#InfosecurityEurope Case Study: Attack Surface Operations at Nationwide

As the UK’s largest building association, Nationwide has 18,000 users, 400 domains and 750 servers in its IT system. The business makes 25,000 technology changes and updates each year.

As financial services providers, society faces increasing cyber threats and the need to comply with industry-specific laws. As a result, organizations are experimenting with the use of new teams within cybersecurity, specifically to manage their attack surface.

According to David Boda, chief security and resilience officer at the Nationwide Building Society, this includes both external and internal risks. Society has a wide range of tools to manage its attack surface, but they wanted a single team to address the risks.

In his closing keynote at Infosecurity Europe 2023, he said, “Lead the threat, monitor your entire attack surface with dedicated perimeter resources, and proactively focus on what matters most to reduce your risk exposure.” It’s a matter of working,” he said. .

“We’re looking for what really moves the risk exposure dial, what drives change and delivers a real return on investment.”

Read more from Infosecurity Europe: Financial institutions building resilience in the face of growing cyber threats

Nationwide will provide the attack surface operations team with a “digital twin” of the organization. This takes data from security tools and creates a digital version of that technology.

“This allowed for more interactive visualizations, giving us a sense of how the assets fit together and how the data flowed,” said Boda. “This is very useful for mapping the attack surface and can also be useful during an incident.”

The new team will also perform a detailed review of society’s technology to identify areas where security can be improved.

In particular, Boda expects the new unit to generate a better return on investment from existing security spending by discovering security features that have shipped but not been implemented, for example, when upgrading applications and tools. increase.

Other team goals include prioritizing and executing remediation activities and implementing changes to help the Security Operations Center (SOC) incident response.

“As a result, the SOC’s job will be easier and the attacker’s job much harder,” Boda said.

Nationwide plans to launch a new team later this year.

Editorial image credit: monticello / Shutterstock.com

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *