Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

10/20/2017
11:00 AM
Raj Rajamani
Raj Rajamani
Commentary
Connect Directly
LinkedIn
RSS
E-Mail vvv
100%
0%

How to Talk to the C-Suite about Malware Trends

There is no simple answer to the question 'Are we protected against the latest brand-name malware attack?' But there is a smart one.

WannaCry scared the world with its massive disruption. NotPetya reminded everyone why they can't forget about exploits after the first time they are used. Mirai irritated consumers for a full day with record-breaking distributed denial-of-service levels from its infected botnet. The good news is that headlines from all of these attacks caught the attention of executives who suddenly started asking if they were vulnerable to these attacks. The bad news? They started asking the wrong questions.

Security is not a one-and-done project; it is a constant battle against creative hackers evolving new and improved threats. But top executives and board members are still learning about security practices, so when they stop at their CISO's desk they only know to ask "Are we protected against WannaCry?"

The only job-preserving answer to that question is "Yes," but that omits so many other factors that leave the executive with a false sense of security. A smart CISO can take advantage of the executive's attention to explain how blocking specific malware variants is only a stopgap measure.

The reality is that malware changes so rapidly that blocking any single variant will provide only a day or two of relief before it comes back just different enough to slip through those defenses again. SentinelOne's Enterprise Risk Index released this April found that less than 50% of malware detected is included in malware repositories. This shows how quickly new threats come and go and the sheer volume of threats to monitor.

Instead, companies need to focus on the underlying vulnerabilities in their systems that leave them open to these kinds of attacks. That could involve finding a SQL injection vulnerability in their databases or reworking a poorly configured network that allows malware to jump from insecure Internet of Things devices to mission-critical systems.

Navigating Internal Team Dynamics
The job of the CISO is to understand these vulnerabilities and to have the knowledge required to close them. Despite the skills shortages that have made finding experienced cybersecurity professionals difficult, most companies have found very competent people to fill these roles. These vulnerabilities remain when CISOs meet roadblocks imposed by the limited resources they have available and by their inability to convince other teams of the necessity of these changes.

Many technology departments resist change. As recently as five years ago, many antivirus users failed to update signature lists on a weekly basis. When it comes to more effective changes such as software updates, IT teams can be even slower. That is not to say they do not sometimes have good reasons; the longer a legacy system is in use, the harder it is to be sure it is compatible with the latest software updates. CISOs may know that these updates are part of the framework that protect vital corporate systems, but without executive backing they don't have the power to force IT teams to keep a regular patching schedule.

The Shifting Malware Landscape
Today, hackers no longer need to invest time in targeted attacks because there are a vast number of unsecured, vulnerable systems that are accessible to them. Instead, they have adopted a "spray and pray" mentality. The end result is that every Internet-connected device —router, server, mobile phone, computer, coffee maker — is under constant threat from constantly evolving malware issued by hackers who don't really care who they infect, as long as it is profitable.

This constant bombardment across all possible attack vectors means that CISOs must be even more vigilant than ever in identifying and closing potential vulnerabilities, not just relying on standardized filters to catch malware as it tries to infect the network. It may seem like a hopeless predicament fighting a never-ending battle against an ever-growing list of unknowns. But the upside is that the executive attention these branded malware attacks have captured brings a new opportunity.

A savvy CISO will take advantage of that momentary attention to say, "Yes, we are protected against WannaCry… today. But we have some vulnerabilities in our systems that need immediate attention." Then, she can impart the expertise she is being paid to have, and convince the executive of the need for a real change in protecting the underlying vectors that leave companies exposed.

Related Content:

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity agenda here.

Raj Rajamani is the vice president of product management at SentinelOne. He joined SentinelOne from Cylance, where he was part of the original executive team. Raj has been developing security solutions for over a decade through his time at McAfee and Solidcore. View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
AI Is Everywhere, but Don't Ignore the Basics
Howie Xu, Vice President of AI and Machine Learning at Zscaler,  9/10/2019
Fed Kaspersky Ban Made Permanent by New Rules
Dark Reading Staff 9/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-4147
PUBLISHED: 2019-09-16
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 158413.
CVE-2019-5481
PUBLISHED: 2019-09-16
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
CVE-2019-5482
PUBLISHED: 2019-09-16
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
CVE-2019-15741
PUBLISHED: 2019-09-16
An issue was discovered in GitLab Omnibus 7.4 through 12.2.1. An unsafe interaction with logrotate could result in a privilege escalation
CVE-2019-16370
PUBLISHED: 2019-09-16
The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.