Categories: Newsletter

Networking Monitoring News – May 2016

Threat Report

“Most organizations today rely on the walls and moats of yesteryear, thinking they are defending against catapults and cannons, while the attackers are instead using drones and highly targeted stealth technology.” HPE 2016 Cyber Risk Report is spot on. Firewalls and Antivirus are old technology. They just cannot do the job by themselves any longer. Unfortunately, this is all many of us have as far as network security is concerned.

The US Secret Service states in their report this year that 86% of organizations currently lack adequate network security capabilities. On average it took 146 days to discover there was a compromised computer/device on the network. Attacks will happen, this is the new norm. An attacker can take a few days to a week to gain access. If we now know attackers will get in, we must be able to detect it as fast as possible. A ClearNetwork monitoring device is a must.

As executives, we must gain insight as to which assets are most critical and valuable to an attacker. Knowing the enemy and what they will be looking to steal is a huge offensive advantage against cyber-crime. Find these assets and make sure they are protected and monitored.

Brute Force Remote Desktops

Attackers are using brute force attacks against your remote desktop servers to gain access to your network for reconnaissance. Once they gain access, they find where the data is and encrypt it. Since they have knowledge of your network now, they have a much stronger position at the negotiation table and will demand a much higher price to unencrypt your data. Best practice is to not put these servers directly on the internet. Tell users they need to VPN into the network first, then connect to their desktops.

Updates

If you haven’t already updated Flash Player and Microsoft Silverlight, you should do so as soon as possible. You will “significantly” minimize your risk of getting hit by the latest in ransomware threats once patches are applied.

Ron Samson

Share
Published by
Ron Samson

Recent Posts

SIEM Management Services: When Log Collection Becomes Too Expensive to Operate Internally

Turn SIEM logs into faster response with managed SOC services—optimize telemetry, tune detections and gain…

2 weeks ago

Cloud Security Monitoring for AWS and Azure: What Your MSSP Should Actually Watch

Detect AWS and Azure identity abuse before it becomes a breach. Learn the signals, log…

57 years ago

Security Operations Metrics That Matter: KPIs for Risk Reduction, Response Speed, and Executive Reporting

Prove security risk reduction with KPIs for exposure aging, critical asset coverage, detection quality, and…

57 years ago

Microsoft 365 Security Monitoring: What SMBs Miss After Basic Configuration

Catch MFA and OAuth abuse in Microsoft 365 before attackers create forwarding rules or steal…

57 years ago

Managed Vulnerability Management: How to Turn Scanner Findings Into Remediation That Reduces Risk

Reduce measurable exposure with managed vulnerability management: validate findings, prioritize exploitable risk, verify fixes, and…

3 weeks ago

Co-Managed Security Operations: How Internal IT Teams Can Keep Control While Gaining 24/7 Coverage

Gain 24/7 security coverage without losing control. Learn how co-managed operations cut alert fatigue, share…

57 years ago