Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

5/11/2018
10:30 AM
Connect Directly
LinkedIn
RSS
E-Mail vvv
100%
0%

The New Security Playbook: Get the Whole Team Involved

Smart cybersecurity teams are harnessing the power of human intelligence so employees take the right actions.

It's common to see the posters in airports, buses, and subways: "If you see something, say something." Over the years, thousands of people have tipped off the police to physical security risks. It's worked so well that New York City's Metropolitan Transportation Authority has launched nine generations of the ad campaign.

Now, smart cybersecurity teams are stealing a page from that playbook, harnessing the power of human intelligence to write a brand-new playbook for their organizations, training users to recognize cyberthreats and take the right actions. It's a collaborative approach to defense in depth, the yin to technology's yang, and a way to turn your users into a layer of protection.

Step 1: Drill Users in the Basics
Many companies tend to cover the security fundamentals intermittently, during new-hire orientation or security awareness month. That's hardly enough. Organizations need to educate users constantly.

Employees should know to verify links or attachments before clicking; it's the simplest way to avoid being infected with malware. If an email recipient knows the sender but wasn't expecting the attachment or link, he or she should contact the sender and ask about it. An ounce of inconvenience is worth a ton of pain.

Employees should learn to practice good cyber hygiene, starting with keeping the operating system and software applications current on any devices, in addition to downloading antivirus/anti-spyware software, configuring automatic updates, and securing their home Wi-Fi.

Before using e-commerce sites, employees should look for "HTTPS" in their browser's URL field. If they don't see these signs of encryption, they shouldn't enter logins or personal information. When an email, say from a user's bank, contains an e-commerce link, the user shouldn't click but instead manually enter the bank's URL.

Organizations should advise employees not to use public computers or Wi-Fi when they shop online, as public Wi-Fi is open and insecure. Also, employees should enable two-factor authentication when online shopping sites offer it.

Of course, security analysts already know these things, but plenty of users don't. That's why the first step is to drill them in the basics.

Step 2: Help Them Recognize Social Engineering
Social engineering comes in many flavors. Step 2 deals with good old-fashioned scams, such as someone in an airport coffee shop looking over your shoulder to steal your network login credentials.   

These days, most social engineering scams land in employees' in-boxes, as email is the preferred attack vector. With most breaches starting out as malicious emails, organizations need to train users to recognize the tactic.

One way to start: help employees be aware of the emotions scammers take advantage of. When users receive emails and are tempted to click, what are they feeling? The thrill of some promised reward? The fun of social sharing? The fear of missing instructions from HR?

The answer could be any of those emotions. One study revealed that phishing motivators are a rich mix of personal messages and business communications — in other words, the contents of a typical in-box.

Here's an example. An account payable specialist gets an urgent email that seems to come from a senior VP. The VP wants her to wire $100,000 to a vendor's account, ASAP. An untrained employee might authorize the transfer. An employee trained in email security would ask a few questions, starting with, "Do we really respond to fund transfer requests via email?"

The biggest companies in the world — along with smaller and midsized firms, government agencies, schools, and more — run formal training to help users recognize and report the latest tactics. Some organizations have "bounty" programs to give employees rewards, cash, or free swag for reporting a verified scam.

All social engineering targets human beings. That's why you need a strategy to harden your human assets.

Step 3: Help Users Help You Fight Malware
The easiest way to penetrate defenses is through employees. Conversely, employees are the last line of defense when technology fails, which happens all the time.

Imagine this subject line: "Free Coffee." Think it would work? It has, at many organizations. So has "Holiday Party Pics" or "Your Package Delivery." People are human. Unless they are trained to be aware of their emotions when reading an email, they'll take a break from work to click on something fun and potentially malicious.

Before the incident response team can identify which users received an email loaded with malware and mitigate the threat, they have to know about it. Someone within the organization — an employee with the benefit of proper security training — has to report the email.

The kind of anti-phishing training explained in step two is a solid way to proceed with step three as well. Companies that have run these programs for years create scenarios for social engineering and malware delivery alike.

It's kind of like in the real world, where employees face real threats. In the new security playbook, you need all of them to become field intelligence agents. To see something, report it, and join your security team.

Related Content:

John "Lex" Robinson has over 30 years' experience in information technology with a focus on value innovation, strategic planning, and program delivery. In addition, he has consulted and managed product and service delivery teams for both small businesses and global Fortune 20 ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Aviation Faces Increasing Cybersecurity Scrutiny
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/22/2019
Microsoft Tops Phishers' Favorite Brands as Facebook Spikes
Kelly Sheridan, Staff Editor, Dark Reading,  8/22/2019
Capital One Breach: What Security Teams Can Do Now
Dr. Richard Gold, Head of Security Engineering at Digital Shadows,  8/23/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-15540
PUBLISHED: 2019-08-25
filters/filter-cso/filter-stream.c in the CSO filter in libMirage 3.2.2 in CDemu does not validate the part size, triggering a heap-based buffer overflow that can lead to root access by a local Linux user.
CVE-2019-15538
PUBLISHED: 2019-08-25
An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a ...
CVE-2016-6154
PUBLISHED: 2019-08-23
The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect).
CVE-2019-5594
PUBLISHED: 2019-08-23
An Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in Fortinet FortiNAC 8.3.0 to 8.3.6 and 8.5.0 admin webUI may allow an unauthenticated attacker to perform a reflected XSS attack via the search field in the webUI.
CVE-2019-6695
PUBLISHED: 2019-08-23
Lack of root file system integrity checking in Fortinet FortiManager VM application images of all versions below 6.2.1 may allow an attacker to implant third-party programs by recreating the image through specific methods.