Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Network Security Is No Game, But A Layered Approach Will Keep Businesses On The Leader Board
Articles

Network Security Is No Game, But A Layered Approach Will Keep Businesses On The Leader Board

ISBuzz TeamBy ISBuzz TeamApril 13, 2017Updated:April 13, 20173 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Remember the board game Mouse Trap? The objective of the game was for the mouse to capture the board, while other players defended the board by trying to manoeuvre the mouse onto trap space to prevent it from securing a win.

Well, let us think of cyber criminals like the board game mouse. Most are attacking organisations for commercial gain. The easier the course laid out before them, the quicker they’ll advance, securing a bigger win. Make something tough and it’ll take so much time and effort to break down, that it will no longer be financially viable.

Unlike the eager board game participant who’ll keep starting over in desperation for a win, the cyber criminal will move on to a new challenge elsewhere. So why use the Mouse Trap analogy in the first place? Too many organisations are inviting cyber criminals to play against them with an “if it’s going to happen it will” attitude to network security that can be self-fulfilling.

Organisations commonly exhibit this defeatist attitude, thinking it’s only a matter of time before they suffer a network security breach and only focusing on how they will clear up the mess after it happens, rather than carrying on trying to prevent it.

However, there’s no point just increasing the size and scope of an organisation’s perimeter defences. I like to think of a castle. There’s little to gain by just widening the moat or building thicker walls. What if the drawbridge is down and the guards asleep? Or someone tunnels under the moat and walls? Or they have a friend on the inside? The most successful breaches of security are usually unpredictable and downright brazen – in the non-cyber world think of the Hatton Garden heist of a few years ago, or even the Trojan horse (the one used by the Greeks after the siege of Troy that is, not the malware).

If you keep the moat and walls but build additional defences inside the castle; ramparts, spikes, bear traps even and section if off you limit the access to each section to a small number of controlled points.  In IT security terms, we’re talking about security zones, micro-segmentation, network access control, authentication-based firewall policies, SSL visibility; there are multiple options. If the malware can’t go anywhere and you have it locked down in a particular part of your network, it can’t proliferate and the problem is contained.

The defences used in mousetrap are based on a Rube-Goldberg style machine, designed to be deliberately complex in order to prevent escape, yet these defences are constructed throughout the game, gifting the mouse with an open playing field early on. It’s easy to get blinkered by focusing on new products and weighing up potential new solutions but by the time you deploy them, it could a case of too little too late.

Sometimes it’s better to step back and have a more considered wider strategic view. For example, we worked with a video games company that was being constantly hit by DDOS attacks on their live gaming site. So they did some lateral thinking and routed the gaming site through a secondary channel. The attackers have gone off and found a softer target.

So be proactive and make it hard for the attackers. Create multiple layers of defence, one-way “streets” and access control systems. They may devote time and effort to breaking down these barriers, but they too have limits to what is and isn’t worthwhile.

[su_box title=”About Dave Nicholson” style=”noise” box_color=”#336588″][short_info id=’101582′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

How to Protect Your VoIP System from DDoS Attacks

September 9, 20258 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}