THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Mick Brons, Manager of Cyber Security Assurance, Southern CompanyMick Brons, Manager of Cyber Security Assurance, Southern Company T he past year has certainly seen its share of highprofile cybersecurity events. From the MOVEit file transfer tool hack to China's sophisticated compromise of Microsoft to Muddled Libra’s costly attack on MGM, attackers have kept the pressure on technology professionals. Every technology leader wants to keep their organization out of the headlines and avoid the adverse impacts of a cybersecurity breach. Those leaders should beware of deceptively attractive security vendor hype and focus instead on the boring daily discipline of a strong security architecture.
Security architecture is the risk-informed application of your security model of choice to your technology environments and solutions. Whether you prefer the layered approach in your defensive thinking (defense-in-depth) or an asset-centric approach (zero trust), your security architecture should feature multiple protective measures and detections that give your organization numerous opportunities to thwart attackers before they reach their objective. Enterprise-wide tools like a web application firewall, device-level tools like endpoint detection and response, logging configurations, and infrastructure tools like traditional firewalls each play a role. Apply greater effort to protect applications or processes of higher business criticality. Rather than believing that defenders must be right all the time but attackers only once, recognize that a well-architected environment requires attackers to be right repeatedly if they wish to do you significant harm.
Make it Easy to Know and do the Right Thing
Although experts and architects inside your security team may shape that architecture or perform targeted solution design reviews to get projects headed in the right direction, security architecture truly happens during implementation. Those 'build/configure’ steps are often performed by other technology professionals who do not report to the CISO, and the security vision needs to translate well into their language. That high-level design diagram may have looked exceptional in Visio, but are sensitive components protected at the networking layer as required? They will if your infrastructure or cloud operations teams are both aligned with your security architecture approach and have a straightforward way to execute. Do your identity provider conditional access settings match your company’s access policy? Complexity is the enemy here; in our well-intentioned effort to accommodate different user scenarios as business needs evolve, resulting convoluted Boolean statements can obscure loopholes a persistent attacker will exploit. Business, security, and identity operations teams will need to collaborate closely to ensure correct outcomes.
"Just As in Business Units Directly Responsible For Generating a Profit, Security Success Will Ultimately Come Down to Everyday Execution By Multiple Technology Teams"
Automated validation is the answer to dynamic complexity
Especially in a large and heterogeneous enterprise, the presence of numerous technologies with supporting teams requires continued effort to validate your architectural design assumptions and combat configuration drift. Invest the time to automate processes or tools that can confirm expected settings, the presence of security protections, and the efficacy of security operations center detections. Do your ransomware protections presume that certain protocols are disabled, specific tools are present, or tailored backup routines are run on a recurring basis? Automate those actions, automate the reporting that shows they are happening, and close gaps when you find them.
Execution, Execution, Execution
Just as in business units directly responsible for generating a profit, security success will ultimately come down to everyday execution by multiple technology teams. A solid security architecture relies on communicating a clear vision that is shared across technology, readily grasped by business units seeking to move faster or make smarter decisions, and consistently implemented in the trenches. Focus on these security architecture fundamentals to keep your security threats at bay and your company out of the news.