News

Hacked deeds: a multi-million dollar business for lawyers and consultants

by Ivan Cimmarusti 10 April 2018

A secure computer is a computer disconnected from the network. But it is also a useless machine. "Investment in cyber security and respect for canons of prudence, perhaps codified in corporate best practices, are the right answers for preventing hacker attacks," assures deputy quaestor Ivano Gabrielli, head of the Cnaipic (National Cybercrime Centre for Critical Infrastructure Protection) of the Postal Police.

At stake is a multi-million business based on the illicit trafficking of sensitive data, often stolen with computer viruses and used to damage the legitimate owners, through computer fraud and extortion. Resale within black markets allocated in the dark web, that part of the Internet that makes controls difficult because it is covered by an anonymisation system, is not excluded. Lawyers and accountants in particular are in the crosshairs, but also those companies that turn to these professionals for financial transactions that should remain secret but risk ending up in the hands of cybercriminal organisations that can resell them, also favouring forms of insider trading.

Sensitive data and privacy
Everything revolves around the sphere of privacy and the trafficking of sensitive data, the online sale of which promises maximum profits but low risks (see interview below). We are talking about confidential material that may concern 'the financial structure of a professional firm or a company,' Gabrielli explains, 'but also data pertaining to the personal sphere of individuals, who could thus also end up the victim of blackmail. Investigators often have to deal with two types of computer crime, which professional firms also incur. The most critical is 'ransomware': a system that can be compared to a 'worm', a worm,' Gabrielli explains, 'that once entered through an email, starts moving from computer to computer, encrypting the contents of files with an access key that is impossible to decipher. Within minutes, the firm finds itself deprived of all its data. To get it back, it has to pay through cryptocurrencies that make even financial investigations difficult'.

Dark web
What is different are 'Ceo' and 'Bec' frauds: the former takes its name from the chief executive officer - i.e. the managing director of a company - while the latter from business email compromise. Through these two forms of fraud, professional firms can have sensitive confidential data stolen that could be used for various purposes, in addition to fraud. Investigators do not rule out the possibility that behind these attacks there may be hackers specifically hired on the dark web to break into the computer systems of professional firms and companies in order to steal sensitive documents relating to sensitive financial transactions.

Protocols and cyber security
Protection must follow two parallel tracks: on the one hand, investment in cyber security, a cost related to improving the security of the IT infrastructure, and on the other hand, planning a proper protocol to which reference can be made in order to minimise the risk of computers being infected. 'Issuing precise corporate cyber security policies can be an important factor in governing risk,' Gabrielli concludes.

Source: http://www.ilsole24ore.com/art/notizie/2018-04-08/con-atti-hackerati–business-milionario-legali-e-consulenti–135839.shtml?uuid=AEjCxNTE&refresh_ce=1

Share:

Degree in Business Administration from the University of Naples 'Federico II' with an MBA in Business Management achieved with high merit in 2008 by winning a scholarship provided by Invitalia S.p.A. from which she was selected in the first months of attendance as the best MBA profile.

After a brief experience in Invitalia S.p.A., he immediately held increasingly important roles in the management of Administration, Finance and Control of companies operating in the defence sector, theInformation Technology, of Cyber and National Security. In addition, she was Treasury Manager in companies operating in theEnergy.

He obtained an Executive Master in Finance (EMF) at SDA Bocconi in 2020, with a specialisation in Corporate Finance & Control and, in 2022, a further specialisation track in Asset, Wealth Management also at SDA Bocconi.

For over five years it has been the Chief Financial Officer of the Defence Tech Group, whose listing process he followed on the Euronext Growth Milan segment of Borsa Italiana.

From 2017 to 2024, she was a member of the boards of directors of all the legal entity of the Defence Tech Group with delegated powers over their financial management and from October 2021 to October 2024 was a Board Member of the Holding Company.

It is currently also Investor Relations Manager of the listed Defence Tech and follows all ESG issues of the Group.

In July 2021, she was recognised by Federmanager as one of the best talents under 44 at national level, receiving an important award as Young Manager 2020.