Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - What Enterprises Should Know Before Using Big Data for Information Security
Articles

What Enterprises Should Know Before Using Big Data for Information Security

ISBuzz TeamBy ISBuzz TeamJune 27, 2014Updated:July 3, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Big?data
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Big Data is a buzzword, but often viewed as a panacea for whatever business problem might come up. “If only we had the data” is a refrain that many CIOs are familiar with. The beauty of today’s business environment is that we DO have the data, we CAN store it and ANALYZE it more cost-effectively than was previously possible. While log data has long been a part of the security discussion with SIEM (security information and event management), enterprises have more flexibility than ever before with amalgamating increasing sources of data and using them to deliver critical security insights. But before an enterprise can jump in to leveraging a torrent of data to improve their security posture, they must take the following steps:

Know where the “crown jewels” are

Understand what your organization’s critical data is – intellectual property, credit card information, user data, etc. Where is that sensitive data located? Who has access to it? Without knowledge and agreement around which systems are mission-critical and the safeguards in place to secure them, your security team cannot even start on the path to leveraging data successfully.

Compliance – not sexy, but necessary

Of all the hot security topics out there, compliance is not something that gets significant airtime unless there’s been a change in standards or significant failure in meeting them. Depending on an organization’s customers, partners and other contractual obligations, standards like HIPAA, PCI and other specific SLAs can alter the way security teams put in place processes to respond to alerts and threats. In an environment where cybercrime is estimated to have caused more than $400 billion in losses to companies and individuals last year, maintaining compliance standards can’t protect you from threats, but it won’t hurt, either.

Where is all this data coming from?

Log data, or machine-generated data, is expected to grow 15 times by 2020, according to a report by the research firm IDC. By creating a schema of all potential relevant data sources, from hardware to user data to sensors and beyond, security teams are better equipped to understand what they can learn from their data, and the queries needed to deliver that information. Ten years ago, the approach of SIEM solutions was to create a set of rules that remained static over time. Log data would be mined based on that set of queries, and it was cumbersome to review and update those queries. Today, enterprises need not be tied to that process and instead can use dynamic, predictive tools that continually adjust queries as IT infrastructure and user behavior changes over time.

Building the “dream” team

Often today, the story of a security breach does not begin with “there were no alerts notifying us of a problem.” All too often (and most recently in the case of Target), the alerts, red flags and blinking lights were there, but the right people with skillsets to address those problems may not have been. Making sure the right people are on board to review, analyze and remediate the issues that your tools identify should be reviewed on a regular basis as your organization and security landscape evolves. Conduct a cost analysis of the frequent security issues your organization faces and match that against the skillsets and certifications of your team. Keeping that balance will enable the security team to remain productive and efficient in addressing threats.

The number and purpose of Big Data tools, technologies and services in the market is reaching a zenith. There’s hype for a reason – the data can provide critical information that can guide the way a business is run and secured. Before falling victim to the marketing speak, security and IT teams must build their business case for how this data will contribute meaningfully to the organization. By first sitting down to consider what I’ve outlined here, I hope your efforts will lead you in the direction of a more secure, data-driven enterprise.

By Joan Pepin , VP of Security/CISO at Sumo Logic

sumo-logicJoan Pepin is VP of Security/CISO at Sumo Logic, the next generation machine data intelligence company. Joan has more than 15 years experience in information security in a variety of industries, including healthcare, manufacturing, defense, ISPs and MSSPs. Her experience spans technical, operational and management level of security, allowing her to bring highly technical research expertise to her role in security management, marketing and strategy. A recognized expert in security policy and lifecycle management, Joan is the inventor of SecureWorks’ Anomaly Detection Engine and Event Linking technologies.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}