the CYBER5

the CYBER5

By Nisos, Inc.BusinessTechnology
Download on the App Store

the CYBER5 episodes

  • Combating Terrorist Messaging on the Open Internet

    In episode 60 of The Cyber5, we are joined by Tom Thorley, the Director of Technology at the Global Internet Forum to Counter Terrorism (GIF-CT). 

    We discuss the mission of GIF-CT and how it's evolved over the last five years, with particular interest on violent terrorist messaging across different social media platforms. We also discuss the technical approaches to countering terrorism between platforms and how their organization accounts for human rights while conducting their mission. 

    Four Key Takeaways:

    1) The Evolving Mission of GIF-CT 

    GIF-CT combats terrorist messaging on digital platforms and is particularly focused on removing live streaming of violence. They were founded in 2017 by Microsoft, Facebook, YouTube, and Twitter to mostly combat advanced ISIS messaging efforts across their platforms, particularly after several high profile terrorist attacks were live streamed. 

    GIF-CT has grown to include 17 different technology companies that participate in the mission of combating terrorist exploitation of their platforms. Since ISIS has been degraded over the last three years, GIF-CT has expanded their mission to include supporting the United Nations Security Council’s Consolidated Sanctions List. 

    2) Behavioral Models as Opposed to Group Affiliation

    Due to the fast adaptation and evolution of terrorism, GIF-CT has moved to track behavioral models of violence rather than attempt to focus on known terrorist groups. They built out an incident response framework to review emergency crisis situations using technology called “hash sharing.” Now, they are looking at expanding into:

     

    • Manifestations of terrorist attacks just carried out
    • Terrorist publications (Inspire Magazine by al-Qaeda) with specific branding
    • URLs, videos, and images where specific terrorist content exists across platforms

     3) Hash Sharing Across Social Media Platforms with Content

    User created content is not associated with an identifiable individual, like an IP address generally tied to a device. When GIF-CT hashes videos, they not only use traditional MD5 hashes, but also use perceptual hashes, which are locality sensitive. These hashing techniques and different algorithms provided by the technology companies, allow images, videos, and URLs to be flagged and potentially removed from the platform in close to real time. 

    There is some new hash sharing technology that is being explored around PDFs. The need has been driven in part because malware is exploited because the backend code of the PDF is manipulated whereas terrorist manifestos are not, they are just content. Technology is being explored by GIF-CT where they can hash certain content strings in PDFs for alert.

    4) Optimizing for Human Rights

    GIF-CT hashing algorithms minimizes impact to human rights during emergency situations and differentiates between legitimate journalism and normal discord between people on the platform. GIF-CT goes through tremendous transparency initiatives that focus their algorithms on violence extremism.

    32 min
  • The Business of Security: Positively Influencing Profit and Loss

    In episode 59 of The Cyber5, we are joined by active security compliance practitioner, Dylan McKnight. 

    We discuss the business of security. We unpacked how security can be effective at driving profitability and not just be a cost center toward an organization. We discuss how compliance measures can drive meaningful metrics around profitability and avoiding breaches. And finally, we talk about where threat intelligence provides the proper risk-based approach for security teams in this process.

    Five Key Takeaways:

    1) Making “Security” Be Seen as More than Just a “Cost Center”

    Prioritize external-facing business leaders and help them to become security stakeholders. Give Sales, Customer Success, and Marketing a reason to care about security. In the technology space it’s important to understand how your organization makes money. You must embed security practices into the contracts to ensure your organization is being a good steward of each department’s data. Third party risk management processes are an example of how this shows up in the everyday.

    In the pre-close world, work with the sales team to ensure security functions are assisting to close deals faster. As a communicator, you must also improve customer relationships through privacy programs and a good incident notification policy after the sale. 

    You must still maintain key relationships with necessary internal stakeholders such as:

    • Internal auditors who will answer to regulators (SOC2, ISO Cert, etc)
    • Engineering team with product development cycle
    • Legal and HR 

    2) Security Roadmap is Critical with Limited Resources 

     

    It’s critical for security practitioners to understand that the vortex of power within technology teams is centered around sales and product engineering teams. Security practitioners lament that they don’t get enough time in front of internal decision makers, that’s why they need to embed themselves in the sales cycle. Critical security functions like identity and access management (IAM) and file integrity monitoring are two examples of having value, but are time intensive and don’t necessarily improve the bottom line unless they are part of customer contracts. 

    However, privacy requirements are becoming critical to engineering and sales teams and a security program should be adapted to meet those needs first.

     3) Developing the GTM-focused Security Playbooks that Scale with the Business Growth

    Risk assessments for what could cause the most business loss are important to start, backed by standards and controls that align to this potential loss. 

    “Move fast and break things” could have monetary losses in security, so it’s important to go to quarterly business reviews with the sales team and understand the pain points in the sales process. Security should exist to make sales move through the process quicker and then by illuminating potential risk. 

    4) Compliance is Important for Maintaining Customers

    It’s cheaper to keep existing customers than gain new customers. To keep existing customers, trust becomes a critical aspect. Transparency around security controls and incident notification with your customers can go a long way to keeping them satisfied during renewals. 

     

    Compliance standards that meet these transparency requirements are beneficial for building trust with customers including the right levels of monitoring of cloud infrastructure and managed detection and response. It’s important to understand how all the different teams use data in the environment and protect what really matters, which in technology companies is usually the “least privilege” permissions around the production environment. 

    5) The Role of Threat Intelligence in Risk Assessments

    Risk-based approaches are always a good starting point. Threat intelligence should be geared to focusing on who, how, and why threat actors are actually attacking your organization. Simple defenses should be built around threats that are happening, not just what is possible. Not only monitoring the dark and open web, but closely analyzing your firewall logs and providing an “outside-in” inspection to closely enrich data your internal telemetry with external signals for more risk-based context and prioritization.

    24 min
  • Tips on Recruiting and Retaining Cybersecurity Talent

    In episode 58 of The Cyber5, we are joined by Magen Gicinto, Director People Strategy and Culture for Nisos. 

    We discuss the “Great Resignation’” that's happening in the work environment during the COVID pandemic and how to realign your “people strategy” to recruit and retain the best talent in spite of those challenges. We address the aspects of recruiting and retaining the best talent and how to calibrate total rewards in consideration of employees’ ever-changing motivations. Finally, we cover the nature of startup culture in the technology sector and the convergence of generalists and specialists in high performance organizations.

    Four Key Takeaways:

    1) Recruiting and Retaining Talent During the COVID-19 Pandemic

    Employees who would have otherwise left their jobs decided to stay put during the pandemic. Now, even though we are still in the throes, people feel safe again to move jobs, which is leading to an unprecedented turnover in the global workforce. In fact, according to statistics published by the U.S. Department of Labor, voluntary turnover dipped significantly in 2020, but in early 2021, it jumped higher than ever before, with 4 million people leaving jobs in April 2021 alone in the U.S.

    Employees that are looking for new opportunities and want to integrate work/life responsibilities are looking for employers who support those values. What remains is employees continue to want opportunities for career advancement and building their skill sets. 

    One core solution for employers is to reimagine the employee experience so you can keep your best people and recruit great talent. Understanding what your employees value and what motivates them is key to reducing churn and attracting new people. High performing People Strategy departments are adept at creating employee engagement, from onboarding through the employee lifecycle, that help to continue to satisfy employee motivations throughout their tenure with an organization.

    2) Experiential Support to Employees Is Critical 

    Organizations that invest heavily in creating the best employee experience will have better success at recruitment and retention. Organizations and teams are most successful when the organization’s strategies, structure, and culture are aligned. 

    During the infancy stage of  startups, there is little consistency for people to hang on to. Leaders are focused on doing what they can to source and hire the best talent, while outsourcing other services. Once you move past the infancy stage and start growing, your attention needs to move to ensuring stability and creating a life cycle for employees. 

     

    Employees who are embedded into the organization from day one who have experience with a strong onboarding regimen will have more staying power and satisfaction with the organization. While white-glove on-boarding is not always achievable at a  startup level (based on lean staffing), companies that can find the resources to do so win it back with stronger employee integration in the entity from day one. 

     3) Challenge Playbooks to Create the Best Employee Experience

    Here are some ways to create an environment where employees can succeed and grow within an organization. This is especially crucial within cybersecurity where the table stakes can be higher, and the goal posts can move quicker. 

    • Set clear goals
    • Be consistent in performance management
    • Understand what obstacles are in the way of them performing at their best so you can help remove barriers to them being successful
    • Keep the lines of communication open 
    • Have honest, fact-based conversations so that when they have concerns about their job or their performance, you’re prepared to address things with perspective. 

     

    4) Prevent Silos and Bring People Together When New Departments are Created

     

    When recruiting, look for talent who create value and can deliver on company objectives. Employees want to have purpose in their work and know that they’re making a difference. As a startup organization, you have a great opportunity to create and influence organizational decisions and add value. Hire individuals who are up for the challenge and want to lean into the company’s goals with the team.

    To avoid departmental silos, it’s important to:

    • Attract and help select the best talent that meets the business’ needs
    • Close any skills gaps
    • Recruit people who value differences in perspectives
    • Look for ways to create new and better ways for the organization to be successful
    • Hire people who are likely to drive results and tackle new challenges using both success and failure as learning opportunities 

    By bringing different departments into the recruitment and retention process, it helps avoid silo-type organizations. It creates more alignment, and helps employees understand what’s going on in the business. Once a new hire comes on, all of the departments are similarly invested in the individual, and can incorporate them, which will allow them and you to begin to utilize their skillsets effectively.

    24 min
  • Evolution of Incident Response Playbooks in the Last Five Years

    In episode 57 of The Cyber5, we are joined by Colby Clark, Director for Cyber Threat Management. He’s also the author of the recently published book, The Cyber Security Incident Management Master’s Guide.

    We baseline incident response playbooks around customer environment, threat, landscape, regulatory environment, and security controls. Afterward, we discuss how incident response (IR) playbooks have evolved in the last five years and they have scaled in the cloud. We discuss telemetry that is critical to ensure an IR team can say with confidence that an incident is accurate, complete and truthful in order to avoid breaches. Lastly, we discuss the criticality of threat intelligence in the IR process and what boards really care about during an incident. 

    Four Topics Covered in this Episode:

    1. The Shift in Incident Response Playbooks

    Playbooks used to be contact lists, and an outline of roles and responsibilities of who to call during a cybersecurity incident. It was typically based on recovery from natural disasters. Today, threat -based playbooks are more specific and actionable tailored to the enterprise environments that were based on compliance and insurance requirements. 

    In Clark’s book, in his execution with clients, 13 distinct domains are relevant for baselining these playbooks; including customer environment, threat landscape, regulatory environment, and security controls. Most importantly, incident management is a repeatable process over a period time that adapts to regulators. Enterprise solution tooling is always behind the tooling of the attackers, and therefore, gap analysis within IR playbooks is a constant job for any IR team.

    1. The Need for Consolidating Cybersecurity Solution Tools
    • Security practitioners sometimes struggle with knowing the business functionality of applications and systems within enterprise networks, which makes identifying what is normal or malicious challenging.
    • If security technology is not tuned with consideration for the people and process involved, the tooling is useless. 
    • Network encryption pervasiveness is making network traffic analysis tools increasingly irrelevant; all important telemetry, to reduce visibility gaps, is moving to the endpoint (devices, servers). Realizing big companies cannot have endpoint detection and response agents (EDR solutions) on every endpoint, means some network traffic capture is still important to track. 
    1. Incident Response Migration and Evolution to the Cloud
    • Tooling: In 2014, EDR tools started to be developed that took over anti-virus software and since then has detected 80% of breaches. EDR, and now XDR (Extended Detection and Response), solutions that operate in the cloud (AWS, GCP, Azure) are the only means to quickly detect and recover from cyber incidents, especially with a distributed workforce. 
    • Protecting Environment: Customer applications that run on cloud servers (production and non-production) bring tremendous frustration for incident response efforts. They do not have on-par visibility to their physical counterparts, particularly with containers. They have reduced controls and limited investigative capabilities, allowing malicious backdoors into environments. 
    • Important Strategies: First, maintain, update, and patch baseline images for containers. Second, turn on logging; nothing is logged in cloud environments by default. Companies have to pay extra money to turn on logging and pay additional licensing fees for security tools (cloud trail logging for AWS, for example). Third, turn on network decryption at the right points. Last, keep maintenance of EDR tooling.
    1. The Importance of Threat Intelligence in Cloud Security
    • Threat intelligence should be built into EDR logging by default and will likely be part of the XDR paradigm in the future.
    • A deep dive RFI (request for information) capability must also be included to ascertain if the intelligence is directly relevant to the organization or just an industry trend. 
    29 min
  • Use of Intelligence for Corporate Security Programs

    In episode 56 of The Cyber5, we are joined by Ray O’Hara, Executive Vice President for Allied Universal.

    We discuss the use of intelligence for corporate security programs, usually overseen by a Chief Security Officer (CSO). We talk about some of the challenges this role faces and how intelligence can be actionable to mitigate those risks. We also work through various case studies, talk about metrics for success, and what technology platforms are used to aggregate intelligence that might be useful in the future.

    Four Topics Covered in this Episode:

    1. Role Shift for Chief Security Officers (CSO)
    • For many large organizations, the chief security officer is the chief strategist for organizing the holistic security strategy and obtaining board approval for the organization. 
    • CSOs are no longer in the day-to-day planning around “guns, guard, and gates.” Instead, they are more strategically focused on business continuity, emergency planning, and crisis management.
    • Risk to business leaders drives the daily activities of CSOs. They need to understand that other business leaders may choose to work around the threat to execute against profit and loss.  
    1. Intelligence Sources for Chief Security Officers
    • Having a dedicated intelligence analyst is an important asset to a chief security officer. 
    • Emerging markets, information on key suppliers, as well as competitor data is routine tasking for an intel analysis who is subordinate to the CSO. 
    • Since security is a necessary cost center on the administrative function within organizations, intelligence analysts need trusted partners to handle the collection and analysis side of intelligence, including social media. Additionally, intelligence analysts ensure that collection and analysis are tailored to business management requirements. 
    1. Sentiment Analysis Combines CISO and CSO Functions
    • Negative sentiment analysis against a company's brand traditionally falls within the CSO's GSOC function. However, this responsibility is starting to move toward information security due to threats to confidentiality, integrity, plus the needs for availability of data, systems, and networks from the Dark Web. As long as coordination is present, it doesn't matter whose lane covers social media sentiment analysis. 
    1. Social Media Monitoring Critical For Reducing Executive Protection Resources
    • Executive protection is expensive when a physical security threat escalates. Effective social media monitoring and direct threat actor engagement help to derive the most accurate protective intelligence. They can be a more cost-effective way to monitor the danger without having 24x7 surveillance.
    26 min
  • Evaluating the Conundrums of OT Security in the Energy and ONG Industries

    In episode 55 of The Cyber5, we are joined by Nate Singleton, a security practitioner who was most recently the Director of IT, Governance, and Incident Response at Helmerich and Payne.

    We discussed the conundrums of operational technology security within gas and energy sectors, including risks downstream and upstream. We also compared the aggressive and constant need for interconnectivity on the information operation technology sides of the house to show that events like the Colonial Pipeline ransomware attack are probably just the beginning of future attacks against critical infrastructure. 

     

    We also discussed what more major oil and gas companies can do to help improve cybersecurity for small companies critical in the oil and gas supply chain.

    Five Topics Covered in this Episode:

    1. Operational Technology is Built to Last, Bringing Nuance to Security
    • Underlying technology controlling oil, gas, and energy PLCs runs on old Linux and Windows servers from 20 years ago and patching for upgrades is expensive and takes a lot of down time. 
    • Routine vulnerability scanning against an entire IP block often seen within regular IT environments can cause major damage, even resulting in the loss of human life, if not conducted carefully and properly in OT environments.
    1. Interconnectivity Comparisons Between Legacy Silicon Valley Tech and Operational Tech Development
    • Security takes a back seat in operational technology for the Energy Industry, just like it does for Silicon Valley product development. 
    • The bigger challenge is often integrating regular IT and application developments that need constant upgrades with OT technology that can’t take the upgrades on time. A “move fast and break things” mentality in OT could get someone killed. 
    • Ransomware and other malware events have the capacity to take down OT production lines for weeks, costing millions of dollars. 
    • While the Colonial Pipeline ransomware event only attacked the IT environment, it did not attack the OT environment, thus demonstrating the potential for future calamities to occur. 
    1. Attacks Against Oil and Gas are Geopolitical in Nature and Will Likely Get Worse
    • Attacks against critical infrastructure are going to get worse and the attacks are often conducted by nation states who have the time to build exploits against the IT environment and are also leveraging sophisticated OT technology. 
    1. Strategies for Protecting Operational Technology in ONG
    • OT security is protecting the IT administrator who can access oil rigs, energy systems, and OT devices. 
    • Reporting must make it from the OT systems to the corporate IT systems so they can see profit and loss. Therefore, many critical infrastructures use the Purdue Model to segment different layers in network infrastructure from the machinery to different levels in the corporate environment so customers can be billed. More granular strategies include:
      1. Updated EDR products in the corporate environment
      2. Multi-factor authentication separating corporate and OT environments
      3. Separate domains for engineers’ ability to browse the internet and check email and upgrade software on the OT networks
      4. Robust firewall policies on the network layer controlling port protocol connectivity back and forth
    1. Threat Intelligence for OT Security
    • Integrating Indicators of Compromise (IOCs) into a SIEM has become an antiquated practice, but they are still valuable for OT environments since they are modeled around constant connectivity and up times. 
    • Client-specific intelligence of what threat actors are doing is most critical because the remediations will take place over weeks and months. A cost-benefit analysis is always going to be levied when allocating resources to fix vulnerabilities. A “block all” approach to threat intelligence is not going to work.
    31 min
  • Personal Information Exposure Can Lead to Disaster

    In episode 54 of The Cyber5, we are joined by Aaron Barr, Piiq Media’s Chief Technology Officer.

    We discuss how data breaches are combined with other open source information to paint a more holistic target profile for bad actors. We also discussed the true information anchors and weaponization that can lead to an online attack against someone. Finally, we discussed what executives and individuals can do to protect themselves and how protective intelligence is playing a greater role in physical security.

    Four Topics Covered in this Episode:

    1. Common Information Anchors Used to Attack Someone Online
    1. Connection to an organization indicating that someone is likely a high net-worth individual.  
    2. Communication platform for content delivery including, email address, social media platform, phone number, etc.
    3. Context for authenticity. The social engineering approach must have the right information about an individual for increased success.
    1. Best Practices for Staying Safe on the Internet
    1. Keep social media postings about personal information, locations, jobs, education as simple as possible. Be careful not to post pictures with background details that give your location or family profile to potential attackers. 
    2. Ensure profile pictures are minimal as those are public regardless if everything else is private.
    3. Password managers should be used for personal accounts. 
    4. People should have at least three personal email addresses. Email addresses should be siloed: a) social media accounts b) bank accounts or personal information c) thrown away for rewards, e-commerce, and gifts. 
    1. Education and Awareness Training Still Important

    Education to executives and the workforce about simple technology such as the ability to flag suspicious emails that get escalated to the security team still goes a long way in securing the workforce.

    22 min
  • Thinking about Cybersecurity Challenges in the Geopolitical and World Economic Context

    In episode 53 of The Cyber5, we are joined by Ciaran Martin, the former United Kingdom National Cybersecurity Center CEO and former Director General for Cybersecurity of GCHQ. He’s currently a professor at the University of Oxford and a strategic advisor for Paladin Capital. 

    We discuss the political, legal, and ethical challenges of today's ransomware threats and the corresponding nation state challenges of Russia, China, and Iran. We also discuss what the U.S. and global economies can do to reduce these threats and how the financial industry can assist in a greater capacity.

    Four Topics Covered in this Episode:

    1. Ransomware’s Social Impact Escalates to National Security Priority

    With semi-conductor shortages caused by the pandemic and corresponding geopolitical rifts between the U.S., Russia, and China, ransomware is at the center of national security threats While ransomware actors are just organized criminals, three characteristics have made this a broader national security threat:

    1. Russia and surrounding states allow criminality to flourish.
    2. Cybersecurity problems exist in western economies due to vulnerabilities caused by poor security practices within development lifecycles.  
    3. Ransomware business models position criminals for success. Executives don’t understand cybersecurity and immediate business impact motivates them to pay ransom.
    1. China Wants Authoritarian Control over Technology; Russia Wants a New Cold War

    The U.S. and Western model of technology has created flaws that lead to ransomware. The “move fast and break things” mantra of Silicon Valley prioritizes connectivity over security. The Chinese model is one of consistent integration, overwatch, authority, and frugality. Russia seeks regional control and the overall weakening of democracies through disinformation and offensive computer network exploitation operations.

    1. Commonalities and Differences of Combating Ransomware Actors and Other Non-State Actors

    Key Differences:

    Ransomware actors are not yet causing widespread harm to individuals.  If this starts to occur, we could see increased offensive campaigns against ransomware actors similar to what we’ve seen against other non-state actors. 

    Non-state actors of the last 15 years were usually under a failed state whereas ransomware actors enjoy state protection in many cases.

    Key Commonalities:

    The world economies will eventually join to stop the movement of money that is used by ransomware actors, repeating what happened to the non-state actors of the last 15 years. 

    1. The Financial Sector Must Step Up to Stop Ransomware

    Cybersecurity risk is well understood by the major financial sectors as it pertains to their own security. Cybersecurity, fraud, insider theft, and general resilience are well understood and defended by the major banks. Aspects of cryptocurrency and money laundering aspects of cyber security are still major opportunities for the FIs.

    26 min
  • Evolution of Nisos Over the Last Six Years from the Operators

    In episode 52 of The Cyber5, we are joined by Nisos Managing and Technical Principals Robert Volkert and Travis Peska who lead operations within the Pandion Intelligence team. 

    We talk about the evolution of Nisos over the past six years, including how we now position ourselves within the private sector threat intelligence market under our new Chief Executive Officer, David Etue. 

    Our managed intelligence mission combines open-source intelligence analysis, technical cyber security investigative tradecraft, and data engineering to solve enterprise threats around cyber security, trust and safety platforms, reputation, fraud, third party risk, and executive protection. We reminisce about our favorite investigations and talk about what’s next for Nisos. 

    Three Topics Covered in this Episode:

    1. How Nisos Has Evolved

    In the last six years, Nisos evolved its mission to focus on being the Managed Intelligence Company™. Using skill sets combining offensive operators, forensic and network analysts, open source intelligence experts, and data engineers, we collect and analyze data to solve problems within six primary intelligence domains:

    1. Cyber Threat Intelligence
    2. Protective Intelligence
    3. Reputation Intelligence
    4. Platform Intelligence
    5. Fraud Intelligence
    6. Third Party Intelligence
    1. Providing the Answers, Not Just Data in Monitoring and RFI Services

    Since our “outside of the firewall” investigations and tradecraft over the years, we realized customizing smaller datasets around customer problems is more helpful to customers and helps differentiate our offering with actionable intelligence with appropriate context. 

    Aggregating data to a product that doesn’t provide the answers is often a waste of resources for many organizations who need to make information actionable to security operations teams and executives. As part of these services, routine monitoring services followed by an aggressive RFI service is generally viewed as the most effective way to quickly answer customer intelligence requirements within a 24-48 hour period. 

    1. Favorite Investigations Over the Last Six Years

    While the most prolific investigations have involved the unmasking of threat actors when the appropriate context is needed, the most well known investigations generally involve attributing attacker infrastructure and unraveling different malicious tool sets against platform technology companies and business applications.

    32 min
  • Building and Implementing Security Programs within Fast Growing Technology Companies

    In episode 51 of The Cyber5, we are joined by Chris Castaldo. Chris is the Chief Information Security Officer for CrossBeam and has been CISO for a number of emerging technology companies. 

    In this episode, we talk about his newly released book, “Startup Secure” and how different growth companies can implement security at different funding stages. He also talks about the reasons security professionals should want to be a start-up CISO at a growing technology company and how success can be defined as a first time CISO. We also talk about how start up companies can avoid ransomware events in a landscape that is not only constantly changing but also gives little advantage for defenders of small and medium sized enterprises.

    Two Topics Covered in this Episode:

    1. 4 Security Lessons for Founders of Start-up Technology Companies

    When a B2B company is pre-seed or before Series A funding, customers might have leeway for lax cybersecurity controls. However, after an A round, policies, certifications (SOC2 or ISO27001), procedures will be required to ensure customer data is staying safe. A B2C technology company might not be asked by the public for certifications, but auditors and regulators may. Basic policies include:

    1. Single Sign-On or an Okta authentication into applications, cloud, and workstations
    2. Password management implementation (LassPass or OnePassword)
    3. Encryption at rest and transit
    4. Vulnerability scanning
    1. Combating Ransomware from The Inside-Out Approach and Integrating Threat Intelligence

    Blocking and tackling from inside-out to get in front of ransomware is challenging. The simple items to tackle are the following: 

    1. Auto-updates for patch management on operating systems
    2. Endpoint Detection and Response products
    3. Proper asset management to have full visibility on all network devices and services

    At the point when resilience and compliance controls are in place and an organization can bounce back from an incident in a timely manner, adversary insights via threat intelligence is a logical next step.  

    28 min

About the CYBER5

From the publisher's feed

The CYBER5 is hosted by Landon Winkelvoss, Co-Founder at Nisos, and features cybersecurity and investigations industry leaders' thoughts and answers to five questions on one topic on actionable…