenticate in and uh log into a box over here in the service network, which is normal for them to do, except that it's coming from the student network. Ah, we don't want that. And you could then obviously there's gonna be a certain amount of enforcement and uh investigation for this as well, which does require um staffing and resources. So there's it's not a a panacea, all these things take work. You also have the normal um, hey, by the way, you mentioned this earlier, the provisioning of accounts. There's a little window of time where account might be provisioned but not yet logged into. There also a time where a password might be a temporary password that's been transmitted to somebody or given to a student before they change it themselves. There might be a point where they haven't yet registered their MFA devices, and each of those points creates a risk where an adversary could insert themselves into that conversation and then either control that account or have a secondary MFA device that's approved or have access to the password, et cetera. So making sure that those windows are as small as possible. I mean, ultimately, if we could have it all done in person, uh it is much easier, but that's unlikely in most cases these days. So it's really a part of validating that the users, the new students have changed their passwords correctly, have deployed MFA correctly, and going through that little sort of validation of that.
Amy CiminnisiYeah, that ties in perfectly with a little story time that I have. Everyone gather around, sit down on our little, you know, rug in the corner of the room. Um back in 2019, um, my parents who are now retired were both high school teachers and ransomware hit their school district. Um, it impacted a lot of different systems. Um, so their internet, staff email, phone system, their like grading portal, uh, you know, that had all the student records in it. It was called Genesis, um, also Schoology or kind of like a Google Classroom learning management system sort of deal. Um, and then also the payroll system, um, which took the longest out of all of those things to get back online. I believe it was over Thanksgiving break and it delayed everyone returning to school. Attendance had to be sent in by hand to the front office. You know, it took them several weeks to get everything back to normal. Um, but like during the regular school year, I, you know, remember to this day how hard my parents worked and how much stress they were under throughout the school year. And cybersecurity is often seen as a hurdle, right? For teachers and staff who are really already overwhelmed with their work. Teaching is a hard job. Um, so is IT. Um, so how can these teams, um, IT teams in particular, frame security practices differently so that, you know, it feels more like a support system than, you know, these hurdles that they're trying to jump over in order to do their work. Um, and maybe that goes for students too. Getting them to use strong passwords uh is really a difficult job. So curious what you think about that.
Pierre CadieuxYeah, no, enforcing that is is crucial to a lot of things, especially like we see password reuse is one of the things adversaries love to do. Um, for lots of reasons. It's it's really easy if you compromise an account uh or a set of accounts and then are able to just try those passwords against other resources and then it works. You're in and it didn't cost you any more time or money. So it's great. Um, the biggest thing on the usability versus security that's always a an inverse relationship.
Amy CiminnisiYeah.
Pierre CadieuxAnd uh one of the things that we often advocate for is transparency to the teachers about why these things are being done, uh, making it as easy as possible, making it um something that is provide a tool that that automates some of this stuff, maybe a tool that helps with it. So password manager, making sure that uh that the school and the administrative folks and the teachers have access to a good password manager that allows them to have complicated passwords and manages it and has this multi-factor authentication plugin, looks for compromised accounts and that sort of thing. Um, that is um a step in the right direction, uh, making sure that any impact to the teachers and students is hopefully managed by the IT team, and the IT team is there for helping and enabling the um the teachers when they have an issue. The challenge is going to always be staffing, and that's one of the things that makes these environments very fragile to these attacks, is that they're the people who are doing the day-to-day imaging of laptops, fixing up the things, fixing the wireless in a room or in an area or fixing networks or whatever, are often the same ones who are also having to do investigations or whatever else. And maybe their expertise lies in certain parts of it, but it's very unlikely that they have uh a lot of depth in the whole thing. And so they're not really security practitioners, but they have to kind of put that hat on. And that when it becomes necessary to either roll out a tool or to investigate something, this is what creates that fragility is that lack of comprehensive skills and staffing that the schools have downsized over the years, and so many schools are in a very fragile state. There's similar, actually, unfortunately, to uh healthcare has similar sort of uh vulnerability level, a lot of risk and very little in the way of defense capabilities. Um, so I I would say that it's part of the school's mission to educate the teachers on the why behind it, give them as many tools as possible to help themselves, and then have an IT team that can support them when they need it. Those are the kind of easiest things I could say. It's not an easy process, it is it is its own thing. Um, and especially with if we look in the future right now, we can all predict pretty reliably that there's going to be more device and operating system patches coming in the next uh three, six, twelve months. Because just normal continued growth every year is exponential or additive at least of the number of vulnerabilities that are found. And now we have this whole, hey, let's find them with AI too. And so we have instead of maybe a new 200, we're gonna maybe have new 2000 patches. And so those have to be considered from a vulnerability management perspective, from an exposure perspective, from a deployment perspective, and managed by the IT teams. It's going to be um a bit of a change for the folks doing the management of this. And I just hope that people don't stop patching and ignore them because of the overwhelmingness of it all. Uh, patch management and vulnerability management's gonna be even more important.
Amy CiminnisiYeah. And we actually put out an episode several weeks back about um how to prioritize patching. Um so that that's just going to become even more crucial um as we get to those thousands and thousands of patches coming out. Yeah. Let's kind of talk about what we do with all of this. Um, if an administrator or an IT lead is listening to this, what do you think is like the single most high priority step that they should be taking right now to protect their institution as the semester kicks off?
Pierre CadieuxSo the highest priority thing I would say is going to be making sure that you have a reliable offline backup of your environment. So you know you can recover it in the event of a disaster, which also includes like ransomware. So that's the first thing because that allows you once you know that's there and you know that it's validated and it's a regular thing and it has some automation to it, you can pretty much forget about it and just let it run its thing. When I say offline backup, I mean not just another file or a server on your own network because adversaries look for those and they will encrypt those as well. And they will then uh make those unavailable to you and what you thought was going to be your liable backup capability now is gone as well. Many, many victims over the years with ransomware have said, Oh, yeah, I've got a backup, but they go log into their backup server and it's encrypted as well, and then they pull their hair out and it's backup. The concept of offline backups is a little bit uh of an older concept, but it was something that was created when we had the idea or the threat of possible like um things like earthquakes and that sort of stuff, we think about disaster recovery. You won't want to have all your backups in one building that may then not be available to you. You want to have them in other places or have it at least not the same network. So even if you have it on a box, a server that's not authenticated to the rest of your domain or whatever, that's actually not bad. That way it prevents the adversary from easily moving from a compromised active directory or authentication system over to the server. If it's separate credentials and separate uh device, that counts. That's okay. That's probably not going to get compromised if they compromise your active directory, unless you know certain other things happen. Obviously, don't use password for use there and don't have a situation where you use the same credentials. That's just asking for trouble. So it needs to be somehow secured separately from the rest of your network, and that will help move you in the right direction. There are actually, though, obviously not just one thing, there's many things. Top three things I was thinking about this earlier: password management plus MFA, making sure you have a way to manage your passwords. Know what you have as far as your assets. Be uh get a good handle on the asset management of your environment, whether that's through segmentation, whether that's through asset management uh systems, whether that's through uh other types of discovery of asset management. Make sure at least the systems you control are well understood and that you have an idea of how to pull those networks where the students are and other things happen so you know from day to day what the change looks like. If you start seeing many, many, many devices, that might be an indication of something going strangely or whatever. And then know how to patch your devices and your operating systems and manage your vulnerabilities um as aggressively as necessary.
Amy CiminnisiRight. And raise the alarm quickly as well. Um we we often see in Taous IR the organizations that are quick to respond or reach out to incident response firms or whoever they have partner-wise, have a higher chance of success of recovery too. Yeah.
Pierre CadieuxAbsolutely. I I but if I had to put a fourth within there, I would say have an incident response plan and know how to use it and know how to execute it. Yeah, but that then I'm then uh uh being very specific about that. But that is also very helpful for other things like disasters, having a disaster recovery plan, which includes IR, is uh probably uh more universally uh useful for places that might have things like tornadoes or other natural events that you have to deal with where the school is closed, snow days, whatever else like that.
Amy CiminnisiYeah, that's a great point. Cybersecurity attacks aren't the only thing you have to worry about during the school year. Yep. Yeah. And then moving past, you know, the survival mode of the first weeks of school, how should districts be evolving that long-term strategy to kind of stay ahead of the curve rather than just reacting to that initial wave of threats in the beginning of the year? I you pretty much mentioned one right off the bat there. Yeah. But yeah.
Pierre CadieuxLove is going to go back to that uh asset management and then managing that into your vulnerability management. So as new vulnerabilities are are disclosed and new risks are identified, have a good answer for how are we prepared? Are we know do we have the countermeasures in place? Do we have the patches deployed? Do we have systems that are vulnerable to this? If so, what's our schedule for patching it, etc.? Taking a good sort of calendared approach of saying patches come out on this Tuesday, we'll have an assessment by whatever day, and we'll have the patches start to be deployed a certain number of days after that, that helps create a sense of expectation about what you're gonna be doing. Obviously, it's gonna be a little bit up and down depending on the number of patches and that sort of stuff and the amount of testing. But starting with your critical, and you you said we have a a um uh some sort of media about uh patch priorities. I would point them to that, definitely. You know, there's definitely a lot of ways of addressing it, but looking at what systems are most critical to your environment, which ones are exposed, which ones um are actually vulnerable to this, and and there's not any mitigation you can put in place temporarily. All those things are are part of the equation for when you should be deploying those patches. Um keeping an eye on any new threats that are out there that are specifically targeting your industry, in this case education, would be important as well.
Amy CiminnisiYes. It's gonna be a wild ride, I'm sure, this school year, but um everyone know that you have a huge community to support you here. And um, yeah, Pierre, thanks so much for coming on.
Pierre CadieuxYep, thanks again.
Amy CiminnisiAbsolutely. Listeners, I will put the link to the Talos Takes episode on how to prioritize your patches below. We'll be back in two weeks with a new episode. Have a fantastic start to the school year, and until next time, stay safe out there.