In response to news of the Saks/Lord & Taylor breach, a Juniper Networks threat analysis expert says it’s likely that 6 million customer payment cards were stolen, including another 1 million in EU/Asia that were not initially reported. Mounir Hahad, Head of Juniper Threat Labs at Juniper Networks commented below.
Mounir Hahad, Head of Juniper Threat Labs at Juniper Networks:
“This breach continues to highlight a couple of things: A breach is only a matter of time for most organizations. As Gartner puts it, assume you have already been breached and work on detecting that breach. The second point being the length of time hackers are able to operate in an environment without being detected. This clearly calls for a very different security posture, one that emphasizes detection over prevention. Most breach prevention methods have to take a quasi-instantaneous decision on allowing or blocking traffic and there is just not enough time to make a bulletproof determination. Organizations have to allocate budget specific to detection, which utilizes all network assets to detect post-infection indicators, such as command-and-control communication as well as analytics-based solutions, which are more capable of identifying low and slow types of attacks spread over time.”
The opinions expressed in this post belongs to the individual contributors and do not necessarily reflect the views of Information Security Buzz.