CYBER SECURITY CYBER SECURITY
Are you ready? How to be prepared for a security incident. By Mouaz Alnouri
I
n February 2021, an Australian university was hit by a ransomware attack. The university quickly shut down its network to identify the infiltration, contain the breach and conduct a proper investigation. As a result, critical operations were offline, new enrolments were suspended and the university could not pay casual staff. A few days later, the university fully restored its IT systems and confirmed there was no evidence to suggest a data breach had occurred. This could happen to any organisation; Australian organisations across all sectors are targets for cyber attacks. Cyber criminals are very determined and the number of cyber attacks is continuously increasing. The ACSC revealed that cyber attacks have increased by nearly 13 percent in FY20/21 from the previous financial year. The increase equates to one cyber attack every 8 minutes compared to one every 10 minutes last financial year. What should organisations do to minimise the time required to investigate cyber security incidents, reduce their impact and restore their systems as quickly as possible?
Effective Incident Response Every organisation should have an incident response plan. An incident response plan enables organisations to respond decisively to a cyber security incident, limit its impact and support recovery. When an incident occurs, the incident investigator will collect data from numerous sources within the organisation to determine whether or not there is a security incident.
34 | Australian Cyber Security Magazine
The investigator will request audit logs, transaction logs, intrusion logs, connection logs, system performance records and above all, User activity logs from firewalls, intrusion detection/prevention systems, routers, switches, servers, desktops, mainframes, business applications, databases, anti-virus, VPNs and any other system with a CPU. This is a process that, if done manually, takes time and effort, causing days worth of delays before responding to the incident. This manual process will potentially increase the organisation's downtime and subsequently the impact of the attack. For effective incident response, every organisation should have a centralised collection of all the logs generated within its environment. The incident investigator can only draw a picture of what has happened after examining the logs, including how the malicious actor has gained access to the environment and what key data and assets the attacker got access to. Furthermore, by quickly examining the logs, the incident investigator can efficiently recommend the best course of action for a rapid response to contain the attack and minimise the impact.
How to store logs centrally A central log repository is a software solution that aggregates logs from many different resources across the entire environment and empowers the organisation’s security team to analyse them when required. This software is called SIEM: Security information and event management.