Skip to main content

What the Hack? Q2 2021

Page 1

Q2 2021

What the Hack? Secon Cyber Quarterly Newsletter


CONTENTS 3 Foreword from our CEO 4 Secon Cyber Leadership Interviews Janakan Nadarajah, Chief Operating

Officer, Secon Cyber, in conversation with Que Tran, Head of IT Europe & Russia, DP World

8 Success Stories How we helped a local authority migrate

and monitor their security estate

10

Vendor Showcase

Six questions with Sudeep Venkatesh, Chief Product Officer, Egress

12 Best Practice Spotlight Call and SMS scams: Why can’t telcos stop them?

14 Insights Demystifying detection and response

19 Upcoming Events

4

SECON CYBER2


A MESSAGE FROM OUR CEO

Foreword from our CEO: It’s quite exciting to have the opportunity as the person to forward this newsletter. In my 22 years in the cyber security industry, it seems that the entire industry is being challenged like never before and is having to keep up with the relentless move to digital and increasing cyber attacks. It appears the social order of IT and cyber security professionals is rearranging itself before our eyes. It’s all very fascinating. We have seen some unprecedented events in recent times, and I am not just talking about the COVID-19 pandemic. There have been seismic cyber attacks which have brought organisations and governments to their knees. During these times, I feel it is really important to discuss, debate and have an open dialogue on these life changing topics to help us learn, grow and build a better future. “What The Hack?” is going to be narrating on the technical, social, and cultural changes within the security industry as they surface in our world. Think of this newsletter as a source of thoughtprovoking titbits to use in protecting your estate, benchmarking against your peers, or increasing your awareness of the industry. It takes time to make your mark with your audience, but little by little we’re going to get to know each other well. For now, let’s just say I hope you enjoy “What The Hack?”

Robert Gupta Chief Executive Officer

WHAT THE HACK - Q2 2021

3


Secon Cyber Leadership Interviews

Janakan Nadarajah in conversation with Que Tran, Head of IT Europe & Russia, DP World J: What’s your current role and what does it involve? Q: I currently lead technology and digital for Europe and Russia region at DP World. DP World is a leading enabler of global trade and an integral part of the global supply chain. We have over 150 operations in 40 countries handling about 10 percent of the world’s container trade. In the last the last 12 months, with regards to the pandemic, the delivery of goods and global trade has become ever more important in our current situation. In addition to the technology leadership, I’m focused on cyber and digitisation and innovation initiatives across the organisation. That’s really, I suppose, three parts. One is to protect the organisation; another is to optimise our business. The other part is to transform both the organisation and industry in how we work and operate. Maritime is one of the oldest industries in the world. With that comes a lot of cultural heritage, but also a lot of opportunities to use technology to drive it forward. My day-to-day work includes a challenging range of things from the people management, which is still a very core part of any business, to working on the business challenges. That’s developing the technology strategy and digital roadmap, working with internal and external teams, and partners, on solutions and product development and what we can do better with regards to our existing operations, but also potential new acquisitions. A lot of work is also working with the risk and audit teams on improving our technical design and security processes and managing the technical integration of new products because we don’t just live in a greenfield environment. The new digital products and security products we put in have to be embedded onto our existing environment so that takes a lot of consideration, thought and planning. 4

J: What brought you your current role and what is it that you like about it? Q: Like most of my career, it’s come about from being inquisitive and connecting with people. Technology is systems and infrastructure and hardware. At the same time, it’s about collaborating with people, those within your teams and those outside of your teams as well. And what do I like about it? It’s a business that materially impacts everyone. We probably take it for granted these days because we click something online and it magically appears at our doorsteps a day later, but it’s a real business that has material impact. Even though I’ve been to so many of the terminals in the business, it’s still amazing every time I go to see the sheer size and scale of the business and the actual automation in place. It’s still a physical business, but enabled by digital. I think that’s what really excites me about the business. J: Is there anything about your role that keeps you awake at night?

Q: I think sometimes it’s about approaching the question in a different way, because obviously if you approach a question in a certain context, then you answer it in a certain context. From my perspective, I would prefer to think of it as what motivates you to get up in the morning, which for me, it’s leading the delivery of secure, leading technology and digital that underpins and drives the organisation forward. That is what motivates me to get up in the morning, to do that work rather than mull over it in the evening. I think it’s more like, we’ve done what we needed to do, the next morning is another day to do even better. J: What are the top two or three biggest lessons you’ve learned as a CIO? Q: I suppose whether it’s as a CIO or whether it’s generally through business life, I think across organisations what you need really is great people, to build a capable team and trust. I think early in my career, I probably wanted to do everything and to revolve everything around myself, be-

“It’s amazing every time I go to see the sheer size and scale of the business and the actual automation in place. It’s still a physical business, but enabled by digital.”

SECON CYBER


cause, as you know, you sort of have a sense of I want to be the superhero, I want to be that capable person. But I think over time, I learned to share as much as possible, be it information, responsibilities, supply relationships, be it actually recognition and rewards to the wider team. I think the second part is actually about communication and talking to people as much as possible. Whether it’s in technology or other parts of an organisation, many issues arise due to lack of, or misaligned, communications. I think talking to people as much as possible is key and asking questions sometimes more than once is really important to get through to the heart of things and get things resolved. A lot of challenges in technology are really about problem solving.

a computer, a vehicle, a vessel, or entire cities. How do you manage security to protect that? I think there’s the element of today, quantum computing is in at least early nascent stages. Today’s security does not even consider what quantum computing can solve. How do you consider that going forward? I think there’s also the part about the need to protect human software. It sounds a bit scary, bit cyborg, but actually, there’s human machine software augmentation and A.I. How do you protect that? Because obviously, the hardware and software are no longer standalone, it’s part of us and how we work. How would you protect that? I know more questions than answers, but I think those are kind of interesting ones to consider and think about going forward.

J: What do you think is the future of digital transformation and its impact, particularly on cyber security?

J: When it comes to cyber security, what is most important to you?

Q: Take how we looked at cyber security previously. Security was previously about how we protected physical assets, and then we’ve moved on in the last few years to get to two-factor, multi-factor authentication, be it on your phone, an app or token. When you look at digital transformation, everything is connected going forward. In the future, we’re not just concerned about protecting a single computer device because essentially everything is a computer device, be it WHAT THE HACK - Q2 2021

Q: I think most important from my perspective is a matter of balance. That’s balancing the risk of protection versus user experience versus performance. I think sometimes we only think of one of those boxes, not all three. We know something with a bad user experience does not get adopted, very rarely. Likewise, something with poor performance very rarely gets sustained over a period of time. I think it’s equally being able to balance the risk of the appropriate level of protection versus the user experience and the performance.

J: What are the biggest challenges you’ve faced in the past when dealing with cyber security? Q: It’s really about people and mindsets. I break it into sort of three things. One is about the mindset that tools can solve all the problems of cyber. We know that they’re an enabler and they are a component of that, but they can’t solve everything because ultimately you need good people, good processes, a good culture, to be security aware and looking to protect your own assets all the time. I think secondly, it’s also about the people side of things. It’s about education, it’s making sure people make the right choices because, you know, smart and sensible are two very different things. You can have very smart people doing things that don’t seem sensible sometimes, especially from a cyber perspective. I think that constant evolving communication, education, and collaboration with people is very important in cyber. The other part is the mindset about cyber security being a onetime event, i.e. you put something in, it solves the problem, be it a piece of software or big piece of hardware or a company that just comes to manage your SOC, suddenly all the problems are solved. We know it’s much larger than that. It’s understanding that it’s not a one-time event and it’s something that is continually evolving. As an organisation, you need to continue to adapt.

5


‘

When things go well, we’re overly optimistic, but at the same time, we get overly pessimistic in resolving a crisis. It’s about balance on being able to handle both and then being able to lead people through those situations.’ J: What expectations do you place on your suppliers and partners? How do you like to engage with them? What can make the process as stress free as possible for you? Q: I think it’s important to recognise that we’re all we are human beings, and we all need to understand that we have our roles. Typically, I will talk when I’m available, when time permits, and I will connect if I have a problem that I need to solve. I know a lot of partners understand that, but some also don’t. Likewise, it would be good for you to also understand why I’m not talking to you; sometimes lack of communication does not mean disengagement. Lack of communication may mean that actually things are going fairly well. From an expectation perspective, we know pricing is one element and sensible pricing is expected. We’re here to build a long-term relationship based on trust. I think even more important is great people providing a great service because I think that’s what truly stands out, be it in the technology space or any other kind of business you’re in. What will help? I think being able to help me with all the background work, providing the information that helps me make a decision. What you don’t want, and what I don’t want either, is we both sit in a room and I can’t say yes or no, or I can’t say stop or proceed. Even more important is the buy in and trust of the wider teams and stakeholders because what you want is everyone to be able to work, regardless of whoever is in the room. 6

J: What advice would you give to someone who’s aspiring to become a CIO or a CISO? Q: There’s probably no one straight path to get to whatever it is, whether it’s CISO, CEO, MD, whatever. I think it’s important to recognise that you’re in your role because you’re definitely capable, but there’s always something to learn. It’s important to continue to be inquisitive, to listen and learn both inside and outside of your domain. I think technical skills are important. I wouldn’t say they’re not important, but we know it’s a moving landscape. I always advocate learning and getting certified before you need it, because it helps you to move forward. As I said earlier, people skills, communication skills are very important and emotional intelligence to connect with others is definitely a good asset to have. From a technology perspective, I think it’s also being able to plan and handle both the bad and good situations. Particularly in technology when things go well, we’re overly optimistic, but at the same time, we get overly pessimistic in resolving a crisis. It’s about balance on being able to handle both and then being able to lead people through those situations. J: Digital transformation was supercharged in 2020 due to the pandemic and need to work remotely. What do you think 2021 will be known for?

dict anything because you’re going to be wildly off the mark. But I think, looking at where we are right now and what we’ve been through, it’s about being able to adapt to what is now the next normal. What does normal reality look like in 2021 now we’ve come out on the other side? With COVID-19 and all the transformation that’s happened in organisations to enable people to work collaboratively and remotely, I think there will be opportunities for new services to adapt us to this new way of living and working because we know people will be outside of their homes regularly now for the first time, sustained in 2021. What does that mean? That probably means opportunities to provide a different set of products or services that probably weren’t possible or weren’t thought about back in 2020 or further back. I think it will bring about a skills challenge as well. I think about how we adapt to changing roles and responsibilities. Obviously, in the last 12 months, it wasn’t as much of worklife balance as work-life integration; rather than from working from home, you were literally working at home. Moving forward, it’s about what do these new roles mean? Are there new industries that evolve out of that? Thinking about the role that technology has to play going forward and acceleration of technology, organisations have seen that people can work remotely and a lot of tasks can be done digitally. Now going forward, what is an automated digital task versus what is a human task and what does that mean to people’s roles and how we work and how we live? Previously what we would have thought about is we’ve had a kind of certain life cycle where we studied really hard to learn some skills, then we kind of worked through a major period of our life to save up to relax at the other side. I think what we’ve seen, and I think will be exponentially increased going forward, is a kept-up dipping in and out of learning and then working and re-skilling, where it’s not just this straight cycle of learn and work, it’s more a bit of learning, bit of working, a bit of learning again. I would say that would be a trend in 2021, seeing the new roles and skills that are going to be needed much more going forward.

Q: I think the thing we learned about predictions from last year is don’t preSECON CYBER


www.seconcyber.com

In your corner.

ConnectProtect® Managed Detection and Response. 24/7 monitoring. Technology agnostic. No fuss.

Examples of technologies ingested into ConnectProtect®:


Success Story

How we helped a local authority migrate and monitor their security estate A decision to upgrade and monitor their cyber security environment left a borough council looking for expert assistance A large local authority recognised the need to update their existing cyber security environment to effectively protect their users, data, and systems. Also, the council lacked any kind of centralised visibility to detect and mitigate potential cyber threats, which they acknowledged as a weak point in their security strategy that could lead to a potential data breach or compliance failure.

What was achieved? With our advice and team of experienced security engineers, Secon Cyber helped the council securely migrate to Sophos email, web, endpoint, and server security solutions without any downtime. In addition to supplying and successfully migrating the council’s cyber security solutions, we provided them with complete visibility and control across their endpoint and server estates with our ConnectProtect® Managed Detection and Response. With this added protection, the council gained 24x7x365 continuous log monitoring, management and proactive incident response by our in-house security operations centre (SOC).

8

SECON CYBER


As part of this project, our team continues to:

Provide visibility, consistency and centralised policy management across the council’s Sophos security estate

Monitor their endpoint and server logs 24x7x365 through our ConnectProtect® platform

Perform proactive threat hunting and investigation using both our SOC and AI

Issue monthly service reviews to address trends and risks we observe in our ConnectProtect® platform and offer advice on how to mitigate these concerns

Click here to read our other success stories WHAT THE HACK - Q2 2021

9


Vendor Showcase:

Six questions with Sudeep Venkatesh, Chief Product Officer, Egress

1

How has the email security landscape transformed in the last decade and what are the key challenges faced today?

The email security landscape has changed massively over the last decade – driven by both digitalisation and the change in the way we use email, and by the ever-increasing sophistication of targeted attacks by cybercriminals. Email is the most popular business communication tool for employees – especially after such a sustained time of remote working – and 80% use it to share confidential information. This usage has widened the surface area for risk of inadvertent loss and people breaking the rules and taking risks when sharing data. Additionally, people are targeted daily by sophisticated phishing and impersonation attacks that can be incredibly difficult to employees to spot on their own. Email security technology has had to innovate and adapt to mitigate these risks. Traditional technologies that rely solely on static rules and policies simply can’t adapt to the changes in user behaviour that can lead to data loss or detect attacks unless they’ve been pre-programmed. Instead, organisations are turning to advanced solutions that use intelligent technologies, like contextual machine learning, to actually mitigate risk and prevent breaches.

10

2

With email security solutions being a high priority for organisations, why is email phishing still responsible for 91% of the breaches?

For two reasons. The first is that people will always be vulnerable to making mistakes – such as replying to spear phishing emails or clicking on malicious links. If you’re tired, busy, stressed and you see an email that for all intents and purposes seems like it comes from your CEO or CFO, there’s every chance you’re going to do what is being requested and move onto your next task without realising you’re causing a breach of security. We can’t train human error away, so we have to turn to technical solutions. Which brings us to the second reason: traditional solutions haven’t been successful in preventing people from falling victim to these attacks. Unlike advanced technologies, they’re not able to respond dynamically to the changing threat – for example, as a user goes to respond to a phishing email with the CEO’s correct display name but sent from ceo@ connpany.com, not ceo@company.com. If nothing else about the email triggers a static rule, they won’t be able to intelligently detect the threat and provide a meaningful prompt to the user, essentially flagging ‘this isn’t the person you think it is!’.

SECON CYBER


3

Why do organisations need email encryption with data loss prevention being in place? The first step is making sure that an email is being sent to the correct recipient(s) with the right documents attached – that’s the data loss prevention. Prevention alone, however, isn’t enough to keep data secure at all times. Sensitive data, like personal information or corporate IP, must be encrypted as it’s shared via email. This protects it from interception during transmission, and with message-level encryption, you’re able to control what recipients can do with the information that’s shared with them, such as preventing them from forwarding emails or printing sensitive data, and exposing it to unauthorised access. This is incredibly important for data controllers’ compliance with regulations like GDPR. One-fifth (18%) of organisations’ email data loss incidents originate within their supply chain, so it’s critical to take the necessary steps to ensure data is handled correctly at all times.

4

Organisations are primarily concerned about external email hacking, should they worry about their internal users and why? Yes. Insider risk is the biggest security threat that organisations face on a daily basis. Hacks hit the headlines, particularly if, as we’ve seen in recent weeks, if they’re highly politicised. And of course, they can be incredibly damaging. However, insider data breaches happen with much higher frequency – in fact, research shows an outbound email data breach occurs every 12 working hours per organisation. These incidents cover by this research include misdirected emails, attaching the wrong files, replying to spear phishing attacks, not using Bcc, not encrypting sensitive data, and intentional exfiltration. While email is the largest risk vector when we consider firstly how people prefer to share data and secondly how attackers prefer to target them, these findings don’t cover other ways data can be inadvertently and intentionally leaked. Remote working, for instance, has led to an increase in digital communication across the board – not just for email, but also use of Teams and WhatsApp to video conferencing. Each channel amplifies insider risk and opens organisations up to a breach if they’re not appropriately secured.

WHAT THE HACK - Q2 2021

5

With Business Email Comprise being on the rise, how can organisations combat this challenge to protect their brand?

BEC attacks are successful because the originate in human error – an employee is the victim of an attack in which they disclose their credentials and their account becomes compromised. As we touched on before, the approach to mitigating this risk also includes training and awareness about issues like safeguarding credentials and only entering them into approved, company-owned systems/applications, as well as good password security, such as not reusing passwords. This education and awareness must then be combined with advanced solutions that can intelligently detect the original attack before human error comes into play – because as we know, people will always make mistakes. Should an incident be identified, organisations then need to ensure they swiftly conduct forensic breach analysis to determine the extent of the incident so they can fully remediate it, as well as ensure employees are forced to change their passwords to stop the same leaked credentials leading to further incidents.

6

How do organisations that operate on a Business to Consumer model, face the challenges caused email encryption?

Recipient friction has always been a problem with traditional approaches to email security because they take a onesize-fits-all approach to authentication, regardless of how trusted the recipient is, the sensitivity of the data being shared and the context in which it’s being shared. Again, contextual machine learning can solve this problem. It can assess the risk to data in real time, reducing authentication friction where the risk is low – for example, a trusted recipient authenticating from a known IP address for data of low sensitivity – and dynamically dial that friction up should any factor increase the risk profile or if the data is more sensitive in nature, including enforcing multi-factor authentication.

11


Best Practice Spotlight

Call and SMS scams: Why can’t telcos stop them? by Ven Dela Luna, Chief Security Engineer In the past few months, scammers have been targeting certain mobile users through calls or text. Alarmingly, I also learned from acquaintances that they have received text messages from people pretending to be from legitimate sources, such as banks and service providers. If one looks closely at the content, the URLs or links provided are either unrelated to the company or utilise a newly registered site, which in most cases are temporary and are immediately offline by the time further investigations can be made. I also heard from some friends that they were scammed into buying a new phone through their contracts. However, the mobile packages got delivered to a different address. This is worse since they use social engineering to trick someone and ensure they go through two-factor authentication. This makes us wonder why telecommunications companies and service providers continue to allow this. It almost seems that the industry is not thoroughly regulated; prosecutions are slow at best and most of the time the scammers are not even charged of any offense, if they get caught that is. The government is tackling this problem by educating users on the danger of these scams. Consumers are also encouraged to help by reporting spam texts and nuisance calls to two different agencies: The Information Commissioner’s Office (ICO) 2. The National Cyber Security 2. Centre (NCSC)

should tackle is enforcing some control, process, and deterrence for those who take such lengths to use legitimate services offered by telcos and other service providers. For telcos, prepay mobile SIMs are easy to buy. One can pop up to any shop and attach these to a device that can send multiple messages. As burner phones are popularly used in crimes, these should be regulated or if possible registered with government entities overseeing communications. In relation to hardlines for companies (standard phone lines), telcos should have careful background checks (not just on the company site) and review their indicated purpose. Audits can be done in the middle of the fiscal year to validate whether they are indeed functioning as what was stated in their applications. The same can be done with households to validate if the registered user is the one holding the other end of the line. For service providers, rigid checks should be in place for domains they host and they should provide ample warning to tenants, as necessary. The above solutions will take a while to be discussed in the government, let alone be implemented. Hence, for the time being, we urge users to: 1. 1.

1. 1.

Users and administrators can also help by submitting sample URLs they get from a SMS to their respective cyber security providers or to a community-based repository, such as Virus Total or Phishtank. One part of the solution that the private sector or the government 12

2. 2. 3. 3. 4. 4. 5. 5.

For administrators, the above also applies, but with a fee. They could opt to leverage fully managed services to protect them from scams and spams, as well as other digital attack vectors. Downplayed as they are, in many instances, phish leads to breach. This multidimensional approach will surely help the government, as well as aid security vendors, in protecting not just enterprises and SMBs, but also standard users at home.

Take advantage of free mobile security solutions (there are a lot of known security providers that offer this for free now, some are even bundled in partnership with telcos) Use free web advice or web filtering solutions Use free AV solutions, or use the premium ones (with fee) Report every spam, scam email, or nuisance call you encounter Always keep your devices, operating systems, and applications up to date SECON CYBER


We believe good people should be protected. ConnectProtect® is the cloud-based security platform developed by Secon Cyber to give you complete visibility and control. Book your demo today

Examples of technologies ingested into ConnectProtect®:


Insights

Demystifying detection and response by Andrew Gogarty, Chief Security Evangelist There is a lot of hype around detection and response, largely driven by the fact that in 2020, the average time to detect and contain a breach was 280 days, according to IBM. Cyber crime continues to impact organisations and the time is takes to identify and respond to a threat is paramount to minimising any potential impact to operations or reputation. And this is where we need to leave the hype behind and focus on what organisations actually need: the ability to quickly detect a breach, identify its impact, and determine how it got in so swift, appropriate action can be taken to effectively respond and contain the breach. There is not a one size fits all solution to this. Some organisations have large cyber security teams, where others are limited on resource, or cyber security might be one of many shared priorities for smaller IT teams. Not wanting to buck the trend, the cyber security industry has rallied to address the problem with a number of approaches, each with their own acronyms, leaving organisations confused with which approach best suits their requirements and internal capabilities. Whichever route you choose to take, you need to focus on the desired outcome, which is how do we detect malicious activity and respond faster to minimise the impact to our organisation? How do we improve our detection and respond faster?

Better Detection •

• • • •

14

Bring together and correlate the alerts from our siloed security tools Leverage threat intelligence to hunt for zero day threats Monitor your security alerts 24x7 Ensure security tools are up-to-date and configured optimally Ensure focus on genuine threats instead of wasting time trawling through false positives

Faster Response • • •

Monitor your security alerts 24x7 Leverage automated response to genuine threats Have all the relevant data points to hand for a targeted response

Before exploring which option is most suited to help your organisation realise your desired outcome, let’s consider the options and how they fit with your environment.

EDR

Endpoint Detection and Response

XDR

Extended Detection and Response

MDR

Managed Detection and Response

SIEM

Security Incident & Event Monitoring

SOC

Security Operations Centre

EDR - Endpoint Detection and Response Ideally suited for: Organisations with an in-house security operations centre with threat hunting and incident response skills. Typically a new feature or add-on offered by traditional endpoint security vendors, or “next-gen” endpoint security vendors, EDR is designed to give better clarity and facilitate a faster detection and response to threats on endpoints for IT teams. It sometimes incorporates automation to isolate affected endpoints. In the event of a breach, the solution pulls together the relevant security logs and provides a graphical map of what endpoints have been impacted and what changes to the endpoint were made. This enables IT teams to quickly focus on impacted endpoints instead of wasting valuable time trying to manually search through logs to get an understanding of how to respond. Most EDR vendors also have the ability to support threat hunting, where you can leverage threat intelligence to search for threats that have not yet been identified by your endpoint security tool. For example, with WannaCry in 2017, many endpoint security vendors did not detect the payload when WannaCry was initially propagating. However, through threat intelligence, we knew about the attributes (or indicators of compromise) associated with WannaCry. Threat hunting empowers IT teams to search for such indicators of compromise in the EDR platform, which then provides information on which endpoints have IOCs associated with that threat. It enables a more proactive and faster response to endpoint threats to minimise any associated impact. Limitations of EDR: Only focused on endpoint security, the last line of defence. It will not help against account takeovers, perimeter breaches or other attacks beyond the endpoint. SECON CYBER


XDR – Extended Detection and Response Ideally suited for: Organisations with an in-house security operations centre with threat hunting and incident response skills. XDR is very similar to EDR, but with the addition of insights provided by other security tools such as firewalls, email security gateways and web gateways. Again, XDR is typically offered by traditional security vendors leveraging their technologies to provide insights from multiple vectors to enrich the information available to IT teams. This provides IT teams with a clearer understanding of how a threat entered their environment in addition to the endpoints that have been impacted. Leveraging the data from multiple security products empowers a more holistic approach to identifying and containing a breach. Having all the benefits of EDR, XDR also enables teams to stop threats coming in by understanding what changes can be made to firewalls, email gateways or web gateways to prevent further infection entering the environment. The power of threat hunting is improved in XDR with more data points to search for potential indications of a threat. Limitations of XDR: Often positioned as centralised visibility but typically requires a single vendor approach to security, which limits threat intelligence to a single source. No or limited support for other security products from different vendors in your environment, thus limiting the total amount of visibility.

MDR – Managed Detection and Response Ideally suited for: Organisations with limited IT resource and no security operations centre or 24x7 support coverage.

WHAT THE HACK - Q2 2021

MDR is a service offered by security vendors or service providers that provides the manpower, expertise and platform (EDR, XDR or SIEM) to monitor and respond to incidents identified by the platform 24x7. To ensure better detection of zero day threats, MDR providers typically leverage the platform, their security intelligence from other customers and threat feeds to perform proactive threat hunting to be able to detect threats that may have circumvented your security solutions. When a threat is identified, the service provider will work with the organisation to perform remedial actions or provide recommendations to effectively respond to and contain a breach. Limitations of MDR: Usually limited by the ecosystem supported by the provider. For example, security vendors’ services will focus on their own products, and service providers will typically require a specific EDR tool on the endpoint to be able to deliver the service. When considering an MDR service, look for a provider that will enable you to leverage your existing investments to feed their platform for a faster time to value.

SIEM – Security Incident & Event Monitoring Ideally suited for: Organisations with an in-house security operations centre with threat hunting and incident response skills. SIEM tools are designed to ingest security logs from all the security tools in an organisation’s environment, giving a central store for security logs. This central store can be used in conjunction with analytics and correlation rules to generate incidents using the data from all the security tools in the environment. SIEM tools help remove the noise of false positives generated by security tools to help identify and focus on genuine threats or risks faced by an organisation.

15


SIEM is available on the market in two main flavours: SIEM that you procure, install and maintain using your own in-house resource, or SIEM as a Service, which is typically a SIEM solution hosted and maintained by a service provider for organisations that lack the required in-house resource. To realise the benefits of the SIEM, it is recommended to have the SIEM monitored 24x7 by an experienced security operations centre. Limitations of SIEM: Typically requires significant effort for ingestion of logs and development of correlation rules. Existing IT teams may not have enough resource, knowledge or experience on how to develop effective correlation rules and perform the required ongoing maintenance. SIEM tools are often licensed by “events per second,” making sizing the right solution difficult for most organisations. This often leads to under or over scoping the solution. These limitations can be overcome by considering SIEM as Service which provides the desired outcomes at a fixed monthly or annual price.

SOC – Security Operations Centre Ideally suited for: All organisations that want to be prepared to be able to detect and respond to threats faster.

16

A SOC (whether in-house or outsourced) compliments the above technologies with the skilled resource to monitor the output from security tools and hunt for threats. They usually leverage one or more of the above detection and response tools to focus the SOC team’s efforts on genuine threats, rather than wasting time on false positives. Limitations of SOC: Typically requires a significant investment in skilled human resource to build an in-house SOC. Monitoring and responding to threats is a 24x7 necessity in today’s threat landscape. Resource investment needs to consider how to ensure a consistent approach is maintained around the clock and that teams have appropriate experience and training to respond to cyber threats effectively. Many organisations are now outsourcing their security operations centres to get the required expertise without the significant investment of building one in-house. If you are still unsure on the best approach for your requirements, that’s what we are here for. Reach out to us so we can take the time to understand your situation and advise on the most suitable approaches for your organisation.

SECON CYBER


www.seconcyber.com

Always on so business can flow. Being closely aligned with our clients means we can help businesses fulfil their true potential by giving them confidence, resilience, protection, and peace of mind.

Managed Detection & Response - Managed Security Services Server Patching as a Service - Security Advisory


Why are remote workers more likely to leak data? Find out with the 2021 Data Loss Prevention Report Egress

ance At a gl

ata n ss D io Egre Prevent Loss rt 2021 o Rep ainst

Data Loss

Prevention

Report

2021

3

Egress Data Loss Prevention

Report 2021

29

e of The rol gy t have to result Data sharing doesn’ k technolo the ris in data loss permanent change, and Why is always2021Where, ? how and when employees work is undergoing and protective measures aid that it has r in need to adapt their defenses and universal productivity highe existed. We security professionals trusted always Email remains the 's have that ss risks environment. at protection to fit the new lo Wh with it come the data been, but distracted employees ?that tired, stressed and been must be done to support time ata a long ing dare not working and more facing these have known ppforen Legacy DLP solutions the entire workforce and information protection. ily ha mistakes, but never has make automate data loss prevention daand to be applied to the employees way it is now. er Go to chapt

er Go to chapt

y in the

er simultaneousl problemsGo to chapt

g ag ndin Defe

a rising data loss, we will see now to contain email If businesses don’t act at risk, at the very point reputations and revenues tide of incidents putting ride out difficult economic to do their utmost to when organizations need

it to ers adm culties of IT lead g diffi eriencin

se feel wor loyees of emp pandemic use of the

conditions.

95%

learning of contextual machine and clients that It is time for the power for employees, employers problem, to restore confidence to result in data loss. data sharing doesn’t have

s say nization data of orga suffered they've year the last loss in

most Data is be at risk likely to with il, on ema

83% s nization

il of orga cing ema experien ches data brea

ic DLP 79% exp using stat

73% beca 85%

are loyees ils of emp more ema sending

42%

% report 59 il IT leaders of ema ease in an incr linked to data loss emic the pand

ers say of IT lead of all that half ’t be won incidents by their detected tools static DLP

ns are not "Legacy DLP solutio be working and more must ees" done to support employ

Download your copy now

www.egress.com


Our upcoming events

22 April Secon Cyber Webinar 14:00 - 15:00 BST Reduce your cyber risk by working smarter Click here to register

29 April Pulse Secure Webinar 14:00 - 15:00 BST Provide anytime and anywhere access to onpremise and multi-cloud applications Click here to register

6 May Red Sift Webinar 14:00 - 15:00 BST Protect your digital brand against email spoofing and compromise Click here to register

WHAT THE HACK - Q2 2021

19


Contact us: www.seconcyber.com Email: hello@seconcyber.com Phone: +44(0)207 657 0707


Turn static files into dynamic content formats.

Create a flipbook
What the Hack? Q2 2021 by Secon - Issuu