Categories: Newsletter

Networking Monitoring News – Apr 2016

Business Disruption

There seems to be a shift in attack methodology. Years ago, attackers wanted it known that they hacked your company. It was a feather in their cap. The last few years we have been dealing with low and slow attacks with hackers trying to remain hidden and maintain access for as long as possible so they could steal as much intellectual property as possible. It appears now that attackers are moving back to making their hacks very public. The main difference now is that they are motivated by money, not the recognition.

Going public with a hack forces a company to react quickly and ups the attacker’s chances of getting paid money or worse, ruining your reputation. Ransomware is here and unfortunately it is getting more sophisticated. Make sure you have solid backups of your data and also make sure you have copies that are offline. We have seen attackers delete network attached storage backup data in an effort to keep companies down if no ransom is paid.

Storing data with security in mind

Most of us have network attached storage or file servers with disk arrays. When we want to save a file, we create a folder or use an existing one that resides on these devices. We click save and forget all about it. We need to ask questions about the data that we are storing, who has access? Is this access read access only or can they change files? Who can delete these files? A great many of us simply have folders with the permissions EVERYONE Full Access. Most of us have all our data organized neatly together so people can easily find what they need.

When attackers steal data, we need to make their job harder. Segmenting data and setting proper permissions works to limit some of the damage done if you do become a victim and also forces attackers to work harder (make more noise on the network) which often enables your administrators and security team to find them. The days of simply having a firewall and anti-virus are over. Attackers have beaten these defenses years ago. Protection is key, detection is a must. As companies, we must have network and system monitoring systems in place.

You may have heard about the recent attack on Panama law firm Mossack Fonseca, where 2.6 Terabytes of data was stolen. A whopping 11.5 million documents!

Ron Samson

Share
Published by
Ron Samson

Recent Posts

SIEM Management Services: When Log Collection Becomes Too Expensive to Operate Internally

Turn SIEM logs into faster response with managed SOC services—optimize telemetry, tune detections and gain…

2 weeks ago

Cloud Security Monitoring for AWS and Azure: What Your MSSP Should Actually Watch

Detect AWS and Azure identity abuse before it becomes a breach. Learn the signals, log…

57 years ago

Security Operations Metrics That Matter: KPIs for Risk Reduction, Response Speed, and Executive Reporting

Prove security risk reduction with KPIs for exposure aging, critical asset coverage, detection quality, and…

57 years ago

Microsoft 365 Security Monitoring: What SMBs Miss After Basic Configuration

Catch MFA and OAuth abuse in Microsoft 365 before attackers create forwarding rules or steal…

57 years ago

Managed Vulnerability Management: How to Turn Scanner Findings Into Remediation That Reduces Risk

Reduce measurable exposure with managed vulnerability management: validate findings, prioritize exploitable risk, verify fixes, and…

3 weeks ago

Co-Managed Security Operations: How Internal IT Teams Can Keep Control While Gaining 24/7 Coverage

Gain 24/7 security coverage without losing control. Learn how co-managed operations cut alert fatigue, share…

57 years ago