4 ms·
The article hits some spot on notes. The other missing piece is just how non-technical organizations can be out of their depth when it comes to the lifecycle of
by gorpomon 5y ago
The article hits some spot on notes. The other missing piece is just how non-technical organizations can be out of their depth when it comes to the lifecycle of IT hygiene, vulnerability management and training its staff to be security minded. A mid-size school district really has two options to secure itself: get the expertise in house, which could result in easily exploitable gaps, or spend non-trivial amount of budget working with endpoint protection vendors. I can imagine it's hard to explain to a rural school board that you either do this now, or pay majorly later.
Luckily for everyone, the endpoint protection market is evolving rapidly, and these solutions do work. Big Game Hunters aren't super humans, they exploit the things that on-the-ball IT teams and endpoint security vendors can easily fix: unpatched vulnerabilities, misconfigured endpoints and mismanaged credentials. Unluckily for everyone, the threat actors, for the reasons laid out in this article, are evolving too. And on top of that there's no shortage of vulnerabilities either.
I expect things to get worse before they get better. But do I expect Big Game Hunting to be a major problem in 15 - 20 years? I don't think so, because eventually every IT device in most any organization will have some type of cloud connected security baked into its cost. Do I think there's a likelihood it will be worse in 2-3 years, most likely yes.