| | DECEMBER - 2018ENTERPRISE SECURITY8IN MY OPINIONSecurity 101: Know Thyself Anyone looking for a sign to show the cybersecurity tide is turning, that the industry is starting to gain back the upper hand from cybercriminals, is going to have to wait abit longer. In the first few months of 2018, we've already seen nearly 700 global breaches impacting almost 1.5 billion data records, according to RiskBased Security's recent "Data Breach QuickView Report." While these statistics show a drop when compared to the same period in 2017, they should serve as a reminder most enterprises are still in need of a sound security strategy. Why, with all the technology and attention paid to cybersecurity, aren't we seeing the needle move in the industry's favor? Spending on cybersecurity technology increases every year. The industry is experiencing amazing growth, and it seems there's no end in sight. But, clearly, throwing money at the problem of growing data breaches is not the answer. The answer is: begin with basics of cybersecurity "blocking-and-tackling" and then spend money on appropriate technology controls. Let me explain.Sometimes, the truth hurts.For all the bold claims made by security vendors, the simple truth of cybersecurity is there is no failsafe; there is no vendor or product that can single-handedly protect a business from the universe of potential threats. But there is power in recognizing this truth because it can help enterprises take back the onus to understand their network environment and build the right security posture from the ground up. Organizations must come to the often harsh realization that technology must not lead, but instead follow, a strategy for dealing with cybersecurity risks. Industry observers and experts have seen a decline in the application of the basic, non-technical planning and governance elements that have been around for decades. This is a key reason why data breaches are increasing.In order to be strategic, rather than reactionary, cybersecurity tactics must be based on a sound approach. This is why the application of technology, alone, is not a strategy. Instead, the starting point should always be the development of a cybersecurity governance framework. By assessing an organization's data the valuable and/or sensitive data held, where it's kept, its age, who has access to it and how, and so on, the business can protect the confidentiality, integrity and availability of that data. With this knowledge, a framework of security controls and policies that includes risk assessments, asset classification, incident-response simulations and comprehensive training at all levels of the business can be developed. Once a guideline for treating risks is established, then and only then can proper technology controls be applied.Looking for risk in all the wrong placesMany organizations don't fully understand all the risks and threats they need to consider. When concerned with cyberthreats, enterprises tend to look outside the organization. However, insider threats are far more common than many companies believe and can be reduced significantly if the business employs basic network forensics, practical network segmentation, thoughtfully managed access controls and the monitoring and analysis of internal network traffic. Proper use of internal network and application data from firewalls, intrusion detection/intrusion prevention systems (IDS/IPS) and logs from network devices are powerful, often overlooked resources in evaluating the security of an organization. Only with a deep TACTICAL DECISIONS IN FIGHTING CYBERATTACKS MUST BE BASED ON A SECURITY FRAMEWORKBy Mike Benjamin, Senior Director of Threat Intelligence, CenturyLink
<
Page 7 |
Page 9 >