enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Wyndham Hotels & Resorts

Endpoint Security Requires Collaboration

Michael Francess, Sr. Manager, Cyber Security Advanced Threat, Wyndham Hotels & Resorts

Having worked in several different-sized security organizations the consistent challenge when it comes to hardening endpoints did not just come from deploying a modern technology control or more data collection. The key driver to success was the culture of collaboration across multiple groups to holistically make changes throughout the computing environment to future improve endpoint resilience. I have observed amongst my peers across different industry verticals that one of the core challenges teams have to execute meaningful change is due to siloing of responsibilities or the inability of teams to work together to solve problems due to the corporate structure or culture focused on individual success above group success. I have come across Security Operations teams that do not have sufficient understanding of not only their networks but also a lack of visibility or understanding of other security controls owned or managed by other teams due to the lack of meaningful information sharing and willingness for the security organization to invest in a single mission to secure the company. I find too many organizations are not focusing on reducing their security alerts or events but investing in larger automation tools to help automate the triage of the existing, or even growing, alert count. We need to shift this paradigm.

For any sized cyber security organization, having strong relationships between your IT operations, engineering, and security teams is so crucial as commodity security events can be prevented with well-thought-out and executed controls across multiple layers. For example, while your Security Operations team likely does not manage your Secure Email Gateway solution, they should have input as front-line responders into the policy to understand what is being blocked and what functionality is turned on. This should apply to other tools in the organization's defensein-depth strategy, such as internet proxy filtering, intrusion detection capabilities, and Microsoft Group Policy objects around auditing and log generation. It’s also crucial for those that invest in a Managed Detection & Response (MDR) or Managed Security Service Provider (MSSP) to share as much information as they can with that vendor to provide as much context as possible. Their success will be your success; just feeding them data with no context will lead to incomplete or even poor outcomes during event triage.

 

  • For Any Sized Cyber Security Organization, Having Strong Relationships Between Your It Operations, Engineering, And Security Teams Is So Crucial

 

By investing time to ensure there is a strong relationship between the solution owners of the Secure Email Gateway and your Security Operations or Threat Intelligence teams, you can greatly reduce your commodity malspam and phishing volume at the front door via ensuring vendor best practices for the configuration of policies. This investment in time and effort will transition down into a drastic reduction in risk to your users and endpoints. A ransomware incident does not occur in a vacuum and typically starts from commodity info stealer malware delivered through email malspam. This initial access vector remains one of the top intrusion verticals in 2023. If you can stop this malware, you will stop It’s crucial you get an idea of what they are being alerted and responding to and find the root causes, and improve resilience by shifting that risk further up the cyber kill chain before that to prevent events becoming incidents or reducing their frequency.

This same approach in collaboration is crucial when it comes to patch management as well. Having strong relationships built on trust and respect is going to be so crucial for the time when the security organization makes recommendations for prioritized patching or when you need to execute an emergency incident response process for patching, such as Log4J.

As a member of information-sharing groups such as RH-ISAC, I can’t emphasize how strong the return of value is for being able to collaborate with our peers openly and transparently. We all face the same challenges and are usually targeted by the same or similar threat actors. Being able to attend working groups dedicated to sharing observable data or helping each other come up with solutions for challenges we are facing when it comes to securing endpoints or other focus areas. In conclusion, we must remember, as the adage goes, the attackers only need to be right once, while the defenders have to be right all the time. We cannot get things right without thorough collaboration between security teams and our IT peers. Building a strong security-driven culture throughout your IT environment, from the administrators through to the users, will lead to strong outcomes and greatly increase enterprise resilience.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.