{"id":100349,"date":"2023-10-19T15:49:43","date_gmt":"2023-10-19T14:49:43","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/?p=100349"},"modified":"2023-11-06T12:41:54","modified_gmt":"2023-11-06T12:41:54","slug":"how-recycling-tech-giant-tomra-showcased-communications-while-battling-a-cyberattack","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2023\/10\/19\/how-recycling-tech-giant-tomra-showcased-communications-while-battling-a-cyberattack\/","title":{"rendered":"How recycling tech giant TOMRA showcased communications while battling a cyberattack"},"content":{"rendered":"\n<p><em>After suffering a security breach, TOMRA followed a Business Continuity plan that fostered transparency, respect and reassurance. James Watts, Managing Director, Databarracks, tells us about the efforts that TOMRA enforced throughout the attack and the importance of having a Disaster Recovery strategy.<\/em><\/p>\n\n\n\n<p>Norwegian multinational, TOMRA, specialises in state-of-the-art sorting and grading technologies for recycling, mining and food. It\u2019s perhaps best known for its reverse vending machines. In the early hours of July 16, the company discovered a cyberattack had affected some of its IT infrastructure. It immediately disconnected several of its systems to contain the breach.<\/p>\n\n\n\n<p>Most of its digital services are designed to run offline for a limited time \u2013 and it added further temporary measures to keep operations up and running. TOMRA\u2019s cybersecurity team began migrating services to the cloud and restoring others. It hired a global cyber response team from Deloitte to assist with the ongoing investigation and response.<\/p>\n\n\n\n<p><strong>Communications<\/strong><\/p>\n\n\n\n<p>Rather than posting every piece of information, at the early stages of crisis comms it\u2019s best to pare it back. It&#8217;s a difficult time, you may not have a complete picture of the situation and you don&#8217;t want to over-commit or share more than is necessary. Consider the critical needs you\u2019re addressing \u2013 and share the minimum effective message.<\/p>\n\n\n\n<p>TOMRA was transparent and concise from the get-go.<\/p>\n\n\n\n<p>The most important thing at this point is to acknowledge the issue and provide some detail on what was done to address it, and what the next steps will be. It stated that it had not been contacted by the attacker or asked to pay a ransom.<\/p>\n\n\n\n<p>TOMRA posted its last update on 25 September. Its investigation found that the attack was in its reconnaissance stage on 10 July, and the target was the company\u2019s internal systems and domain, rather than its customers.<\/p>\n\n\n\n<p><strong>Getting it right from the offset<\/strong><\/p>\n\n\n\n<p>TOMRA\u2019s first post about the attack on its website stated that it had been targeted by an \u2018extensive cyberattack\u2019, that relevant authorities had been notified and that systems had been disconnected immediately to contain the breach. The company also shared a contact email for any questions.<\/p>\n\n\n\n<p>Getting ahead of the news, laying out the response and inviting questions like this creates reassurance for the customer that you\u2019re in control of the situation \u2013 and that you have a plan. It buys you time.<\/p>\n\n\n\n<p>The update that followed was a recap of the situation so far, adding that \u2018no new hostile activities have been detected.\u2019<\/p>\n\n\n\n<p>It gave a status update on each of its external services, and whether or not they were operating as usual. This is the critical information their customers are looking for, written plainly.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.tomra.com\/news-and-media\/news\/2023\/tomra-july-20th-update-on-cyberattack\"><\/a>In TOMRA\u2019s fourth update, new sections were added \u2013 \u2018What we know about the attack\u2019 and \u2018How we work\u2019 \u2013&nbsp; along with developments on the previous day.<\/p>\n\n\n\n<p>When it was able to, TOMRA shared some key findings from its investigation so far. It established a clear timeline, starting with the detection of the threat and the steps taken to isolate it.&nbsp;<\/p>\n\n\n\n<p>It \u2018found no trace of evidence that TOMRA clients, customers, partners or their systems are at risk from the attack\u2019. It added that it would \u2018bring back services one by one as they are confirmed to be safe and secure.\u2019<\/p>\n\n\n\n<p><strong>Leadership in a crisis means honesty and transparency<\/strong><\/p>\n\n\n\n<p>In an open letter \u2013 \u201cThe Value of Team Spirit in Challenging Times\u201d \u2013 TOMRA President and CEO, Tove Andersen, addressed the attack and the question of whether they had been sufficiently prepared, writing honestly about the effect it had on the company.<\/p>\n\n\n\n<p>The impact of vulnerability in a crisis from the leader of a company this size shouldn\u2019t be underestimated. This letter puts TOMRA\u2019s people at the centre of its incident response, forming the impression of a team in sync.<\/p>\n\n\n\n<p><strong>Keeping customers updated<\/strong><\/p>\n\n\n\n<p>TOMRA\u2019s sixth update breaks down the target, timeframe, development, investigation and technical details of the attack. This update showcases the progress the investigation has made and the resources dedicated to it. It gives a fuller picture of the incident and reiterates the topline for customers \u2013 that their data is safe.<\/p>\n\n\n\n<p>Through August, the company continues with status updates on external systems and recovery progress. They don\u2019t add much new information, but they demonstrate a desire to keep customers and industry in the loop.<\/p>\n\n\n\n<p>By September, TOMRA\u2019s update is focused more on recovery. It lays out its plans for building resilience, including MFA, migrating to Zero Trust Architecture and centralising its vetting process for IT hardware.<\/p>\n\n\n\n<p>Its final update has it all. It starts with a recap, runs through recovery, key findings from the forensics report, comments from Andersen, strategies for rebuilding with greater resilience the lessons learned and changes made. It signs off as the final dedicated update on the attack and shares a communications email address.<\/p>\n\n\n\n<p><strong>Social media<\/strong><\/p>\n\n\n\n<p>Though sparse on social, TOMRA used its two LinkedIn posts well. One shared the CEO\u2019s statement, the other acknowledged that the company had been quiet on social media since the attack and explained that employees were working overtime to help customers get back to normal. It added: \u201cWe are glad we can start sharing again our usual insights and information about what we care about most: enabling a world without waste.\u201d<\/p>\n\n\n\n<p>This approach leveraged the crisis to re-establish the company\u2019s mission statement. It informed readers that there had been an issue, that the company was dealing with it and that the priority was still its core business values.<\/p>\n\n\n\n<p>This was probably one of TOMRA\u2019s strongest responses throughout the incident. It\u2019s informative enough to be a good placeholder post and reaffirmed control of the situation.<\/p>\n\n\n\n<p><strong>Takeaways<\/strong><\/p>\n\n\n\n<p>TOMRA\u2019s response to this cyberattack looks pre-planned to a tee. The regular output of communications, a growing amount of information and concise recaps of the situation thus far wouldn\u2019t have been possible without a highly prepped and practised team effort.<\/p>\n\n\n\n<p>When disaster strikes, how well you know the drill can make a massive difference in your reputation management, which is vital to your Business Continuity planning. Overall, we believe TOMRA\u2019s communications during the attack are a great example of how to do it right.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>After suffering a security breach, TOMRA followed a Business Continuity plan that fostered transparency, respect and reassurance. James Watts, Managing Director, Databarracks, tells us about the efforts that TOMRA enforced throughout the attack and the importance of having a Disaster Recovery strategy. Norwegian multinational, TOMRA, specialises in state-of-the-art sorting and grading technologies for recycling, mining [&hellip;]<\/p>\n","protected":false},"author":50,"featured_media":100350,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[51,17482,57,573,7359,476,24],"tags":[10451,19214,7109,19216,834,19215],"class_list":["post-100349","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-case-study-newsletter","category-cybersecurity","category-enterprise-security","category-features","category-industry-expert","category-nordic","category-used","tag-business-continuity","tag-databarracks","tag-disaster-recovery","tag-james-watts","tag-norway","tag-tomra"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/100349","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/50"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=100349"}],"version-history":[{"count":8,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/100349\/revisions"}],"predecessor-version":[{"id":101242,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/100349\/revisions\/101242"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/100350"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=100349"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=100349"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=100349"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}