Also, most XDRs detect this behaviour really well now.
Also, most XDRs detect this behaviour really well now.
That is the most optimistic thing I've read in a long time!
I still consult with companies storing all of the company-owned accounts (facebook, instagram, website admin, government & tax portals, etc.) in a spreadsheet called "passwords.xlsx", in a folder called "passwords", on the root of the network with no access control. Frequently.
(they do not have their backup ducks in a row, nor have any clue what "XDR" stands for)
Basically an XDR looks not only at malware but also at potentially malicious actions. This is a much more complete view because not every malicious action is triggered by malware. It can also be simply a user (and AI automation/control will be a new thing there). Big names in this are Crowdstrike (yes that one that killed half the enterprises), SentinelOne, Microsoft Defender for Endpoint (not to be confused with the normal consumer defender). An XDR will notice when a PC is doing a port scan, when a process is trying to gain root rights, when significant numbers of files are suddenly rewritten. It will immediately kill the process and/or trigger a ticket to the SOC (Security Operations Center). Who can take global actions on all endpoints to immediately kill the malware everywhere. It's pretty cool, you can trace back the entire process history, what launched what, what was were the system call parameters etc.
Big companies really have this stuff figured out. Unfortunately exfiltration is harder to detect if the malicious actor is doing it through a cloud service that the company also subscribes to.
If a company doesn't know what XDR is they are probably < 100 employees.
Indeed, I do cybersec consulting primarily for small to medium-sized businesses.
And I would say, especially for small businesses, somewhere over half of them have no backup plan (among all the other issues). So, sadly, it is far from true that "most companies have their backup ducks in a row" .
Of course those are also the fattest targets for these actors. We get some really serious stuff very regularly. Which I can't elaborate on, but I mean, the threat model for a small / medium business is also much less heavy.
Also, most enterprises have cybersecurity insurance that will just pay out (and thus keep this activity going, sadly). I don't think smaller businesses would have that.
I've walked into billion dollar orgs and campaigned unsuccessfully for backups. And I have seen sole traders with cyber insurance.
Your time is much better spend detecting or preventing compromise.
And yes compromise detection is of course the priority. But it's not just one or the other. We do everything at the same time. The swiss cheese model and all that.
> If a company doesn't know what XDR is they are probably < 100 employees.
To say that "most companies are < 100 employees" would be to understate the margin by which that is true. According to https://www.naics.com/business-lists/counts-by-company-size/, there are 17,769,699 companies total in the US, of which 166,964 are > 100 employees (leaving the unknowns to one side). That's less than 1%.
Just because it's crime doesn't mean it's free money