DECEMBER - 2018ENTERPRISE SECURITY| | 9understanding of typical day-to-day network behavior, such as how much data an employee downloads on a given workday, can a business develop a realistic perspective of its network operations and recognize early on when suspicious activity occurs. What we need right now is more threat intelligence, right?An example of a product area on which organizations have probably overspent (with disappointing results) is "threat intelligence" which happens to be one of the most overused, and poorly defined terms in our industry. A plethora of threat intelligence vendors have launched their wares on a now-weary market suffering from threat fatigue, mostly resulting from these products and services creating interesting, but not truly actionable, data. Still, threat intelligence should not be ignored. It just needs to be used properly, with appropriate expectations of what it can deliver. Network forensics, when coupled with real-time threat data, can alleviate threat intelligence fatigue -- a familiar complaint of CSOs/CISOs. With the sheer volume of potential threats, the broad range of possible attack vectors and the steady stream of new vulnerabilities, many enterprises find threat intelligence overwhelming and ineffective. For example, CenturyLink monitors roughly 1.3 billion security events impacting more than 104 million unique victims per day. The threatscape is only growing, but not every piece of intelligence is relevant to an individual business. To avoid being inundated with irrelevant information, business leaders should leverage their cybersecurity frameworks to pinpoint the threats most applicable to their industry, their business and their particular areas of concern. Where do we go from here?Security costs are spiraling out of control, in some cases reaching north of 20 to 30 percent of IT budgets today. As businesses compete on seemingly ever-diminishing margins for customers hungry for a differentiated experience, this simply isn't sustainable. But enterprises already have within their walls concrete and virtual the keys to reducing cybersecurity expenses and complexity, improving their security postures and improving the performance of their businesses. Every tactical decision made in fighting cyberattacks must be based on a security framework: starting with a basic one is better than nothing. From there, moving on to new and revolutionary technologies, such as next-generation firewalls, threat intelligence, deception techniques, mission-oriented resilient clouds (MRCs), and so on, will become far more effective and manageable. It's important to note: the foregoing is not meant to be a comprehensive list of what organizations should do. Rather, it is meant to encourage a governance-oriented approach and frame of mind when faced with building a viable cybersecurity program. Frameworks are built over time, and they should not be overly complex. For organizations that don't have one in place, wish to review the one they currently have or have no idea where to begin, an excellent place to start is with the National Institute of Standards and Technology's(NIST) cyber framework guidelines. This will offer far more in bolstering an organization's security posture than many leaders realize. ESFrameworks are built over time, and they should not be overly complex
<
Page 8 |
Page 10 >