Sunday, March 7, 2021
  • Setup menu at Appearance » Menus and assign menu to Top Bar Navigation
Advertisement
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
No Result
View All Result
Home Internet Privacy

In the Wake of the SolarWinds Hack, Here’s How Businesses Should Respond

January 27, 2021
in Internet Privacy
In the Wake of the SolarWinds Hack, Here’s How Businesses Should Respond
585
SHARES
3.3k
VIEWS
Share on FacebookShare on Twitter

Throughout 2020, businesses, in general, have had their hands full with IT challenges. They had to rush to accommodate a sudden shift to remote work. Then they had to navigate a rapid adoption of automation technologies.

And as the year came to a close, more businesses began trying to assemble the safety infrastructure required to return to some semblance of normal in 2021.

You might also like

Researchers Find 3 New Malware Strains Used by SolarWinds Hackers

Bug in Apple’s Find My Feature Could’ve Exposed Users’ Location Histories

Mazafaka — Elite Hacking and Cybercrime Forum — Got Hacked!

But at the end of the year, news of a massive breach of IT monitoring software vendor SolarWinds introduced a new complication – the possibility of a wave of secondary data breaches and cyber-attacks. And because SolarWinds’ products have a presence in so many business networks, the size of the threat is massive.

So far, though, most of the attention is getting paid to large enterprises like Microsoft and Cisco (and the US Government), who were the primary target of the SolarWinds breach. What nobody’s talking about is the rest of the 18,000 or so SolarWinds clients who may have been affected. For them, the clock is ticking to try and assess their risk of attack and to take steps to protect themselves.

And because a number of the affected businesses don’t have the resources of the big guys, that’s a tall order right now.

So, the best many companies can do to take action right now is to make their networks a bit of a harder target – or at least to minimize their chances of suffering a major breach. Here’s how:

Begin with Basic Security Steps

The first thing businesses should do is make certain that their networks are as internally secure as possible. That means reconfiguring network assets to be as isolated as possible.

A good place to start is to make sure that any major business data lakes follow all security best practices and remain operationally separate from one another. Doing so can limit data exfiltration if unauthorized users gain access due to a security breach.

But that’s just the beginning. The next step is to segment network hardware into logical security VLANS and erect firewall barriers to prevent communications between them (where possible). Then, review the security settings of each group and make adjustments where necessary. Even hardening VoIP systems are worth doing, as you never know what part of a network will be used as an entry point for a broader attack.

And last but not least, review employee security practices and procedures. This is especially important after the rushed rollout of work-from-home policies. Make it a point to see that every employee is operating according to the established security standards and hasn’t picked up any poor operational security habits. For example, did anyone start using a VPN for free, believing they were improving their home network security?

If so, they need to stop and receive training to make better security judgments while they’re still working remotely.

Conduct a Limited Security Audit

One of the problems that businesses confront when trying to re-secure after a possible network breach is that there’s no easy way to tell what – if anything – the attackers changed after gaining access. To be certain, a lengthy and complex forensic examination is the only real option. But that can take months and can cost a fortune to conduct. For smaller businesses that aren’t even certain that a breach even happened to them, though, there’s a better approach.

It’s to take a limited sample of potentially affected systems and conduct a simple risk-limiting audit. Begin with at least two representative computers or devices from each business unit or department. Then, examine each for signs of an issue.

In general, you would look for:

  • Disabled or altered security and antivirus software
  • Unusual system log events
  • Unexplained outgoing network connections
  • Missing security patches or problems with automatic software updates
  • Unknown or unapproved software installations
  • Altered filesystem permissions

Although an audit of this type won’t guarantee nothing’s wrong with every device on your network, it will uncover signs of any major penetration that’s already taken place. For most small to medium-sized businesses, that should be enough in situations where there’s no clear evidence of an active attack in the first place.

Engage in Defensive Measures

After dealing with the network and its users, the next thing to do is deploy some defensive measures to help with ongoing monitoring and attack detection. An excellent place to start is to set up a honeypot within the network to give potential attackers an irresistible target. This not only keeps them busy going after a system that’s not mission-critical but also serves as an early warning system to administrators when a real attack does take place.

There are a variety of ways to accomplish this, ranging from pre-built system images all the way up to more sophisticated custom deployments. There are also cloud solutions available for situations where on-premises hardware is either inappropriate or undesirable. What’s important is to build a system that monitors for the exact kind of behavior that would indicate a problem within its environment.

A word of caution, though. Although a honeypot is built to be a target, that doesn’t mean it should be left completely vulnerable. The idea is to make it an attractive target, not an easy one. And, it’s crucial to make sure that it can’t be used as a stepping-stone to a bigger attack on actual production systems.

For that reason, it’s worth it to engage the services of a trained cybersecurity professional to help make sure the system doesn’t turn into a security liability instead of a valuable defensive measure.

Remain Vigilant

After taking the steps above, there’s nothing more to do but wait and watch. Unfortunately, there’s no better way to maintain a network’s security than by remaining ever-vigilant. And in a situation like the one unleashed by the SolarWinds hack, businesses, and IT organizations, in general, are at a significant disadvantage.

That’s because they’re facing an enemy that may or may not already be within the gates, meaning they can’t fall back on typical walled-garden security approaches.

So, as 2021 gets underway, the best thing any business can do is get their security house in order and try to limit the damage if they’ve already been breached.

It’s more than worth the effort in any case because the current threat environment is only going to get worse, not better. And the SolarWinds hack, as serious and wide-ranging as it is, won’t be the last major security crisis businesses have to face.

So, it’s time to buckle up because the new decade is going to be one heck of a ride, network security-wise – and it will pay to be ready for it.


Credit: The Hacker News By: noreply@blogger.com (The Hacker News)

Previous Post

ModelOps vs. MLOps - Data Science Central

Next Post

10-years-old Sudo bug lets Linux users gain root-level access

Related Posts

Researchers Find 3 New Malware Strains Used by SolarWinds Hackers
Internet Privacy

Researchers Find 3 New Malware Strains Used by SolarWinds Hackers

March 6, 2021
Bug in Apple’s Find My Feature Could’ve Exposed Users’ Location Histories
Internet Privacy

Bug in Apple’s Find My Feature Could’ve Exposed Users’ Location Histories

March 6, 2021
Mazafaka — Elite Hacking and Cybercrime Forum — Got Hacked!
Internet Privacy

Mazafaka — Elite Hacking and Cybercrime Forum — Got Hacked!

March 6, 2021
Google Cloud Certifications — Get Prep Courses and Practice Tests at 95% Discount
Internet Privacy

Google Cloud Certifications — Get Prep Courses and Practice Tests at 95% Discount

March 5, 2021
CISA Issues Emergency Directive on In-the-Wild Microsoft Exchange Flaws
Internet Privacy

CISA Issues Emergency Directive on In-the-Wild Microsoft Exchange Flaws

March 5, 2021
Next Post
10-years-old Sudo bug lets Linux users gain root-level access

10-years-old Sudo bug lets Linux users gain root-level access

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

January 6, 2019
Microsoft, Google Use Artificial Intelligence to Fight Hackers

Microsoft, Google Use Artificial Intelligence to Fight Hackers

January 6, 2019

Categories

  • Artificial Intelligence
  • Big Data
  • Blockchain
  • Crypto News
  • Data Science
  • Digital Marketing
  • Internet Privacy
  • Internet Security
  • Learn to Code
  • Machine Learning
  • Marketing Technology
  • Neural Networks
  • Technology Companies

Don't miss it

Maza Russian cybercriminal forum suffers data breach
Internet Security

Maza Russian cybercriminal forum suffers data breach

March 7, 2021
Clinical presentation of COVID-19 – a model derived by a machine learning algorithm
Machine Learning

Clinical presentation of COVID-19 – a model derived by a machine learning algorithm

March 7, 2021
Okta and Auth0: A $6.5 billion bet that identity will warrant its own cloud
Internet Security

Okta and Auth0: A $6.5 billion bet that identity will warrant its own cloud

March 7, 2021
Researchers at Utrecht University Develop an Open-Source Machine Learning (ML) Framework Called ASReview to Help Researchers Carry Out Systematic Reviews
Machine Learning

Researchers at Utrecht University Develop an Open-Source Machine Learning (ML) Framework Called ASReview to Help Researchers Carry Out Systematic Reviews

March 7, 2021
CISA issues emergency directive to agencies: Deal with Microsoft Exchange zero-days now
Internet Security

CISA issues emergency directive to agencies: Deal with Microsoft Exchange zero-days now

March 7, 2021
Why do Machine Learning strategies fail and how to deal with them?
Machine Learning

Why do Machine Learning strategies fail and how to deal with them?

March 7, 2021
NikolaNews

NikolaNews.com is an online News Portal which aims to share news about blockchain, AI, Big Data, and Data Privacy and more!

What’s New Here?

  • Maza Russian cybercriminal forum suffers data breach March 7, 2021
  • Clinical presentation of COVID-19 – a model derived by a machine learning algorithm March 7, 2021
  • Okta and Auth0: A $6.5 billion bet that identity will warrant its own cloud March 7, 2021
  • Researchers at Utrecht University Develop an Open-Source Machine Learning (ML) Framework Called ASReview to Help Researchers Carry Out Systematic Reviews March 7, 2021

Subscribe to get more!

© 2019 NikolaNews.com - Global Tech Updates

No Result
View All Result
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News

© 2019 NikolaNews.com - Global Tech Updates