The Ethical Hacker Who Steals Corporate Secrets—Legally
Tom Van de Wiele walks into a CEO’s office pretending to be a telecom contractor. In the few minutes he gets, he plugs a keylogger between keyboard and computer – a device the size of a USB stick that records every keystroke and sends it out over an encrypted channel. There is no panic, no Hollywood tension. This is just another day for the man F-Secure pays to break into its clients’ most guarded spaces.
As Principal Security Consultant for the Finnish-listed cybersecurity firm, Van de Wiele leads a Red Team. His job is to legally steal corporate secrets, transfer money between bank accounts, copy whole databases, and sometimes leave a sticker under the boardroom table reading “Greetings from F-Secure. This could have been a microphone.” The goal is to paint a threat picture: which attack scenarios worked, where the company is adequately protected, and where glaring holes remain.
F-Secure, which generated €158 million in revenue in 2016 and was named a Visionary in Gartner’s Magic Quadrant for Endpoint Protection Platforms for the ninth time in 2018, deploys Van de Wiele’s team when a client needs a reality check. Every action is governed by a written contract and a “get-out-of-jail” letter that tells security staff to call a special number if the hack is detected.
But Van de Wiele’s most uncomfortable message is not about clever gadgets. It is that a determined attacker with a moderate budget and enough time will get in. “A targeted attacker will always be able to penetrate a company,” he says. The real question is whether the organisation has made that intrusion so expensive that the criminals move on.
Why 'We Trust Our Employees' Is a Recipe for Breach
The Myth of the Unbreachable Perimeter
The idea that a company can keep all attackers out is, in Van de Wiele’s words, a dangerous illusion – especially at senior management level. His Red Team spends up to 70% of its project timeline on reconnaissance, often knowing the target better than the target knows itself. By the time the physical or digital break-in starts, the attacker has already bypassed most defences. The insight here is not defeatism but a shift in investment logic: spend less on the moat alone and more on detecting and containing the intruder who will inevitably cross it.
Trust Isn't a Security Control
When his team asks a client how many customer records a helpdesk or sales team can access, the answer is invariably “all of them,” followed by “but we trust our employees.” Van de Wiele calls this exactly the wrong mindset. Attacks, he argues, are defined by three factors – access, motive and opportunity – and a company’s job is to manage all three. Every ransomware headline, he notes, was made possible by an employee clicking a link, not by the criminal bypassing a firewall in a vacuum. The technical fix is not suspicion but least-privilege access, something many firms still skip.
The IoT Wave: When Everything Becomes a Target
Van de Wiele cites “Hyppönen’s Law” – named after his colleague Mikko Hyppönen – that anything smart and connected can be hacked, and if it can be hacked, it will be. He expects attacks to move beyond data encryption into physical extortion: heating systems in hospitals, smart cars that refuse to unlock until a ransom is paid. The rise of cryptocurrency, he says, supercharged ransomware because it gave attackers a convenient and anonymous payment rail. Yet there remains no meaningful incentive for manufacturers to build security into connected devices, and no clarity in the supply chain about who is responsible for it.
GDPR as a Forced Audit
The EU’s General Data Protection Regulation, which came into force in May 2018, gets a rare note of approval from Van de Wiele. His observation is blunt: most companies do not know what data they possess, let alone what it is worth. That ignorance is what exposes consumers to breaches at dentists, telecoms and countless other holders of personal records. GDPR, he believes, compels organisations to perform the inventory they should have been doing all along – not as a compliance chore but as the foundation of any real security strategy.
What Boardrooms Must Do to Stop the Next Attack
- Deploy least-privilege access immediately. Van de Wiele’s standard shock question – “Do your sales or helpdesk staff really need to see every customer record?” – should be applied to every role. Restrict data access to the minimum required, because trust alone cannot resist a phishing link.
- Invest in genuine red team exercises, not box-ticking audits. A simulated attack that plants a keylogger in the CEO’s office or copies your payment database reveals gaps no questionnaire can. The exercise must mirror the time and creativity a real adversary would bring, and the results must drive actual change in architecture and process.
- Map and classify your data. Van de Wiele points out that many companies cannot secure what they do not know they hold. Before the next compliance deadline, create a complete inventory of personal and sensitive business data – and assign ownership, value and protection requirements to each dataset.
- Audit the security of every connected device you buy. Hyppönen’s Law applies to your office routers, building control systems and smart manufacturing kit. Demand transparency from suppliers about firmware updates, default credentials and vulnerability handling, and quarantine devices that cannot demonstrate a basic security posture.
- Prepare your incident response for the worst-case scenario, not the convenient one. If a criminal locks your production line or your customers’ payment data is leaked, the response cannot start with finding the contract number on your insurance policy. Run table-top exercises that force executives to decide when to pay, when to communicate, and how to keep the business running during a multi-day crisis.
Comments 0