How a Car-Jacking Influenced my Security Posture
John C. Checco, D.Sc.
Information Security Executive ∴ Innovator ∴ Firefighter ∴ Speaker
Are you prepared?
I mean really prepared ... for anything ... like a car-jacking? I wasn't.
During this incident I was running on instinct. But afterwards I started analyzing what went right - and what could have gone terribly wrong.
The Attempted Car-Jacking
Accidents happen. Some people only learn how to drive from Grand Theft Auto. I've accepted that. So when a car side-swiped me on the West Side Highway in NYC, I went into evidence mode - taking out my mobile phone to take pictures of the damage, insurance cards, driver's license and license plates. My phone was ready.
However, once I saw three men get out of the Zipcar , my assessment of the situation changed dramatically. My purpose now was to take control of the situation without escalating. As the driver approached me, I showed him I was video recording him. He backed away. I stood up and insisted on seeing his identification. He backed away even further.
The second man was peering into my passenger side window. I fell back on a de-escalation technique I was taught to vocalize what I believe they were thinking. I calmly asked them, "Are you looking to see if there's anything valuable? Are you looking to see how you're going to take the car?" The second man backed away.
The third man identified my dashcam and immediately waves off the other two. The men retreat into their vehicle and take off.
So ... I survived. And the attempted car-jacking was thwarted with only minor damage to my car. Was it luck? Was it really something I did?
I want to believe it was a combination of tools (dashcam / mobile phone), continuous situational assessment (change in narrative), protocols (evidence mode), playbooks (de-escalation techniques), and mindset (my ability to stay calm and not act like a victim before becoming one).
In hindsight, it was most likely the $40 dashcam as the tipping point that saved me from a few thousand dollars in stolen assets and personal harm.
领英推荐
Could it have gone bad? Absolutely. Indeed, luck was a major factor. In the end, if they asked, I would have given up the car without a fight.
I have car insurance to replace the vehicle. And although I have health (and life) insurance to cover me if I struggled with them, injury (or death) is a bad trade-off for a car only worth a few thousand dollars.
The Security Posture Trade-Off
It occurred to me that the there is a lesson here for all of us: $40.
Are we prepared for cyber events? Probably not as well as you believe. We were not prepared for the Morris Worm in 1988, StuxNet in 2010, WannaCry Ransomware in 2017, nor SolarWinds Sunburst / SuperNova in 2020. At the time these were new tactics; but in the aftermath, we learned and adapted.
Organizations can take some lessons from my attempted car-jacking.
Insurances such as cyber insurance, E&O and D&O, are necessary when all these steps fail to stop a threat actor from taking your car.
However, relying on insurance as an incident management strategy is a bad trade-off. Spend the $40.
I hope I've learned and adapted from this experience, because I was indeed lucky. I may act differently next time ... or not.
Network security researcher, martial artist, home(office)body.
1 年This was so well stated. And glad you are safe.
Information Security Leader | CISO
1 年Glad you’re safe. Thank you for sharing John.
Principal Application Security Architect / Threat Modeling Lead @ Aquia | Ph.D. in Space Cybersecurity student @ CapTechU | Application Security Podcast Co-Host | Public Speaker
1 年Glad you are safe! Thank you for sharing, John.
Advisory Services in the areas of Cybersecurity and Information Security programs
1 年Thank you John, glad you are safe.
President and Cofounder Synthetic Decision Group Inc.
1 年Glad it worked out well for you.