THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Wednesday, December 21, 2022
The threat landscape is constantly evolving as cybercriminals are getting more sophisticated and it seems new cyber threats are arising daily.
FREMONT, CA:Due to the increasing sophistication of cybercriminals and what appears to be a daily emergence of new cyber threats, the security landscape is continuously changing. Businesses can't change the threat landscape as cyber defenders. What management can do is speculate on how that environment might neutralise a threat, how it might gain entry, how it would navigate the infrastructure, and what damage it might cause. To create strategies to defend it, businesses must have a precise map of our attack surface.
Attack surface management (ASM), which includes the continuing process of asset discovery and risk classification, has received a lot of attention lately. A comprehensive map of attack points is provided by ASM solutions, which provide a constantly updated image of the entire technology infrastructure and the level of protection. This is especially crucial in light of how intricate modern IT stacks are.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Forrester estimates that 37 per cent of the world's cloud data centres are located in the Asia Pacific, with major corporations making inroads in countries including New Zealand, Malaysia, Thailand, and Indonesia. IDC estimates that 57 per cent of small and medium-sized enterprises (SMBs) in the Asia Pacific excluding Japan (APEJ) will increase their spending on cloud apps and services by 31 per cent from the previous year and that this trend will continue through the year 2025. This widespread use of cloud computing in the area inevitably attracts cybercriminals who use it as a springboard for their nefarious schemes.
Organisations evaluate themselves using ASM, which simulates the perspective of an adversary. This method pushes decision-makers to think about where attackers will strike first, which is useful for prioritising maintenance, upgrades, patching, tool acquisition, and policy implementation. They must concentrate on external attack surface management (EASM) in the multi-cloud and hybrid environments where regional organisations currently find themselves since this is where the conflict is currently taking place. Every application, port, server, website, cloud, and container must be examined, evaluated, and given a treatment priority ranking.
EASM which is natively connected enables cybersecurity teams to quickly and easily view the environment, including on-premises assets and remote cloud regions. Even if companies operate in a flexible business environment with shadow IT and a continuously shifting roster of technology partners, service providers, and other third parties–who come and go–analysts will be able to identify assets and their weaknesses before attackers do. Businesses need to move past the era of segregated asset management. Before, everything might have been departmentalized, from endpoints to development projects. But now they must acknowledge that this empowers dangerous actors. Security teams have a thorough, contextual awareness of what each asset does, how it is configured, and which department or person is in charge of it to formally manage configuration management databases (CMDBs).
Unfortunately, many EASM solutions do not provide a proper picture of assets, making assessment, prioritisation, and remediation difficult. Instead of enabling competent resources to innovate and contribute value, this gap results in manual processes that are prone to error and imprison them in boring workflows. This may result in decreased job satisfaction and worse rates of cybersecurity talent retention. This decline in security employees is a problem for the company given the geographical shortage of such skills.
Organisations must take into account the employee experience while creating a successful cybersecurity team, just as they must do in all other jobs. The complete external attack surface must be visible to analysts and threat researchers. New assets must automatically notify them. They must be able to monitor changes to the assets. Additionally, workloads must be able to be monitored anywhere they are used, including on public clouds. Nothing should evade the vigilant eye of the security team, including shadow IT, IoT sensors, devices, inactive IP addresses, and more.
When externally facing assets are no longer necessary for business operations, security and IT can collaborate to decommission or reconfigure them using the appropriate EASM solution. Regardless of location or ownership, the finest EASM platforms instantly link assets with business functions. These data points assist analysts in connecting the dots between an asset with an external facing and sensitive data or crucial systems (as an attacker would).
EASM is essential to the management of digital assets. It facilitates discovery by doing away with the need for extensive, time-consuming surveys of assets stored on-site, in the cloud, at the residences of employees, and in the buildings of partners, subsidiaries, and suppliers. Through the presentation of an attack path by attackers on the open Internet and how this might result in the loss of crucial data, proper EASM even enables organisations to gain control over asset attribution.
EASM makes it possible to conduct an ongoing risk analysis. Security teams are equipped with useful information by learning the when and how of each asset's production. Monitoring arrangements enhance this information (for example, unsanctioned open ports, unapproved services or expired or expiring SSL certificates). Additionally, EASM systems can help security professionals discover potential vulnerabilities through automated light scans and take appropriate action before malicious actors can do so by integrating with sources like the linked device search engine Shodan.
The combination of EASM and CMDB provides real-time visibility of the complete stack, which is what today's cybersecurity experts need most. A previously hidden or uncontrolled asset becomes apparent, and risk mitigation advances significantly. Automated processes identify vulnerabilities at a large scale, simplifying the once-complex task of thorough research and asset-by-asset patching.
More in News