A Cybersecurity Incident, a Golf Course Conversation, and Why No Industry Is Too Boring to Be Targeted

No one expects a cybersecurity incident to begin in the cardboard industry. Yet as our guest Kayne McGladrey explains, cybercriminals don’t care what your company manufactures—they care about opportunity. In this episode, Kayne shares how an unexpected conversation with a golf buddy led to a cybersecurity contract, and why one of the most unassuming industries turned out to have a story worth telling.

Together, we explore the incident itself, how trust and professional networks can open doors in unexpected ways, and why manufacturing organizations of every kind have become attractive targets for cyberattacks. It’s a fascinating reminder that behind every product—even a simple cardboard box—there’s a complex IT infrastructure that deserves to be protected

You can read more from Kayne at https://kaynemcgladrey.com/.

Listen now on Apple Music, Spotify, Deezer, Youtube or where-ever you get your panic attacks.

The Unseen Target: Cardboard Manufacturing

In today’s digital age, when we think about cybersecurity breaches, high-profile targets such as tech giants or healthcare systems come to mind. But as Kayne McGladrey suggests, smaller industries like cardboard manufacturing can also be compelling targets. Cardboard boxes may seem unremarkable, yet they play a vital role in global logistics — every product shipped to your doorstep is protected by cardboard. This seemingly simple industry is not only surprisingly profitable but crucial due to its dependency on high uptime.

“We think about the damage done to hospitals, we think about critical infrastructure. But today, I want to talk about the unassuming target — cardboard manufacturing.”

A Manufacturing Breach: The Perfect Storm

The sequence of events leading up to this breach began with various hints the company missed. Despite receiving FBI TLP (Traffic Light Protocol) white alerts about ransomware campaigns targeting manufacturers, the company failed to act.

  • The IT team, overwhelmed with alerts, logged these warnings into their risk register but lacked actionable steps.
  • The operations team noticed lagging production lines, an omen of impending problems, but dismissed them as routine maintenance issues.

This disconnect set the stage for what would become a significant operational disruption during a long weekend — the prime time for cyber attackers to strike when defenses are likely down.

Incident Escalation: A Call from the Green

Kayne describes the unusual way the breach was discovered — a phone call from a CEO’s golf buddy. The informality of this escalation highlights the company’s unpreparedness:

  • The IT team had all the clues but no action plan.
  • The communication breakdown between IT and operations teams was glaring, with no shared understanding of risk or response strategies.

“This phone call wasn’t about rescheduling a golf game — it was the harbinger of the impending chaos.”

This incident underscores the importance of robust inter-department communication and structured incident response plans.

Operation Recovery: Fast Action in Crisis

Once the breach became evident, the race to stabilize operations began. Multiple teams, including incident response (IR), legal, and ultimately a ransomware negotiator, were assembled overnight:

  • The IR Team and Offensive Security: Kayne’s expert team included offensive security veterans who quickly began analyzing and mitigating the breach.
  • Complex Legal Considerations: Ensuring legal privilege is crucial during such incidents to manage sensitive communications. The complexities of attorney-client privilege underscore the need for professional legal counsel during cybersecurity crises.

Despite the chaos, the discovery of the threat actor’s poorly secured infrastructure and key material propelled the recovery efforts:

“We found the key material. It wasn’t exactly passwords.xls, but it was close enough.”

Ransom Negotiations: The situational irony of engaging a ransomware negotiator in an increasingly humorous dialogue with the attackers added a surprising twist to the intense situation.

Lessons Learned: Strengthening Cyber Resilience

The cardboard company’s cyber ordeal emphasizes several critical lessons for businesses:

  1. Comprehensive Risk Registers: Avoid treating risk registers as mere compliance exercises. They should be comprehensive and involve the entire business, not just IT.
  2. Enhanced Communication: Establish clear communication channels between IT and operations, fostering mutual understanding and preparation for potential breaches.
  3. Regularly Test Incident Response: An effective incident response plan should be periodically tested and updated to ensure preparedness.
  4. Invest in Telemetry: Implementing systems that monitor, record, and provide insights into network activities is essential for reconstructing attack paths and responding effectively to incidents.

It’s also worth appreciating the role of luck in this tale — the attacker’s minimal persistence paths, unsecured keys, and a holiday-induced production dip were fortuitous factors that aided in the company’s recovery.

Conclusion: From a Brush with Disaster to Future Readiness

The tale of the cardboard manufacturer is a stark reminder of the unforeseen vulnerabilities that can exist in seemingly straightforward operations. As businesses, especially those in niche sectors, navigate the digital landscape, establishing comprehensive security measures and fostering a culture of cybersecurity awareness is paramount.


Leave a Reply

Your email address will not be published. Required fields are marked *