Cyber’s Focus On Prevention Hasn’t Worked, Making Cyber Resilience Elusive


We’ve spent decades chasing the illusion of “perfecting prevention.” The industry has poured billions into digital walls, endpoint solutions, SIEM, SOAR and user awareness training—all to build a world in which breaches don’t happen.

However, that world doesn’t exist. The cloud-first shift, SaaS sprawl and identity-driven access have fragmented the enterprise environment and expanded the attack surface in all cardinal directions. In this landscape, prevention has fallen short and been outpaced. Successful attacks keep rising. Credential theft. Exploits. Lateral movement. Data exfiltration. The breach isn’t the exception—it’s the pattern. Stop trying to stop every attack. Start building resilience.

Read more…
Source: Forbes News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • U.S. National Cybersecurity Plan Promises to Safeguard Maritime Sector

    January 18, 2021

    The U.S Government released on January 5, 2021, a cybersecurity plan to secure the nation’s maritime sector against cybersecurity threats that could endanger national security. The Maritime Cyber Environment With International Maritime Organization’s (IMO) mandate “to ensure that cyber risks are appropriately addressed in existing safety management systems” and the increasing number of cyber-attacks against maritime and ...

  • Microsoft addresses a Critical RCE vulnerability affecting the Netlogon protocol CVE-2020-1472

    January 14, 2021

    Microsoft addressed a Critical RCE vulnerability affecting the Netlogon protocol (CVE-2020-1472) on August 11, 2020. We are reminding our customers that beginning with the February 9, 2021 Security Update release we will be enabling Domain Controller enforcement mode by default. This will block vulnerable connections from non-compliant devices. DC enforcement mode requires that all Windows ...

  • CISA’s Hometown Security program

    January 14, 2021

    The U.S. Department of Homeland Security’s (DHS) most important mission it to protect the American people. As part of this mission, DHS fosters collaboration between the private sector and the public sector to mitigate risk and enhance the security and resilience of public gathering sites and special events. DHS provides expert counsel and recommendations on protective ...

  • NSA Recommends How Enterprises Can Securely Adopt Encrypted DNS

    January 14, 2021

    The National Security Agency released a cybersecurity product, “Adopting Encrypted DNS in Enterprise Environments,” Thursday explaining the benefits and risks of adopting the encrypted domain name system (DNS) protocol, DNS over HTTPs (DoH), in enterprise environments. The release provides solutions for secure implementation based on enterprise network needs. DNS translates domain names in URLs into IP ...

  • Parler social network drops offline after Amazon pulls support

    January 11, 2021

    Parler has dropped offline after Amazon pulled support for its so-called “free speech” social network. The platform had been reliant on the tech giant’s Amazon Web Services (AWS) cloud computing service to provide its alternative to Twitter. It is popular among supporters of Donald Trump, although the president is not a user. Amazon took the action after finding ...

  • Card-Not-Present Fraud: 4 Security Considerations for Point of Sale Businesses

    December 23, 2020

    As the retail world’s center of gravity shifts to the cloud, payment card fraud has followed suit. According to Verizon’s retail vulnerabilities study, attacks against e-commerce applications are by far the leading cause of retail data breaches. This trend mirrors similar outcomes in other industries, like food service. A complimentary Verizon study finds remote attacks ...