I understand why security is important but the majority of staff (particularly non-technical) see you as a blocker.
Security is everyone’s responsibility and creating an environment where it’s like this, and making it as easy as possible to get people to report stuff they see without playing the blame game is key to getting trust and demonstrating that togetherness.
There’s only really hate in them v us type environments (I’ve seen it also in other cross team interactions like Dev v Ops for e.g.) or security teams blindly giving teams lists of controls to implement without having even done any kind of risk assessment with the asset owner (and quite possibly without taking other business risk priorities into account).
As for convincing non-technical staff of the importance: The technical vulnerability (or whatever) needs relaying in business risk terms they can understand.
I'm curious cause while I'm not on my company's security team, due to heightened awareness and wanting to ensure we're protecting our trade secrets, etc, we've ramped up security in basically every way across the entire organization, and it's been basically a pleasant ride internally for all few thousand members of the company across the globe. The technical teams (dev, support) had some speed bumps, but a frank discussion with IT Security to discuss what our need was and why it wasn't being met, we found acceptable new routes. If anything, we've used the locking down of potential security risks as a leap-board to overhaul and optimize a LOT of workflows for the better.
Our customers now, that's another story, and it's like trying to make a pet take medicine. Our largest customers are fine and understand (even appreciating) the security changes we made for our interactions, but a lot of the small business customers only care about the fact that they can't do what they previously used to in some cases.
But I'm fairly curious what resistance people are seeing from their implementations and what these implementations are.
For example, try building a new website for a company, only to have the security team insist that you fix "defects" such as not tying sessions to IP addresses. Yeah, fuck all the people on mobile phones hopping between networks. It would make sense for accessing internal data, but not for what amounted to a marketing site for public consumption.
Like I said at the open, this can happen with any department or team- security, I think, might tend to happen a little more frequently, if only because it is logical that they do need a certain amount of autonomy to do their jobs well.
Good Infosec people are as rare as hen’s teeth.
Infosec employees follow the same anemic HR compensation song and dance, often lumped in with all engineering as a category.
Security startups are known as "cockroaches," they never die but are a hard bunch to grow into unicorns.
Contracting really only seems amenable to a small bump in lifestyle business level rates.
The best way for a practitioner to personally capitalize depends on their background. For instance, someone with infrastructure support experience may make an excellent incident responder. Someone who deeply understands how systems would could be a talented pentester.
Edit: From a compensation perspective the solution is to take your growing experience to the next company willing to pay for it.
As a piece of software grows in length, the releases must be fewer and further apart. Otherwise, the team is taking shortcuts and the liability will eventually catch up with them.
With that framework in mind: if large software company X stretches out their release schedule, their share price will fall, eventually appealing to activists who want to control/replace leadership (ironically for doing the right thing).
I’m a true and through capitalist—please don’t get me wrong, but this is creative destruction at its finest!
What's wrong with being large enough to live well,
but still do the job correctly, and not botch your email migration?
Have you considered starting a ransomware gang?
In recent years I’ve seen no evidence “Infosec people” are worth more than general engineers, and quite a lot that they are worth considerably less. And yes, this is when it comes to security matters.
The industry, as far as I can tell, is about 80% chancers who got into Infosec because they couldn’t cut it creating software.
The other 5% are super smart and are basically engineers who specialize in security.
I feel like many cyber people get certs and then hope for nothing bad to happen. When something bad happens, they claim that someone else didn’t do something right or get fired and move on.
There are surely people out there who know security, but how does someone who doesn’t know security choose the right people to hire?
The very software that was the vector of this attack is produced by a company claiming to improve security.
How do I spend the least amount to get "security"? Rather than, what risk mitigation is appropriate for my business, and how can I gain value from approaching or exceeding that?
It feels like part of the problem is not blending IT security into a peer level with the Operations org, as that's what it functionally is to most companies these days, and looking at it from a revenue risk mitigation perspective makes more sense for funding it appropriately.
I think it’s worse than that. It’s not just security that lacks investment, it’s the whole IT infrastructure.
Obviously the observations of one lowly employee can’t be generalised much, but creaky infrastructure seems too common.
1. MFA all the things
2. don't disable windows updates
3. don't give Domain Admin rights to half the company
4. don't use shitty software
For some reason, companies refuse to do these simple steps, and then they get hacked. It's not a technical problem, it's a political problem. Sysadmins naturally want to run their networks in the least secure way possible, and in shitty orgs, there's no one there to stop them. Over and over again, it's the same thing, and it's hard to have sympathy when standard security posture seems to be getting more and more lax as time goes on.
Most large corporate ransomware attacks spread by hosting into the Active Directory Domain server. It will slowly spread to each corporate machine as the users log in.
It seems this was the way Software AG, the second largest German software company, was hit by Clop.
As they did not pay the ransom their private emails are available on the internet, scans of their CEO passport etc...
https://www.cpomagazine.com/cyber-security/clop-ransomware-a...
Maybe ransomware gangs will finally prompt the industry to fix security practices...Also, maybe the technical stack that most companies hit by these ransomware attacks use, should be mentioned every time we see these news ;-)
Absolutely. Microsoft is a mess. I could go on for hours about how Windows networks are fundamentally insecure, and cannot be fixed without a massive psychological shift. Sysadmins love it though for some reason, probabally because it gives them way more power than they should ever need over their users.
I love hearing war stories from people who worked offense at places like Google, with almost zero AD footprint. Even the most basic attacks take SOOO much more effort. I would love it if a ChromeOS centric Zero Trust model actually became a thing, but it's not going to happen naturally. Maybe if we let all these ransomwared companies fail spectacularly, and refuse to bail them out, then the only companies that will be left will be those who care.
Unfortunately telling people not to use Windows rarely goes over well. To that main point, as bad as Microsoft is, there are so many companies that are so much worse. This Kaseya thing is essentially a rootkit with shitty authentication. Installing this thing on endpoints is a fundamentally flawed concept, yet here we are.
As for machine administration, it's ChromeOS, what needs administration? Just keep logs of auth and app usage on the server side and you have all the logs you ever need to track down bad behavior. Nothing can be installed on a majority of client systems, and nothing needs to be installed, as it should be.
Thoughts?
If you find yourself in a SOC a where everyone is stressed out and nobody has any mobility, learn what you can then move on.