1

From blind spots to signal clarity - securing our hybrid world

 11 months ago
source link: https://itwire.com/business-it-news/security/from-blind-spots-to-signal-clarity-securing-our-hybrid-world-202305081920.html
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

Tuesday, 09 May 2023 05:18

From blind spots to signal clarity - securing our hybrid world

By David Sajoto

GUEST OPINION: We’re only as strong as our weakest link, so in a time when our attack surfaces are growing beyond what traditional security measures can keep up with, we must work to understand unknown threats and improve attack signal clarity.

CISOs and their SOC teams are working with a frustrating lack of visibility. As more incidents occur in the cloud, a prevention-first mindset can quickly become a “blindness tolerated” mindset — one that ultimately enables attackers. Signal clarity must be the priority. We can enhance clarity through the implementation of three pillars designed to address three unknowns.

Cloud becomes the norm, and security suffers

Following a few years of rapid change, Gartner finds worldwide end-user spending on public cloud services is forecast to grow 20.7% to total $591.8 billion in 2023, up from $490.3 billion in 2022 and higher than the 18.8% growth forecast for 2022. 

When it comes to Asia Pacific specifically, IDC finds cloud adoption is heavily impacting business growth and resilience. Companies throughout the region stated they plan to allocate around 34% of their overall budget to infrastructure-as-a-service platforms (IaaS) as they look to manage and control critical parts of their businesses without having to spend on data centres and physical servers.

When it comes to security, according to IBM Security researchers, 45% of breaches in 2021 happened in the cloud. While Vectra has found that 72% of security leaders fear an attacker has already infiltrated their environment, they lack the means to verify if or where this has happened.

What defines an unknown? Breaking down three blind spots

A top blind spot for organisations is unknown exposure. And with a constantly expanding attack surface, security teams now have more surfaces where unknowns exist. Governance, risk, and compliance (GRC) leaders often collaborate with cloud security posture management (CSPM) teams on vulnerability detection (misconfigurations, neglected updates, etc), but often this is not enough to prevent attackers from infiltrating the cloud. In fact, according to a 2021 survey by CheckPoint Software, 75% of successful cyber-attacks in the previous year exploited vulnerabilities that were more than two years old.

Next, unknown compromise. This is a worst-case scenario for CISOs, especially given the limitations of today’s point solutions to cover networks, endpoints and everything in between. The likes of IaaS, PaaS and SaaS can make a hybrid cloud landscape complex and difficult to secure. Siloed tools sending a snowstorm of false positives to security teams enable attackers to slip by unseen, especially as their tactics continue to advance.

The white noise problem also feeds into our third unknown — unknown threats. Even when a vulnerability has been discovered, it can be a difficult task to discover the infiltrator and its payload. Defenders and incident response teams can be slowed by point solutions, dashing from pane to pane trying to piece it all together. This can lead to late discovery as security teams sift through mountains of false positives, by which time attackers have already done their damage.

Tackling three primary challenges and barriers to clarity

Once these top three blind spots have been addressed, we must move towards signal clarity. First, our people need our support. We know that in Asia Pacific security leaders are struggling to hire skilled people or retrain as needed. This is leaving gaps in our expertise and more pressure on team members who are there. We need to support staff to tackle the escalation in threat incursions and their sophistication and to grasp the intricacies of cloud security.

The second challenge lies in our processes. When IBM Security tells us it takes organisations an average of 10 months to identify and contain a breach, we know we have to implement automation to effectively reduce manual tasks and improve workflow orchestration. And third, we must address our technology shortfalls, where blind SOCs scramble ineffectually to get a handle on their environments and the threats they face.

Three deliverables to improve attack signal clarity

To follow the theme of ‘three’, here are three deliverables that will ensure true Attack Signal Intelligence in a hybrid cloud. 

The first is attack coverage. SOC teams must consolidate their threat visibility and detection capabilities across their entire hybrid and multi-cloud attack surfaces - IaaS, PaaS, SaaS, identity, and networks. 

The second is signal clarity, which calls for SOC teams to know when an attack is taking place and the motions made by the attacker after they gain access — so teams can clearly prioritise it as a critical threat. This forms the heart of Attack Signal Intelligence and leverages some of the most advanced AI in the industry. It is this signal clarity that will allow investigators and hunters to get back to doing what they do best — investigating and hunting threats.

Finally, intelligent control means having the right context at your fingertips to speed up investigations, automate workflows, and target the response action to disrupt or contain an attack. Invest in the right tools, processes, and playbooks to boost SOC efficiency and effectiveness. 

Protecting our systems and teams

If we can’t improve clarity and visibility over our hybrid cloud environments, then what promises to be a huge benefit to our organisation could instead be our downfall. Thankfully, we can clean up our methods and give Attack Signal Intelligence its overdue turn at the wheel.

About David Sajoto – Vectra vice president Asia Pacific and Japan

David Sajoto is Vice President, Asia-Pacific and Japan (APJ). With over 20 years of experience, David has a proven track record of building and executing against business strategy and go-to-market plans, achieving aggressive revenue growth and profitability in the APJ region.

David is responsible for expanding Vectra’s operations and overall business growth in the APJ region. Before joining the company, David served as Vice President of APJ at ExtraHop, where he led strategic growth initiatives in the region and developed long-term strategies for regional field operations.

Read 119 times

Please join our community here and become a VIP.

Subscribe to ITWIRE UPDATE Newsletter here
JOIN our iTWireTV our YouTube Community here
BACK TO LATEST NEWS here

GARTNER MARKET GUIDE FOR NDR 2022

You probably know that we are big believers in Network Detection and Response (NDR).

Did you realise that Gartner also recommends that security teams prioritise NDR solutions to enhance their detection and response?

Picking the right NDR for your team and process can sometimes be the biggest challenge.

If you want to try out a Network Detection and Response tool, why not start with the best?

Vectra Network Detection and Response is the industry's most advanced AI-driven attack defence for identifying and stopping malicious tactics in your network without noise or the need for decryption.


Download the 2022 Gartner Market Guide for Network Detection and Response (NDR) for recommendations on how Network Detection and Response solutions can expand deeper into existing on-premises networks, and new cloud environments.

DOWNLOAD NOW!

PROMOTE YOUR WEBINAR ON ITWIRE

It's all about Webinars.

Marketing budgets are now focused on Webinars combined with Lead Generation.

If you wish to promote a Webinar we recommend at least a 3 to 4 week campaign prior to your event.

The iTWire campaign will include extensive adverts on our News Site itwire.com and prominent Newsletter promotion https://itwire.com/itwire-update.html and Promotional News & Editorial. Plus a video interview of the key speaker on iTWire TV https://www.youtube.com/c/iTWireTV/videos which will be used in Promotional Posts on the iTWire Home Page.

Now we are coming out of Lockdown iTWire will be focussed to assisting with your webinars and campaigns and assistance via part payments and extended terms, a Webinar Business Booster Pack and other supportive programs. We can also create your adverts and written content plus coordinate your video interview.

We look forward to discussing your campaign goals with you. Please click the button below.

MORE INFO HERE!


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK