Transcript
A (0:00)
Everyone is working hard, but you need a central coordinator that perhaps extend beyond that is capable of extending beyond traditional incident coordination. So now what you're actually doing is your personality shopping. You're looking for an individual, someone with the right set of behaviors, someone who's able to ensure commitments are met during the incident, is able to produce real time reports on progress and able to pull simplicity from the complexity. And of course they have to have the right demeanor, someone who stays calm under pressure.
B (0:34)
This is katiecast as a primary target
A (0:38)
for ransomware campaigns, security and testing and performance. We can actually automate that, take that data and use it.
C (0:49)
Joining me now is Alex Loizzu, Managing director at Intrinsic Security. And today we we're discussing the human impact of a cyber incident. Alex, thanks for joining and welcome.
A (0:59)
Thank you, Carissa.
C (1:00)
So, Alex, for those perhaps who don't know, you are the former CISO of Medibank who was unfortunately breached in 2022. So I wanted to bring you, Alex, on the show today to walk through the incident from where it sat and also for full transparency. Alex won't be able to talk about certain things due to the sensitivity of the incident, but we did feel the need to bring Alex on to share who has lived through these stories that we all hear about. So on that note, Alex, can you take us back to the moment you first got the alert or the call about the breach?
A (1:37)
Absolutely. So that takes us to the evening of the. Effectively, the call that no SISO wants to receive. Although at that point we didn't quite understand the significance of what we were seeing. It didn't start as a fire alarm, but rather, you know, just a detection of unusual behavior by the team. For anyone who has run a large environment, unusual behavior isn't something that is, dare I say it, that unusual usually is something benign or someone has misconfigured something. In this instance, however, we kicked off our playbooks. We investigated it thoroughly, as we always do, and then through the 12th of October, you know, as our investigation expanded, we started to bring in external specialists. We were able to confirm that no, the unusual behavior was in fact a breach. And then that takes us onwards to the 13th of October when we made our first public statement.
C (2:29)
So I really want to get inside your mind on when you get a call or you get informed about what's happening. How do you feel in that moment?
