How to handle the Snowflake data breach

View profile for Johnathan Bald

Cyber Risk Professional 🤖 | Leading and Empowering High Performing Sales Teams | Classic Car Enthusiast 🚗 | Diehard Skier ⛷

***#Snowflake #DataBreach Remediation Actions Below**** Everyone is still grappling with how to handle the recent Snowflake breach. On June 5th, Black Kite was able to detect which of your vendors in your ecosystem were impacted. Taking it a step further, we provide recommended questions to ask your vendors combined with prescriptive remediation actions. Read the full blog from Black Kite’s Chief Risk and Intelligence Officer: https://lnkd.in/gAvef3SK QUICK BLOG RECAP: (TLDR) WHY SHOULD #TPRM PROFESSIONALS CARE ABOUT THE #SNOWFLAKE INCIDENT? Snowflake is a cornerstone for approximately 10,000 companies and organizations, providing essential cloud computing and analytical services. TPRM professionals need to pay close attention to this incident, even if they do not directly interact with Snowflake. The interconnected nature of modern supply chains means that a breach in one critical provider can cascade through numerous organizations. What questions should TPRM professionals ask vendors about the incident mentioned in the FocusTagTM? TPRM professionals should ask their vendors the following specific questions: ·        Do you use Snowflake’s cloud storage services? If so, have you implemented multi-factor authentication (MFA) for all user accounts? ·        Have you recently updated your security protocols to address credential-based attacks? ·        Are you actively monitoring for indicators of compromise (IoCs) related to the Snowflake breach? ·        What measures are you taking to protect data stored on cloud platforms like Snowflake? ·        Have you communicated with Snowflake regarding the incident and followed their security recommendations? ·        How are you ensuring the security of data accessed via Snowflake credentials? Remediation Recommendations for Vendors to This Risk To mitigate risks associated with the Snowflake incident, vendors should: ·        Implement MFA on all Snowflake accounts. ·        Monitor account activities for unusual behavior. ·        Follow Snowflake’s guidance on detecting unauthorized access. ·        Update cybersecurity strategies and ensure all staff are aware of the incident. ·        Maintain communication with Snowflake for updates and further recommendations. We believe in sharing intelligence to improve everyone's cyber posture together! #snowflake #DataBreach #TPRM #CyberRisk

Shawn B.

Expert in Third-Party Risk Management | Information Security Leader

9mo

You guys did a great job with the tagging of clients utilizing Snowflake. It gave us a fantastic start to determining which partners of ours utilize the solution, which allowed us to have a swift process! All in all, Black Kite gave us the opportunity to better improve our security posture by identifying partners and then working with them to remediate or place compensating controls! Fantastic work by your team!

Ferhat Dikbiyik, Ph.D., CTIA

Passionate Cybersecurity Researcher at Black Kite

9mo

Thanks, Johnathan Bald, for the shout-out.

See more comments

To view or add a comment, sign in

Explore topics