THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Thomas Titus, Director Information Security, Everest Reinsurance [ NYSE: EG ]As we sift through the pieces that remain in the aftermath of the China APT41 hacking group attack, we know that they targeted and breached at least 6 U.S. State networks. Over almost a year, starting February 2021, the hacking group took advantage of vulnerable internet-facing web applications to first get a foothold into state networks and then plow ahead to undertake extensive credential collection. The investigation into this attack now reveals that there were a variety of new techniques, evasion methods, and capabilities that APT41 used. Needless to say, such attacks will continue, and state-level systems will continuously face the pressure to ward them off.
A mindset shift is the need of the hour. Enterprise cybersecurity must transform from being a regulatory compliance initiative across enterprises to becoming an active warfare undertaking. Just as nation-states prepare for imminent wars, enterprises too must be ready to defend and simultaneously take proactive measures to anticipate potential cybersecurity threats and change their anticipation and mitigation strategies and tactics.
The key to pulling this off is communication flows.
However, getting the communication to engineer a shift in gears in the way cybersecurity systems are designed and deployed won’t be easy. A recent MIT study throws some light on the possible challenges. A survey conducted to ascertain how boards deal with cybersecurity issues revealed that almost 50 percent of board members were unclear on their roles. This is despite discussions they undertook within enterprises on issues related to cybersecurity. A significant 23 percent of respondents in the study admitted that there wasn’t any coherent strategy in place to deal with this pressing issue. A structured communication process, therefore, is the need of the hour. Here’s how enterprises can undertake this initiative in three stages at a rapid pace and with comprehensive coverage of all levels in the enterprise.
STAGE I – INTELLIGENCE GATHERING & RISK ASSESSMENT
To effectively communicate the cybersecurity strategies within the enterprise, one must be well informed of the risks the enterprise is exposed to and the threats it can face. This involves cybersecurity intelligence gathering from within the enterprise and without from the landscape it operates. Internal intelligence-gathering typically comes from enterprise-wide risk and vulnerability assessment, results of pen tests, gauging enterprise personnel cyber hygiene using simulated scenarios like phishing tests and tabletop incident response exercises. Technical intelligence is obtained by collecting telemetry from all types of devices and security systems in the enterprise and is fed into a Security Incident and Event management platform for analysis and generation of alerts of various severities. External intelligence is obtained through information that is dissipated through governmental cybersecurity organizations like FBI US-CERT and CIA, industry and non-governmental cybersecurity organizations like MITRE, news organizations, online forums, and specialized information gathering from the Dark Web.
STAGE II – RISK ANALYSIS & INFORMATION RELAY
All the gathered intelligence, both external and internal, must be analyzed at the various levels of the cybersecurity management structure within the enterprise. Technical intelligence gathered is analyzed by the security analysts and conveyed to the next level for confirmation. Communication plays a key role in how the gathered intelligence is converted into meaningful information and relayed to the next level of analysts. This is because this intelligence forms the basis for a particular tactical control action being taken or not. The discovery of an existence of a specific vulnerability or type of attack must be conveyed in precise terms to the right infrastructure teams to take corrective action. This could be deciding to apply the right patch to the vulnerable system or making changes in security systems to stop or deny a particular type of attack. Tactical actions taken in the lower levels of cybersecurity warfare rely on effective and relevant communication.
STAGE III – INSIGHT GENERATION & ENTERPRISE RESPONSE
Over a period, all the tactical actions taken and intelligence gathered from the first level of cybersecurity infrastructure within the enterprise is distilled by middle and upper-level management and communicated to the C-Suite executives or the Board of Directors. These form the basis of any strategic cybersecurity goals set for the future of the enterprise. Strategic goals formulated are then communicated to lower levels for implementation. Clear communication is essential for tactical actions to be taken based on long-term strategic goals. The MIT study recommended that while the board focuses on strategizing on managing business risks, cybersecurity professionals must focus their action to secure the enterprise’s technical, organizational, and operational levels.