How the Last Big Breach Will Help You Prepare for the Next Cyber Crisis

Sarah Armstrong-Smith, Chief Security Advisor at Microsoft, told UK Cyber ​​Week 2023 that security teams need to take advantage of past failures to make meaningful changes in how they approach incident response. said.

Armstrong-Smith says learning lessons from the past is essential to developing an effective cybersecurity incident response strategy.

According to Armstrong-Smith, the notion of a “black swan” event (so rare and unpredictable as to be unpredictable) is a “fallacy”. Such events included the 9/11 terrorist attacks and his COVID-19 pandemic, and there were many similar cases that authorities could have been prepared for. For example, a few years before COVID-19, he had two coronavirus outbreaks.

Based on the work she does for the UK Ministry of Defense (MoD), there is consensus that it is only a matter of time before a cyberattack on critical infrastructure causes a very large event leading to “multiple fatalities”. she answered the audience’s question.

This is due to the increasing penetration of attackers into production networks. This can cause far more disruption than access to IT networks. “We already have that capability. It’s only a matter of time,” he outlines Armstrong-Smith.

Armstrong-Smith said cybersecurity departments are typically not good at learning lessons from cyberattacks and incidents that have already happened. “It doesn’t matter how many times you see these incidents, they just keep happening over and over again,” she said.

It’s also important that they analyze public findings on major events and tell us why such seismic and often preventable situations occur, she explained. Some common themes have been identified that are very relevant to the world.

  • change in design or use – Over time, buildings, technology, and products will undergo numerous upgrades and changes while in use, but “do not tell people on the ground that these changes have occurred.” means that incident responders rely on the old plan if something goes wrong.
  • communication – Armstrong-Smith noted that it is often expected that all decisions must be communicated from top to bottom in an organization, which significantly delays action and loses the context of those decisions. Instead, teams on the ground need “specific and direct instructions.”
  • lack of empowerment – In any incident, first responders can vary greatly depending on the time and problem that occurred. Therefore, in situations where immediate decisions are required, there should be clear rules about “who is empowered and how much”.
  • strict plan – Many incident response plans are so rigid, Armstrong-Smith said, “As soon as you get off that plan, everyone panics and things go awry dramatically.” Therefore, organizations should establish a “critical path” and clearly distinguish between instructions and recommendations during an incident.

The key to effective incident response in cybersecurity is people and providing regular training that replicates real-world situations.

“You need real-time training for the real-time risks you’re trying to address,” added Armstrong-Smith.

Therefore, simulated training exercises should resemble as closely as possible previous cyber incidents or near misses against the organization. I’ve never seen a company approaching,” he said.

For example, in the event of a ransomware breach, organizations often believe that backups can be used to restore systems, she said. “That’s not how ransomware works,” she outlined Armstrong-Smith, because attackers often delete backups.

Only through realistic training exercises can security teams truly understand what they are trying to protect and why, she added. For example, it’s easy to think only of security’s role in protecting infrastructure and forget about the impact on people.

In a separate session on the first day of UK Cyber ​​Week 2023, Amanda Finch, CEO of the Chartered Institute for Information Security (CIISec), explained the recent research the agency has conducted in relation to training and development in this area. quoted.

Industry professionals said analysis, thinking and problem solving (57%) were the most important skills for working in cyber, rather than technical subjects (18%), followed by communication (24%). I was.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *