Allan Liska, Lead Threat Intelligence Analyst at Recorded Future: “‘Too often I hear from companies, ‘Why would they target us?’ That is not how ransomware targeting works.”

Allan Liska, Lead Threat Intelligence Analyst at Recorded Future, not only has the best Twitter/X handle of anyone we’ve interviewed, he also provides some of the best, most actionable advice we’ve heard. (We’ll let Allan reveal the handle below.)

“I think the biggest mistake I see happen at many organisations, especially smaller and medium-sized organisations, is thinking that they arenโ€™t a target. Too often I hear from companies, ‘Why would they target us?'” he told us.

“Ransomware groups, for the most part, target vulnerabilities, not organisations. They are looking for software to exploit, leaked credentials to use or clicked phishing emails,” he explained. “Who or what the victim is, is not something they worry about until after the attack and then they are going to try to make money from anyone they can.”

That’s just a short excerpt from a wide-ranging interview that also covers the biggest threats facing organisations today, specific issues around ransomware and the increasingly important role that governments play when it comes to ransomware and cybersecurity.

Could you please introduce yourself to our audience and share how you ended up working in the cybersecurity industry?

My name is Allan Liska, although across the industry Iโ€™m often known by my Twitter/X handle, the โ€˜Ransomware Sommelierโ€™.

Iโ€™m a ransomware researcher and intelligence analyst at Recorded Future. I began my working life at a network operations centre, configuring routers and switches for a large internet service provider’s (ISP) backbone network. This ISP got into data centres and I moved to help set up and manage their servers and networks. Then we got hit by the Code Red Worm (a LONG time ago now!) and we spent weeks removing, preventing reinfection, patching and putting a plan in place to prevent the next worm.

From that moment on, I found myself in the “cybersecurity industry”.

What are the biggest cybersecurity challenges those in leadership roles are facing today?

It’s funny, if you had asked me the same question in 2021, much of the answer would be the same as it is now. There are always budget issues and there is never enough money to tackle all the projects needed for the improvements businesses want and need to make. Asset and vulnerability management, in particular, are still challenges for many organisations.

However, today you have the added bonus that company leadership and the board of directors are keenly aware of “cybersecurity issues” (just not always enough to increase your budget) so you have to be able to effectively communicate the challenges, on top of trying to actually solve them.

Cybersecurity leaders can no longer just be technical, they have to be effective storytellers. They have to be able to translate the 1s and 0s of security into business speak and become ambassadors for the security organisation. That is one of the reasons why intelligence is such an important part of any security organisation.

Being able to provide the right level of information to the right people in a format they can understand is one of the primary uses of threat intelligence – yes, you have to be able to speak effectively to the CEO and Board of Directors, but you have to be just as able to speak to the accounting team to explain the dangers of business email compromise and how that organisation is a target. And you have to be able to talk to the developers to help them understand the risk of leaked code on code repositories.

More than ever, for security across an organisation to be effective, you have to be able to explain the role each department has in keeping the company safe and how that department might be uniquely targeted.


Worth a read: Thomas Barton, Senior Incident Response Analyst at Integrity360: โ€œโ€˜Encryptionless ransomware attacks have become very popularโ€


What are some of the major challenges youโ€™re seeing in ransomware and what do cyber professionals need to be aware of?

There is A LOT of ransomware right now and there is a whole cybercriminal ecosystem that has been built up to support ransomware groups. This means the barrier of entry for new ransomware actors is almost non-existent and we’ll continue to see more growth in the ransomware — at least in the short term — even with the high-profile takedowns we’ve seen.

What do I mean by a cybercriminal ecosystem? Almost all ransomware attacks involve at least two different threat actors. There are Initial Access Brokers (IABs) who spend their time gaining access to networks. There are many ways they do this: stolen credentials, exploitation, phishing attacks and so on. The IABs do not carry out the ransomware attack, they take the access theyโ€™ve gained and they then sell that access to the ransomware operator who carries out the actual attack.

This division of labour serves as a force multiplier for both the IAB and the ransomware operator. The IAB can invest in the automation of the initial access attack because they know they have ready buyers for the networks. This means they can work very quickly, compromising a lot of networks.

On the other hand, the ransomware operator can carry out more attacks because they donโ€™t have to worry about the initial access part. They basically get to start in a network — most likely with Admin access โ€“ and that allows them to move a lot faster to carry out the ransomware attack.

In addition to the IABs, there are all types of tools that developers have created to make the process of carrying out ransomware attacks a lot more efficient. Some of those tools were originally developed for red team use but have been co-opted by ransomware groups; others were specifically developed to be used by ransomware groups.

What are some of the biggest mistakes youโ€™re seeing businesses make when it comes to ransomware?

I think the biggest mistake I see happen at many organisations, especially smaller and medium-sized organisations, is thinking that they arenโ€™t a target. Too often I hear from companies, โ€œWhy would they target us?โ€

That is not how ransomware targeting works. Ransomware groups, for the most part, target vulnerabilities, not organisations. They are looking for software to exploit, leaked credentials to use or clicked phishing emails. Who or what the victim is, is not something they worry about until after the attack and then they are going to try to make money from anyone they can.

This attitude also leads to the second big mistake I often see: not planning for the ransomware attack ahead of time. Putting together a ransomware incident response plan can make the process of recovering from an attack can save an organisation a lot of time and money. It also has the add-on effect of helping better secure the network against ransomware.

Any good incident response plan includes running tests of that plan, and during the testing organisations often find gaps in security that they werenโ€™t aware of. When that happens, you can put a plan into place to reduce or eliminate those gaps and now youโ€™ve improved your security posture and hopefully prevented the attack.

Regular testing of a ransomware incident response plan might have the benefit of making your organisation more prepared to stop the attack in the first place.


Worth a read: IBM and Wimbledonโ€™s Catch Me Up cards to give personalised write-up for every singles tennis player in 2024โ€™s Championships


What are some prevention strategies you believe every business should adopt?

Good security always starts with the basics. It is clichรฉ to say that, but it is true. So, what are the basics:

  • Asset/Data Management
  • Identity Management
  • Vulnerability Management

We used to discuss asset management simply in terms of equipment: how many laptops, servers, routers, etc., do you have and what software is running on those systems? Thatโ€™s still a big part of asset management, but data governance is also a part of asset management now. You have to know where your data is, how it is being secured, who has access to it and what the recovery plan is if something happens.

In the case of both traditional asset management and data governance, this applies to everything inside your network as well as everything stored with other providers. You canโ€™t afford to treat the cloud as distinct when it comes to understanding your asset and data inventory.

Identity management involves knowing who is part of your organisation and who has access to your systems, locally but in the cloud as well. This means understanding when new people are hired and let go and when contractors are brought on. It also means understanding what systems an employee should โ€“ and should not โ€“ have access to and knowing when an employeeโ€™s credentials may have been compromised so you can quickly take action. Finding compromised employee credentials on your own can be challenging, using a third party to alert you when there are employee credentials being sold on underground forums or marketplaces can simplify this process and help you remediate these kinds of alerts in an automated fashion.

Vulnerability management means understanding when new vulnerabilities will impact your organisation, and when they wonโ€™t. It also means understanding which vulnerabilities are truly high priority and ensuring those get immediate attention. This is another example where intelligence plays a critical role. There are thousands of vulnerabilities announced every month. Trying to assess them all manually can cripple anyone trying to do vulnerability management. Using intelligence to understand not just the highest-priority vulnerabilities, but the ones that are highest priority to YOUR network removes that paralysis and allows your vulnerability management team to be much more efficient.

Everything else you do in your security program builds on these fundamentals. If you want to enable MFA (yes, you should) you need to know that everyone and EVERY SYSTEM is properly enrolled in MFA. If you want to add an EDR tool, you need to make sure it is rolled out to ALL OF the endpoints and servers. None of the more advanced security tools are going to be effective without a strong base. 

What role do you think governments play when it comes to ransomware and cybersecurity?

Governments must do what they legally can to make it easier for organisations to function. Obviously, no government can completely get rid of crime, much less cybercrime. But governments can help. They can put out regular bulletins about security threats and what organisations should do to protect themselves from these threats. The bulletins should be clear, easy to understand and contain practical guidelines for all businesses.

Governments should also be a resource for victims of attacks. It should be easy for a victim to know who to call and those who call should feel confident that someone will respond to them. Unfortunately, the government cannot help every victim of an attack, but it can make it easier for victims to at least report the crime. To that end, governments should serve as a clearing house for statistical information about the rates and types of cybercriminal attacks. This could help people understand what threats are on the rise and who those threat actors are targeting.

Governments should be aggressively going after threat actors who carry out attacks, both threat actors inside and outside of their borders. Shutting down infrastructure, and issuing arrest and sanctions where possible makes it more expensive for threat actors to operate and helps reduce the amount of cybercrime. Finally, governments should be helping to set standards for security. Explaining how organisations can ensure they are meeting minimum security requirements and understand what the next steps to improvement are.

Avatar photo
Tim Danton

Tim has worked in IT publishing since the days when all PCs were beige, and is editor-in-chief of the UK's PC Pro magazine. He has been writing about hardware for TechFinitive since 2023.