4 ms·
If you have paid any attention to cyber security... well anything in the last 5-10 years this should be expected? "Insider threats" are typically the one group
by dugite-code 2y ago
If you have paid any attention to cyber security... well anything in the last 5-10 years this should be expected?
"Insider threats" are typically the one group that any security firm can actually do anything about in an active manner. Every other threat group comes at you, not the other way around.
- hsdropout 2y agoAgreed. This is also a feature of Microsoft's Purview product: https://learn.microsoft.com/en-us/purview/insider-risk-management-configure https://learn.microsoft.com/en-us/purview/insider-risk-manag...
- TeMPOraL 2y agoIn other words: security firms are like drunkards looking for their lost keys under the nearest street light instead of where they lost them, because it's easier to see under the street light. Having paid attention to cyber security over the past decade, this tracks.
- deleted 2y ago[deleted]
- night862 2y agoNo, it is due to the game theoretic phenomenon called "The Attacker's Advantage" which is usually interpreted to simply mean "An attacker has to only succeed once, defenders must succeed every time." but in general refers to the strategic landscape of infosec. Frankly, the thought of "Actively Coming At" infosec threats is personally appalling. Feelings aside, you couldn't "actively" "come at" APT actors from the future with unknown techniques, and the way to "actively come at", so to speak, entire categories of "cyber threats" would be to fund detailed white box security testing on your IoT devices or VoIP handsets, for example. Much cheaper to oppress your workforce. At least that will shorten the checklist. Worst case scenario, you can catch the next wave of offshoring if you push it too far and they unionize.
- zdragnar 2y agoPretty much any security training will identify insiders, malicious or not, as a vector. That's the whole point behind phishing attacks against corporate employees. Back in the day of windows auto-playing CDs and USB files, dropping random official looking drives around the parking lot was a thing: https://www.wired.com/2011/06/the-dropped-drive-hack/ https://www.wired.com/2011/06/the-dropped-drive-hack/ Then you get into data exfiltration by employees who were bribed, etc.