Transcript
respective threats, focusing primarily on endpoints and identity posture. So when you think about it, attackers are still very much using the basics to breach organizations. What do I mean by that? So when you think about posture and security management, you hear in the news all about zero days and major breaches but oftentimes what you don't hear about is that MFA exclusion or MFA exception that somebody's temporarily allowed and that you've forgotten about right, that an adversary is taking advantage of. Or weak password management or poor password posture. Other things, common tools for example, that remote management and monitoring tool, so that RMM tool within your environment that you've since forgotten about that an adversary has installed and now has a direct backdoor into your environment. All of these are basic IT hygiene issues which oftentimes you've either forgotten about or have just let go by the wayside. And this is what attackers are primarily taking advantage of versus the zero days. Just in the last year as an example, our SOC has observed almost a 300% so 277% in RMM abuse. So coming back to that basic security hygiene issue that I mentioned, this is where adversaries, and I'll talk about an example later on, where adversaries for example fool and trick users, end users into installing legitimate tooling, so legitimate RMM tools, so that they can have a backdoor within your environment. Your EDR is not going to pick that up, your AV is not going to pick that up. Why? Because they're actually legitimate tools that are being misused by adversaries within your respective environment. Other areas as well, so almost 40% of organizations have had their identities or breached via shady logins. So what does that mean? So this doesn't necessarily mean a credential that shouldn't be within your environment. What we mean by that is they're using legitimate credentials within your respective environment of employees that they've probably gained access to those credentials on the dark web or coming back to easy or poor password management or poor credential management. So what does that really mean? We surveyed a number of organizations and what we found again in the last year that almost 50% of them had a major breach or incident that they had to deal with and it was not from a zero day. So this is what we see all the time, day in and day out, adversaries are taking advantage of simple misconfigurations, some of those examples that I mentioned earlier. Worse than that, when you think about beyond a breach, what happens when the posture within your environment impacts business operations? So a software install or a new application installed that you can't do because the respective security controls in the environment aren't up to snuff. So for example, your environment's not patched enough to install a software update and that delays a software update within the respective environment. In a survey that we conducted almost to what 55% of the more than half of organizations had to delay or cancel a software update within their respective environments due to weak posture management. And then of those respective organizations, many take more than a day, so more than 24 hours to actually update or correct that misconfiguration. Guess what? If an adversaries within your organization, they've probably got away with anything and everything that they need within the first 10 minutes within your organization. So guess how much data or how much information they can get away within your organization within a 24 hour period? Chances are they've got everything and they've done everything that they want to do within your organization. So this is an example of just one of the issues that I had mentioned earlier, where this is a phishing campaign that an adversary sent to an employee in one of our organizations that we protect. And as you can see, it's a Teams update and the end user, it looks really legitimate because from a phishing perspective, the end user thinks they're doing a Teams update. When they click on the Teams update, a rogue malicious RMM tool is installed within their environment. That's not necessarily something that's going to be picked up by EDR or AV. Why? Because when you look at the actual tool, it's a real RMM tool, but it's controlled by the adversary. So now from an IT perspective, if you don't have good controls or understand, should this RMM tool be installed in my environment? If I'm an IT person, am I looking in the environment and I see, for example, a data RMM tool installed within the environment, it's signed by Microsoft, it's a real RMM tool, but as the end user has given backdoor access into the respective environment, that RMM tool is controlled by an adversary. Your AV, your EDR, nothing's going to pick that up. The only real way to pick this up would be by using endpoint posture management. Because by using endpoint posture management, I understand this is a list of respective applications that I should be running within my environment that's approved within my environment. So in this case, had I been running endpoint posture management, I would have realized quickly that, hey, this data RMM tool shouldn't be installed within the respective environment and be able to block that. In another example, say MFA is great except for that one user who's complaining about MFA, and you create the exception for that one user, and you forget to re-enable MFA for that one user, and guess what? The adversary is going to find that one user account that doesn't have MFA and take advantage and abuse that. That's exactly what happened in this respective case here, where, let me go back, where the adversary took advantage of the only MFA account that was, excuse me, the only credential that didn't have MFA enabled in this respective environment and went ahead and infiltrated the respective organization. So this is really where it becomes super important to think about both endpoint and identity, where how can we shift left and look at the respective posture. It's got nothing to do with detecting malicious activity or behavior, it's more restricting your security controls and restricting what's allowed to run within your respective environment. Is my MFA configured correctly? So how do I shift left my security controls so that I not only lock down and address all of these simple misconfigurations, but at the same time then, when I'm shifting left, I'm addressing those misconfigurations and posture within my environment from an identity and endpoint perspective. And then within that environment, anything that does slip through, you have your ITDR, so your Identity Threat Detection and Response, and your EDR, so your Endpoint Detection and Response to address that. So you're not only moving the barriers, so remember I mentioned earlier, 50 odd percent or 45 odd percent of organizations had been breached last year in survey data that we had done simply from misconfigurations. So you're already wiping out almost 50% of issues that adversaries are taking advantage of. These are some of the use cases in that that we do focus on, so it's better from a security perspective to focus on what's the respective outcome that you're trying to achieve. Are you trying to achieve endpoint integrity? So to address some of those use cases, ransomware, infostealers, etc. Or are you looking to address identity resilience and protecting yourself from any things like account takeover or BEC attacks, as an example. Then ultimately, operational readiness, where you need to have full visibility of the respective environment, so that you're addressing what's going on between multiple attack vectors. So not only on your endpoint, but on your identities as well, and how do you stitch all of that together so you have visibility across all of those respective attack vectors.