Todayโs article is going to focus on the overall problem with Cyber Security, rather the major lack of common sense where it should be for modern age digital defenders. A lot of what Iโm going to say in this article might be obvious to some, but rest assured, ITโS NOT OBVIOUS to MANY that work in Cyber. If it were, then I myself, as well as well established professionals wouldnโt be โwinkingโ or hinting at this time and time and time again.
๐ Article ๐ Glossary ๐ Catalog ๐ Home ๐ Search ModeTodayโs article is going to focus on the overall problem with Cyber Security, rather the major lack of common sense where it should be for modern age digital defenders. A lot of what Iโm going to say in this article might be obvious to some, but rest assured, ITโS NOT OBVIOUS to MANY that work in Cyber. If it were, then I myself, as well as well established professionals wouldnโt be โwinkingโ or hinting at this time and time and time again.
We have all the means and tools available, even the information which is publicly available and FREE, however, what if that were the very problem itself and WHY we have such BAD Cyber Security practices to date.
Keep reading and youโll find out exactly what I mean by that.
I'll be discussing the following topics in order: ๐ Public Disclosures Hurt Us ๐ Lack of Emphasis on Security ๐ Lack of Security Talent You can click on any of the topics to simply check that one out if it interests you! NOTE: Articles are read from LEFT to RIGHT via 2 columns! Read the first column all the way down and then move to the next one!
Here's a quick run down on all the main links that are in the article in case you want to check them out first. ๐ LinkedIn Version
Ever see the latest news on MAJOR security breaches or recent white papers from security researches that get publicly disclosed online? Yeah, THIS, although that information is nice, is part of the problem as to WHY threat actors are constantly able to adapt and stay two steps ahead of us. It also gives threat actors INGENIOUS ideas on how to piggyback off of recent breaches and evolve them, sharing that information with each other. Donโt even get me started on โliving off the landโ stuff that becomes possible when we โtalkโ too much.
When you disclose PUBLICLY HOW certain breaches took place or how to prevent them on a technical level, youโre telling threat actors STEP BY STEP on HOW to breach your security systems. It's even worse since we have DEDICATED platforms that help fill threat actors on all this juicy information.
A good example of what I mean by this, and this is no insult to anyone, would be the beloved Wiz. As much as I LOVE Wiz and a lot of other Security focused places that disclose Security research information to everyone, time and time again Iโve been able to get full in depth information on recent exploit techniques, where, if I were a threat actor, could allow me to devise said exploits against other infrastructures.
Even without places like Wiz that do all of this, itโs still mandated by law that breach disclosure occurs.
Nowโฆ. how to handle disclosures? Wellโฆ to be rather bluntโฆ. Sum it up as quick as possible. No need for a diagram and all that. I know this sounds bizarre, but hear me out. Itโs the job of SECURITY professionals to break down and study HOW a breach took place with just an overall summary and devise mechanisms of their own in order to defend against it, even apply needed patches if necessary for all systems. This of course would REQUIRE companies to have a DEDICATED budget for proper Cyber Security procedures which most still sleep on.
Now, what do I mean by โsumming it up as quickly as possibleโ? Ever seen a CVE that just dropped and you tried replicating it but have no idea how? THIS is what I mean by that. The CVE simply explains HOW the breach occurs without full in depth information on to the tee things, leaving it up to Security professionals to test and check against it on their own and figure out how to defend against it, OR, if youโre a threat actor, figure out how to replicate the exploit (which threat actors arenโt too keen on sharing how to do since they profit off of selling that information).
Now, this isnโt a shocker to most folks that work in Cyber Security, but security is almost NEVER in mind for most business infrastructures
๐When developing complex systems and software
๐Budgets
๐Competent teams
๐Incident response
๐Security Audits
๐Penetration tests
And the list goes on.
Now this might rub a few the wrong way.. BUTโฆ. WE DO HAVE SHORTAGE OF CYBER SECURITY TALENT. Not by numbers, NO, there is plenty of that. The PROBLEM is we donโt have the RIGHT talent in the RIGHT places. We have people that SHOULD be in Cyber, NOT in Cyber, and people that shouldn't in Cyber if that makes sense.
Cyber Security isnโt a game, thereโs A LOT on the line should an infrastructure FAIL to prevent a breach: reputational value, financial assets, and of course overall jobs that are on the line that can be impacted should financial assets be impacted from security breaches. Not even just the company itself, but the very end user data hosted in them puts said individuals at risk which can lead to stuff like identity theft and a lot more.
A consistent trend, as disappointed as I am to say thisโฆ Is we have folks in Cyber that donโt โunderstandโ security. Most of them know how to regurgitate what they โknowโ on Security related subject matters, maybe even use a good chunk of the tools to defend, even attack if possible (if they even, since most pentests are being automated now a days), but this doesnโt mean they โunderstandโ security.
A lot of this is due to the movement of not having to be โtechnicalโ to work in Cyber or over prioritization on โsoft skillsโ which leads to a lot of folks that arenโt technical enough to apply basic to advanced Security frameworks/procedures, all of which is more prevalent when dealing with leadership roles like CISOโs for example. This leads to MANY recurring situations where security breaches, basic ones that can EASILY be prevented.
How to find the right talent? We already have. The problem is Cyber Security has become a celebrity thing where only the cool kids get into the club. Itโs become less about security and more about ego.
Itโs also problematic that budgets simply donโt โexistโ for said talent if that makes sense, rather, a refusal to make them.
If you enjoyed this post give it a thumbs up! Iโll be keeping track of whose reacting from now on as there is a โspecialโ reason for it. Just know the more you support my content the more there is in stored!
- The Hacker Who Laughs ๐ธ๐ธ๐๐ธ๐ธ