What Do the Russian Hacks Mean to Your Organization?

What Do the Russian Hacks Mean to Your Organization?

There has been quite a bit of talk – and jokes – about the “Russian attackers” in recent days. So is the threat real and how does it impact your organization?

Russian hackers claim they will try to disrupt the U.S. election (as if it is not already disrupted by the presidential candidates). Last week, the Obama administration claimed that senior Russian officials authorized hacks into the Democratic National Committee and tampered with online voter registration. Experts responded by saying that the impact is likely more psychological. 

But the threat is real. You can actually see attacks happening this second at map.norsecorp.com. There’s a war going on out there that most never see. 


Norse_Security_Attack_Map_1016.png


The threats are increasing in both their severity and frequency. You can easily find a hacker’s kit on the Internet and start using it. A rising number of people are making money through hacking and exploiting people. (Go ahead and Google it, but don’t click.)

New Attacks
The term “hackers” is quite broad, covering everything from the development of crypto lockers, worms and other forms of malware to attempts to take down systems using methods like a distributed denial of service attack, known as DDoS attacks. (See how to protect against malware attacks.)

In the case of DDoS attacks, hackers prey on devices that operate on the edge of your network. That’s everything from the new smart refrigerators to sensors, surveillance cameras, IP telephony and wireless access points.

They find an unprotected device and then use it to complete the attack. The rise of the Internet of Everything (IoE) enables hackers to use millions of devices at one time to attack an IP address, so they cannot be stopped easily during the process. That means your business could look like it is hacking another system – until it is traced back to Russia. Yes, it’s crazy.

How do you protect yourself from DDoS attacks? Much of the protection comes from how your security architecture is set up. Think of it like an onion – with a variety of layers. Organizations of all sizes now need a comprehensive security program. Here’s a look at what that includes:

PART 1: Layers of Protection

  • Firewall: Begin with a strong, external facing layer of protection with a firewall that establishes limited access to the inside of your network (onion). Keeping your firewall software up to date is critical. When it gets out of date, it can be just like not having one at all.
  • Intrusion Detection System: This device or application monitors your network or systems for malicious activity or policy violations and alerts your system administrator.
  • Intrusion Prevention System: Like an intrusion detection system, this system monitors network traffic. However, because an exploit may be carried out very quickly after the attacker gains access, intrusion prevention systems also have the ability to take immediate action, based on a set of rules established by the network administrator.
  • Mobile Device Management: This software system allows you to monitor and manage mobile devices on the network, including limiting access and even locking or wiping phones in case of a breach.

PART 2: Testing and Evaluation
Test your plan to ensure the policies and procedures you have outlined are being met. Often times, organizations bring in a third-party technology advisor to assist. When we are the ones managing clients' networks, we ask another company to conduct penetration testing.

While this has become a requirement in some industries, such as financial, it is a good practice for any type of organization of any size. It includes everything from assessing access points to physically viewing the systems. Is the server door locked? Can someone get your admin password? Essentially, we try to break in and test each policy. 

PART 3: Educate End Users
Most security breaches come from within an organization. An employee inadvertently clicks on a malicious link or plugs a device into the system that contained a virus that takes it down. (See how to protect against email hacks.)

One of the best lines of defense is education. Help your users understand how to use technology safely. Educate them on the policies and procedures you have in place – and even test their adherence to them. 

Every organization is at risk and the risk is real. Don’t brush it off and think it won’t happen to you. Protect your organization. You have too much at stake and we need more organizations stepping up to prevent hacks.

 

Learn More About A Technology Assessment Contact a Marco Rep

Related Posts

Ransomware Response Plan: A Step-by-Step Guide for SMBs
Ransomware Response Plan: A Step-by-Step Guide for SMBs

I've helped businesses through ransomware attacks, and the first hour matters more than almost anything else. What you do in that hour decides how fast you recover, how much you lo...

The Best Data Backup Solutions for Your Business
The Best Data Backup Solutions for Your Business

Too many businesses assume their backups are fine — only to get a terrible surprise if a server crashes, someone deletes the wrong folder, or ransomware locks everything down overn...

Healthcare Cybersecurity in 2026
Healthcare Cybersecurity in 2026

Cyberattacks and IT incidents have risen sharply in 2025 and 2026, and if current trends are any indication, cybercriminals are becoming bolder and far more dangerous. Just this pa...

5 Common Healthcare Cybersecurity Challenges (And How MDR/SOC Can Help)
5 Common Healthcare Cybersecurity Challenges (And How MDR/SOC Can Help)

In our conversations with healthcare clients, we hear the same five security challenges come up again and again. If you're reading this, you're probably dealing with some version o...

The State of Healthcare Cybersecurity in 2026
The State of Healthcare Cybersecurity in 2026

When I work with healthcare clients, one of the first things I tell them is that I completely understand how difficult it has been to prioritize cybersecurity updates when their va...

NIST Cybersecurity Framework: Full Overview & Guide
NIST Cybersecurity Framework: Full Overview & Guide

Back in 2013, the federal government directed NIST (National Institute of Standards and Technology) to work with industry leaders to build a common framework for cybersecurity risk...

Urgent PaperCut NG/MF Vulnerability: What You Need to Know
Urgent PaperCut NG/MF Vulnerability: What You Need to Know

If you run PaperCut NG or PaperCut MF, this is the one advisory to stop and read today. In short: PaperCut has confirmed active, real-world exploitation of a vulnerability affectin...

How To Measure Your Cybersecurity Posture Against the NIST Framework
How To Measure Your Cybersecurity Posture Against the NIST Framework

A lot of businesses aren’t sure whether they actually have cybersecurity best practices in place. To be fair, cybersecurity is a moving target, and what was considered sufficient p...

The AI Governance Framework Every Org Needs Before Scaling AI
The AI Governance Framework Every Org Needs Before Scaling AI

AI is showing up in the enterprise faster than most governance programs can keep pace with: forecasting models, customer service bots, code generation tools, decision-support syste...

What Is Vishing?
What Is Vishing?

Vishing is short for “voice phishing.” Like other forms of phishing attacks — including email and text-based scams — the goal is to trick someone into handing over credentials, fin...