3 ms·
So fluff about logs being deleted to do their security sales pitch. No stance, just noting what it is. Main sales pitch here: “We saw this happen in two incid
by theultdev 3y ago
So fluff about logs being deleted to do their security sales pitch. No stance, just noting what it is.
Main sales pitch here:
“We saw this happen in two incidents of Cuba ransomware. One company (Company A) had continuous monitoring in place with MDR, so we were able to spot the malicious activity and halt the attack within hours to prevent any data from being stolen.
“Another company (Company B) didn’t have this friction; they didn’t spot the attack until a few weeks after initial access and after Cuba had already successfully exfiltrated 75 gigabytes of sensitive data. They then called in our IR team, and a month later, they were still trying to get back to business as usual.”