Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

5/10/2019
10:00 AM
Todd Weller
Todd Weller
Commentary
50%
50%

How We Collectively Can Improve Cyber Resilience

Three steps you can take, based on Department of Homeland Security priorities.

At the 2019 RSA Conference earlier this year, Chris Krebs, director of the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA), outlined several key priorities the agency is focused on for protecting US critical infrastructure. The US government is at the forefront when it comes to cybersecurity trends, so being aware of its focus can help private sector organizations improve cyber situational awareness and reduce risk.

Protecting Networks and Data from Nation-State Actors
CISA watches the usual suspects: Russia, China, Iran, and North Korea. Its key focus here is supply chain risk and minimizing the government's attack surface by keeping what it views to be risky vendors' equipment and applications out of US critical infrastructure networks.

In 2018, the US government banned technology from Russia-based Kaspersky Labs. With a heavy focus on China and 5G, it is now heavily focused on Huawei. Overall, the government is concerned that technology equipment from perceived risky foreign vendors could be used for malicious purposes.

Another area of focus is foreign VPN applications and, specifically, China-based applications from Dolphin, Opera, and Yandex.

Collective Cyber Defense
Krebs also discussed the importance of "collective cyber defense." A key issue here is that we can't fight the cyber battle alone. He indicated that multiple stakeholders have some piece of information about what's going on — whether that's a specific threat; tactics, techniques, and procedures; and/or vulnerabilities. It is critical that threat information is shared in a timely and practical way, and it's hard to get the maximum effect if this information is sitting in a limited number of hands.

On a broad basis, with collective cyber defense, CISA is refining its Automated Indicator Sharing (AIS) program to include more context and specificity in order to provide more value-added threat intelligence to the private sector. 

Election security is another area in which CISA is facilitating collective defense. CISA facilitated the signing up over 1,400 local jurisdictions to the recently formed Elections Infrastructure ISAC in just a nine-month period. CISA also facilitated the deployment of intrusion detection and prevention sensors, with these now covering 90% of elections infrastructure (based on votes cast), up from 32% in 2016.

Key Takeaways
Based on CISA's focus, there are three key things that private sector organizations can do to improve their cyber operations:

1. Increase your focus on supply chain and third-party risk. Third-party risk is a key area in security, and many large security organizations have established dedicated organizations in this area. All organizations should make moves to assess and manage this risk. This includes risks related to technology platforms that are powering your business as well as risks related to the various third-party entities with which you do business.

2. Revisit some basics regarding attack surface reduction. One easy step is to limit the use of technology from "questionable" vendors. Revisit the "who" and "what" is on your network and "whether" they should be on there. For example, if you aren't doing business with Russia, don't allow traffic from Russia on your network. Of course, given the global nature of business and computing, that's not that easy for many companies, but advanced filtering capabilities like dynamic whitelisting can allow you to block traffic from a country by default while allowing access from trusted sources, such as Office 365, Amazon Web Services, content delivery networks, etc.

3. Expand your usage of threat intelligence and information sharing to benefit from collective defense.Today's cyber threat environment requires a broader view of attacker activity than any one entity or cybersecurity vendor can provide. Expanding your use of threat intelligence can improve your cyber situational awareness and reduce risk. Easy steps here range from incorporating high-quality open source threat intelligence sources to joining DHS's AIS program to consuming and sharing threat information with industry peers through sharing communities (information-sharing and analysis centers and organizations).

Related Content:

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

Todd Weller, Chief Strategy Officer at Bandura Cyber, works with organizations of all sizes to improve their ability to use, operationalize, and take action with threat intelligence.  He brings over 20 years of cybersecurity industry experience with a unique blend ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 10/30/2020
6 Ways Passwords Fail Basic Security Tests
Curtis Franklin Jr., Senior Editor at Dark Reading,  10/28/2020
'Act of War' Clause Could Nix Cyber Insurance Payouts
Robert Lemos, Contributing Writer,  10/29/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How to Measure and Reduce Cybersecurity Risk in Your Organization
In this Tech Digest, we examine the difficult practice of measuring cyber-risk that has long been an elusive target for enterprises. Download it today!
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-27652
PUBLISHED: 2020-10-29
Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
CVE-2020-27653
PUBLISHED: 2020-10-29
Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
CVE-2020-27654
PUBLISHED: 2020-10-29
Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands via port (1) 7786/tcp or (2) 7787/tcp.
CVE-2020-27655
PUBLISHED: 2020-10-29
Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via inbound QuickConnect traffic.
CVE-2020-27656
PUBLISHED: 2020-10-29
Cleartext transmission of sensitive information vulnerability in DDNS in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via unspecified vectors.