enterprisesecuritymag

ENTERPRISE SECURITY| | 9MAY - 2022good inventory could have quickly identified whether or not Orion was installed, which version, and the specific systems that may be impacted. Network Traffic MonitoringNetwork traffic monitoring and intrusion detection/prevention capabilities can identify outbound beaconing or command-and-control connections that are used to exploit compromised software and systems. Network segmentation and limiting internal server traffic to the Internet will assist in minimizing the impact of a supply chain attack, along with other malicious activity. Companies that have mature vulnerability management programs can build response playbooks that align with their zero-day response and mitigation playbooks. Malicious software introduced by a supply chain attack may follow similar steps;· Determining the scope of the concern, which is enabled through good inventories;· Applying patches, fixes, or isolating impacted systems. · Establishing playbooks and a process to receive updates or signatures for security tools, including vulnerability scanners, anti-virus and end-point detection tools, and network security tools. Early detection, along with a well-thought out and tested response plan,will help to minimize the overall impact of a security incident. Study Your Playbook, Then Practice, Practice, PracticeA documented and tested disaster recovery plan has never been more important. The Kaseya breach demonstrates the real possibility of ransomware bypassing all protective controls that are in place. Companies need to assume they are not immune and operate as though a breach is a matter of "when" not "if." To be prepared, assume a realistic worst-case scenario. Also, regularly and systematically review and update your disaster recovery plans. Running simulations can help key team members understand their role and help organizations move more quickly through the process when time is of the essence. Failing to Plan is Planning to Fail. Benjamin Franklin knew his stuff when he defined the importance of establishing a plan and response strategy. Planning your incidence response is not unlike any other project you assume. Consider it project management ­ just without a defined implementation date. Every plan you take on requires initiating the project, planning the milestones, executing the punch list of activities, monitoring and controlling, and ultimately closing the project. The difference is that incidence response planning is never complete. As you review it and assess new technology, staff expertise, and best practices, it will need to be updated. Along the way, expect supply chain attacks to increase in frequency and impact. Commit now to evaluating your processes, procedures, and technologies in order to identify gaps and opportunities to improve. The threat landscape is ­ and will continue to be ­ dynamic. Supply chain attacks have proven to be effective and will become more sophisticated, especially against the unprepared. Count on cybercriminals modifying and improving their tactics based on their successes and failures. You should do the same. ESPaul MocarskiThe plan must be detailed and actionable in order to serve as a playbook on how to respond to these types of incidents
< Page 8 | Page 10 >