Integrity Attacks are Inevitable - is your Treasury Ready?
“For the treasury function, what is scariest is the changing nature of cyberattacks,” says Alec Ross, author and senior advisor for innovation to recently-declared US presidential candidate Hillary Clinton, speaking Thursday at the EuroFinance International Cash & Treasury Management Conference in Miami.
Ross notes that cyberattacks are classified in three ways:
An integrity attack is the most malignant form of cyberattack. For example, a hacker could get inside a bank and effectively manipulate the account holdings of every person or business in the system, thereby wiping out the ability to determine how much money each client has in their account.
Most treasury departments have not yet experienced these attacks, but Ross expects that is going to change. He sees those that have so far been spared falling victim over the next two or three years.
Ross notes that the 2012 cyberattack against Saudi Aramco, the world’s biggest corporate by market capitalisation, was an integrity attack. This attack resulted in the Saudi Arabian oil and gas giant being forced to write off its 30,000 computers and coming close to taking its oil rigs offline. The attack “essentially wiped out all of the data infrastructure at the world’s largest company,” explains Ross.
What Treasurers Can Do
Ross advises treasury departments to take action now to prepare themselves for these looming attacks. Four basic steps they can take are as follows:
“In the same way in which everyone needs to be able to read a balance sheet, anyone who wants to continue to ascend in their career needs to understand the very basics of cybersecurity,” Ross concludes.
“If you run the treasury inside your company, you cannot just say that the CIO or the CTO is in charge of my data integrity, my system’s integrity and my trading system’s integrity. You need to spend time with that CIO, CTO or outside consultants and become sufficiently conversant in it – so that if there is a problem you can actually add value.”