Story image

Businesses too slow on attack detection – CrowdStrike

13 Dec 18

Endpoint protection provider CrowdStrike has announced the release of the 2018 CrowdStrike Services Cyber Intrusion Casebook, which provides insights into the frontlines of incident response (IR) cases spanning 2018.

It offers recommendations for organisations looking to safeguard critical data and improve overall breach preparedness, detection and response capabilities.

The 2018 CrowdStrike Services Cyber Intrusion Casebook reveals IR strategies, lessons learned, and trends derived from more than 200 notable cyber intrusion cases, spanning a multitude of industries, that CrowdStrike Services engaged on during the past year.

The Casebook provides a look at distinct IR use cases to offer trends in adversary behaviour, motivation, and tactics, as well as response scenarios.

It provides an investigative analysis of specific cases, dives into forensic artefacts uncovered in multiple instances referencing the MITRE ATT&CK framework, and offers best practices for organisations looking to improve cyber defences.

Some key findings include:

  • Organisations are not making substantive progress to detect intruders and stop breaches overall. This year, 75% of the organisations CrowdStrike engaged with were able to internally detect a breach. This represents merely a seven percent increase over the prior year’s findings, indicating that organisations have only slightly improved their ability to detect breaches. Dwell time also remained relatively the same at an average of 85 days compared to 86 in 2017. This statistic reflects the number of days between the first evidence of a compromise and its initial detection.
     
  • Commodity malware was often observed as a precursor to larger, more disruptive attacks. An organisation’s susceptibility to commodity malware is also an indicator of the effectiveness of their entire security strategy: If their systems can be compromised with commodity malware, then what could a more sophisticated attacker do?
     
  • There was a rise in the number of attacks that leveraged social engineering and phishing. Across the IR cases observed, the CrowdStrike team observed a dramatic increase in the number of attacks leveraging social engineering, phishing and spear-phishing, jumping from 11% in 2017 to 33% in 2018. This accounted for one-third of all attacks investigated by CrowdStrike Services. Web server attacks comprised the biggest single attack vector, but showed a decline from the 37% noted last year to 19.7%.

CrowdStrike Services chief security officer and president Shawn Henry says, “Cyber-related attacks continue to proliferate as eCrime actors and nation-states ramp up their sophistication.

“It’s absolutely critical that today’s businesses are aware of emerging attack trends and adversary motivations in order to implement a more proactive stance to cybersecurity.”

“It is not a question of if you will be targeted, because it will happen to everyone. This is a business risk, and Boards of Directors and the C-Suite need to have a sense of urgency to protect their organisations’ viability.

“The CrowdStrike Services Casebook contains indispensable content that provides valuable insights into proactively preparing for security incidents and responding efficiently in the wake of an attack.”

The 2018 Casebook offers guidance on remaining protected against today’s ever-evolving threat landscape, including integrating next-generation endpoint security and proactive strategies to increase cyber resiliency.

Tools such as machine learning and behavioural analytics help prevent exploits and never-before-seen threats, while proactive threat hunting can help uncover even the most stealthy adversary.

Additionally, solutions that provide for efficient remediation capabilities can aid in mitigating the threat before a small infection or compromise turns into something larger and more costly to the organisation.

IoT breaches: Nearly half of businesses still can’t detect them
The Internet of Thing’s (IoT’s) rapid rise to prominence may have compromised its security, if a new report from Gemalto is anything to go by.
Carbon Black: What does cybersecurity have in store for 2019?
Tom Kellerman has shared five insights for the year ahead, including a particularly bold one.
Hands-on review: The Ekster Wallet protects your cards against RFID attacks
For some time now, I’ve been protecting my credit cards with tinfoil. The tinfoil hat does attract a lot of comments, but thanks to Ekster, those days are now happily behind me.
Report on SingHealth breach condemns poor security practices
The 2018 Singapore SingHealth data breach was poorly managed and riddled with vulnerabilities from the start.
Tesla wants people to hack its Model 3
Tesla is offering white hat hackers what could be the chance of a lifetime – the opportunity to hack one of its Model 3 vehicles.
How to tackle cyber threats in your home
How should you start securing your devices? The company has provided tips for actions you can take across social media, home routers, TVs, and many more.
Endace joins IBM Security app exchange community
EndaceProbe Network Analytics Platform captures, indexes, and stores network traffic while hosting a variety of network security and performance monitoring applications.
Datto names new CEO as founder steps back
Austin McChord continues as a board member as the former president and COO takes over as CEO.