3 ms·
I don't think it's super helpful for most orgs to try (to stay ahead of NSO type orgs), honestly. You can't have a 100% secure computer, so you are already maki
by cloudsec9 6y ago
I don't think it's super helpful for most orgs to try (to stay ahead of NSO type orgs), honestly.
You can't have a 100% secure computer, so you are already making some compromises. And, by definition, a zero-day is something that you have no forewarning of.
I think MOST orgs don't have to worry about NSO or state-level actor attacks. Most orgs are far more susceptible to ransomware and phishing, and should focus first on those.
The best approach to mitigating Zero-days is _detection_, to be honest. Would your shop be able to detect files flowing out? Odd time access? Weird probes from a computer inside the network?
Security through obscurity is never a good solution. That means bespoke stuff that might be hard to work with, but doesn't necessarily improve your security posture.
You want to develop a deep defense with good detection and monitoring with review. That will help you not just with Zero days, but all security aspects.