We are incredible, resilient and adaptable. Despite a now effectively global lock down, many businesses have continued to operate, and organizations once terrified of change have spun up new systems and processes in a matter of weeks. The last month has been equal parts scary and inspiring.
The shift to 100% remote work was not by choice, and many poor decisions are being exposed as we speak. From insecure video conferencing to a litany of conference call fails to more serious risks with scarier impact, this sudden shift is straining systems that were not designed for a global pandemic use case. Nonetheless, we're muddling along.
What Are the Risks?
Beyond the headlines and the rumors, how much risk is in the system? One good proxy is to measure the number of infrastructure and devops servers exposed to the internet. These computers play a fundamental role in managing, securing and automating fleets of servers. Tools with names like Jenkins, Ansible, Chef, Puppet, Terraform and CircleCi are used to deploy systems and code, making them ideal targets for attackers.
So how many of these systems are out there? Using Jenkins as an example, we can see that there are 254,819 Jenkins servers exposed to the internet. Many of these machines can be exploited with code easily available for free on code sharing sites (intentionally not linking to it here, because don't be 😈). What is even worse than automation servers foolishly exposed to the public internet are the Jenkins machines 6,800+ that are publicly accessible.
What other risks are out there? Public wifi networks, exposed remote desktop protocol, and many other run-of-the mill risks. Remote desktop over public internet, unsurprisingly has ticked up over the last month, but not as much as one might have expected. Like many misconfiguration issues, public RDP is a long term problem, just being exposed today. One other long simmering issue that may yet cause a major incident are our industrial control systems.
How Will You Know Your Risk?
If you're a fintech or a digital health startup that transitioned to working remotely, you are probably not worried about industrial control systems, but you should definitely scan your IP space. If you don't want to use a paid service like Shodan, feel free to use a free scanner like Nmap. In addition to generic scans and searches for infrastructure you know you have, now is a good time to dust off any risk assessments. Check the section on Business Continuity Protocol, and see how man issues have been resolved. My guess is more than a few items are still in progress.
If you don't have a risk assessment or your last one is too out of date, now is a good time to do a micro assessment. Is your asset inventory up-to-date? Just do a quick and dirty mapping of assets to threats and impact. Below is the framework, I used to do a little checkup for our team:
| Assets | Threats | Impact | |
| SaaS | CMS, CRM, etc. | Credential stuffing, DDoS | Loss of information, Downtime |
| Devices | Laptops, Mobile, etc. | Loss, Theft, Compromise | Asset write down, 3rd Party Liability |
| Software | In house developed, Code editors, Security apps, DevOps tools, etc. | Malware, Insecure code | 3rd Party Liability, confidentiality |
| Infrastructure | Public Cloud, Server Management | Deletion, Ransom, DDoS, Data breach | Asset write down, Downtime, confidentiality |
| Communications | Slack, Email, Video chat, Text, Phone | Phishing, Data breach | Confidentiality, Downtime, Direct financial impact |
What is To Be Done?
Once you've done a short checkup on your assets and risks, start mitigating. Don't know where to start? Here are three concrete tasks you can do to improve your remote work security posture:
- Scan your infrastructure.P
- Use RDP over VPN only
- Encourage employee best cyber practices
We've made great strides in the last month, now let's not let all the success we've had turn into an opportunity for bad people to profit off a crisis.