life_support_heart_and_lung_machine

Companies are getting hacked with impunity because we’re not doing the basics. It’s not because we lack Threat Intelligence. It’s not because of APTs. It’s not because of China.

It’s because we’re failing at stand, walk, run. We’re stuck at the standing phase debating the intricacies of hurdles and long-jump. It’s our first day in Karate class and we’re trying on black belts. We’re a gaping chest wound, and people are showing up with smiles, kale, and yoga pamphlets.

If you have a friend, customer—whatever—that’s on infosec life support, here are the three things to have them focus on.

  1. Asset Control
  2. Patch Management
  3. Egress Traffic

1. Asset Control

You can’t defend what you don’t know exists.

2. Patch Management

If you’re not patched, patching is the priority.

3. Egress Traffic

Outbound traffic is a window to your compromised soul.

These are triage steps—the very basics in each category. The next few I’m less sure of the order of, and they depend more on your organization. But they look something like:

But don’t think about 4, 5, and 6. Think about 1, 2, and 3.

Stand, walk, run.

Notes

  1. Jeremiah Grossman got me thinking about this list with a tweet last week.
源链接

Hacking more

...