3 ms·
I'd guess it's because the majority of corporate IT actually is not as secure as most companies think. In my own professional experience, and conversing with pe
by korethr 5y ago
I'd guess it's because the majority of corporate IT actually is not as secure as most companies think. In my own professional experience, and conversing with peers and friends who work infosec, the security profile of most companies is a hard exterior shell, with a deliciously juicy squishy center. These companies might think they're super secure. After all, they just bought a fancy new Data-loss-prevention appliance, and just passed a SOC2 audit, so this means they're secure, right? Nevermind that this expensive appliance is effecively MITM-ing all TLS within the company, and is running an unsupported version of Tomcat for its web-UI that must be on a publicly reachable IP in order for the service to work. Nevermind that mid-level IT were ordered to not mention to the auditor the different ways various security controls could be trivially bypassed by a high school student, not if they wanted to keep their jobs. Nevermind that Sales throws an absolute fit to the CEO every time IT tries to remove their exception to the password complexity requirements, forcing them to use a different password than incrementing the number at the end of "P@ssword57". Nevermind that IT was told to stop trying to set up network ACLs in Azure because restricting traffic between network segments is interfering with Dev's delivery velocity. I could keep going forever with examples from my own career or synthesized from my peer's war stories.
But with a hard shell and squishy center security posture, all it takes is one security event, and you're pwned. All it takes is one salesman to click on a phishing email, one data entry drone to get hit by a drive-by ad while watching YouTube during lunch break, one Internet-facing server to miss a security patch, etc. Once with a foothold, these ransomware gangs move with speed and thoroughness that comes of lots of practice. Depending on the size of the enterprise, and how well it is or is not segmented, compromise can spread from patient zero in days, if not hours.
It's not all doom and gloom. Seeing these events happen, or having the near-death experience of surviving a ransomware attack is (at least temporarily) lighting a fire under companies' asses to get their shit together, and start keeping their support contracts current. Detection and response tools are getting better. I know of a managed EDR solution that kills all connections except the control connection back to their security center and clears out the routing table so no new connections can be made. Then they call you.
But for every company that is taking steps to secure themselves against the current threat landscape, there are plenty more that are failing to do so, whether out of naivety or complacence.