Attackers only have to get it right once: Defenders 100% of the time!
๐๐ญ๐ญ๐๐๐ค๐๐ซ๐ฌ ๐จ๐ง๐ฅ๐ฒ ๐ก๐๐ฏ๐ ๐ญ๐จ ๐ ๐๐ญ ๐ข๐ญ ๐ซ๐ข๐ ๐ก๐ญ ๐จ๐ง๐๐, ๐๐๐๐๐ง๐๐๐ซ๐ฌ ๐ก๐๐ฏ๐ ๐ญ๐จ ๐ ๐๐ญ ๐ข๐ญ ๐ซ๐ข๐ ๐ก๐ญ 100% ๐จ๐ ๐ญ๐ก๐ ๐ญ๐ข๐ฆ๐!
Do defenders really have to get it right 100% of the time though? ๐ค
Iโve heard this phrase so often over the last decade and sometimes by people who should know better, ๐ข๐ญโ๐ฌ ๐ญ๐ข๐ฆ๐ ๐ญ๐จ ๐๐๐ฅ๐ฅ ๐๐ ๐จ๐ง ๐ญ๐ก๐ข๐ฌ! ๐ฉ
Its true attackers do have the element of surprise to a certain extent and can attack at any time using any means possible.ย But the reality is for the most part they are opportunists and if you have:
๐ต solid cyber security foundations
๐ต a layered approach to trip up an attacker
๐ต monitoring and alerting in place that is effective
๐ต automated blocking in place for the most nefarious activities
You will identify and stop most attacks from happening.ย If you have the ability to go further and use:
๐ข an assumed breach mindset
๐ข proactive threat hunting
๐ข incident response techniques (DFIR)
๐๐ก๐๐ง ๐ญ๐ก๐ ๐๐ญ๐ญ๐๐๐ค๐๐ซ ๐๐๐ง๐ง๐จ๐ญ ๐ก๐ข๐๐.ย In your own organisation think about the layered defences you already have.
As an example, you should have a perimeter email gateway with policies and controls in place to detect malware, spam, phishing emails.ย You should also have a next generation Firewall in place that performs further checks and prevents bad traffic from entering your enclave.ย You then might have network monitoring, intrusion prevention systems and finally endpoint detection and response.ย Hopefully some of these components are monitored with the right alerting in place to pick up those attacker behaviours as they make their way in and around your network.
Like any crime scene attackers will leave breadcrumbs that can be easily found if you know where to look.ย Getting those breadcrumbs into your security operations strategy mix and alerting mechanisms isnโt always easy, but will go a long way to shifting the balance back in you the defenders favour.
So you donโt have to be perfect because neither is your attacker, after all they are only human and can trigger anyone of the controls or alerts you have in place.ย The trick you must have though is to be smarter and outwit them.ย ๐ฏ๐ก๏ธ
๐๐ก๐๐ญ ๐๐จ ๐ฒ๐จ๐ฎ ๐ญ๐ก๐ข๐ง๐ค?