1
00:00:00,000 --> 00:00:02,320
Hey everyone and welcome to another deep dive.

2
00:00:02,320 --> 00:00:04,920
Today we're diving into the world of cybersecurity.

3
00:00:04,920 --> 00:00:06,480
It's a critical topic these days.

4
00:00:06,480 --> 00:00:07,440
That's for sure.

5
00:00:07,440 --> 00:00:09,080
Not just about protecting gay anymore.

6
00:00:09,080 --> 00:00:10,200
Right. It's everything.

7
00:00:10,200 --> 00:00:12,800
It really is the foundation of our digital lives now.

8
00:00:12,800 --> 00:00:13,720
Could new green more.

9
00:00:13,720 --> 00:00:16,080
And that's what makes this document we're looking at today.

10
00:00:16,080 --> 00:00:16,800
So relevant.

11
00:00:16,800 --> 00:00:18,400
Oh yeah. What have we got?

12
00:00:18,400 --> 00:00:23,760
002, Chris domain 7, section 2 dot PDF.

13
00:00:23,760 --> 00:00:27,440
It outlined some of the real world strategies used every single day

14
00:00:27,440 --> 00:00:29,360
to combat cyber threats.

15
00:00:29,360 --> 00:00:30,680
Real world stuff.

16
00:00:30,680 --> 00:00:31,480
I like it.

17
00:00:31,480 --> 00:00:32,280
Get's right to the point.

18
00:00:32,280 --> 00:00:35,720
So HECTION 1, understanding the fundamentals, intrusions and

19
00:00:35,720 --> 00:00:36,720
defensive measures.

20
00:00:36,720 --> 00:00:37,920
The fundamentals are key.

21
00:00:37,920 --> 00:00:38,560
Absolutely.

22
00:00:38,560 --> 00:00:38,920
Okay.

23
00:00:38,920 --> 00:00:40,760
Picture this.

24
00:00:40,760 --> 00:00:42,320
You're at a packed concert.

25
00:00:42,320 --> 00:00:42,760
Okay.

26
00:00:42,760 --> 00:00:43,600
I'm picturing it.

27
00:00:43,600 --> 00:00:44,960
The bands about to start.

28
00:00:44,960 --> 00:00:46,240
Everyone's hyped.

29
00:00:46,240 --> 00:00:49,920
Suddenly you see someone trying to sneak past security.

30
00:00:49,920 --> 00:00:50,800
Ah, no, no, no.

31
00:00:50,800 --> 00:00:51,800
No ticket, no shame.

32
00:00:51,800 --> 00:00:54,160
That is a great analogy for an intrusion actually.

33
00:00:54,160 --> 00:00:57,960
Trying to get into a system, get that data without authorization.

34
00:00:57,960 --> 00:01:00,520
And just like at that concert, you've got security guards right.

35
00:01:00,520 --> 00:01:04,160
Well, organizations have intrusions, detection systems,

36
00:01:04,160 --> 00:01:07,520
IDSs or intrusion prevention systems.

37
00:01:07,520 --> 00:01:08,160
Yeah.

38
00:01:08,160 --> 00:01:09,000
IPSs.

39
00:01:09,000 --> 00:01:10,440
So it's like a layered approach.

40
00:01:10,440 --> 00:01:12,640
You've got security guards, AMD.

41
00:01:12,640 --> 00:01:13,880
You've got the ticket checkers.

42
00:01:13,880 --> 00:01:14,640
Precisely.

43
00:01:14,640 --> 00:01:18,720
And these IDS and IPSs, they're like the first line of defense

44
00:01:18,720 --> 00:01:21,200
constantly on the lookout for anything suspicious.

45
00:01:21,200 --> 00:01:22,200
Exactly.

46
00:01:22,200 --> 00:01:26,080
But when something happens, how do organizations react in real

47
00:01:26,080 --> 00:01:26,680
time?

48
00:01:26,680 --> 00:01:28,320
Yeah, that's the critical moment.

49
00:01:28,320 --> 00:01:29,720
That's where science come in.

50
00:01:29,720 --> 00:01:32,360
Security information and event management systems.

51
00:01:32,360 --> 00:01:33,160
Science.

52
00:01:33,160 --> 00:01:34,000
Science.

53
00:01:34,000 --> 00:01:37,080
Think of it like a high-tech command center.

54
00:01:37,080 --> 00:01:39,400
Instead of generals, you've got analysts,

55
00:01:39,400 --> 00:01:41,040
monitoring a massive screen.

56
00:01:41,040 --> 00:01:41,560
Okay.

57
00:01:41,560 --> 00:01:45,600
And the science, the system, is pulling in data from everywhere.

58
00:01:45,600 --> 00:01:47,920
Firewalls, servers, applications, everything.

59
00:01:47,920 --> 00:01:48,360
Wow.

60
00:01:48,360 --> 00:01:51,080
So it's like the central nervous system for cybersecurity.

61
00:01:51,080 --> 00:01:51,920
You got it.

62
00:01:51,920 --> 00:01:54,120
But, you know, a command center is only as good as the people

63
00:01:54,120 --> 00:01:55,440
making the decisions right.

64
00:01:55,440 --> 00:01:56,440
That's true with everything.

65
00:01:56,440 --> 00:01:57,280
The human element.

66
00:01:57,280 --> 00:02:01,320
You need skilled analysts to interpret that data to connect the dots.

67
00:02:01,320 --> 00:02:02,320
You'd be surprised.

68
00:02:02,320 --> 00:02:04,080
Sometimes it's seemingly minor alert.

69
00:02:04,080 --> 00:02:05,080
Like what?

70
00:02:05,080 --> 00:02:08,600
Something like a log in from an unusual location at an odd hour.

71
00:02:08,600 --> 00:02:09,960
Could be nothing or wrong.

72
00:02:09,960 --> 00:02:13,360
Or it could be the first sign of a major breach.

73
00:02:13,360 --> 00:02:14,760
Exactly.

74
00:02:14,760 --> 00:02:17,880
I remember early in my career, we had this one alert.

75
00:02:17,880 --> 00:02:19,800
It seems so insignificant at first.

76
00:02:19,800 --> 00:02:20,640
What happened?

77
00:02:20,640 --> 00:02:23,800
It ended up being a really sophisticated fishing attack,

78
00:02:23,800 --> 00:02:26,400
aimed at a high-level executive.

79
00:02:26,400 --> 00:02:30,280
But because we had that robust sign system in place,

80
00:02:30,280 --> 00:02:33,600
and a sharp analyst who knew what to look for, you caught it.

81
00:02:33,600 --> 00:02:37,320
We stopped it before any sensitive information was compromised.

82
00:02:37,320 --> 00:02:37,960
Wow.

83
00:02:37,960 --> 00:02:40,520
That just shows you even with all the technology in the world.

84
00:02:40,520 --> 00:02:41,960
You need the human expertise.

85
00:02:41,960 --> 00:02:43,520
It all comes back to that.

86
00:02:43,520 --> 00:02:48,440
So, signs, clearly critical, but also incredibly complex.

87
00:02:48,440 --> 00:02:49,040
That's fair.

88
00:02:49,040 --> 00:02:53,960
What's with all this aggregation, normalization, correlation, stuff?

89
00:02:53,960 --> 00:02:54,640
It's a lot.

90
00:02:54,640 --> 00:02:57,320
Imagine you're trying to solve a puzzle.

91
00:02:57,320 --> 00:03:01,960
But the pieces are scattered everywhere, and some are even written in different languages.

92
00:03:01,960 --> 00:03:03,280
That's what a sum does.

93
00:03:03,280 --> 00:03:05,560
It gathers all these security logs and events.

94
00:03:05,560 --> 00:03:06,560
Okay.

95
00:03:06,560 --> 00:03:10,400
Put some in a common language that's normalization part, and then tries to find the connections

96
00:03:10,400 --> 00:03:11,400
between them.

97
00:03:11,400 --> 00:03:12,400
Correlation.

98
00:03:12,400 --> 00:03:13,800
To reveal the bigger picture.

99
00:03:13,800 --> 00:03:18,200
Okay, so it's like piecing together clues in a digital detective story.

100
00:03:18,200 --> 00:03:21,120
But how do they even begin to make sense of all that data?

101
00:03:21,120 --> 00:03:23,440
Well, that's where aggregation comes in.

102
00:03:23,440 --> 00:03:27,080
The CM doesn't just dump all of this information on analysts at once.

103
00:03:27,080 --> 00:03:31,160
It aggregates or groups, similar events and data points together.

104
00:03:31,160 --> 00:03:34,360
So analysts can quickly identify those patterns anomalies.

105
00:03:34,360 --> 00:03:37,160
So it's really about identifying those red flags early on.

106
00:03:37,160 --> 00:03:38,160
Yes.

107
00:03:38,160 --> 00:03:40,560
But then what happens next?

108
00:03:40,560 --> 00:03:42,200
This is where it gets interesting.

109
00:03:42,200 --> 00:03:45,960
This is where it gets even more interesting, and that's where we'll pick up next time.

110
00:03:45,960 --> 00:03:51,240
With a deeper look at SOAR, security orchestration, automation, and response.

111
00:03:51,240 --> 00:03:54,680
Ooh, SOAR sounds intriguing.

112
00:03:54,680 --> 00:03:55,960
Can't wait to dig into that.

113
00:03:55,960 --> 00:03:58,120
Okay listeners, you heard it here first.

114
00:03:58,120 --> 00:04:00,960
We're about to take this deep dive to the next level.

115
00:04:00,960 --> 00:04:01,960
Don't touch that dial.

116
00:04:01,960 --> 00:04:03,560
We'll be right back.

117
00:04:03,560 --> 00:04:04,560
All right.

118
00:04:04,560 --> 00:04:08,040
So before the break, we're really getting into the nitty gritty of seams.

119
00:04:08,040 --> 00:04:10,680
Those cybersecurity command centers.

120
00:04:10,680 --> 00:04:12,760
But you left us hanging with that cliffhanger.

121
00:04:12,760 --> 00:04:13,760
Soar.

122
00:04:13,760 --> 00:04:14,760
Ah, yes.

123
00:04:14,760 --> 00:04:18,720
So, security orchestration, automation, and response.

124
00:04:18,720 --> 00:04:22,880
The ACM is fantastic at collecting analyzing data, but it doesn't actually do anything

125
00:04:22,880 --> 00:04:24,680
about the threats it uncovers.

126
00:04:24,680 --> 00:04:26,120
That's where SOAR comes in.

127
00:04:26,120 --> 00:04:29,760
Takes those alerts from the sign and helps automate the response.

128
00:04:29,760 --> 00:04:33,960
So it's like having what pre-programmed responses for different security events.

129
00:04:33,960 --> 00:04:38,960
So if the sum sees something suspicious happening, SOAR can just automatically take action.

130
00:04:38,960 --> 00:04:39,960
Exactly.

131
00:04:39,960 --> 00:04:44,040
Let's say you're a sign to text a fishing attack in progress.

132
00:04:44,040 --> 00:04:48,920
Or can automatically start blocking those malicious emails, quarantine any accounts that

133
00:04:48,920 --> 00:04:52,960
might be affected, even start tracing that attack back to its source.

134
00:04:52,960 --> 00:04:53,960
Wow.

135
00:04:53,960 --> 00:04:55,800
All without a human analyst having to even lift a winger.

136
00:04:55,800 --> 00:04:56,800
That's incredible.

137
00:04:56,800 --> 00:05:00,120
It's like having a whole team of security experts working around the clock, but it's

138
00:05:00,120 --> 00:05:01,120
automated.

139
00:05:01,120 --> 00:05:02,120
That's the beauty of it.

140
00:05:02,120 --> 00:05:06,040
It frees up those human analysts to focus on the really complex stuff.

141
00:05:06,040 --> 00:05:11,520
The things that need that human intuition, human expertise, threat hunting, incident response.

142
00:05:11,520 --> 00:05:12,520
Right.

143
00:05:12,520 --> 00:05:13,800
But even with a sign, even with SOAR.

144
00:05:13,800 --> 00:05:14,800
That's really just the beginning.

145
00:05:14,800 --> 00:05:20,280
Our source material is 002, Chrispoke, domain7section2.pdf.

146
00:05:20,280 --> 00:05:23,400
It really emphasizes this continuous monitoring.

147
00:05:23,400 --> 00:05:27,400
Yeah, because it's not a set it and forget it, kind of deal.

148
00:05:27,400 --> 00:05:29,920
The threat landscape is constantly changing.

149
00:05:29,920 --> 00:05:32,280
New vulnerabilities pop up all the time.

150
00:05:32,280 --> 00:05:34,320
All the time, new threats emerging every day.

151
00:05:34,320 --> 00:05:37,320
Like imagine training a team of athletes.

152
00:05:37,320 --> 00:05:40,200
You wouldn't just train them once and then expect them to go out and win championships

153
00:05:40,200 --> 00:05:41,200
year after year.

154
00:05:41,200 --> 00:05:42,200
Right.

155
00:05:42,200 --> 00:05:46,800
See that ongoing coaching, the practice, the feedback to really stay at the top of

156
00:05:46,800 --> 00:05:47,800
their game.

157
00:05:47,800 --> 00:05:48,920
Okay, I like that analogy.

158
00:05:48,920 --> 00:05:52,880
So how does continuous monitoring actually work in practice?

159
00:05:52,880 --> 00:05:57,960
Our source material hit outlines a six step process, a cyclical process, which is key

160
00:05:57,960 --> 00:05:58,960
here.

161
00:05:58,960 --> 00:06:02,760
It's defined, established, implement, analyze, respond, review.

162
00:06:02,760 --> 00:06:04,680
Okay, so break that down a little bit.

163
00:06:04,680 --> 00:06:07,640
So first, you've got to define your objectives.

164
00:06:07,640 --> 00:06:09,480
What are you trying to protect?

165
00:06:09,480 --> 00:06:11,560
What are your biggest threats?

166
00:06:11,560 --> 00:06:14,240
Then establish your monitoring infrastructure.

167
00:06:14,240 --> 00:06:18,120
What tools, what procedures you're going to use, then of course you got to implement them.

168
00:06:18,120 --> 00:06:21,560
And then continuously analyze that data you're collecting.

169
00:06:21,560 --> 00:06:24,480
If there's an incident, you respond accordingly.

170
00:06:24,480 --> 00:06:29,160
And then review the whole process to see what worked, what could be improved, always learning,

171
00:06:29,160 --> 00:06:30,160
always adapting.

172
00:06:30,160 --> 00:06:32,240
It's that feedback loop that's so crucial.

173
00:06:32,240 --> 00:06:33,240
Exactly.

174
00:06:33,240 --> 00:06:35,800
And a big part of that analyze phase.log analysis.

175
00:06:35,800 --> 00:06:36,800
Okay, log analysis.

176
00:06:36,800 --> 00:06:37,800
Okay, log analysis.

177
00:06:37,800 --> 00:06:41,720
Starting through all those digital trails that every user, every system, leads behind.

178
00:06:41,720 --> 00:06:47,320
Precisely, every action taken on a network, it gets recorded in logs, every log in attempt,

179
00:06:47,320 --> 00:06:49,840
every file access, every email sent.

180
00:06:49,840 --> 00:06:53,600
Log analysis is about making sense of all that data.

181
00:06:53,600 --> 00:06:57,320
Connecting the dots, looking for those patterns, those subtle anomalies, that might just

182
00:06:57,320 --> 00:06:58,320
point to a threat.

183
00:06:58,320 --> 00:07:00,040
It's like those crime dramas, right?

184
00:07:00,040 --> 00:07:03,040
They're analyzing phone records, piecing together, someone's movements.

185
00:07:03,040 --> 00:07:04,040
Exactly.

186
00:07:04,040 --> 00:07:06,960
A single log entry might not tell you much on its own.

187
00:07:06,960 --> 00:07:13,080
And when you start correlating events across multiple systems, across time, you start to see

188
00:07:13,080 --> 00:07:14,520
the bigger picture.

189
00:07:14,520 --> 00:07:19,320
Let's say you see a user downloading a huge amount of data at 30 AM.

190
00:07:19,320 --> 00:07:21,400
Maybe not that unusual on its own, right?

191
00:07:21,400 --> 00:07:27,640
But what if that same user just minutes before, accessed a sensitive database for the first

192
00:07:27,640 --> 00:07:28,640
time ever?

193
00:07:28,640 --> 00:07:29,640
Okay.

194
00:07:29,640 --> 00:07:32,200
And what if their login location shows there suddenly in a different country?

195
00:07:32,200 --> 00:07:34,160
Now, you've got a pattern.

196
00:07:34,160 --> 00:07:35,160
Something worth investigating.

197
00:07:35,160 --> 00:07:36,160
Exactly.

198
00:07:36,160 --> 00:07:38,720
We've talked a lot about intrusions, right?

199
00:07:38,720 --> 00:07:40,240
People trying to get it, I am.

200
00:07:40,240 --> 00:07:42,680
But what about data getting OUT?

201
00:07:42,680 --> 00:07:45,120
Egress monitoring, right?

202
00:07:45,120 --> 00:07:46,400
Egress monitoring.

203
00:07:46,400 --> 00:07:50,480
All about controlling the flow of data leaving your network.

204
00:07:50,480 --> 00:07:51,480
Uh-huh.

205
00:07:51,480 --> 00:07:56,720
Imagine setting up a custom's checkpoint, but for all data leaving your organization.

206
00:07:56,720 --> 00:07:57,720
Okay.

207
00:07:57,720 --> 00:08:01,400
So if someone tries to, I don't know, sneak out of flash drive full of sensitive information.

208
00:08:01,400 --> 00:08:02,840
Yeah, out the back door.

209
00:08:02,840 --> 00:08:04,840
Egress monitoring should be that a catch it.

210
00:08:04,840 --> 00:08:09,880
So, about setting those rules, those policies for what data can leave when and who we can

211
00:08:09,880 --> 00:08:10,880
go to.

212
00:08:10,880 --> 00:08:14,320
So it's like a security guard checking your bag on the way out of a museum, making sure you're

213
00:08:14,320 --> 00:08:16,560
not walking away with any priceless artifacts.

214
00:08:16,560 --> 00:08:17,560
Exactly.

215
00:08:17,560 --> 00:08:19,920
And attackers, they're becoming more creative.

216
00:08:19,920 --> 00:08:23,240
Data loss prevention techniques, DLP, or becoming essential.

217
00:08:23,240 --> 00:08:26,600
These technologies can actually identify sensitive data.

218
00:08:26,600 --> 00:08:29,400
Think credit card numbers, intellectual property, things like that.

219
00:08:29,400 --> 00:08:30,400
Okay.

220
00:08:30,400 --> 00:08:33,280
And then block any unauthorized attempts to send it outside the network.

221
00:08:33,280 --> 00:08:39,360
So it's like what a super sniffer dog at that custom's checkpoint able to sniff out even

222
00:08:39,360 --> 00:08:42,240
the most cleverly hidden contraband?

223
00:08:42,240 --> 00:08:43,920
Love the analogy.

224
00:08:43,920 --> 00:08:46,000
But even DLP isn't foolproof.

225
00:08:46,000 --> 00:08:50,200
Attackers are always finding new ways to get around those security measures.

226
00:08:50,200 --> 00:08:52,640
One method that we see a lot is steganography.

227
00:08:52,640 --> 00:08:54,120
Steganography, that's a good one.

228
00:08:54,120 --> 00:08:56,040
It's like hiding in plain sight, right?

229
00:08:56,040 --> 00:08:57,040
Exactly.

230
00:08:57,040 --> 00:08:59,080
Hiding a secret message in an image file.

231
00:08:59,080 --> 00:09:00,080
You got it.

232
00:09:00,080 --> 00:09:02,760
It's like digital camouflage for data.

233
00:09:02,760 --> 00:09:07,920
And while it can be used for perfectly legitimate purposes, it's also a favorite tool for

234
00:09:07,920 --> 00:09:13,080
cyber criminals to try and sneak that stolen data past the security checkpoints.

235
00:09:13,080 --> 00:09:17,200
So that's why organizations are using specialized diginography detection tools.

236
00:09:17,200 --> 00:09:22,200
They analyze those files no matter how well disguised and try to uncover any hidden messages.

237
00:09:22,200 --> 00:09:24,600
It's a constant arms race, isn't it?

238
00:09:24,600 --> 00:09:26,200
Always one step ahead.

239
00:09:26,200 --> 00:09:30,920
The security experts build the walls higher and the attackers just find craftier ways to

240
00:09:30,920 --> 00:09:31,920
tunnel through them.

241
00:09:31,920 --> 00:09:34,200
It really is a means you think of those old spy movies.

242
00:09:34,200 --> 00:09:35,200
It does.

243
00:09:35,200 --> 00:09:40,400
Which speaking of spies brings us to another critical aspect of cyber security.

244
00:09:40,400 --> 00:09:42,080
Threat intelligence.

245
00:09:42,080 --> 00:09:43,080
Knowing your enemy.

246
00:09:43,080 --> 00:09:44,080
Oh, yes.

247
00:09:44,080 --> 00:09:45,720
Tell us more.

248
00:09:45,720 --> 00:09:47,720
So threat intelligence.

249
00:09:47,720 --> 00:09:49,800
Knowing your enemy.

250
00:09:49,800 --> 00:09:53,080
How do organizations actually get that intel?

251
00:09:53,080 --> 00:09:54,080
It's a process.

252
00:09:54,080 --> 00:09:55,800
A combination of things really.

253
00:09:55,800 --> 00:09:57,200
There's open source intelligence.

254
00:09:57,200 --> 00:10:01,840
Things like keeping an eye on hacker forums, monitoring malware campaigns, staying

255
00:10:01,840 --> 00:10:04,680
up to date on the latest vulnerabilities that are being exploited.

256
00:10:04,680 --> 00:10:05,680
You know, that kind of thing.

257
00:10:05,680 --> 00:10:06,680
Okay.

258
00:10:06,680 --> 00:10:07,840
But then there's also closed source intelligence.

259
00:10:07,840 --> 00:10:11,840
This is stuff that comes from security vendors, government agencies, organizations that

260
00:10:11,840 --> 00:10:14,480
have dedicated teams who are tracking these threats.

261
00:10:14,480 --> 00:10:19,440
So it's like having this global network of informants feeding you information about what's

262
00:10:19,440 --> 00:10:20,440
happening.

263
00:10:20,440 --> 00:10:24,160
And what do organizations actually do with all this intelligence?

264
00:10:24,160 --> 00:10:26,240
Well they use it to anticipate.

265
00:10:26,240 --> 00:10:30,280
To try and get ahead of those threats, mitigate them before they even happen.

266
00:10:30,280 --> 00:10:31,280
Proactive.

267
00:10:31,280 --> 00:10:32,280
Exactly.

268
00:10:32,280 --> 00:10:36,640
It's about understanding the tactics, the techniques these attackers are using.

269
00:10:36,640 --> 00:10:38,880
And then strengthening their defenses accordingly.

270
00:10:38,880 --> 00:10:41,640
And I'm guessing this is where the cyber kill chain comes in.

271
00:10:41,640 --> 00:10:42,640
Absolutely.

272
00:10:42,640 --> 00:10:45,800
We touched on it earlier, but I think now is a good time to really kind of dive in a

273
00:10:45,800 --> 00:10:46,800
little deeper.

274
00:10:46,800 --> 00:10:47,800
Yeah, good idea.

275
00:10:47,800 --> 00:10:48,800
Yeah.

276
00:10:48,800 --> 00:10:51,600
So the cyber kill chain is developed by Lockheed Martin.

277
00:10:51,600 --> 00:10:55,000
And it breaks down a cyber attack into seven stages.

278
00:10:55,000 --> 00:11:00,880
So for instance, reconnaissance, weaponization, delivery, exploitation, installation, commanding control,

279
00:11:00,880 --> 00:11:03,000
and then finally actions on objective.

280
00:11:03,000 --> 00:11:04,000
Seven stages.

281
00:11:04,000 --> 00:11:05,000
Okay.

282
00:11:05,000 --> 00:11:09,000
And by understanding each of these stages, organizations can then start to identify their own

283
00:11:09,000 --> 00:11:12,000
weaknesses and build better defenses to address them.

284
00:11:12,000 --> 00:11:15,920
So it's like a playbook in a way you can anticipate the attackers moves.

285
00:11:15,920 --> 00:11:16,920
Yes, exactly.

286
00:11:16,920 --> 00:11:20,200
So like, let's take reconnaissance for example.

287
00:11:20,200 --> 00:11:22,320
What actually happens during that phase?

288
00:11:22,320 --> 00:11:25,280
So reconnaissance, this is all about gathering information.

289
00:11:25,280 --> 00:11:27,720
Think of it like, you know, casing a bank before robbing it.

290
00:11:27,720 --> 00:11:28,720
Okay.

291
00:11:28,720 --> 00:11:32,800
The attackers, they might be scanning your website looking for vulnerabilities, maybe searching

292
00:11:32,800 --> 00:11:38,240
for employee information online, even trying to gain access through fishing emails.

293
00:11:38,240 --> 00:11:39,240
Yeah.

294
00:11:39,240 --> 00:11:40,240
Just to see what they're dealing with.

295
00:11:40,240 --> 00:11:47,240
So if organizations can recognize those signs that reconnaissance happening early on,

296
00:11:47,240 --> 00:11:50,280
they might be able to stop that attack before it even really gets started.

297
00:11:50,280 --> 00:11:51,280
Wow.

298
00:11:51,280 --> 00:11:53,400
That's the power that cyber kill chain framework.

299
00:11:53,400 --> 00:11:59,280
It gives you that roadmap for understanding how attackers think and how to disrupt them.

300
00:11:59,280 --> 00:12:01,320
It's amazing how much strategy goes into this.

301
00:12:01,320 --> 00:12:03,200
It really is like a chess match, isn't it?

302
00:12:03,200 --> 00:12:04,200
It really is.

303
00:12:04,200 --> 00:12:06,840
Both sides constantly trying to outmaneuver each other.

304
00:12:06,840 --> 00:12:11,320
And we've talked a lot about these external threats, hackers, you know, outside the organization

305
00:12:11,320 --> 00:12:12,480
trying to break in.

306
00:12:12,480 --> 00:12:16,000
But what about the threats that come from inside an organization?

307
00:12:16,000 --> 00:12:17,320
The insider threat.

308
00:12:17,320 --> 00:12:18,840
Ah, yes.

309
00:12:18,840 --> 00:12:19,840
The insider threat.

310
00:12:19,840 --> 00:12:21,160
That's a whole other ballgame.

311
00:12:21,160 --> 00:12:22,600
That's where it gets really tricky.

312
00:12:22,600 --> 00:12:24,840
Because how do you even begin to address that?

313
00:12:24,840 --> 00:12:28,200
Well, this is where user-in-ended behavior analytics comes in.

314
00:12:28,200 --> 00:12:29,200
We call it UEBA.

315
00:12:29,200 --> 00:12:30,200
UEBA.

316
00:12:30,200 --> 00:12:35,280
So most security tools, they focus on those known threats, those known vulnerabilities.

317
00:12:35,280 --> 00:12:36,280
UEBA.

318
00:12:36,280 --> 00:12:41,120
It's about understanding what's normal behavior within an organization and then identifying

319
00:12:41,120 --> 00:12:43,080
anything that deviates from that norm.

320
00:12:43,080 --> 00:12:47,680
Because it's like having what a security camera that's not just recording what people are doing,

321
00:12:47,680 --> 00:12:49,840
but also analyzing their behavior.

322
00:12:49,840 --> 00:12:51,720
To see if anything is out of character.

323
00:12:51,720 --> 00:12:53,040
Perfect analogy.

324
00:12:53,040 --> 00:12:58,200
So for example, let's say you have an employee and they normally only have our access

325
00:12:58,200 --> 00:12:59,960
marketing documents.

326
00:12:59,960 --> 00:13:05,120
But suddenly, they're downloading huge amounts of financial data in the middle of the night.

327
00:13:05,120 --> 00:13:06,120
Red flag.

328
00:13:06,120 --> 00:13:07,120
Exactly.

329
00:13:07,120 --> 00:13:10,840
Or imagine a user's account and it's exhibiting unusual activity, maybe they're

330
00:13:10,840 --> 00:13:13,440
logging in from multiple locations at the same time.

331
00:13:13,440 --> 00:13:15,880
Or accessing systems they've never even touched before.

332
00:13:15,880 --> 00:13:17,760
These are things that might indicate something's up.

333
00:13:17,760 --> 00:13:19,240
It's like in real life, right?

334
00:13:19,240 --> 00:13:21,880
And you notice someone's acting out of character.

335
00:13:21,880 --> 00:13:25,760
It might not be anything nefarious, but it's worth at least a second look.

336
00:13:25,760 --> 00:13:29,480
But how do you even teach a system what normal is in the first place?

337
00:13:29,480 --> 00:13:30,480
That's the thing with UEBA.

338
00:13:30,480 --> 00:13:32,760
It learns over time.

339
00:13:32,760 --> 00:13:39,720
It builds up this baseline of normal behavior for every user, every entity on that network,

340
00:13:39,720 --> 00:13:42,400
just by analyzing all the historical data.

341
00:13:42,400 --> 00:13:45,120
And then it's constantly looking for those anomalies.

342
00:13:45,120 --> 00:13:48,880
Anything that deviates from the baseline, it flags it for the security team so they

343
00:13:48,880 --> 00:13:49,880
can investigate.

344
00:13:49,880 --> 00:13:53,960
Wow, so this is like having a digital detective constantly on the lookout.

345
00:13:53,960 --> 00:13:54,960
Pretty much.

346
00:13:54,960 --> 00:13:55,960
That's amazing.

347
00:13:55,960 --> 00:13:57,960
But this is incredibly complex stuff.

348
00:13:57,960 --> 00:14:03,440
I mean, what kind of expertise goes into building and managing these systems?

349
00:14:03,440 --> 00:14:05,280
Well, you've got your security analyst, of course.

350
00:14:05,280 --> 00:14:09,120
They're modern, the alerts, they're investigating incidents responding to threats as they

351
00:14:09,120 --> 00:14:10,120
happen.

352
00:14:10,120 --> 00:14:12,120
Then you've got security engineers.

353
00:14:12,120 --> 00:14:13,120
They're the architects.

354
00:14:13,120 --> 00:14:14,640
They build these security systems.

355
00:14:14,640 --> 00:14:19,800
Configuring firewalls, implementing intrusion detection systems, setting up those seam and

356
00:14:19,800 --> 00:14:21,840
sore platforms, the whole nine yards.

357
00:14:21,840 --> 00:14:23,000
Right, it takes a team.

358
00:14:23,000 --> 00:14:27,600
And then you have your security researchers who are constantly probing for those new vulnerabilities,

359
00:14:27,600 --> 00:14:30,240
developing new techniques, trying to stay one step ahead of the bad guys.

360
00:14:30,240 --> 00:14:33,280
This is a whole ecosystem of people working together.

361
00:14:33,280 --> 00:14:34,280
Absolutely.

362
00:14:34,280 --> 00:14:35,600
And it's not just technical skills either.

363
00:14:35,600 --> 00:14:37,480
It's that communication, that collaboration.

364
00:14:37,480 --> 00:14:38,480
It's all critical.

365
00:14:38,480 --> 00:14:42,080
Right, because you could have the most sophisticated security systems in the world, but if someone

366
00:14:42,080 --> 00:14:44,320
leaves their password on a sticky note.

367
00:14:44,320 --> 00:14:45,320
Exactly.

368
00:14:45,320 --> 00:14:46,320
Or falls for a fishing scam.

369
00:14:46,320 --> 00:14:47,320
It's all for nothing.

370
00:14:47,320 --> 00:14:48,320
It's about layers.

371
00:14:48,320 --> 00:14:49,320
You need the technology.

372
00:14:49,320 --> 00:14:52,040
You need the people and the processes to make it all work.

373
00:14:52,040 --> 00:14:57,400
Well said, we've covered a lot of ground in the steep dive from the front lines, intrusion

374
00:14:57,400 --> 00:15:01,840
detection, all the way to the nuances of user behavior analysis.

375
00:15:01,840 --> 00:15:04,080
And it's clear, cybersecurity.

376
00:15:04,080 --> 00:15:06,560
It's not a one-size-fits-all solution.

377
00:15:06,560 --> 00:15:11,240
It's this multifaceted, always evolving field.

378
00:15:11,240 --> 00:15:12,240
Oh, we evolving.

379
00:15:12,240 --> 00:15:14,240
That requires vigilance adaptability.

380
00:15:14,240 --> 00:15:17,800
A real deep understanding of both the technical and human elements.

381
00:15:17,800 --> 00:15:19,480
Significent, I bet, or myself.

382
00:15:19,480 --> 00:15:22,880
And you know, if there's one thing I hope our listeners take away from this deep dive,

383
00:15:22,880 --> 00:15:25,000
it's that staying informed is key.

384
00:15:25,000 --> 00:15:29,640
The more you know about the latest threats, the mitigation strategies, the better equipped

385
00:15:29,640 --> 00:15:33,360
you'll be to navigate this digital world safely, securely.

386
00:15:33,360 --> 00:15:34,360
Could an agree more?

387
00:15:34,360 --> 00:15:38,920
Sir, dear listener, as you go about your digital day, remember the lessons we've talked about.

388
00:15:38,920 --> 00:15:42,120
Cyber security, it's not just about protecting data.

389
00:15:42,120 --> 00:15:46,360
It's about protecting our interconnected world, ensuring a safer, more resilient, digital

390
00:15:46,360 --> 00:15:47,960
future for everyone.

391
00:15:47,960 --> 00:16:12,960
Until next time, stay curious, stay vigilant, and stay secure.

