SolarWinds bolsters its security response capabilities following hack
The company is in the process of 'creating a new, highly-secure environment based upon the latest practices'
SolarWinds has revealed that it is in the process of bolstering its cyber security response and monitoring capabilities, seven weeks after a “highly sophisticated” cyber attack on its IT management systems.
The software provider is working on expanding teams, techniques, and processes responsible for monitoring, responding, and “hunting” for threat actors such as those who coordinated December’s attack.
In a webcast hosted by the company, SolarWinds' security advisor and former Facebook CSO Alex Stamos said that enterprises should not only invest in appropriate security tools, but also “embrace the inevitability” that they, too, could be hacked.
“The unfortunate truth is when you go against one of these adversaries of this level, you're dealing with people that have a huge amount of time and motivation to break into your company,” he said.
“People that have dedicated research teams that are looking for zero-day in the products you use, dedicated development teams who are building new tools and new command and control systems to break in, that are not going to be caught by existing antivirus, and that come in every day with their job to break into your company.
How to improve cyber security for remote working
13 recommendations for security from any locationDownload now
Stamos recommended that, instead of focusing solely on preventing the initial compromise, enterprises must take into consideration their detection, monitoring, alerting, and response strategies and tools on every step of the cyber kill chain.
He also advised companies to measure the effectiveness of their response by using red team and tabletop exercises, as well as employing “trusted third parties” to handle the top two percentile of activity, leaving the 98% for internal teams.
Stamos was taken on by SolarWinds last month in order to help manage the software provider’s recovery from December’s cyber attack, alongside former CISA head Chris Krebs. Krebs and Stamos have recently formed a security consulting business, of which expertise SolarWinds is expected to benefit from.
During the webcast, the company also announced that it has secured its existing build environment and is in the process of “creating a new, highly-secure environment based upon the latest practices”, which includes integrating a systems development life cycle in all the environments concerned with product development.
The ultimate law enforcement agency guide to going mobile
Best practices for implementing a mobile device programFree download
The business value of Red Hat OpenShift
Platform cost savings, ROI, and the challenges and opportunities of Red Hat OpenShiftFree download
Managing security and risk across the IT supply chain: A practical approach
Best practices for IT supply chain securityFree download
Digital remote monitoring and dispatch services’ impact on edge computing and data centres
Seven trends redefining remote monitoring and field service dispatch service requirementsFree download