Transcript
So if you're going to be resilient, you need to be prepared for that when. Here's something nobody in security wants to admit. Everyone is vulnerable. I work in cybersecurity. I almost got phished. I work in cybersecurity, and this is the closest I've ever got to being phished. You're getting, you know, Amazon links or USPS delivery links. Maybe you're busy and you're just you happen to click the link and you almost enter your credentials. I got called by Google. These people had really done their homework. They want me to install TeamViewer, which I don't want to install TeamViewer. It all set all the sensors off. Hoping attackers don't get in isn't a plan, especially when they're using AI to move faster, scale bigger and operate with zero regulation. Nowadays, both the earliest adopter and the most aggressive adopter of AI is the adversary. AI is being used to obfuscate phishing emails, craft really legitimate looking phishing wars. And build out tools like the Evil Tokens infrastructure. Now they can feed lists of names and LinkedIn profiles through AI models and build out custom campaigns to target those individuals in a fraction of the time it would have taken them in the past. Attackers aren't hacking systems anymore. They're hacking humans. Prevention alone isn't a realistic strategy anymore. The unfortunate reality is the weaknesses that we see often exploited today are the weaknesses that were still there 20 years ago. It oftentimes is just a failure of the basics, a failure of the common controls being applied correctly. And that's where I believe it's more about education and informing partners around what the true risks are. That gap between knowing there's a problem and doing something about it starts with visibility. You have to understand what you have, how attackers are going to come at you and what normal even looks like in your environment. Understanding your attack surface, understanding how are attackers going to target and break into your organization. Understand what user activity is normal and what you're expecting to see. Having a plan in place of where are the backups? Are they off site, on site? What security products are in use? Having just an asset management system, knowing what is stood up and when it is stood up and having a catalog of that. The thing that's been most consistent to me as far as getting successful outcomes is controlling the surface of what you have to review. If you have a massive haystack and you're looking for a needle, you're really going to struggle. And it's just more likely you're going to miss the attack in the first place because you're responding to too many false alarms. A clean baseline gives you something to measure against. From there, it's all about putting the right detection tools in place, the ones that cut through the noise and get your team to the right outcomes faster. Most organizations don't get compromised because a user purposefully did something wrong. We're all busy. We all do a lot of things. It is crucial to make sure you're actually investing in your team with like security awareness training type materials so they understand the threats that they actually face. Pulling out an identity detection threat response tool allows you to very rapidly identify a potentially malicious login and disable that account automatically. The big thing I always tell people is, you know, there's a massive advantage to bringing an MDR partner in and that they have global visibility into millions and millions of endpoints. And when it comes to detection and response, I feel like if you really can't make the jump to a 24-7 team, it just makes a lot more sense to outsource that to some sort of MDR provider, somebody who can watch that for you. The difference between a bad day and a business ending disaster is how fast you react when things go sideways. The first piece of advice I'd give any organization with an internal IT team or an internal security team is to run a tabletop exercise. The last time you want to be running through your incident response plan is in the middle of an active incident. Do you have to understand and define and have agreement like, hey, when this happens, person A is going to do this, person B is going to do this, person C is going to do this. I'm going to use this tool. I'm going to use it this way. Identify who's involved in that process, who's doing the response, who is handling conversations with legal, any sort of press releases, things of that nature. It's going to make it much smoother and calmer for everybody when the breach happens, not if the breach happens. I can't recommend enough. Doing that in a dry run through a tabletop scenario is going to allow you to identify the gaps in your incident response plan, plug them and allow you to be more effective in the event of a true incident. If your security plan still starts and ends with keep the bad guys out, it's time for a new plan. Resilient teams assume the breach is coming, give their people the right tools and practice incident response before they actually need it. So if you're going to be resilient, you need to be prepared for that when and you need to know that when it comes, you're going to have to jump on it. You're going to have to have the incident response plan. But what makes things really effective is being able to have that monitoring. So when things happen, you have the resiliency and you can put into action what you've prepared for.