We all have that one incident that made us totally rethink our approach to security. What was yours, and how did you learn from it?

like
Posting as :
works at
You are currently posting as works at

This was really recent in a 10 year career and the incident itself wasn’t bad—but more by luck as it could have been *bad*. The change in approach is more because of why I missed it + some reporting work I was doing at the same time.

We got notified by a third party, no name but if you list off the orgs, agencies, or that a threat actor was on one of our servers. It doesn’t help that they were kind of vague other than giving me one IP.

It turned out to be one of the hosts in our VDI environment. I did have some logs; session from the authentication to the vdi environment and network firewall, but the parsing of those logs wasn’t great and this was due to CVE-2023-4966 (session hijack on netscaler, and MFA was bypassed due to this) which itself did not leave any real evidence — except that the source and client IP would differ. Since that is a rare case for legitimate use, both fields weren’t captured outside of the original message text. There were no logs collected on the host and because it was VDI, the VM would periodically get destroyed and I could not go back to grab this information. Had they gotten a privileged account it could have been much worse.

Now for the reporting, trying to rework how I was doing our vulnerability reporting had already gotten me to the point of reevaluating how I’m handling that data and its processing. With the timing, I saw the same difficulty with logging.

The lesson learned here:

- I cannot possibly be the only one responsible for understanding the logging functionality, format, and options of every single thing in our environment. The system owners need to step up to their role here.
- Getting this to happen also means our logs can’t go into a black hole that they’ll never see after making the configuration changes. They should be able to see the logs and identify when something’s off. If logging is already happening then maybe this should also include more data than strictly security (metrics, applications logs, etc— all of which also can be useful for security )
- We have a real need to standardize how we’re documenting our environment, configuration, and services. This is also basic but previous leadership actively worked against me trying to get it done. So I’d be primarily focused on ensuring that detecting and responding to threats based on what we did have could be done as quickly as possible.

The approach I’ve been taking for the last half year has been based on this.

My top priority is transitioning our security program to a collaborative model where those system owners are responsible for understanding their system’s security and monitoring for security notifications. Security will be responsible for maintaining, monitoring, and auditing the inventory, configurations, and data being collected. Identified outside of defined change management need to be validated and documented as a change (as the change management itself is that validation and can be accepted as is). Insecure configuration, vulnerabilities, and other findings are included and sent to those owners. Data collected should be provided to those folks, as programmatically as possible so queries and automations can be made without having to understand the minutia of the whole environment. Networking or Server people can make changes targeting what they know to be wholly accurate and more importantly where to find it (one webui/api vs 10 different manners of documenting it) or simply sync the “true” inventory to what they’re currently doing. I won’t need to worry about constantly having to redo discovery to catch changes either not documented or spread documentation across network shares, wikis, and spreadsheets. I can focus on the overall security instead of constant battles with searching for info or trying to suss out some log means.

But it all really comes down to ensuring we have the information to do that, it’s continuously up to date, and it’s relevant and usable to the people I need securing their stuff.


Folks just starting in security, every ciso will say “you can’t protect what you don’t know” to the point it’s like their Pokémon word but lemme tell ya. It goes well beyond just knowing. You can’t secure what you can’t validate and you can’t validate or secure what you don’t understand. “Information silos” and knowledge gaps in your environment are as big of a threat as the actual threat actors. You’ll miss attacks, of catch them much later. You’ll declare an incident—or breach—when it may not be necessary. You’ll spend hours searching for info that you shouldn’t need to.

like

Whoaaa as a former auditor that last paragraph is messsing me up. Very true!

like

Seeing low hanging fruit as low hanging. I used to see forgot password functionalities as a low hanging thing to test for, until I came across instances where I could takeover accounts by abusing that. Every finding is important.

like

Okay, I’ll share, but first — let’s do your adult film star name. Your first name is the name of your first pet, and your last name is the name of the street you grew up on.

like

I worked on an online website serving customers, we lost the whole stack in one data center as the mid tier went offline. Turns out the cleaner had pulled the plug. Seems so stupid and its one we joke about but we didnt have anything protecting the plugs to stop physical accidents.

It made me step back and think holistically about the service and consider where things can go wrong. Again cliche but a lot of risk is human element and is often not directly related to what you want to protect.

Related Posts

Hasta lunes, Miami

Post Photo
like

What's the compensation for Contract Senior Manager at PwC in Texas? Glass door has no information about this.

like

Why are the lesbian bars so few in the US? I am loving the only lesbian bar in Houston, but I need variety. Can you actually meet girls well at a traditional gay bar? F/25/Houston here

like

What is the rejection rate for canada wp this year?
I have been rejected for us visitors visa twice two years back.. so having doubts about canada wp.. would this cause any issues?

like

I heard food is free in exl is that true

like
like

What do you now know about freelancing that you wish you knew when you started?

like

Hi ZSers,
Anyone looking for a male flatmate or looking for a flat? I have to move in before 18th of July. Any leads would be appreciated.
Thanks in advance!

like

I don’t have the relieving letter as of now.. it will take some time for my current organisation to release it.. how can i ho forward with the onboarding???

like

I just learned that I get to argue all of our pre-trial motions and do a direct examination at an upcoming trial. What are your best tips for preparing and setting yourself up for success? I want to hear them all! I’m beyond excited for the opportunity. It’s for our biggest client, so I really want to impress!

like

Have an opportunity to finally get out of insurance defense. But not really sold on the firm. Could finally get out of ID, but then could also end up at another place I really don't like. Def want my next firm to be long term as I've jumped around.

like
like

Any recs for recruiters in the DC area that are good for lit/arb?

like

How much should i save from my salry for securing post retirement life and all general commitments before that. I'm 30 now. Assume no Inheritance. Current in hand 1.85 lpm

like

Any tips on how to bring in clients to the firm? I do L&E and one of the things my firm goes over during annual evals is whether we bring in business, even for third year associates.

like

Should Dropbox be used as the main file system for a busy Litigation office? Help me prove that it shouldn’t and suggest a software that your firm uses.

like

Can I pay income tax challan using credit card?

I'm a long time user of mvelopes budgeting software, and we just got a notice that they're shutting the platform down at the end of the year.

Looking for a recommendation for an "envelope based" replacement. They suggested Every Dollar, but it doesn't handle credit cards well.

like

Does anyone know how to declare in my individual tax return, RSA and Stock Options from a US Company that I have? Non exercised yet.

like

What advice would you give someone starting out. Offer in hand - starting first as a SNOW Business Analyst while learning how to be a Developer. No coding experience but 7 YOE in consulting.

like

Additional Posts in Cyber Security Bowl

Anyone familiar with Istari-Global and their collective of cyber risk companies? What’s their perception in the market? Opportunity to join US team. Thanks!

like

Any BCG Platinion Cyber folks here?
What kinna work do you guys do? Planning to make the switch after 5 years with Uncle D. Wanna hear from you guys about culture, projects and areas of expertise.

like

Anyone got insights on IBM Security? Areas of expertise? QoL? Pay, etc.

Curious how MBB's cybercapabilities are viewed within the cyber world. Experiences, thoughts?

like

Anyone know what kind of experience or certifications I should be aiming to get if I'm trying to break into a pentest role? I just graduated last year and have about a year of sysadmin experience and am trying to get into it asap. So, I'm already applying/job hunting and probably won't get much replies but. Should I be looking at more security analyst/admin roles first? Going for certs? Getting a masters? Wondering what I can do to improve my chances. TIA

like

How to make a jump to cloud security when I just have SOC experience? Currently studying for Solutions Architect cert

like

We’re hiring across the board at KPMG for cyber / cyber risk work - shoot me a DM if interested. (Pays well!)

likehelpful

How much does Deloitte pay for cybersecurity or devops senior Deloitte roles

like

How is Booz Allen cyber strategy and risk management consulting? Got a recruiter inquiry

like

Deloitte Cyber, how long did it take you to receive an offer after final interview?

like

Anyone at Protiviti in their Cybersecurity consulting practice willing to chat? Looking to inquire about pay, culture, etc. Thanks!

like

Is there a demand for privacy professionals? Been seeing this discussed more and more recently

like

Joining a group that specializes in incident response. Any recommendations on things I can do this summer to prepare on fundamentals/certs?

like

Currently working in an IT audit role, what is the best way to transition into cyber ?

like

New to the U.S., is the Healthcare Industry (via HIPAA), the only industry in the U.S. that legally mandates having a designated Privacy Officer? So for example, although GLBA has obvious privacy requirements, unlike with healthcare, financial institutions in the U.S. are not mandated by law to have a designated Privacy Officer?

like

Thinking about getting the AWS Cloud Practitioner certification. Does EY have any amazon resources or training materials that they provide? Any advise from people who have taken it before? Thanks!

like

Would you expense a speeding ticket on your way to an IR?

funnylike

Views on carbon black as a product?

helpful

Any company is hiring EU citizens and helping with visa? interested in moving to USA. I'm lawyer, cissp, cisa, cipp/e and specialized n data privacy, cybersec ops and risk management with 8+ years exp

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal