HomeSecuritySonicWall ransomware attacks are a lesson for mergers and acquisitions

SonicWall ransomware attacks are a lesson for mergers and acquisitions

Recent ransomware attacks on organizations with SonicWall SSL VPNs may teach more than just the need for patch management and authentication and access control. Some of the victim companies had vulnerable SonicWall appliances in their IT networks as a legacy from previous mergers or acquisitions, suggesting that information security leaders need to be more involved in preparing for M&A deals or risk being hit by hackers.

See also: SonicWall vulnerability allows firewall crashes

SonicWall

Those are the findings of a report this week from researchers at Reliaquest. They examined a series of attacks between June and October using the Akira ransomware strain to target SonicWall SSL VPNs and found a link: In almost every incident, hackers gained access to a corporate network by compromising a SonicWall appliance that had been inherited from a smaller acquired business. When asked, Reliaquest would not disclose how many incidents it had investigated. But the report says that in each case, IT was unaware that the appliances were present in their environment.

“Standard M&A due diligence is not enough,” the report states. “Security teams must proactively secure legacy technologies, prioritizing early visibility into new environments, such as remote access tools, to address risky configurations and outdated credentials before attackers can exploit them.” The warning is not new. Experts have been saying for years that examining the financials of a potential acquisition is not enough. A review of IT assets should also be included so that boards understand both the financial and cyber risks of a deal.

See also: SonicWall: State-owned hackers behind September breach

SonicWall ransomware attacks are a lesson for mergers and acquisitions

IT leaders need to drive the message that security risk is a risk to the business. The board should be reminded that it is responsible for assessing both the cyber and financial risks of a deal. If information security leaders are asked to be part of an M&A team, the actual assessment of the potential acquisition should be delegated to a third-party expert. This is because the security team will not have the time to do it themselves, and the other party will likely be more willing to disclose sensitive IT information to a third party than to a competitor.

Those conducting cybersecurity assessments of a potential acquisition should start with an inventory or list of IT assets before asking whether the organization has an information security policy and underlying policies. After an acquisition, CSOs should treat the new network as a third-party connection request and keep it segregated until the underlying risks are quantified before attempting to integrate the environments, he added. An acquisition’s cybersecurity posture should be a high priority for review during the due diligence period. The security team should be properly connected to the rest of the organization, including the corporate development (corpdev) team that typically leads mergers and acquisitions.

See also: Experts warn of widespread SonicWall VPN breach

SonicWall ransomware attacks are a lesson for mergers and acquisitions

In its report, Reliaquest notes that SonicWall appliances are often used by small and medium-sized businesses, which are often targets of M&A by larger companies. However, it said it cannot be certain that the companies were targeted by Akira operators because they had merged organizations that had SonicWall appliances. It said that in the incidents it examined, once they entered the victims’ networks, the attackers immediately sought out privileged accounts, such as those from legacy service providers (MSPs) or administrator logins that had been transferred during the M&A process.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS