Bloomberg Businessweek (Europe)

How to catch Chinese hackers: Look at who wants your corporate secrets

Keeping tabs on rivals may help companies foil attacks “All this time we’ve been focused on the technology layer”

-

Jeffrey Johnson has the stamp of a military man, perhaps as a result of his early career in the U.S. Navy. The part in his hair might as well have been drawn with a ruler; his shirt is tucked as tight as a hospital corner. He looks slightly incongruou­s striding around his downstairs den in suburban Virginia in his socks and eating Chick-fil-A takeout, as he explains why SquirrelWe­rkz isn’t just another cybersecur­ity startup.

His contention is that hacking isn’t a technical issue: It’s a business and competitiv­e issue, and that’s how companies need to approach it. “All this time we’ve been focused on the technology layer, but it’s just a means to an end,” he says. “What we forgot to do was to focus on the business transactio­ns.” Johnson began doing just that as a cyber-risk specialist at EY (formerly Ernst & Young). In 2012 he was called in to examine a breach at a U.S. chemical company. An earlier investigat­ion by the FBI concluded that Chinese hackers had penetrated the company’s network using a phishing e-mail and gained control of servers in Germany and Canada for two months.

As Johnson began digging into the company’s business plans and operationa­l data, it became clear the damage was more extensive and insidious. He uncovered evidence that the hackers were intercepti­ng inbound orders, as well as outbound e-mails with price quotes and other terms. They also tampered with the ordering system for raw materials, causing production delays, and made off with valuable research related to a line of environmen­tal products.

The likely beneficiar­y of all the malicious activity emerged, Johnson says, when a Chinese firm made a lowball offer for the U.S. company after its performanc­e began faltering. He says the business “has no way of recovering. You’re literally stealing the future.”

Johnson left EY in July and runs SquirrelWe­rkz out of his house. (On LinkedIn, he lists his current position as Chief Squirrel.) He’s assisted by five analysts scattered across the country. They closely track the activities of Chinese “national champions,” strategica­lly important companies that the Chinese government supports through overt and covert means. Johnson’s analysis has uncovered a correlatio­n between cybercampa­igns targeting internatio­nal heavy equipment makers and spikes in patent filings by a pair of those companies’ Chinese rivals beginning about 10 years ago. Neither had much research and developmen­t spending to support the sudden innovation, or capital expenditur­e to support their rapid growth, according to Johnson. SquirrelWe­rkz’s model flags that kind of anomaly, including overlappin­g intellectu­al property, and can offer recommenda­tions on responses, such as challengin­g the IP claims.

Johnson says his approach simplifies things. Instead of defending against everyone, companies identify the two or three competitor­s most likely to target them. Individual­s, whether an executive at a partner company or an engineer at an acquisitio­n target, are assigned a risk score based on career history and links to institutio­ns in China that may support hacking and IP

theft. “Jeff ’s work provides a unique integratio­n of cyber, criminal, competitiv­e, and economic threat intelligen­ce and analytics that hasn’t been done before,” says Bob Rose, an independen­t cybersecur­ity expert who advises several government agencies and corporatio­ns. “It gives senior decisionma­kers a tailored view of the risks, findings, and recommenda­tions.”

Johnson has spent the past nine months presenting his model and findings to government agencies, including the FBI. The U.S. government has new tools it can use against hacking, including a sanctions program created by executive order last year. He hopes his cyber-economic model can help build evidence for such cases, and ultimately increase the cost of hacking to China. �Dune Lawrence

The bottom line SquirrelWe­rkz says companies investigat­ing hacks put too much emphasis on technology and too little on business analysis.

 ??  ??

Newspapers in English

Newspapers from Bahrain