July 15, 2020

An effective Cybersecurity program?

An effective Cybersecurity program?

The ever-growing threats of cyberattacks have made every small and big enterprise spend a fortune on implementing a vigilant and resilient cybersecurity program. A popular cybercrime magazine Cyber Security Ventures predicted in June 2019 that the global cumulative cybersecurity spending of five years would exceed $ 1 trillion mark by 2021. However, if we look at the Mandiant Security Effectiveness Report for 2020, the numbers tell a different story. As per the report, 53% infiltrations and 68% ransomware attacks were unnoticed while 91% of the attacks did not even generate an alert. These numbers that we just mentioned raise a profoundly serious question about the effectiveness of our security defences.

Source of Infiltrations Ransomware and Attacks

Even though organizations are spending a significant portion of their budget on security, the return on investment seems to be negligible. As per the information compiled by the Identity Theft Resource Centre and the U.S. Department of Health and Human Services, nearly 3.2 million records were exposed in the first two quarters of 2020. The primary reason for this gigantic failure is the insanity of cybersecurity strategies, at least by the definition from Albert Einstein which states “the definition of insanity is doing the same thing over and over again and expecting different results.” People still follow the traditional approach to security while expecting vigilance and resilience. It is rightly said in our previous blog post that battling a fleet of cannons is not possible with swords and spears.

Security Operations Centre is a combination of people, process and technology which are tightly coupled to each other. An inefficiency or gap in any one of the three would collapse the entire security defence. A typical process flow of most security operations looks something like the diagram below:

A set of point products such as firewall, IDS/IPS, WAF, etc. ensure protection and technologies such as SIEM, Threat Intel and UEBA analyse and correlate the data collected by the point products to establish a detection mechanism. The analytics and correlation results are then consumed by the security analysts for decision making and an action is taken on the same set of point products. This entire workflow is driven by a set of processes implemented by the organization. However, with evolving threat vectors and increasing attack volume, this workflow tends to fail.

Though only 9% of attacks generate an alert, security analysts are suffering from alert fatigue. This implies that there is a significant disparity in configuration of alerts which fail to capture red flags while just adds to the noise in the system. At the same time, since only 26% of the alerts are investigated due to several other factors, there is a possibility that the other 74% may had some or may be many true positives as well which were overlooked.

These inefficiencies and gaps in each stage of security lifecycle from technology implementation to operations, process creation to establishment and resource onboarding to effective utilizations sums up to the overall failure of cybersecurity defence and as a result, we get poor to low return on investments made on security. All attempts to an effective cybersecurity program fail due the fundamental flaws in our security strategies and as they say, change is the only constant, same is required to increase the effectiveness of our cybersecurity programs.

Author: Amit Mishra

[sharethis-inline-buttons]

Sign up to receive our monthly Newsletter & Blogs

First Name

Last Name

Email*

Please verify your request*

SUBMIT

Recent Resources

Dive into our library of resources for expert insights, guides, and in-depth analysis on maximizing Uni5 Xposure’s capabilities
Enterprise security team reviewing connected exposure signals

AI Native SOC: Architecture, Workflows, and Governance

Learn how an AI native SOC connects normalized security data, analyst workflows, governance, and threat exposure metrics into one accountable operating model.
Read More
Enterprise security leaders reviewing risk based vulnerability management platform architecture

Risk Based Vulnerability Management Platform Guide

Learn how a risk based vulnerability management platform connects asset, threat, and remediation context, with enterprise buying criteria for better decisions.
Read More
Enterprise security team reviewing vulnerability assessment coverage

Vulnerability Assessment Tools: Enterprise Guide

Compare vulnerability assessment tools by coverage, integrations, prioritization, validation, and remediation workflow with an enterprise evaluation checklist.
Read More
Enterprise security team evaluating exposure management pathways

Tenable Competitors: An Enterprise Evaluation Guide

Compare tenable competitors across scanning, prioritization, validation, orchestration, and CTEM fit to choose an enterprise-ready exposure management platform.
Read More
Enterprise security team reviewing connected exposure and incident signals

What Is Rapid7? Products and Use Cases

What is Rapid7? See how its capabilities cover vulnerability management, attack-surface visibility, detection, response, and risk evaluation.
Read More
Enterprise security team reviewing threat intelligence and asset risk

Threat Intelligence Report: From Insight to Action

Learn how to assess a threat intelligence report, validate source and recency, map findings to assets, and turn credible risk into remediation work.
Read More

What’s new on Hive Pro?

Get through updates and upcoming events, and more directly in your inbox

Reduce real exposure. Not just vulnerability volume.