What will you do on the day the walls come down?

Imagine the following scenario: a group of hackers take over the Azrieli Towers in Tel Aviv, they demand that we pay a ransom of 10 million shekels, and if we don't, they will turn on the sprinklers in all the offices and flood the building. As a demonstration of their capabilities, they disable the parking lot and prevent the barriers from opening. Sounds like a crazy scenario to you. ?
Cyber ​​protection - the day the walls are breached

Table of Contents

I am Nir Brown and I am the head of a division business continuity and the organizational resilience at Elements. We specialize in improving preparedness for crisis situations and emergency events, and managing dealing with them - both in the physical world and in the virtual world.
The subject of our conversation today is What if - what will happen in the organization when the walls are breached?
And they will.

In the Middle Ages, the great cities developed within a wall. The concept was that the only way to protect yourself is to surround the city with a wall, and the higher and stronger the wall, the better. And to the wall they added another outer wall and other measures such as turrets, and gates, and a moat and guards and boiling oil and more.
And finally, in the vast majority of cases, the wall was breached...
And if the wall was not breached by force - use more force: catapults, ladders, battering rams, towers. For every defense system, an attack system was developed that overcame it. And in those cases where force didn't help either - in the end we found some USER who opened the gate, on purpose or by mistake. And when nothing helped, they brought a Trojan horse..

Because in the end, it's an unfair competition between defender and attacker, and in this game of cat and mouse, the attacker will always win..
The defender must succeed every time. He must not leave any weak spot, and he must not let his guard down even once. And the attacker, he just has to keep trying... and trying, until he finds the exposed weak spot.
And when the attacker has already entered the city, after having exhausted all resources in the battle on the wall itself - the war inside the city becomes a much more complex challenge, both militarily and from a leadership perspective.

In the world Cyber ​​defense The situation is exactly the same. Organizations invest a lot in defense walls and solutions to prevent cyber attacks: firewall and antivirus and IDR and SOC and SIEM and dozens of other smart tools and technologies that in the end are all designed for one thing only - to prevent the attacker from succeeding and penetrating the organization's walls.
But what if in the end he does succeed? What if we come to work one morning and discover that the system has been hacked?

the mother Do we know how to conduct the war within the walls?

In the last year alone, hundreds of millions of dollars have been paid out as a result of Ransomware attacks:

  • Garmin paid $10 million
  • Treblex paid 6 million
  • The City of New Bradford paid $5.3 million
  • Tower was attacked, and Sapiens, Vorint and who not?

And these are only the large published attacks, and these are only the direct damages that result from the payment to the attackers.
And what about the cumulative damage: the loss of income and the shutdown of work, and the hardware that needs to be replaced, and the costs of restoration and claims, and the legal litigation and the insurance premium that goes up and up, and fines, and... the price can be unimaginable. And the recovery time can be very long.

And the biggest problem is that too many organizations are ignoring this mine today. Too many organizations assume this is the CISO's problem. That is his responsibility.
How many organizations have built an action plan for the terrible moment when the flashing message pops up: you have been hacked?
How many organizations know what to do? To pay or not to pay? Are we even allowed to pay? Will the insurance reimburse us? What are the chances of recovery? Who can help us? What is the expected damage? How do you estimate the expected damage? How do you manage this event? What is legally allowed? Are we subject to GDPR? How do you conduct negotiations? With whom do you conduct negotiations? And a million more questions without answering which it is impossible to manage the event in a serious way.
And no, these are not technological questions, these are business, strategic questions, and therefore the ones who need to deal with them are not the technological factors. This is the core of the business - and therefore it should concern the management of the business.

and yet. With all the importance I attach to society's readiness for attacks by the information system, I fear that we are dealing here with the previous war and not the next, and here I want to highlight an even more troubling point.
According to a survey published just a few days ago, in three quarters of the attacks the attackers managed to encrypt the information. Despite this, only a quarter of the entities that were attacked - really paid the ransom. The rest were able to recover by restoring from backups or in other ways. For comparison, just four years ago, in a similar survey, the result was that 70% of the organizations paid the ransom.

This means that from the point of view of the attacker, ransomware attacks are a high-risk investment. There is a very high chance that you will not see the money in the end. May the effort be in vain. Too many organizations have learned how to defend themselves effectively. And like in the neighborhood, when your neighbors invest in protection and protection measures such as a fence and a multi-bolt and alarms - buy a dog. Because the thieves will look for the easy target, the house with the open window or the person who left the key under the carpet at the entrance.
And in the cyber world the most open and breached window is the control systems and infrastructures.

To date, we have hardly seen ransom attacks on infrastructure, but, actually... why not?
I started with the example of the attack on the Moshe Aviv Tower. A similar story with even more serious consequences also happened in a hotel in Austria.
But why stop at an office building? The real big money is in the industrial plants.
If an attacker manages to break into the control network that manages the bromine tank of a chemical plant - show me one manager who would be brave enough not to pay and risk the attacker blowing up the tank? Such an attacker will be able to demand and receive any amount he wants.
An attacker who takes over the production line of an industrial plant could do unimaginable damage - such that stealing information would be child's play compared to him.
And if in the IT world we can always hope that we will be able to restore from a backup, and if not then the attacker will give us the encryption key -
In the world of control systems and infrastructures, no backup will help us. The damage will be irreversible.

In general, we tend to throw too much of what we know about cyber defense in the IT world into the world of control system protection. And that's a mistake. Because the world of control systems behaves differently:

  • In the world of control systems, backup is irrelevant, because what is important is the physical asset and not the information
  • And in the world of control systems, the damage is physical and irreversible
  • And in the world of control systems, the rate of upgrades and updates is very low, there are many other critical systems that are based on Windows XP or even DOS. Systems written in the days when a virus was just the flu.
  • And above all, whoever manages the protection of the information systems, has already realized the importance of protecting and securing information and is aware of the risks and threats. This is his profession. Whoever manages the control systems - in most cases comes from the world of operations. What interests him is that the production lines will continue to work. May the grantors and chillers not stop. Information security is in a very low place in his awareness. And even if it's a generalization, it's not very rude.


One of the most common claims we've heard in organizations is that there is no information security problem in the control networks because they are completely disconnected from the Internet and the outside world. To date, this claim has not stood the test of reality in any of the organizations we have tested. All were open to the Internet, and almost all without any serious protection measures. And no one understood the severity of the threat and its meaning.

So it is true that the attackers are not yet skilled and sophisticated enough, and have not yet really discovered the potential of attacking control systems. But attackers learn faster.
And when they succeed the price will be much higher. 

Our conclusions are clear

The question is not if our defense systems will be breached, but only when and where. We have to assume that one day the attacker will succeed in penetrating us, if it hasn't happened already. True, it's a well-worn cliché, and everyone says it all the time. This is still the most important lesson that everyone must remember and besiege.
The most exposed and most neglected weak point is in the control systems - that's where the big money is and that's where the big opportunity for the bad guys is. They may not have realized it yet, but it won't stay that way forever

And this is really not a problem of the CISO. Or at least not just his. Managements must prepare for the threat scenario, prepare for it and build a coping plan that will allow the business to reduce the damages and continue to function, even when the technological walls are breached.
And like any plan - there is no meaning to the plan without it Practice cyber incidents Real and tangible of the management in managing cyber incidents in general and cyber control systems in particular.

Organizations that internalize these conclusions and prepare accordingly will be able to deal with attacks of any kind and minimize the damage. X and those who don't... well, even the bad guys have to live on something. (:
Thank you very much for listening, you are welcome to contact us with questions, comments, ideas and of course if you need assistance in formulating a disaster recovery plan - DRP, or a preparedness exercise.

Questions and Answers – FAQ

What does dealing with cyber incidents involve?

Cyber Incidents Management It is a management process that aims to ensure that the organization knows how to act in real time – from the moment the breach is discovered until the return to normal. It includes early identification of the attack, real-time incident management, coordination between IT, cyber, management and spokesperson teams, damage assessment, prioritization of actions, media management with the public, and finally, learning lessons and recovery.

At Elements, we emphasize that a cyber event is not just a technological event, but first and foremost a managerial and strategic event, which requires making business decisions in real time.

What does a real cyberattack look like when it happens?

In many cases, cyberattacks begin quietly. An innocent file, a link sent in an email, or unsecured access to a control system. Sometimes it is only after hours or days that the scope of the attack is revealed – file encryption, system shutdown, damage to physical infrastructure, etc. In such a scenario, the organization is required to implement a systematic response plan: stop the infection, prevent further damage, decide whether and when to pay a ransom, and communicate the information to the public and customers. Without advance preparation, the incident may escalate quickly and cause long-term damage – financial, business, and reputational.

What is the right way to prepare for a cyber incident before it happens?

Early preparation is key. It includes analyzing cyber risks, building a disaster recovery plan (DRP), training management and teams in attack scenarios, and creating an internal and external communications plan for the organization.

At Elements, we also incorporate crisis simulation exercises using the CHESS system, which allows management to experience a real cyber event under controlled conditions - to identify vulnerabilities and practice decision-making under pressure.

Why the responsibility for dealing with cyber attacks doesn't belong solely to the departmentIT?

One of the most common mistakes in organizations is to see a cyber incident as solely a technological issue. In reality, when an attack occurs, managers, finance people, lawyers, spokespeople, human resources, and more are also required.

Decisions like whether to pay a ransom, how to update customers and employees, or how to rebuild trust after an incident are managerial, not technical, decisions. Therefore, every organization must develop a holistic approach to cyber crisis management that includes all levels.

What happens after the attack is over?

After the incident is contained, the equally important phase begins – recovery and analysis. The organization needs to learn lessons, update its contingency plans, improve security procedures, and restore systems to full operation. In many companies, this is also an opportunity to reexamine the organizational culture – the levels of awareness in the organization, trust in processes, and the ability to cooperate under pressure. At Elements, we accompany the organization through this phase as well, until full control is regained and organizational resilience is built for the long term.

What is the most common mistake when dealing with cyberattacks?

The biggest mistake is the assumption that "it won't happen to us." In practice, no organization is immune today; from government agencies and international corporations to small businesses. Without a defined plan, every minute that passes during an attack could cost a fortune. Therefore, it is important to prepare in advance, implement a systematic plan, and regularly practice dealing with cyber events in real time.

Elements has extensive experience in advising companies and organizations in the field of defense and dealing with cyber crises. For more information, please contact: 072-2650145, or using Referral form.

More articles