Useful tips to prepare for cyber-threats

By Paul Rummery, Securenet Consulting

Cyber Theats
Unauthorised Access
Web Application Vulnerability
OS and Virtual Machine Vulnerabilities Endpoint and Network Attacks 

Data Leakage

...the threat landscape is vast. Attackers will exploit vulnerabilities from a number of sources across your infrastructure. Some useful tips on where to plug these gaps;




Identity and Access Policies - There is a need to monitor user data and resource access, even the activities of everyone who has privileged levels of access to the organisation's systems and data in order to discover internal threats. System, database, network and user administrators have privileged levels of access to systems and data. Outsourcers and other service providers may also have this level of access. There is the potential for availability and security risk due to unauthorised system changes. There are also risks associated with inappropriate data access by privileged users. A targeted attack might succeed in compromising a privileged account, which could then be used to directly gain access to critical or sensitive data.


Data Access Monitoring - Because the ultimate goal of many targeted attacks is the theft of data, it makes sense to apply security monitoring to data access. Data loss prevention (DLP) technology provides a means for organisations to identify sensitive data and monitor its access and movement. Integration of DLP alerts into the SIEM would provide data context to security monitoring.


Application Activity Monitoring - The application layer is a popular attack path for a number of reasons. Web application vulnerabilities can be discovered and exploited from the outside, and the vulnerabilities tend to exist for a long time (due to long remediation cycles). Application credentials are easy to steal from users that are victims of spear phishing attacks or from users that access corporate applications from unmanaged (and corrupted) privately owned devices.

Securenet provide assessment services to report identified vulnerabilities across your network infrastructure (cloud, web applications, network gateway, core systems, mobile users and end points). We can then advise and provide the technical expertise to remediate known issues based on your existing technology and recommend leading edge solutions available in the market, designed to mitigate unknown threats, alert and action on suspicious behaviours.

---------------------------------------------------------------------------------------------------------------

WANT TO LEARN MORE? Contact Securenet Consulting