Off the top off my head, hunting within your network and reducing attackers' dwell time is another strong recommendation. Proxying internal network traffic with SSL-decrypt and rules-based analysis is another. Defining boundaries and firewalling off infrastructure to limit the blast radius is another. Scanning project code, dependencies and containers, and so on.
It really requires a holistic approach and commitment. There is no one right answer here but it's something we all need to take seriously, imo.
Disclosure: Have worked for several cyber-security startups with former .gov and .mil professionals while assisting many sensitive federal agencies myself.
I think it's tough for non-security professionals who feel burdened and never get to see the benefits.
If an internal resource is exfiltrating information somehow, the goal is to uncover that activity.
Satellites? Shot down.
Fiber? ISP and higher-level routers are owned or simply DDOSed
Cellular? what parts of the edge are owned is down, the core networks get targeted heavily. At best this will be spotty.
The big internet-interconnects? Targets for cruise missiles and any other viable attacks.
BGP? Fully poisoned and needs to be cleaned up before anything works.
I'd expect the DoD to have their own networks up that are much more resilient. But our current highly interconnected, triered, and multi-faceted internet is going down the moment war between the great nations breaks out. It is simply too easy, and too valuable for the enemy not to do this.
[0] https://www.forces.net/news/chief-defence-staff-russia-cutti...
[1] https://en.wikipedia.org/wiki/2008_submarine_cable_disruptio...
Just that would decimate the West and would need decades to recover from.
I'm thinking folks with WIFI gadgets and COTS networking gear could very well build local connectivity, but those islands would be unable to talk to each other. The WIFI gadgets would have to mesh up over distances which are likely to exceed their range.
Jamming and a generally dirty RF environment is likely in a war of such magnitude, so perhaps distributed laser links would work best, if one could create line of sight between the link nodes.
We run phishing simulations and red teams dozens of times a year for F500 and high tech firms. MFA tokens are never what saves someone. Ever. We always get in. Often with phishing or smishing.
I talk with many other folks that do red teams and phishing engagements.it’s of course anecdotal, but it’s a rather large and high impact customer set across people I know and our own customers.
It will save some people some of the time. But not like people think.
If my own deep experience and what I have seen in the field doesn’t convince you, that’s fine. I’m just sharing what I know to help people understand.
I'm an application security champion (in addition to being a dev) at my company and I'm looking for a new job. I see very little for security and almost none that are entry level. The ones I do see don't pay as well as the dev jobs either.