Estimated reading time: 1 minute, 41 seconds

Lessons from the MOVEit and Casino Hacks

According to cybersecurity experts, plenty of lessons can be drawn from two recent sets of major cyberattacks: the separate breaches of Las Vegas casino giants MGM Resorts and Caesars Entertainment, along with the mass-hack exploiting a vulnerability in Progress Software’s widely used MOVEit file-transfer software.

hacker 1944688 640MGM and Caesars were following widely regarded best practices when it came to cybersecurity, right down to running vulnerability tests and cyberattack simulations, as The Nevada Independent reports. Gus Fritschie, senior vice president of cybersecurity firm Bulletproof, told the newspaper the fact that they were hacked anyway “just goes to show you that anybody is vulnerable.”

At a webinar sponsored by Bulletproof parent company Gaming Laboratories International, Fritschie recommended making security training and education a bigger priority. He noted that human beings are still organizations’ most vulnerable point.

With class-action lawsuits flying, both MGM and Caesars will have their work cut out to shore up their reputations for safeguarding customer information, gaming industry consultant Brendan Bussmann reportedly said.

Among cybersecurity experts, Caesars is generally thought to have paid a multi-million-dollar ransom. Stephanie Benoit-Kurtz, a cybersecurity consultant on the faculty at the University of Phoenix College of Business and Information Technology, reportedly said that the amount of ransoms will probably increase and such princely sums will embolden hackers to launch more attacks.

Meanwhile, KonBriefing now counts more than 2,000 organizations and at least 60 million people who were impacted by the MOVEit hack.

Marc Bleicher, chief technology officer at Surefire Cyber, told PlanAdviser that the hack “is a great lesson” about the importance of vetting third-party service providers. “I tell all my clients to treat any third-party service or product provider as an extension of your team and apply the same information and security standards that you would internally to assess whether they’re the right vendor for you.”

Mario Paez, national cyber risk leader at Marsh McLennan Agency, told PlanAdviser that he recommends running cyberattack simulations. What failed to prevent breaches at MGM and Caesars could still help others guard against future attacks.

 

Read 506 times
Rate this item
(0 votes)

Visit other PMG Sites:

PMG360 is committed to protecting the privacy of the personal data we collect from our subscribers/agents/customers/exhibitors and sponsors. On May 25th, the European's GDPR policy will be enforced. Nothing is changing about your current settings or how your information is processed, however, we have made a few changes. We have updated our Privacy Policy and Cookie Policy to make it easier for you to understand what information we collect, how and why we collect it.