John Fitzpatrick’s Post

View profile for John Fitzpatrick, graphic

Lab539 | HPCsec | Cyber Security

For a long time the cyber security industries solution to an adversary carrying out their actions on objectives is to call in incident response. I think the belief that when an adversary is carrying out their actions on objectives it's too late is misguided. Actually, it's often the place where you can defend most effectively. There are three reasons that I see for this dynamic: 1) Defence is usually seen as mitigating an adversaries actions rather than controlling an adversaries actions, so by default defenders are putting themselves on the back foot. 2) Often defensive focus is put on defending assets, systems or privileges rather than preventing undesirable outcomes. 2) Defence is often too tooling centric. If you want to do anything more than prevent generic threats then that tooling needs telling what to do, it needs to be given context specific to what outcomes you wish to prevent. Give it context and it can be extremely powerful. I wrapped some of this thinking up in a recent post on the Lab539 website. My thinking generally is that, far too frequently, the cyber security industry is not looking past the positioning phase of an attack: https://lnkd.in/en-VZ3r5 #CyberDefence #TCDO #CyberDefense #Lab539 #CyberDefendersKillChain

The Lab539 Cyber Defenders Kill Chain — Lab539 - Tailored Cyber Defense (TCDO)

The Lab539 Cyber Defenders Kill Chain — Lab539 - Tailored Cyber Defense (TCDO)

lab539.com

Ben J.

Passionate about startups 😃😃😃

9mo

So true! It's important to shift our focus from just mitigating to actually controlling the adversary's actions. 💪🛡️ #CyberSecurity

To view or add a comment, sign in

Explore topics