No Result
View All Result
  • Login
Friday, May 16, 2025
theadvisertimes.com
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
No Result
View All Result
theadvisertimes.com
No Result
View All Result
Home Market Analysis

Never “Too Small For Cybercriminals”: One Town’s Cautionary Tale

by theadvisertimes.com
11 months ago
in Market Analysis
Reading Time: 5 mins read
A A
0
Never “Too Small For Cybercriminals”: One Town’s Cautionary Tale
Share on FacebookShare on TwitterShare on LInkedIn


Earlier this month, the town manager of Arlington, Massachusetts, notified constituents that Arlington fell victim to a classic cybercrime, business email compromise (BEC). Through account compromise of its employees and account spoofing of its vendor, bad actors were able to reroute four monthly electronic funds transfer payments for a high school building project totaling nearly $500,000. The fraud was uncovered when that vendor notified the town that they hadn’t been paid in four months.

In a world of Scattered Spiders and Midnight Blizzards and UNC2452s, why is Arlington’s BEC important? Because it’s happening all the time to towns, municipalities, regional health systems, and small businesses lacking the resources to prepare for such an event. There’s no such thing as “too small” or too “off the radar” for opportunistic cybercriminals. Our 2023 Security Survey found that 63% of security decision-makers in the public sector and 74% of security decision-makers in organizations with 20 to 999 employees reported at least one breach in the last 12 months.

Once aware of the BEC, the town took necessary incident response steps, including notifying law enforcement and its bank, hiring outside counsel, and conducting a forensic investigation, all of which highlighted what it lacked prior to the attack, including:

Employee awareness training. As a result of the attack, Arlington is “[instituting] mandatory cybersecurity training for all staff” through a grant from the state. Awareness training advancing toward human risk management focuses on building a security culture within an organization that encourages employees to pause and ask questions when receiving messages from third parties, management, or even IT staff. The use of urgency, authority, and novelty are hallmarks of social engineering to be met with healthy skepticism but that can only be achieved in cultures that reward employees for vigilance, even if that results in a slight delay of legitimate transactions or tasks.
Wire transfer protocols. The letter stated that the town contracted an auditor to review payment processes and “bolster internal controls with a stricter policy related to wire transfer payments.” No one employee should be responsible for a decision to change the destination of funds. Organizations must put in place multistep verification processes that ensure that several sets of eyes are on messages related to transfers and that legitimate parties on the receiving end of transfers confirm the destination verbally via a number not included in email communication and confirm receipt of payment, among other anti-fraud best practices.
Advanced email security. Interestingly, the town manager’s letter noted that “ […] the IT department had already begun to reconfigure email security settings in November to improve our email security,” indicating that some email security protections were in place but either not advanced enough or configured properly to block phishing messages. The fewer phishing emails delivered to inboxes, the less organizations need to rely on employees to make the right choices in interacting with them. Your enterprise email security solution should also extend protections developed for the email inbox to messaging, collaboration, file sharing, and SaaS applications across multiple devices and throughout the day-to-day workflows of your employees.
Multifactor authentication. In addition to stepping up email security, the town manager stated that multifactor authentication (MFA) would be rolled out to select employees immediately and to all staff in the future as part of a state grant. MFA, especially phishing-resistant MFA, would likely have prevented attackers from accessing and monitoring the email threads related to projects and payments by requiring one or more forms of authentication and delivering the convenience of a passwordless experience and better protection against social engineering attacks.
Detection and response tech. The letter addressed already-in-progress improvements, including the rollout of endpoint detection and response (EDR) “as part of the upcoming fiscal year.” The addition of EDR to the town’s security tech stack will likely thwart other malicious activity, but it, along with its more comprehensive successor, extended detection and response (XDR), requires skilled practitioners to interpret alerts and take appropriate response actions. If your organization lacks practitioners with the right skills to derive value from an EDR or XDR solution, consider managed detection and response, or for less than the cost of hiring skilled talent from the outside, fill skill gaps with a skills and training platform.

What Arlington Got Right: Breach Notification And Communication

The town manager’s notification letter to the community was commendable. It was straightforward and direct, with assurances for concerns that were likely top of mind for residents, like whether resident data was compromised (it was not), whether the town was able to recover any funds (the bank recovered $3,308), and whether the loss negatively impacts the completion of the high school building project (it does not).

The letter also covered expected elements from a clear notification. It outlined what the town could share about what happened, how the town’s IT department responded, and steps that the town will take next. It also included a FAQ covering the impact to the building project and town budget, as well as questions related to security and the incident.

Breaches Break Already-Fragile Town Budgets

The attack and the needed remediation steps in its aftermath add financial pressure to a town already struggling with its budget. Like many municipalities this past year, Arlington faced an unexpected jump in expenses — like rising health insurance costs for town and school employees — and had to vote on a budget override to make up the shortfall without cutting services too deeply.

Budget overrides can be a contentious topic at town meetings — the entire town meeting tradition in New England is fascinating and perhaps the subject of another blog — and Arlington’s vote for a $7 million override back in November came with a commitment to not propose any more budget overrides until FY2027.

Arlington can ill afford a half-million-dollar outlay from a BEC or any other cybersecurity attack. Like with many other towns and municipalities feeling similar pinches, officials must be on high alert for attacks like this that might be a drop in the bucket for an enterprise but debilitating for a small-town budget.

What’s A Cash-Strapped Town (Or SMB) To Do?

The first step is understanding where your town stands in terms of cybersecurity maturity. Massachusetts towns can use the state’s Municipal Cybersecurity Roadmap to get a good picture. Municipalities can then chart their course based on their maturity levels. Don’t wait for an attack to act. Look for free and low-cost federal and state programs that are provided to help towns improve their cyber resilience, such as CISA and FEMA’s State and Local Cybersecurity Grant Program. And for town board members seeking to gain support for the program, the MassCyberCenter provides examples of real stories that have financially impacted towns. Municipalities outside of Massachusetts should see what resources are available from their state government or federal programs.

No matter your organization’s size or sector, there’s more you can do to 1) improve your program’s maturity and 2) emphasize to leadership the critical link between security and revenue as it relates to your key constituencies. Forrester clients can schedule an inquiry or guidance session with us to discuss further.



Source link

Tags: CautionarycybercriminalsSmallTaletowns
ShareTweetShare
Previous Post

Gimme Credit sees new 10-year bond outperforming By Investing.com

Next Post

Coinbase down 9% this month, aligned with Bitcoin’s tumble

Related Posts

2 Undervalued China Stocks Worth Buying as Trade Tensions Cool

2 Undervalued China Stocks Worth Buying as Trade Tensions Cool

by theadvisertimes.com
May 16, 2025
0

U.S.-listed Chinese stocks have come back in favor with investors following their tariff-related selloff. The stocks benefit from stabilizing US-China...

Crude Oil Cracks, Gold Glitters, USD/JPY Drifts as Soft US Data Hammers Yields

Crude Oil Cracks, Gold Glitters, USD/JPY Drifts as Soft US Data Hammers Yields

by theadvisertimes.com
May 16, 2025
0

US PPI fell 0.5% vs 0.2% gain expected—biggest drop in over a year Retail control group and factory output also...

There Are Only Two Major Opportunities For OMS Vendors To Win New Deals Right Now

There Are Only Two Major Opportunities For OMS Vendors To Win New Deals Right Now

by theadvisertimes.com
May 15, 2025
0

It’s a tough market for everyone in commerce and commerce tech right now. There are lingering market circumstances, such as...

The Power of Proactive Health Check

The Power of Proactive Health Check

by theadvisertimes.com
May 15, 2025
0

Tracking brand health isn’t just a strategy- it’s a necessity. Like all other forms of health, it requires ongoing monitoring...

Europe Mid-Session Bell: DAX Consolidates After All-Time Highs

Europe Mid-Session Bell: DAX Consolidates After All-Time Highs

by theadvisertimes.com
May 15, 2025
0

Asian Session Market WrapAsian stocks dropped on Thursday after rising for four straight days, as the boost from US-China trade...

These 7 Stocks Have the Wind at Their Backs – and Room to Run Another 51%

These 7 Stocks Have the Wind at Their Backs – and Room to Run Another 51%

by theadvisertimes.com
May 15, 2025
0

After weeks of turbulence, the stock market bulls have roared back into life. The has surged nearly 16.13% since bottoming...

Next Post
Coinbase down 9% this month, aligned with Bitcoin’s tumble

Coinbase down 9% this month, aligned with Bitcoin's tumble

2:00PM Water Cooler 6/25/2024 | naked capitalism

2:00PM Water Cooler 6/25/2024 | naked capitalism

  • Trending
  • Comments
  • Latest
Relationship tips for financial advisors to educate clients

Relationship tips for financial advisors to educate clients

May 6, 2025
Wealth management challenges in talent, private investing

Wealth management challenges in talent, private investing

May 14, 2025
How advisors can help investors prepare for the unknowns

How advisors can help investors prepare for the unknowns

May 5, 2025
Prytek buys control of Israel fintech co TipRanks

Prytek buys control of Israel fintech co TipRanks

August 15, 2024
The risks of investing in private equity

The risks of investing in private equity

May 8, 2025
Rocky Mountain Chocolate Factory outlines growth strategy By Investing.com

Rocky Mountain Chocolate Factory outlines growth strategy By Investing.com

July 16, 2024
Brazil’s Marfrig moves to cap takeover of BRF, combining as MBRF

Brazil’s Marfrig moves to cap takeover of BRF, combining as MBRF

0
How to trade gold and bitcoin after the big market rally

How to trade gold and bitcoin after the big market rally

0
Consumer sentiment slides to second-lowest on record as inflation expectations jump after tariffs

Consumer sentiment slides to second-lowest on record as inflation expectations jump after tariffs

0
IndusInd Bank Q4 Results: IndusInd Bank to declare Q4, FY25 results on May 21

IndusInd Bank Q4 Results: IndusInd Bank to declare Q4, FY25 results on May 21

0
SEC Warns of FOMO, Pushes Long-Term Strategies as Crypto Matures

SEC Warns of FOMO, Pushes Long-Term Strategies as Crypto Matures

0
9 Good Reasons You Need a Vetted Financial Advisor on Your Side

9 Good Reasons You Need a Vetted Financial Advisor on Your Side

0
IndusInd Bank Q4 Results: IndusInd Bank to declare Q4, FY25 results on May 21

IndusInd Bank Q4 Results: IndusInd Bank to declare Q4, FY25 results on May 21

May 16, 2025
SEC Warns of FOMO, Pushes Long-Term Strategies as Crypto Matures

SEC Warns of FOMO, Pushes Long-Term Strategies as Crypto Matures

May 16, 2025
Tokenization makes investing more accessible — Robinhood exec

Tokenization makes investing more accessible — Robinhood exec

May 16, 2025
U.S. debt no longer earns a top grade at any of the major credit rating agencies after Moody’s downgrade

U.S. debt no longer earns a top grade at any of the major credit rating agencies after Moody’s downgrade

May 16, 2025
*HOT* Jack Link’s Beef Sticks Original 20-Count only .49 shipped!

*HOT* Jack Link’s Beef Sticks Original 20-Count only $7.49 shipped!

May 16, 2025
CEO compensation disclosure gets fresh scrutiny from Trump’s SEC

CEO compensation disclosure gets fresh scrutiny from Trump’s SEC

May 16, 2025
theadvisertimes.com

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Economy
  • Financial Planning
  • Investing
  • Market Analysis
  • Markets
  • Money
  • Personal Finance
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • IndusInd Bank Q4 Results: IndusInd Bank to declare Q4, FY25 results on May 21
  • SEC Warns of FOMO, Pushes Long-Term Strategies as Crypto Matures
  • Tokenization makes investing more accessible — Robinhood exec
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • About Us
  • Contact Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.