On December 22, 2022, password management company LastPass announced
that an unknown threat actor leveraged information obtained during an August 2022 security incident to access a third-party cloud-based storage service that LastPass uses to store archived backups. Although LastPass claims that the threat is minimal due to their data encryption methods, attackers could have access to:
- Customer account information and related metadata, including company names, end-user names, billing addresses, email addresses, telephone numbers, and the IP addresses from which customers were accessing the LastPass service; and
- Unencrypted data, such as website URLs, as well as fully encrypted sensitive fields, such as website usernames and passwords, secure notes, and form-filled data
As a result of the breach, LastPass recommends that customers take an extra measure of caution and change their master passwords to prevent any potential downstream risks such as from a credential stuffing attack.
This incident is yet another example of how organizations can be impacted by a third-party vendor breach and events in their fourth-party ecosystem. This post reviews three practices to improve discovery and mitigation of vendor security incidents, and offers some basic questions to probe vendors on their exposure to the latest LastPass data breach.
3 Best Practices for Third-Party Vendor Data Breach Mitigation
Although it is not possible to eliminate all risk from every vendor relationship, your third-party risk management program can still deliver the visibility and automation to effectively find and mitigate the risk before further damage or disruption to your business can occur. Start with these three steps:
1. Identifier les fournisseurs susceptibles d'utiliser la technologie concernée
Knowing which vendors use an impacted technology requires knowing who your vendors are in the first place, and that means building a centralized vendor inventory. You can’t accomplish this by using spreadsheets, or by delegating vendor management to line-of-business teams. It has to be done centrally in a system that everyone in the organization with a hand in vendor management can access. You should be able to import vendors from those spreadsheets or use an API connection to an existing procurement solution into a central system of record.
Once you have centralized all your vendors use vendor questionnaires supported by passive scanning capabilities to help you identify fourth-party technology relationships. In this particular breach case, this exercise would reveal which vendors use LastPass (and by proxy, the third-party cloud backup provider that was breached). Collecting information about fourth-party technologies deployed in your vendor ecosystem helps to laser in on organizations using the impacted technology so you can prioritize vendors to further assess.
2. Procéder à des évaluations des risques spécifiques à l'événement
Once you have identified vendors with the impacted technology deployed in their environments, engage those impacted vendors with simple, targeted assessments that align with known security standards and best practices such as NIST 800-161
and ISO 27036. Results from these assessments will help you target needed remediations to close potential security gaps. Good solutions will provide built-in recommendations to speed the remediation process and close those gaps quicker.
Start your event-specific assessment with the following eight questions, weighting answers according to your organization’s risk tolerance:
| Questions | Choix des réponses |
|---|---|
| 1) Is your organization using LastPass? | Veuillez choisir l'une des options suivantes :
a) Oui b) Non |
| 2) If the organization is using LastPass, have users’ master passwords or stored passwords been compromised as part of this breach? | Veuillez choisir l'une des options suivantes :
a) Oui b) We haven’t determined whether master and stored passwords have been breached. c) No |
| 3) Has the organization required users to change their master passwords and stored application passwords? | Veuillez choisir l'une des options suivantes :
a) Oui b) Non |
| 4) What is the nature of the impact to the organization as a result of this cyberattack?
Texte d'aide : Il convient de tenir compte de l'endroit où l'impact s'est produit, ainsi que du niveau d'impact. Impact significatif : la vulnérabilité a entraîné une perte de confidentialité ou d'intégrité des données. Impact élevé : la disponibilité du système a été périodiquement compromise, entraînant une perte partielle de la confidentialité ou de l'intégrité des données. Faible impact : aucune perte de confidentialité ou d'intégrité des données ; perturbation minimale ou inexistante de la disponibilité du système. |
Veuillez choisir l'une des options suivantes :
a) Nos systèmes ou applications critiques ont subi un impact important. b) L'impact sur nos systèmes ou applications critiques est important. c) L'impact sur nos systèmes ou applications critiques est faible. d) La cyber-attaque n'a pas eu d'impact sur nos systèmes ou applications critiques. |
| 5) Have best practice controls been implemented to mitigate damage from this breach?
Help text: LastPass recommend the following steps: 1. Immediately log out of all active LastPass sessions. |
Please select all that apply:
a) We have enforced changes to master passwords. b) We have updated our LastPass account email addresses. c) We have reviewed our account history for suspicious login activity. d) We have restricted our account to only trusted devices. e) We have restricted our account to only trusted locations. |
| 6) Does the compromise affect critical services delivered to client? | Veuillez choisir l'une des options suivantes :
a) Oui b) Non |
| 7) L'organisation dispose-t-elle d'un plan d'enquête et de réaction en cas d'incident ? | Veuillez choisir l'une des options suivantes :
a) Yes, a documented incident investigation and response plan is in place. b) No, a documented incident investigation and response plan is not in place. |
| 8) Qui est désigné comme point de contact pour répondre aux questions supplémentaires ? | Veuillez indiquer le contact principal pour la gestion des incidents liés à l'information et à la cybersécurité.
Nom : Titre : Courriel : Téléphone : |
Prochaines étapes : Activer votre programme de réponse aux incidents par des tiers
If a cybersecurity incident occurred in your vendor ecosystem, would your organization be able to quickly understand its implications to your business and activate its own incident response plan? Time is of the essence in incident response, so being more proactive with a defined incident response plan will shorten the time to discover and mitigate potential vendor problems. A more programmatic third-party incident response plan could include:
- une base de données centralisée des fournisseurs et des technologies sur lesquelles ils s'appuient
- Évaluations préétablies de la résilience, de la continuité et de la sécurité de l'entreprise afin d'évaluer la probabilité et l'impact d'un incident.
- La notation et la pondération permettent de se concentrer sur les risques les plus importants.
- Recommandations intégrées pour remédier aux vulnérabilités potentielles
- Des rapports spécifiques aux parties prenantes pour répondre à l'inévitable demande du conseil d'administration
For more on how Prevalent can help your organization accelerate its discovery and mitigation of third-party risks, contact us or schedule a demo today.
Note: These are basic questions meant to expose some initial information and offer answer options that can help to weigh the risk to your organization. Your organization may choose to ask different or additional questions. Prevalent customers also have access to this assessment in their questionnaire libraries.
3. Contrôler en permanence les fournisseurs concernés
You have to be continuously vigilant not only for risks stemming from this particular attack, but for the next attack too. That’s why you should look for credentials for sale and for signals of an impending security incident by monitoring the Internet and dark web using continuous cyber monitoring.
Monitoring criminal forums, onion pages, dark web special access forums, threat feeds, paste sites for leaked credentials, security communities, code repositories, and vulnerability and hack/breach databases is essential. You can monitor these sources individually, or you can look for solutions that unify all the insights into a single solution, so all risks are centralized and visible to the enterprise. The latter approach enables you to correlate the results of continuous monitoring with risk assessment answers to validate whether vendors have controls in place.
Note de l'éditeur : cet article a été publié à l'origine sur Prevalent.net. En octobre 2024, Mitratech a fait l'acquisition de la société Prevalent, spécialisée dans la gestion des risques liés aux tiers et basée sur l'IA. Le contenu a depuis été mis à jour pour inclure des informations alignées sur nos offres de produits, les changements réglementaires et la conformité.
