The main mission of any CISO is not to prevent breaches of their infrastructure, rather, it's to safeguard you organizations' sensitive data and identity. I've said many time in the past that there are no device breach notifications but there are plenty of data breach notification laws. There are many ways to protect data and identity like encryption, monitoring outbound traffic, increasing user awareness, multi-factor authentication. These are important things but they are a means to achieve a goal. Resilience is the key to a sound defensive strategy. Here are some thoughts.
- We play defense not offense. 95% of companies hire cybersecurity people to defend their company from cyberattacks. They don't hire them to attack other sites. That's what the remaining 5% do. However, to play good defense, one must know how to play good offense. In other words, a Blue Team should have strong Red Team skills.
- One must accept the fact that a breach will happen regardless of whatever controls are in place. The old defensive strategy of building a "wall" to keep the bad guys out has failed. While there are many variants of the now popular Zero Trust Network philosophy, there are 2 key points that must be in place:
- The network is hostile.
- Data and identity are the new borders
- The key to a successful defensive strategy is resilience not prevention. A sound resilience strategy is key to recovery.
Resilience
- find your sensitive data. Consolidate it into something like a data lake.
- Map where your sensitive data goes within your network borders as well as outside your borders.
- Backup this data lake by taking snapshots, doing old school incremental backups and store the backups offline in a read-only mode. For example, NetApp devices allow the creation of a read-only snapshot.
- Test your recovery processes frequently.
Protect and Proceed1. If assets are not well protected.2. If continued penetration could result in greatfinancial risk.3. If the possibility or willingness to prosecuteis not present.4. If user base is unknown.5. If users are unsophisticated and their work isvulnerable.6. If the site is vulnerable to lawsuits from users, e.g.,if their resources are undermined.Pursue and Prosecute1. If assets and systems are well protected.2. If good backups are available.3. If the risk to the assets is outweighed by thedisruption caused by the present and possibly futurepenetrations.4. If this is a concentrated attack occurring with greatfrequency and intensity.5. If the site has a natural attraction to intruders, andconsequently regularly attracts intruders.6. If the site is willing to incur the financial (or other)risk to assets by allowing the penetrator continue.7. If intruder access can be controlled.8. If the monitoring tools are sufficiently well-developedto make the pursuit worthwhile.9. If the support staff is sufficiently clever and knowledgableabout the operating system, related utilities, and systemsto make the pursuit worthwhile.10. If there is willingness on the part of management toprosecute.

