Given the increased complexities and sophistication of cyber adversaries today, the demand for skilled IT security practitioners has outweighed the supply — particularly those skilled in security operations, intelligence, data analytics and forensic analysis. Drawing parallels to healthcare, increases in medical device, imaging, research/development and clinical care has involved much the same way. These advances in technologies have given us the ability to detect faster, “diagnose” and prevent. The outgrowth has created a broad shortage of practitioners with both the clinical/tactical skills and the operational experience necessary within today’s evolving threat landscape. So what does a Cyber Doctor look like and what are we doing to educate and train the next generation of “security care givers”?
(more…)
In my last post, I discussed a common syndrome experienced by many organizations called “SOC Enterprise Amnesia” whereby the most valuable data (intelligence) gleaned from events/incidents is flushed and forgotten as operational fatigue sets in while the volume of security control and instrumentation data continues to overwhelms the operators field of view. The outgrowth of this state is called “Operational or Organizational Thrashing”.
(more…)
In recent blog posts I discussed the concept of Switch Targeting and the fundamentals of how adversaries use seemingly trusted hop points as vectors in and out of primary targets. I also introduced the concept of R3 or (Readiness – Response – Resiliency) based on my experience in the field helping organizations position themselves to detect where these switch targets may be based on attack infrastructure intelligence.
(more…)
In Part I of my post on Switch Targeting, I discussed the fundamentals of how adversaries use seemingly trusted hop points as vectors in and out of primary targets similar to how bank robbers target, stage and execute their robberies. Now I want to introduce the concept of the three “R’s” or R3 based on my experience in the field helping organizations position themselves to detect where these switch targets may be relative to their own attack infrastructure as part of designing a Next Generation Security Operations Center (SOC). R3 is comprised of three focal areas for the Chief Information Security Officer (CISO) to consider —- Readiness, Response and Resiliency.
(more…)
Conventional computer network defense (CND) concepts in the past 10 + years introduced practices such as adversary “beach head, pivot point, lateral traversal, command/control” analysis for passive cyber defense. If I don’t see it on my network, then I must not be a target and/or my business is of no interest to advanced threats actors, right? The correct answer is in asking yourself as a business, “why me?”
(more…)