It’s worth revisiting Colonial Pipeline, as Axios just did. The critical difference between this incident and others – Colonial themselves did the shutdown, not Russian hackers. The ransomware only infected computers tied to the pipeline’s billing systems, but Colonial has said it decided to stop the flow of fuel through the pipeline as a precaution to prevent the file-encrypting malware from spreading to its operations.
And in related news, Investigators weren’t able to get information on the history of police calls to the home of a mass killing suspect due to a ransomware attack that knocked Dallas government computers down, law enforcement officials told Rebecca Lopez of news channel WFAA in a story this weekend. Police and fire leaders in the same city, meanwhile, said that response times had slowed. Officers are relying on backup plans, like resorting to using pen and paper during system outages.
I did want to follow up on the story I reported about the German police seeking homicide charges in a ransomware attack. They opted against doing so in the end due to inconclusive evidence.
We’re not any better on security talent — The global cyber workforce reached an all-time high of 4.7 million people last year, up about 11% from 2021, a study from nonprofit (ISC)² found.
But the workforce gap —the expected shortfall in filling new needed roles — grew more than twice as much (26%).
Finally, a security note for you. Microsoft will be throttling traffic from unsupported and unpatched Exchange servers starting today, impacting on-prem servers connecting to Exchange Online.
We’re well into societal impact for security, and thus the responses are promotional. This reinforces for me the language required to convey security to companies. It’s about impact. Avoid technical language, and speak in simple, practical, impactful terms. Use concrete examples, model the impact, and recognize it’s part of the technology spend. Not the whole spend.

