Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Penn State Cyberattack Highlights Need for Managed Security Services
Articles

Penn State Cyberattack Highlights Need for Managed Security Services

ISBuzz TeamBy ISBuzz TeamMay 25, 2015Updated:May 25, 20154 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Cyberattack Highlights Need for Managed Security Services
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Penn State University network attack

Penn State’s College of Engineering revealed that it was the target of sophisticated cyberattacks that shut down its network.

An official at Penn State mentioned “In fact, on an average day last year, Penn State alone repelled more than 22 million overtly hostile cyberattacks from around the world.” This is an interesting number, however I would surmise they are counting the amount of perimeter based source IP addresses they are blocking using general static firewall, VPN, and IPS rules that stop general drive by attacks blasting the internet.

What may be more important are how many known abusive attackers are hitting their perimeter, how many are permitted through their firewalls, and how many of those are target attacks or return communication to an already compromised device. In our Security Operations Centers we are finding organizations with a similar size to the single College at Penn State will need to monitor over 250 million security events per day from internal and permitter resources in an attempt to discover the 3-5 Actionable Incidents a day that indicate a compromise they need to block in the kill chain within minutes to prevent continuation of the attack toward an ultimate breach or malicious event.

Putting this into more perspective, we find on average an organization of this size will be attacked by known abusive attackers more than 10,000 times per day and roughly 3-5% of the communications are permitted through the firewalls of most organizations. Most organizations can’t or don’t block these communications because they have to keep certain ports open for normal business communications or they do not have strong perimeter security policies enforced (or in some cases their policy doesn’t match their configuration – sound familiar). Of the 3-5% of permitted communications from known abusive attackers that we track for our clients, we discover on average 2 to 3 targeted attacks per day performing reconnaissance or staging, and 2-3 correlated events considered to be a compromises per week.

Even with the best SIEM 2.x generation technologies finely tuned with advanced correlation and behavior algorithms in place, an organization will maybe reduce the 250 million security events per day down to 100 suspicious threats per day they need to ‘investigate’ to determine the 3-5 events that require immediate ‘Action’ on a daily basis. The additional two part challenge is 1) who has a minimum of 20 trained security analysts in a SOC to monitoring and investigate 100 suspicious threats per day, and 2) how do you react immediately to break the communication with the abusive attacker, quarantine the device, or disable the User account while you wait for your in-house remediation response team or contracted forensic investigators to role?

In our view, most organizations just don’t have the capital, desire, or ability to staff and manage a 20 (or more) person Security Operations Center to perform advanced SIEM management, 24×7 security event monitoring, or incident investigations. The answer to this equation today is to partner with a SOC-as-a-Service company that also offers a SIEM-as-a-Service. These companies provide the world class SOC services needed by all sizes of organizations to compete with the large number of world class threat actors.

We would also recommend venturing toward a provider that is more than the traditional MSSP providing general firewall management and more toward a new generation of SOC-as-a-Service provider that provides advanced Use Case correlation tuned to your business context, and provides automated active Breach Prevention activities to break the communication with the abusive attacker, quarantine the device, or disable the user account. This provides visibility into your security program posture, knowledge of who is attacking you and what they are targeting, as well as active defenses allowing you time to role in the reinforcements.

By Brad Taylor, CEO, Proficio (www.proficio.com)

Brad TaylorBio : Brad has 20+ years experience in the enterprise software, security, and networking industry as a senior executive in sales, marketing, business development, acquisitions, operations, and venture capital. He has built and managed multiple sales teams as a VP of Sales and assisted in two highly successful IPO’s with RSA Security (RSAS, now EMC) and ArcSight (ARST). In addition, he has helped several companies get up and running to successful sales and market positions as a VP of Worldwide Sales / Marketing / Business Development for companies including eIQnetworks, SOA Software, and AirTight Networks.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Understanding Cloud Access Security Brokers (CASB)

March 28, 202410 Mins Read

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read

Master Cloud Compliance Tools: Achieve Regulatory Success

March 28, 202411 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}