Categories: Newsletter

Networking Monitoring News – Apr 2016

Business Disruption

There seems to be a shift in attack methodology. Years ago, attackers wanted it known that they hacked your company. It was a feather in their cap. The last few years we have been dealing with low and slow attacks with hackers trying to remain hidden and maintain access for as long as possible so they could steal as much intellectual property as possible. It appears now that attackers are moving back to making their hacks very public. The main difference now is that they are motivated by money, not the recognition.

Going public with a hack forces a company to react quickly and ups the attacker’s chances of getting paid money or worse, ruining your reputation. Ransomware is here and unfortunately it is getting more sophisticated. Make sure you have solid backups of your data and also make sure you have copies that are offline. We have seen attackers delete network attached storage backup data in an effort to keep companies down if no ransom is paid.

Storing data with security in mind

Most of us have network attached storage or file servers with disk arrays. When we want to save a file, we create a folder or use an existing one that resides on these devices. We click save and forget all about it. We need to ask questions about the data that we are storing, who has access? Is this access read access only or can they change files? Who can delete these files? A great many of us simply have folders with the permissions EVERYONE Full Access. Most of us have all our data organized neatly together so people can easily find what they need.

When attackers steal data, we need to make their job harder. Segmenting data and setting proper permissions works to limit some of the damage done if you do become a victim and also forces attackers to work harder (make more noise on the network) which often enables your administrators and security team to find them. The days of simply having a firewall and anti-virus are over. Attackers have beaten these defenses years ago. Protection is key, detection is a must. As companies, we must have network and system monitoring systems in place.

You may have heard about the recent attack on Panama law firm Mossack Fonseca, where 2.6 Terabytes of data was stolen. A whopping 11.5 million documents!

Ron Samson

Share
Published by
Ron Samson

Recent Posts

EDR Alert Fatigue: Which Endpoint Alerts Need Human Investigation and Which Need Better Tuning

Cut EDR alert fatigue without creating blind spots. Learn to prioritize high-risk signals, automate enrichment,…

4 days ago

Third-Party Vendor Access Security: How to Monitor Remote Support Accounts and Reduce Supply Chain Risk

Secure third-party remote access with MFA, accountable owners and complete visibility—critical as vendors feature in…

57 years ago

PCI DSS 4.0.1 Security Monitoring: What Merchants Must Operationalize Beyond Annual Compliance

Turn PCI DSS 4.0.1 monitoring into faster payment threat response—master Requirements 10, 11 and 12,…

57 years ago

OT Security Monitoring for Manufacturers: How to Protect Plant Networks Without Disrupting Production

Protect plant uptime with passive OT security monitoring. Map legacy assets, baseline traffic, and detect…

57 years ago

Business Email Compromise Response: The First 24 Hours After a Microsoft 365 Account Takeover

Contain a Microsoft 365 BEC in 24 hours: revoke sessions, preserve evidence, stop payment fraud,…

57 years ago