SMBs need to take immediate action on Microsoft Exchange vulnerabilities

General News

Summary

This is a situation that can disproportionately affect small and medium sized businesses (SMBs) and other smaller organizations, like state and local governments. If you find information on your Exchange servers that matches what’s in the Microsoft advisory, then your system has likely been compromised by these attacks and you’ll need to take further action to recover. Chris Krebs, the former head of the United States Cybersecurity & Infrastructure Security Agency (CISA) notes in his guidance how difficult it is to know for sure that a system ISN’T compromised in this Tweet: Thoughts on the Hafnium Exchange hack: (1) it’s going to disproportionately impact those that can least afford it (SMBs, Edu, States, locals), (2) incident response teams are BURNED OUT & this is at a really bad time, (3) few orgs should be running exchange servers these days. https://t.co/bc5yutThve — Chris Krebs (@C_C_Krebs) March 6, 2021 He recommends people assume they’re compromised and increase monitoring or, if you can’t do that because you don’t have the expertise, that you take recovery steps like the ones outlined in option 1. Unfortunately, as Chris Krebs noted “it’s going to disproportionately impact those that can least afford it (SMBs, Edu, States, locals)” and the information currently available doesn’t make clear to these audiences what they need to do.

Classifications

industries
No industries detected
applications
Accounting and Taxes

AskAI Classifications

Labels
SaaS Cloud Computing Enterprise Software

Linked Companies

Microsoft
$1B+