Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Cyber crime: How to stay one step ahead
Articles

Cyber crime: How to stay one step ahead

ISBuzz TeamBy ISBuzz TeamMarch 18, 2015Updated:July 3, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
IT Security From the Inside Out
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

These days, cyber crime is a lucrative business, and cyber criminals take their time to investigate their potential target before they go in for the steal to make the cyber attack as profitable as possible and to minimise the risk of getting caught. They look for weak spots in the corporate network and defences which they can exploit and really do their homework before they attack.

In most cases, organisations may not even realise that they have been attacked, and it could be months before they realise and remediate the breach. In fact, according to recent research, 71% of victims did not detect a breach themselves and it was identified by third parties, and worse still, the median number of days from the date of the initial intrusion to the date of detection was 87, meaning that half of compromise victims became aware of a breach within approximately three months of the initial intrusion. The damage that can be done over three months is just unfathomable. (Source: Trustwave Global Security Report 2014)

So in order for organisations to stay one step ahead of attackers, who have the advantage of time on their side, it is crucial to adopt strategies to identify weak spots and take proactive measures to understand their network better than their attackers.

Do you know where your data is?

A number of high profile data breaches made headlines recently, such as at Talk Talk’s supplier and the compromise of POS system supplier Nextep, highlighting the fact that cyber criminals are after organisation’s data. The organisation’s “crown jewels” could be their Intellectual Property, client or Personally Identifiable Information data or financially sensitive information, and it is therefore imperative that the organisation and the IT team / CIO not only fully understand where that data is, but also who has access to it. Only then will they be able to fully understand how to protect it accordingly.

Practise makes perfect

Not all security events are equal, and so organisations need to classify different types of incidents so that the response that is activated, is in line with its scope and severity.

For example, an attack that occurs as a result of malware planted in the corporate network requires an extremely different approach to one in which an employee has exfiltrated confidential corporate data. Of course, in both cases, the organisation would need to investigate the actual exposure of the attack. However, if the risk is determined to be relatively low, the relative response may be to close the loophole and remediate the specific issue. On the other hand, in higher risk situations where employees or customers may be involved, the response team and the response would be completely different and the organisation may experience financial loss or reputational damage.

Unfortunately, this is an area where many organisations struggle. It means that they may not be able to respond to that specific incident within the appropriate time frame, or that a team may not be drilled in the correct procedure to follow.

Security Alerts – Stay one step ahead

Although there are many tools and technologies readily available today to help organisations detect data breaches, it is important that organisations become proactive in their understanding to determine their capabilities of handling the vast amount of security alerts, as even the best perimeter defences only tell half the story.

On any given day, there will be countless security alerts coming in from the firewalls, intrusion detectors, DLP tools and other systems – however, these mainly arrive once the damage has been done. Worryingly, in many cases, the real security risks, worthy of further investigation, may get lost in the mountains of incoming security alerts and the organisation will continue to be in the dark about the breach. This can be exacerbated by the fact the once a risk is identified, the team may not have the ability to view the status of the various end points.

Conclusion

By understanding the corporate environment, and having an active view of the “crown jewels”, organisations will spot behavioural changes within their environment and identify an acceptable “baseline” if any changes occur.

Once these processes are well managed, organisations can correctly categorize the various security alerts, qualify them, and understand how to respond appropriately.

By Nick Pollard, Senior Director, Professional Services EMEA & APAC at Guidance Software

About Guidance Software

guidance-encase-logoFounded in 1997, Guidance Software is recognized globally as the world leader in e-discovery and other digital investigations.Our EnCase® software solutions provide the foundation for corporate government and law enforcement organizations to conduct thorough and effective computer investigations of any kind, including intellectual property theft, incident response, compliance auditing and responding to e-discovery requests-all while maintaining the forensic integrity of the data. We also offer customized services in e-discovery, incident response, computer forensics, evidence presentation and trial testimony, using a team of former law enforcement professionals, e-discovery and litigation support experts, information assurance specialists and project managers who have front-line, hands-on experience in all areas of digital investigations. Guidance Software trains more than 6,000 corporate, law enforcement and government professionals annually in the areas of computer forensics, enterprise forensics, e-discovery, and computer incident response. Courses and materials are offered in a variety of languages in Guidance Software facilities worldwide, through partners and online. Our customers are corporations and government agencies in a wide variety of industries, such as financial and insurance, technology, defense, energy, pharmaceutical, manufacturing and retail. There are more than 40,000 licenses of EnCase® technology worldwide. The EnCase Enterprise platform is used by more than half of the Fortune 100, including Allstate, Chevron, Ford, General Electric, Honeywell, Northrop Grumman, Pfizer, UnitedHealth Group and Viacom.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}