ILMA Compoundings December 2016 - 13

NOTES FROM AFPM

"I'll Take Ransomware
for $17,000"
Dan Strachan

O

n New Year's Day, some media groups will list the
terms and phrases that were popular during the
previous year. I would bet money that some of these
lists will include the term "ransomware."
Ransomware has been around for a while, but it made its public
debut this year at Hollywood Presbyterian Medical Center in
California. Malicious actors hacked into
the hospital's IT system and held it for
ransom. It was a de facto kidnapping
of the IT system. The hospital paid the
ransom of $17,000.
So, you ask yourself, how was an outside
entity able to "kidnap" an IT system?
Ransomware is a program that takes
control of a computer system by
encrypting all the information on it. It's
like someone changing all the locks in
your house and not giving you the new
keys until you hand over money. The
outside entity probably could hack into
the computer system through an open
port, a USB drive or a virus that was
downloaded.
Now, you might ask yourself, why this
particular hospital?
Answer: It was easy. This wasn't Mass
General or Johns Hopkins. This was
a small entity. I don't know anything
about Hollywood Presbyterian's IT
department, but I would bet money that
someone there thought they were too
small to be on any hacktivists' radar. They were wrong.
There are other examples of ransomware this year ranging
from fast food outlets to retail. An insurance industry report
finds that the ransoms sought from target companies remain
low, often in the region of $1,000. But these are not the only

costs incurred by companies that suffer attacks. Add to this
ransom payment the additional costs of system review and
mitigation (for a small company, this would mean hiring an
outside firm), downtime, supply-chain disruption and the
possible harm to the company's reputation with its customers
and suppliers, and the price tag is much higher than the
ransom.
I've said it in previous Compoundings
articles and will say it again: No
company is too small to be hacked into.
Companies must be on the defensive
and never rest on their laurels. Just
because you've never been hacked is no
guarantee that you will not be hacked
in the future. There are those out there
who see what happened at this hospital
and are thinking it is a great way to make
some money.
You should err on the side of caution
and assume hacktivists are looking at
your IT and maybe even your SCADA
systems. Ask yourself: Will they be able
to hack into your system? What would
happen if you couldn't access your IT
system because an outside entity has
encrypted it?
While the ransom seems very small, the
ramifications of this event need to be a
wakeup call. You are never too small to
be hacked.

Strachan is director, industrial relations and programs, for the
American Fuel & Petrochemical Manufacturers (AFPM). He may be
reached at 202-457-0480 or dstrachan@afpm.org.

Compoundings December 2016 * 13 * Vol. 66 No. 12



ILMA Compoundings December 2016

Table of Contents for the Digital Edition of ILMA Compoundings December 2016

ILMA Compoundings December 2016 - 1
ILMA Compoundings December 2016 - 2
ILMA Compoundings December 2016 - 3
ILMA Compoundings December 2016 - 4
ILMA Compoundings December 2016 - 5
ILMA Compoundings December 2016 - 6
ILMA Compoundings December 2016 - 7
ILMA Compoundings December 2016 - 8
ILMA Compoundings December 2016 - 9
ILMA Compoundings December 2016 - 10
ILMA Compoundings December 2016 - 11
ILMA Compoundings December 2016 - 12
ILMA Compoundings December 2016 - 13
ILMA Compoundings December 2016 - 14
ILMA Compoundings December 2016 - 15
ILMA Compoundings December 2016 - 16
ILMA Compoundings December 2016 - 17
ILMA Compoundings December 2016 - 18
ILMA Compoundings December 2016 - 19
ILMA Compoundings December 2016 - 20
ILMA Compoundings December 2016 - 21
ILMA Compoundings December 2016 - 22
ILMA Compoundings December 2016 - 23
ILMA Compoundings December 2016 - 24
ILMA Compoundings December 2016 - 25
ILMA Compoundings December 2016 - 26
ILMA Compoundings December 2016 - 27
ILMA Compoundings December 2016 - 28
ILMA Compoundings December 2016 - 29
ILMA Compoundings December 2016 - 30
ILMA Compoundings December 2016 - 31
ILMA Compoundings December 2016 - 32
ILMA Compoundings December 2016 - 33
ILMA Compoundings December 2016 - 34
ILMA Compoundings December 2016 - 35
ILMA Compoundings December 2016 - 36
ILMA Compoundings December 2016 - 37
ILMA Compoundings December 2016 - 38
ILMA Compoundings December 2016 - 39
ILMA Compoundings December 2016 - 40
ILMA Compoundings December 2016 - 41
ILMA Compoundings December 2016 - 42
ILMA Compoundings December 2016 - 43
ILMA Compoundings December 2016 - 44
https://www.nxtbook.com/ygsreprints/ILMA/G127535ILMA_vol71_no7
https://www.nxtbook.com/ygsreprints/ILMA/G126213ILMA_vol71_no6
https://www.nxtbook.com/ygsreprints/ILMA/G125546_ILMA_vol71_no5
https://www.nxtbook.com/ygsreprints/ILMA/G124996_ILMA_vol71_no4
https://www.nxtbook.com/ygsreprints/ILMA/G123886_ILMA_vol71_no3
https://www.nxtbook.com/ygsreprints/ILMA/G123315_ILMA_vol71_no2
https://www.nxtbook.com/ygsreprints/ILMA/G122980_ILMA_vol71_no1
https://www.nxtbook.com/ygsreprints/ILMA/G121540_ILMA_vol70_no11
https://www.nxtbook.com/ygsreprints/ILMA/G120882_ILMA_vol70_no10
https://www.nxtbook.com/ygsreprints/ILMA/G120035_ILMA_vol70_no9
https://www.nxtbook.com/ygsreprints/ILMA/G121XXX_ILMA_vol70_no8
https://www.nxtbook.com/ygsreprints/ILMA/G120XXX_ILMA_vol70_no7
https://www.nxtbook.com/ygsreprints/ILMA/G119XXX_ILMA_vol70_no6
https://www.nxtbook.com/ygsreprints/ILMA/G118112_ILMA_vol70_no5
https://www.nxtbook.com/ygsreprints/ILMA/G117382_ILMA_vol70_no4
https://www.nxtbook.com/ygsreprints/ILMA/G116888_ILMA_vol70_no3
https://www.nxtbook.com/ygsreprints/ILMA/G115555_ILMA_vol70_no2
https://www.nxtbook.com/ygsreprints/ILMA/G114774_ILMA_vol70_no1
https://www.nxtbook.com/ygsreprints/ILMA/g110500_ILMA_vol69_no12
https://www.nxtbook.com/ygsreprints/ILMA/g110500_ILMA_vol69_no11
https://www.nxtbook.com/ygsreprints/ILMA/g110500_ILMA_vol69_no10
https://www.nxtbook.com/ygsreprints/ILMA/g109884_ILMA_vol69_no9
https://www.nxtbook.com/ygsreprints/ILMA/g109284_ILMA_vol69_no8
https://www.nxtbook.com/ygsreprints/ILMA/g108494_ILMA_vol69_no7
https://www.nxtbook.com/ygsreprints/ILMA/g107507_ILMA_vol69_no6
https://www.nxtbook.com/ygsreprints/ILMA/g106483_ILMA_vol69_no5
https://www.nxtbook.com/ygsreprints/ILMA/g105803_ILMA_vol69_no4
https://www.nxtbook.com/ygsreprints/ILMA/g104743_ILMA_vol69_no3
https://www.nxtbook.com/ygsreprints/ILMA/g103647_ILMA_vol69_no2
https://www.nxtbook.com/ygsreprints/ILMA/g102869_ILMA_vol69_no1
https://www.nxtbook.com/ygsreprints/ILMA/g101930_ILMA_vol68_no12
https://www.nxtbook.com/ygsreprints/ILMA/g100836_ILMA_vol68_no11
https://www.nxtbook.com/ygsreprints/ILMA/g99200_ILMA_vol68_no10
https://www.nxtbook.com/ygsreprints/ILMA/g98468_ILMA_vol68_no9
https://www.nxtbook.com/ygsreprints/ILMA/g97711_ILMA_vol68_no8
https://www.nxtbook.com/ygsreprints/ILMA/G96767ILMA_vol68_no7
https://www.nxtbook.com/ygsreprints/ILMA/G95397ILMA_vol65_no6
https://www.nxtbook.com/ygsreprints/ILMA/G94323ILMA_vol68_no5
https://www.nxtbook.com/ygsreprints/ILMA/G93127_ILMA_vol69_no4
https://www.nxtbook.com/ygsreprints/ILMA/G91785_ILMA_vol68_no3
https://www.nxtbook.com/ygsreprints/ILMA/G90956_ILMA_vol68_no2
https://www.nxtbook.com/ygsreprints/ILMA/G89146_ILMA_vol68_no1
https://www.nxtbook.com/ygsreprints/ILMA/G87981_ILMA_vol67_no12
https://www.nxtbook.com/ygsreprints/ILMA/G85409_ILMA_vol67_no11
https://www.nxtbook.com/ygsreprints/ILMA/G83595_ILMA_vol67_no10
https://www.nxtbook.com/ygsreprints/ILMA/G81672_ILMA_vol67_no9
https://www.nxtbook.com/ygsreprints/ILMA/G80238_ILMA_vol7_no8
https://www.nxtbook.com/ygsreprints/ILMA/G79388_ILMA_vol7_no7
https://www.nxtbook.com/ygsreprints/ILMA/G78361_ILMA_vol7_no6
https://www.nxtbook.com/ygsreprints/ILMA/G77448_ILMA_vol7_no5
https://www.nxtbook.com/ygsreprints/ILMA/G75899_ILMA_vol67_no4
https://www.nxtbook.com/ygsreprints/ILMA/G75036_ILMA_vol67_no3
https://www.nxtbook.com/ygsreprints/ILMA/G72720_ILMA_vol67_no2
https://www.nxtbook.com/ygsreprints/ILMA/G72220_ILMA_vol67_no1
https://www.nxtbook.com/ygsreprints/ILMA/G70970_ILMA_vol66_no12
https://www.nxtbook.com/ygsreprints/ILMA/G69813_ILMA_vol66_no11
https://www.nxtbook.com/ygsreprints/ILMA/G67522_ILMA_vol66_no10
https://www.nxtbook.com/ygsreprints/ILMA/G66343_ILMA_vol66_no9
https://www.nxtbook.com/ygsreprints/ILMA/G64859_ILMA_vol66_no8
https://www.nxtbookmedia.com