Agilant Solutions, Inc.

Are We Far Too Eager In Search of a Silver Bullet?

Written by Steven Forti, Chief Information Officer (CISO) | Jul 23, 2024 10:03:38 PM

In the world of security, we must stay one step ahead of our attackers. We are consistently reminded by experts and tragic events experienced by others. Ransomware, Malware, Trojans, and hostile code lurk around every corner. Thus, when a manufacturer demonstrates prowess and provides what many deem to be a single umbrella of protection, we jump on it. Checking all the default boxes because it will afford us the greatest level of protection. But at what cost?

Last week’s outage should serve as a cautionary tale that comes with "placing all our eggs in one basket." Crowdstrike is an excellent product. I am a big fan myself. But, has it ever been prudent to apply software updates in mass quantity before we’ve had a chance to review the outcome on production systems? In my 30 years of experience in the technology world, the answer is a resounding no. No, we haven’t.

But we are now. The question is why? Why are we migrating so far off the proverbial reservation in this context? The answer is becoming increasingly clear.  In a rapidly changing threat landscape, we feel we must. When the reality couldn’t be further from the truth.

And last week we paid the price for it.

Crowdstrike, or any other endpoint solution, should be one of many system controls aggregated to protect us. No single product should operate on a standalone level. Instead, there should be sound risk mitigation strategies. Whether we are doing this consciously or not, I have seen this happening firsthand on the ground.

Beyond The Silver Bullet

Due to many great organizations like Crowdstrike, we enjoy a variety of tools and bedrock principles. These tools and principles have evolved over decades of trial and error. We have learned how attacks begin, how they escalate, and what they need for success as they transition through each stage of their lifecycle.

The tools include Next-Generation Firewalls (NGFWs). NGFWs act like the "towering walls of Troy" at our perimeter. Configured with crafted rulesets that leverage the entire suite of tunable parameters the vendor makes available. Rules that account for the various ways attackers trick lesser configured systems into allowing reverse shells, desktops, and VPN connections through protocols never meant to facilitate such activities.

We have the tried and true principle of endpoint system hardening which removes many of the default values attackers often leverage to breach them. Our team has the principles of Zero trust where we limit every type of access, both ingress and egress, allowing only that which we are certain represents the least risk to our operations. 

We have network controls that come bundled in all modern, enterprise-class, devices which limit lateral movement in the event of single host compromise. And our team has robust monitoring solutions, which will provide early warning signs of an attack thus allowing us to disrupt the attack lifecycle before it reaches critical mass.

A Holistic Approach To Security

As we can see from these limited examples, we enjoy an extensive list of facilities within our war chest. Both in the form of product add-ons and performance enhancements. All of which come with the careful consideration of our existing investments.

So let’s start using them all together as compliments to one another instead of in silos. And, let's move forward confident that automatic updates to our endpoint systems can be delayed for several hours without fear of compromise. 

Otherwise, we may be setting ourselves up for another great denial service event of similar magnitude. That in itself runs contrary to our entire purpose as cyber security leaders.

This is exactly the type of overarching framework and synergy among various products and operations we are providing to our valued customers right now at Agilant Solutions, Inc.

Want to learn more about how Agilant can strengthen your cybersecurity defenses? Click here.