Get Ahead of the Game by Combating Cyber Criminals

Get Ahead of the Game by Combating Cyber Criminals

Cybercriminals are building ladders faster than organizations can build walls, and while their tactics continue to evolve, so too has the typical hacker profile. No longer led by “script-kiddies” or those pursuing academic challenge, today hackers oversee well-funded development efforts with very specific financial or political goals.  As a result – and despite best efforts – the good guys are usually a step (or many steps) behind. 

Hackers have adopted a number of attack methods, which include combinations of social engineering attacks, malicious mobile applications, phishing scams, and ransomware, to name a few. These attacks have been and in all likelihood will remain, successful methods of penetrating corporate networks.  

Fortify defenses, collect intelligence, and respond rapidly

Given the recent surge in data breaches, there is a clear need for a paradigm shift in how we approach security. Existing fortifications still need to remain strong, but the deep analysis of networks and systems to detect potential threats is equally critical. Ultimately, organizations need to contain the risks posed by threats that may already be inside their walls.  

How security defenders detect and respond to existing vulnerabilities also needs to change. Verizon’s 2015 Data Breach Investigations Report indicates that organizations take an average of 205 days to detect a data breach. This gives threat actors plenty of time to conduct surveillance, steal data and spy on their targets.

Often times a data breach is a drawn out process that slowly siphons data from an organization. This approach of gradually extracting data allows these attacks to go unnoticed for extended lengths of time. Organizations need to improve the process by which they detect and respond to threats so they can reduce the window of opportunity.

Separate the meaningful from the mundane

The average organization receives more than 16,000 alerts every week. According to a report from Ponemon Institute, only 4% of these alerts are investigated. In what is now one of the most notable cyber security incidents, Target famously ignored an alert that could have potentially reduced the scale of the attack it experienced two years ago. The consequences were millions of stolen customer payment details, hundreds of millions of dollars in fines and settlements, and the dismissal of corporate leaders.

By sheer numbers, investigating every single alert is unrealistic for most organizations. So how do we better qualify these alerts and effectively reduce / refine this to a manageable number? There needs to be a greater focus placed on discerning the meaningful events from the benign. This has been a longstanding challenge, but one that can be overcome by leveraging big data to gauge and prioritize these threats. Understanding user behavior and historical trends can also help identify usage  irregularities or network anomalies, which can often be an indication of a tangible threat.

Most organizations implement a medley of security solutions to combat different vulnerabilities; encryption, DLP, endpoint security, anti-malware, firewalls, among other solutions. This is important since sophisticated attacks will not be isolated to a single layer within your security infrastructure.

As cybercriminals advance in their penetration of your network, their presence will often expand from one area to another – attacking more and more devices and users as they learn your environment and understand the potential opportunity.  The breach itself is simply their entry point into your network. Once they’re inside, they will examine each security layer to plan their offensive. This activity could produce benign or minor blips that – if properly analyzed – could provide you with the early heads-up you need to avoid a bad outcome.

Share your war stories

Organizations are learning from previous attacks, but unfortunately for many, the damage has already been done.

One valuable model is to cultivate a network of peers where knowledge and experiences can be shared. This is important since, once an attempted attack is detected, odds are the same technique will be used on other targets. One recent development is with crowdsourced platforms which are evolving, providing a forum for IT professionals to collaborate and share threat intelligence.

By sharing these experiences (without revealing any sensitive information), IT security leaders can improve their defenses. Think about it…with the exponential growth of vulnerabilities and so many successful attacks, relying on your singular experience means you’re unaware of the majority of the attacks that could be heading your way.

By gathering intelligence from a wider circle of experience, you’re expanding your knowledge and ultimately your ability to respond to these types of attacks.

Featured

  • Maximizing Your Security Budget This Year

    Perimeter Security Standards for Multi-Site Businesses

    When you run or own a business that has multiple locations, it is important to set clear perimeter security standards. By doing this, it allows you to assess and mitigate any potential threats or risks at each site or location efficiently and effectively. Read Now

  • New Research Shows a Continuing Increase in Ransomware Victims

    GuidePoint Security recently announced the release of GuidePoint Research and Intelligence Team’s (GRIT) Q1 2024 Ransomware Report. In addition to revealing a nearly 20% year-over-year increase in the number of ransomware victims, the GRIT Q1 2024 Ransomware Report observes major shifts in the behavioral patterns of ransomware groups following law enforcement activity – including the continued targeting of previously “off-limits” organizations and industries, such as emergency hospitals. Read Now

  • OpenAI's GPT-4 Is Capable of Autonomously Exploiting Zero-Day Vulnerabilities

    According to a new study from four computer scientists at the University of Illinois Urbana-Champaign, OpenAI’s paid chatbot, GPT-4, is capable of autonomously exploiting zero-day vulnerabilities without any human assistance. Read Now

  • Getting in Someone’s Face

    There was a time, not so long ago, when the tradeshow industry must have thought COVID-19 might wipe out face-to-face meetings. It sure seemed that way about three years ago. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • ComNet CNGE6FX2TX4PoE

    The ComNet cost-efficient CNGE6FX2TX4PoE is a six-port switch that offers four Gbps TX ports that support the IEEE802.3at standard and provide up to 30 watts of PoE to PDs. It also has a dedicated FX/TX combination port as well as a single FX SFP to act as an additional port or an uplink port, giving the user additional options in managing network traffic. The CNGE6FX2TX4PoE is designed for use in unconditioned environments and typically used in perimeter surveillance. 3

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area. 3

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions. 3