{"id":28444,"date":"2023-05-11T09:41:40","date_gmt":"2023-05-11T13:41:40","guid":{"rendered":"https:\/\/www.oxebridge.com\/emma\/?p=28444"},"modified":"2023-05-11T09:41:40","modified_gmt":"2023-05-11T13:41:40","slug":"dragos-rep-says-company-could-prevent-hacks-from-ever-happening-gets-hacked-4-days-later","status":"publish","type":"post","link":"https:\/\/www.oxebridge.com\/emma\/dragos-rep-says-company-could-prevent-hacks-from-ever-happening-gets-hacked-4-days-later\/","title":{"rendered":"Dragos Rep Says Company Could Prevent Hacks &#8220;From Ever Happening,&#8221; Gets Hacked 4 Days Later"},"content":{"rendered":"<p>Not a good day to be an <del>overexcited<\/del> enthusiastic sales rep at Dragos, the cybersecurity provider. Over on LinkedIn (naturally), a slightly over-enthusiastic Dragos rep named <a href=\"https:\/\/www.linkedin.com\/in\/rob-west-54b7526\/?lipi=urn%3Ali%3Apage%3Ad_flagship3_detail_base%3Bx2oOW7tlT4OVmuDf614U4g%3D%3D\">Rob West<\/a> made the <del>batshit<\/del> bold claim that Dragos could prevent cybersecurity hacks and extortion &#8220;<em>from ever happening<\/em>&#8221; in the first place. In fact, he said it twice, just in case no one believed him the first time. Which was probably a good idea.<\/p>\n<p>In a <a href=\"https:\/\/www.linkedin.com\/posts\/activity-7057035295925362689-cLex?utm_source=share&amp;utm_medium=member_desktop\">post<\/a> by another cybersecurity bro, Josh O&#8217;Sullivan of Ardalyst linked to a\u00a0story about how the Marinette Marine shipyard, which makes vessels for the US Navy, <a href=\"https:\/\/news.usni.org\/2023\/04\/20\/ransomware-attack-hits-marinette-marine-shipyard-results-in-short-term-delay-of-frigate-freedom-lcs-construction\">had been hacked<\/a>. O&#8217;Sullivan claimed &#8212; with a straight face &#8212; that <em><strong>CMMC<\/strong> <\/em>would have prevented this from happening.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-28445\" style=\"border: 1px solid #000000;\" src=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/05\/cybersecuritycults1.jpg\" alt=\"\" width=\"500\" height=\"380\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/05\/cybersecuritycults1.jpg 680w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/05\/cybersecuritycults1-150x114.jpg 150w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/05\/cybersecuritycults1-197x150.jpg 197w\" sizes=\"(max-width: 500px) 100vw, 500px\" \/><\/p>\n<p>Umm, no. But that will become clearly evident around 2026, as we watch all those CMMC-certified companies posting about their own ransom incidents.<\/p>\n<p>Not to be undone, West &#8212; whose <a href=\"https:\/\/www.linkedin.com\/in\/rob-west-54b7526\/\">LinkedIn profile<\/a> says he&#8217;s Dragos&#8217; Senior Enterprise Account Manager for US Navy \/ US Marine Corps Sales &#8212; offered up <em><strong>another<\/strong> <\/em><del>snake oil cure<\/del> solution.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-28447\" style=\"border: 1px solid #000000;\" src=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/05\/cybersecuritycults2.jpg\" alt=\"\" width=\"500\" height=\"117\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/05\/cybersecuritycults2.jpg 613w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/05\/cybersecuritycults2-150x35.jpg 150w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/05\/cybersecuritycults2-200x47.jpg 200w\" sizes=\"(max-width: 500px) 100vw, 500px\" \/><\/p>\n<p>Because you don&#8217;t reach the position of Senior Enterprise Account Manager for US Navy \/ US Marine Corps Sales without spamming your products in the comments sections at LinkedIn, West then repeated himself:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-28446\" style=\"border: 1px solid #000000;\" src=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/05\/cybersecuritycults3.jpg\" alt=\"\" width=\"500\" height=\"128\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/05\/cybersecuritycults3.jpg 673w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/05\/cybersecuritycults3-150x38.jpg 150w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/05\/cybersecuritycults3-200x51.jpg 200w\" sizes=\"(max-width: 500px) 100vw, 500px\" \/><\/p>\n<p>West couldn&#8217;t even be bothered to read the article he was linking to, because if he had, he would have realized that Josh O&#8217;Sullivan was just posting a story to sell his <em><strong>own<\/strong> <\/em>cybersecurity consulting (for Ardalyst), and doesn&#8217;t work at Marinette Maritime. So Josh O&#8217;Sullivan couldn&#8217;t hire Dragos to fix the problem if he wanted to. But this sort of inability to read the room is on brand for <del>desperate<\/del> aggressive sales reps who stalk the comments sections of LinkedIn posts.<\/p>\n<p>And, it has the added benefit of being hilarious to watch.<\/p>\n<p>Then, for some reason, <em><strong>another<\/strong> <\/em>cybersecurity consultant chimed in to shill for Dragos, too. <a href=\"https:\/\/www.linkedin.com\/in\/jaime-mizell-3966564\/?lipi=urn%3Ali%3Apage%3Ad_flagship3_detail_base%3BpK16hyvaRhCbUjloNtjl7Q%3D%3D\">Jaime Mizell<\/a> of FCN IT, also sold Dragos as <del>cancer cure<\/del> the ultimate solution while giving West another chance to &#8230; well, do whatever the hell he thinks he&#8217;s doing:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-28448\" style=\"border: 1px solid #000000;\" src=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/05\/cybersecuritycults4.jpg\" alt=\"\" width=\"500\" height=\"218\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/05\/cybersecuritycults4.jpg 671w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/05\/cybersecuritycults4-150x65.jpg 150w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/05\/cybersecuritycults4-200x87.jpg 200w\" sizes=\"(max-width: 500px) 100vw, 500px\" \/><\/p>\n<p>All nice, except that the universe had other plans for Dragos, perhaps teaching a lesson that not only does pride goeth before a fall, and all that.<\/p>\n<p>You see, just <em><strong>four days<\/strong><\/em> after West posted his <del>stunningly daft<\/del> bold claims, Dragos itself had been hit by a cybersecurity &#8220;incident&#8221; and a cyberextortion demand. Per the reporting from <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/cybersecurity-firm-dragos-discloses-cybersecurity-incident-extortion-attempt\/\">BleepingComputer<\/a>:<\/p>\n<blockquote><p>While Dragos states that the threat actors did not breach its network or cybersecurity platform, they got access to the company&#8217;s SharePoint cloud service and contract management system.<\/p>\n<p>After failing to breach the company&#8217;s internal network, they sent an extortion email to Dragos executives 11 hours into the attack.<\/p><\/blockquote>\n<p>While Dragos was quickly able to patch the problem, this flies in the face of West&#8217;s absolutely nutjob claims (yes, I stopped doing strikethrough jokes) that Dragos could &#8220;<em>have prevented<\/em>&#8221; cyberattacks and then keep them &#8220;<em>from ever happening again<\/em>.&#8221;<\/p>\n<p>According to <a href=\"https:\/\/www.scmagazine.com\/analysis\/business-continuity\/ransomware-attack-gets-personal-for-dragos-chief\">SC Media<\/a>, the hack was the usual result of a single employee having been compromised, something that Dragos is unlikely to <em><strong>ever<\/strong><\/em> present a miracle cure for:<\/p>\n<blockquote><p>The incident began on Monday when an unnamed \u201cknown criminal group\u201d gained access to select Dragos&#8217; systems by compromising the personal email address of a new sales employee prior to their start date. The group then impersonated the new employee and completed initial steps in the company\u2019s onboarding process. The activity was eventually flagged in an alert from their Security Information &amp; Event Management, and the compromised account was blocked.<\/p><\/blockquote>\n<p>As far as I can tell, this is the first time Dragos was hacked, so it remains to be seen if they can literally &#8220;<em>prevent this from ever happening again<\/em>&#8221; but, clearly, logic and a functioning brain stem dictate that no single cybersecurity solution is as 100% foolproof as West claims. And now, if anything, their posturing paints a big, fat, red target on their backs, as hackers will flock to Dragos just to embarrass the living shit out of them.<\/p>\n<p>We get it: cybersecurity is important, and the risks are high. But the industry is filled to the nose-hairs with shills, charlatans, and carnival barkers, all claiming their particular solution (<em>CMMC! ISO 27001! Zero Trust!<\/em>) is the thing that permanently fixes everything.<\/p>\n<p>You know that&#8217;s not true. We all do.<\/p>\n<p>Oh, and just wait until the CMMC players get hacked. Get out the popcorn for the comments sections on <em><strong>that<\/strong> <\/em>day.<\/p>","protected":false},"excerpt":{"rendered":"<p>Cybersecurity solutions firm Dragos was hit with ransomware attack just four days after claiming they could prevent such incidents.<\/p>","protected":false},"author":2,"featured_media":28449,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","mc4wp_mailchimp_campaign":[],"footnotes":""},"categories":[5],"tags":[7679,938,8315,65,954],"class_list":["post-28444","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-opinion","tag-cmmc","tag-cybersecurity","tag-dragos","tag-iso-27001","tag-nist","et-has-post-format-content","et_post_format-et-post-format-standard"],"_links":{"self":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/28444","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/comments?post=28444"}],"version-history":[{"count":1,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/28444\/revisions"}],"predecessor-version":[{"id":28450,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/28444\/revisions\/28450"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/media\/28449"}],"wp:attachment":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/media?parent=28444"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/categories?post=28444"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/tags?post=28444"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}