"According to a recent study cited by the U.S. House Small Business
Subcommittee on Health and Technology, nearly 20% of all cyber attacks
hit small businesses with 250 or fewer employees. Roughly 60% of small
businesses close within six months of a cyber attack." (Source: Forbes)
This is an amazing statistic. It's something we've been talking a lot about it our local Manchester, NH area. Having just opened in April, we've been doing our networking. For the last several years I've been working in and with large enterprise, global in scope corporations --both as an employee, and as a government Infosec worker --a director at the DoD Cyber Crime Center (DC3). This mostly home based from the Baltimore-DC area, but now, participating in the local ISC2 meetings and talking with the owners of local businesses instead of the CISOs of large companies, I've come to the realization that our government (at least DoD) really has no clue just how bad it is for small and medium sized companies. I recall a conversation with a CISO who told me that nearly 60% of their critical suppliers were companies with less than 25 employees!
So during my local polling at a local Chamber event, many of the companies had no idea what APT was, nor had they any idea that employees walking working from home, leaving the company, angry on the job (scheming to leave), building their own companies on the side, etc., can, and do take information from their current employer. And not only do they take information from their current employer, they often times use this information to compete. The Forbes article talks of an a company who continues to lose contracts to the same competitor, only to realize they'd left the employee's computer access turned on after he left.
Carnegie Mellon has a center that does Insider Threat studies. I did a bit of work with them a few years ago. They do case studies of insider threats --how do insiders break, steal, compete with their former employers either as they're heading out the door, disgruntled and terminated, or just plain through stupidity while still employed (I had an employee once who used our corporate web template to build his own website selling pianos!). In nearly every case, interactions between HR and the employees managers could have helped prevent many of these issues. In all of these cases, monitoring employee computer use, notifying the employee that their system would be monitored during personnel improvement plans, during the last two weeks of employment, and post employment could have saved these companies a lot of heart ache, and more importantly, a ton of money.
So where does Wapack Labs fit?
Most small businesses have no clue what a forensic lab can do for them.
Wapack can tell you, with high levels of certainty, if employees are, or have stolen from you. We'll make two copies of the hard drive, placing an exact duplicate back in the machine. We'll place the original in our safe (for use in court if needed), and examine the second exact copy. We'll look at everything from outbound emails, to copies of files moved to external media (i.e.: USB sticks).
If you've got a problem employee, don't wait. Call us today for a free consult. We'll help devise a strategy that will help protect you from losses of insider threats. And if you get hit with an attack from outside of your company, Wapack can help with that too.
Happy Memorial Day!
Saturday, May 25, 2013
Thursday, May 2, 2013
Your Company Is Walking Out the Door
Today just about every company in America has their vital
proprietary information on computers. Everything from email, client lists,
pricing models, to trade secrets is stored on company computers. In many cases
those computers leave the office daily, or sometimes never show up onsite if
the employee works from home. Even if your company utilizes the most rigid
security rules and not a single computer leaves the facility, emails are still
sent back and forth from smart phones. A lot of the time attachments can be
saved directly from emails to the smart phones and then transferred on from there
without the company’s IT department ever being aware.
This situation becomes even more precarious when you include
companies that allow people to bring their own device (BYOD). In these
situations company data often resides on the personal laptop or in a “cloud”
solution where the data are available from any device connected to the
internet. What happens when the employee leaves? Can you guarantee that nothing
was stolen, deleted maliciously, or taken to a competing shop? Without
conducting a proper digital forensic investigation by certified examiners you
may never know what was taken. Even if your internal IT department does their due
diligence in trying to determine a theft, without the proper forensic handling
of the evidence, it may not be admissible in court.
Attorney Sid Leach from the law firm Snell & Wilmer
wrote an excellent paper (“What Every Lawyer Needs to Know about Computer Forensic Evidence”) pertaining to the valuable information that digital
forensic investigations reveal. Whether it pertains to fraudulent activities,
non-compete contracts, harassment, or intellectual property theft, Mr. Leach
explains that “A forensic examination of a departing employee’s laptop or
computer workstation can provide a goldmine of information concerning what the
ex-employee was doing”.
In my own experiences I have seen companies both large and
small with employees leaving abruptly or on bad terms causing suspicions as to
their activities. It is always in the company’s best interest to at least have
a forensic examiner create a forensically sound bit-by-bit copy of the device
before it is used by another employee. In these situations, even if your
company doesn’t proceed with an immediate investigation, at least you have a
court admissible copy to work from if anything were to arise in the future.
Wapack Labs is a digital forensic firm based in Manchester, NH with certified
and experienced digital forensic examiners to handle any investigation or
discovery need. Contact us today to see how we can help you!
Saturday, April 27, 2013
Fully operational!
Wapack, while slow, is starting off nicely. Our lab is fully stocked and running its first pieces of analysis. This was our third week in operation at Wapack Labs. It's a great feeling, having our first pieces of work come through the door.
After termination, many employees will delete information from their drive. This is not always a reason for concern. Wapack can, often times, restore data that had been deleted. We can, as well, help identify information that might be being sent out of a company before the employee is terminated. Sampling employee laptops, submitting terminated employee laptops for analysis, or placing restrictions on employee movement while under a personal improvement plan or termination notice are all considered good practice, and Wapack Labs can help. Give us a call!
-Jeff
- We kicked off the lab doing work a nice piece of development business that helped bootstrap the lab.
- This week we received a set of drives sent to us by an IT consultant. We did our best for these guys. The array had died and the consultant had come to a point where they needed help. We were able to see and make copies of almost everything, and are working at pulling data off as we speak. Not everything will come off cleanly, but hopefully enough to allow their customer to keep operating.
- This week we were asked to author a proposal for another piece of work through a local law firm. Our proposal is in. Fingers crossed.
After termination, many employees will delete information from their drive. This is not always a reason for concern. Wapack can, often times, restore data that had been deleted. We can, as well, help identify information that might be being sent out of a company before the employee is terminated. Sampling employee laptops, submitting terminated employee laptops for analysis, or placing restrictions on employee movement while under a personal improvement plan or termination notice are all considered good practice, and Wapack Labs can help. Give us a call!
-Jeff
Friday, April 12, 2013
Why use Digital Forensics? Let us help you solidify your case!
Why Use Digital Forensics?
Working in the digital forensics field has opened my eyes to
many other professional practices. Specifically in my job I deal with a lot of
lawyers, law firms small and large, and plenty of litigation protocol. One of
the most interesting aspects of the law field to me and specifically when
dealing with on-stand experts, is that you don’t ask a question you don’t
already know (or think you know) the answer to. This important factor made me
think: Why don’t more litigators use digital forensics in their cases? Having a
certified forensic expert helping you in your case is like giving you the
answers to questions you haven’t even thought about asking!
Recently I worked in Chicago where I collaborated with
lawyers throughout the country who had various levels of experience with
digital forensics and computer investigations. One of my most memorable cases
was an attorney from a very small law firm in the suburbs of Chicago who dealt
with Employment and Labor law. This attorney had come to me with ongoing litigation
concerns about an employee who left a company and went to work for a direct
competitor within a matter of weeks.
This employee had been in a position where they were privy to a lot of
sensitive data about the company (product specs, pricing models, client lists,
sales leads, etc.). While we already knew that the employee had violated their
non-compete contract, counsel was worried that the business might have been
harmed by the theft of this sensitive information. I was brought in to either
put these fears to rest, or create a “slam dunk” case with empirical digital
evidence.
Not long after our initial conversation where I addressed
what kind of things we may find in a digital investigation, counsel was able to
procure the work laptop from the company. Within a week of receiving the device
I was able to image (duplicate the evidence to be able to work on a copy),
parse, index, and analyze the entire system. Combined with a simple
questionnaire from the client, I had a complete understanding of the activities
on the system. In this case (as with most investigations) I focused on the
employee’s last two weeks at the company. I was able to pin down that before
leaving the company (and pretty much right before walking out of the door) the
employee was attaching USB thumb drives to the system, and copying data to
these drives. Along with the USB devices, I could see that through emails and by
viewing his Internet history (Gmail, DropBox, LinkedIn) that the employee had
been planning to leave the company for some time. The combination of the
employee’s actions, coupled with solid digital evidence, proved that sensitive
information was taken from the company laptop, and copied to personal devices.
Information provided by digitial forensic examination of the laptop provided
counsel with ample means to win their case.
The best part for me on a personal level was that this case
was the first time the attorney had ever used a computer investigation. It
provided me the ability to teach counsel exactly what we do, how digital
forensic science is proven in court, and how best to phrase his questions and
shape his case to present what we found. Not only was this his first case
involving digital forensics, but it was my first deposition as well! That give
and take provided a great working relationship for the case going forward and
the follow on investigations that arose from it.
At Wapack Labs we are driven to
provide that same level of service to litigators throughout the Employment and
Labor, Intellectual Property, and Technology law practices. Give us a call to
see how we can help! Find us online at http://wapacklabs.com/ or give us a call at 603-606-1246. Be sure to follow us on LinkedIn as well as this blog.
Subscribe to:
Posts (Atom)


