• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechCyber Saturday

What Separates the Hacks and the Hack-Nots—Cyber Saturday

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
July 27, 2019, 1:31 PM ET
Photo-Illustration by Tres Commas; Original Photographs, Shield: Gabe Ginsberg—Getty Images; arrows: Getty images
Photo-Illustration by Tres Commas; Original Photographs, Shield: Gabe Ginsberg—Getty Images; arrows: Getty imagesPhoto-Illustration by Tres Commas; Original Photographs, Shield: Gabe Ginsberg—Getty Images; arrows: Getty images

In the latest issue of Fortune, which features our Global 500 list, I penned an essay about whether American corporations are equipped to defend themselves in cyberspace. Perhaps surprisingly, the answer to that question increasingly appears to be, “Yes.” At least that’s according to the experts I consulted. In lieu of a newsletter column today, below is an excerpt from that piece.

Attend any cybersecurity confab, and you’ll encounter some version of the following refrain. “There are two types of companies in this world: those that have been hacked and those that don’t yet know they’ve been hacked.”

The phrase that launched a thousand quips was coined by Dmitri Alperovitch, a Moscow-born entrepreneur and one of the world’s foremost hacker-sleuths. In 2011, as head threat researcher at antivirus pioneer McAfee, he created the classification while investigating—and publicly revealing—half a decade’s worth of (likely Chinese) cyber­attacks on more than 70 organizations, including defense contractors, tech companies, and the United Nations.

Now the huff of resignation is due for an update. “I’ve since modified that phrase,” Alperovitch tells Fortune. “The first two companies still exist, but now there’s a third type that’s able to successfully defend itself against intrusion.” Ah, hope yet!

One could write off Alperovitch’s addendum as a savvy sales pitch. As the cofounder and chief technology officer of CrowdStrike, a cybersecurity company that stunned investors with a share price–popping IPO in June, there’s no wonder he’s feeling a bit of good cheer.

But there’s something to Alperovitch’s revision. Richard A. Clarke, former White House security adviser to both Bushes and to Clinton, agrees with the new, tripartite framing. He says as much in his just-published book, coauthored with Obama cyber lead Robert K. Knake, The Fifth Domain—a reference to cyber as the newest theater of war, after land, sea, air, and space.

Consider NotPetya. The devastatingly global computer-wiping attack, which Russia released on the world in 2017, caused billions of dollars of damage to corporations such as FedEx, Maersk, and Merck.

But not all firms succumbed. “What you don’t hear about is the list of American companies that were there doing business in Ukraine”—ground zero for the attack—”that didn’t get damaged,” Clarke says. Firms like Boeing, DowDuPont, and Johnson & Johnson “were the dogs that didn’t bark, and in our book, we tried to figure out why.”

So, what separates the hacks from the hack-nots? At a technical level, the unharmed firms had patched their machines against the vulnerability exploited by NotPetya. But a more fundamental question is, Why did some companies patch, while others neglected to?

In a word: prioritization. The most resilient organizations have buy-in across the—literal—board. Any executive who blocks a chief information security officer better have a damn good reason. Else the CEO will surely hear about it.

You can read the rest of the story here.

Robert Hackett | @rhhackett | robert.hackett@fortune.com

THREATS

From Russia With Love. In 2016 Russia targeted election systems in all 50 states, the Senate Intelligence Committee has concluded in a new report. Despite this and recent warnings from special counsel Robert Mueller about attempted interference in the next presidential race, Senate Majority Leader Mitch McConnell is blocking two election security bills that would provide $775 million in grants for states to secure their voting systems. Newsweek reports that McConnell has been receiving campaign donations from top voting machine lobbyists, while the Washington Post has gone so far as to label McConnell "a Russian asset" for standing in the way of greater protections.

An Apple a day. A whistleblower working for Apple has told the Guardian that contractors tasked with grading quality control for Siri, the company's voice assistant, regularly hear people's sensitive information. "There have been countless instances of recordings featuring private discussions between doctors and patients, business deals, seemingly criminal dealings, sexual encounters and so on," the source said, noting that the recordings also show location, contact details, and app data. The whistleblower believes Apple should offer consumers more clear data privacy policy disclosures.

Passing the bar. U.S. Attorney General William Barr gave a keynote speech about the threat of "warrant-proof" encrypted communications at the International Conference on Cyber Security at Fordham University this week. "We must ensure that we retain society’s ability to gain lawful access to data and communications when needed to respond to criminal activity," he said. Cybersecurity experts warn that any legally mandated backdoor will be unavoidably abused by hackers and spies. 

Off the hook. Marcus Hutchins, better known by his online alias "MalwareTech," the so-called accidental hero who stopped a global ransomware infection called WannaCry from spreading in 2017, has been sentenced to one year of supervised release on charges of developing and selling banking malware. When I wrote about his case in April, I argued that Hutchins should receive a light sentencing to be further reduced through public service. I'm glad to see the justice system recognize Huthins' unusual talents. As the judge said, per TechCrunch, It’s going to take people like Hutchins "to eliminate this entire subject of the woefully inadequate security protocols."

Share today’s Cyber Saturday with a friend: http://fortune.com/newsletter/cybersaturday/ 

Looking for previous Data Sheets? Click here

ACCESS GRANTED

Settling the score. Equifax is paying at least $650 million in a settlement related to its 2017 data breach affecting nearly 150 million people. Of that sum, $425 million is earmarked for consumers. Here's Slate with an exhortation urging victims of the breach to go claim what's theirs. And here are step-by-step instructions for doing so. 

Go claim your $125 from Equifax. Right now. Even if $125 isn’t a sum of money that matters to you, even if you don’t feel you were really directly affected by the breach. Even if the prospect of filling out a relatively brief online form fills you with more dread than the theft of all your personal data.

Consider it a part of your civic duty: driving up the costs of data breaches for corporations so they have an incentive to invest more heavily in security. The payouts to individuals are part of the $575 to $700 million settlement that Equifax reached with the Federal Trade Commission, the Consumer Financial Protection Bureau, and 48 states. (Indiana and Massachusetts are still pursuing their own lawsuits against Equifax.)

FORTUNE RECON

FaceApp’s Russia Link Is the Latest Alarm in an Ongoing Digital Red Scare by Alyssa Newcomb

Fighting Deepfakes Gets Real by Bernhard Warner

160 Million Government Records Exposed in Data Breaches Since 2014, Study Finds by Natasha Bach

The FBI Is Still So White by Ellen McGirt

Senate Confirms Army Veteran Mark Esper as Secretary of Defense by Robert Burns

Financial Data Privacy? Consumers ‘Could Care Less’ by Jen Wieczner

Brexit is Jeopardizing the U.K.’s Cybersecurity—And Fueling the Rise of the “Splinternet” by Jeremy Kahn

Apple Card: Are the Limited Rewards Worth It for the Privacy? by Xavier Harding

ONE MORE THING

Starting over. Let us not forget how data breaches affect lives. A couple who adopted a child had to relocate and change their names after their personal information was accidentally leaked to the birth parents, reports the Hackney Gazette, a local British newspaper. The family received £106,000 for its troubles.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Sam Altman walks inside a courthouse
LawOpenAI
Sam Altman defends himself as a ‘honest and trustworthy businessperson’ in trial testimony detailing his past dealings with Elon Musk
By The Associated Press, Barbara Ortutay and Matt O'BrienMay 12, 2026
47 minutes ago
An employee pulls out a server rack shelf at the rear of a Trainium3 UltraServer at an Amazon Web Services QA lab in Austin, Texas, on February 3, 2026.
AIAmazon
‘That doesn’t sound very healthy’: Amazon’s reported tokenmaxxing might gamify AI usage, analyst warns
By Eva RoytburgMay 12, 2026
48 minutes ago
amazon
RetailAmazon
Amazon’s promise of 30-minute delivery collides with memories of Domino’s drivers crashing in the late 1980s
By Anne D'Innocenzio and The Associated PressMay 12, 2026
56 minutes ago
robot
AIRobots
This South Korean hotel worker is training a robot to fold a banquet napkin: ‘I’ve been doing this about once a month’
By Kim Tong-Hyung and The Associated PressMay 12, 2026
1 hour ago
DHS wants $7.5 million to build facial recognition wearables for ICE agents. Some are already using ones off the shelf
LawMeta
DHS wants $7.5 million to build facial recognition wearables for ICE agents. Some are already using ones off the shelf
By Catherina GioinoMay 12, 2026
2 hours ago
turner
CommentaryMedia
Ted Turner built the original infinite scroll. The attention economy is running on his playbook 
By Nick LichtenbergMay 12, 2026
3 hours ago

Most Popular

Forget U.S. debt, China's total borrowing is in 'a league of its own'—much worse and deteriorating faster, analyst says
Economy
Forget U.S. debt, China's total borrowing is in 'a league of its own'—much worse and deteriorating faster, analyst says
By Jason MaMay 11, 2026
1 day ago
Microsoft’s CFO admits she joined the tech giant without even knowing her salary—and then missed her first day of work
Success
Microsoft’s CFO admits she joined the tech giant without even knowing her salary—and then missed her first day of work
By Preston ForeMay 11, 2026
1 day ago
OpenAI CEO Sam Altman says Gen Z and millennials are using ChatGPT like a 'life advisor'—but college students might be one step ahead
Tech
OpenAI CEO Sam Altman says Gen Z and millennials are using ChatGPT like a 'life advisor'—but college students might be one step ahead
By Sydney LakeMay 10, 2026
2 days ago
U.S. hotels are calling the World Cup a 'non-event' and 80% warn bookings are falling short of expectations, report finds
North America
U.S. hotels are calling the World Cup a 'non-event' and 80% warn bookings are falling short of expectations, report finds
By Sasha RogelbergMay 12, 2026
14 hours ago
Trump Mobile quietly rewrote its fine print to say the gold Trump phone may never be made, a year after taking $100 deposits
North America
Trump Mobile quietly rewrote its fine print to say the gold Trump phone may never be made, a year after taking $100 deposits
By Marco Quiroz-GutierrezMay 11, 2026
23 hours ago
Red flag test: former CEO explains why he rejects job candidates who say they can start right away
Success
Red flag test: former CEO explains why he rejects job candidates who say they can start right away
By Orianna Rosa RoyleMay 9, 2026
3 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.