Role of Deception in the 'New Normal' episode artwork

EPISODE · Apr 6, 2020

Role of Deception in the 'New Normal'

from Info Risk Today Podcast · host InfoRiskToday.com

As global enterprises get their arms around supporting and securing a near-total remote workforce, their digital adversaries are adapting - and so is the role of deception technology. Carolyn Crandall of Attivo Networks discusses how deception can help mitigate new risks.

Episode metadata supplied by the publisher feed · Published Apr 6, 2020

Embed this episode

NOW PLAYING

Role of Deception in the 'New Normal'

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Hi, I'm Tom Field, Senior Vice President of editorial with information security media group. I'm talking about the evolving role of deception in the new normal, and I'm speaking with Carol and Crandall. She's the Chief Deception Officer and CMO with the TELO Networks. Carol, it's such a pleasure to talk with you again.

It's a pleasure to be here. So Carol and enterprises now are almost suddenly supporting 100% remote workforceers or close to it. How are you seeing cybersecurity organizations adapt to this sudden need? Initially, I think everybody's really focused on just getting all the workers online.

This is new, many states are still evolving to it. At this point, I don't think all dates, but there's about 20 that have not moved to a stay-at-home mandate. But as organizations are continuing to move towards needing to shelter at home, set up remote workers, it's really causing organizations to take a look at what they have for infrastructure. Are they going to be operating in a SaaS environment, a full VPN, a split VPN?

And then thinking through the consequences behind it, right? If they were all of a sudden taking everybody through a complete back-haul to their organization, do they have the bandwidth, the equipment software to do things like that? If they need to shift to a split VPN, how are they going to make adjustments to their security and doing so? What controls do they even have in SaaS environments?

That they would have typically had if people were logging in from within the corporate network? And so there's a whole bunch of new considerations that the security teams are being faced with and having to put the switch on almost overnight. And again, once I think people will start to get through just uptime, right? How do we get some employees up and running, then it's going to be a quick turn to think about the security piece of it.

Carolyn, what are some of the specific pain points you're hearing about from your customers now? Yeah, once they get past the operational and so this is the uptime piece of it, they're starting to think about what are the changes to the security. So I mentioned earlier the point about split VPNs and if you think about coming through that, a lot of the physical web filtering firewalls, IDS, ITS systems are not going to work like they used to. A lot of the traditional baseline that they had for looking at anomalous behavior are no longer going to be affected because everything has changed.

And then also having these folks coming in through VPN, it becomes very difficult to pinpoint the source of an attack. And so these are things that again, once people get past the basic uptime piece of it that they're thinking through how do I not now have a weakness through my VPN infrastructure that could be exploited by these attackers? And then on the second piece is even if they're moving to a fast or cloud-based operation, that brings a different set of security concerns into play. And do their current detection controls work the way that they lead them to within the new operating environment?

So I just, you know, I've seen a lot of change. You know, initially for a couple of weeks when people had to change, it was at uptime and now we're starting to get more calls with people going, okay, this may be going longer than we think. We need to put something that's more sustainable in the place and looking at some of the deficiencies with the current architectures that they need to close the cap on. You mentioned the attackers.

How are you seeing the adversaries adapt to this new remote workforce? Well, of course the obvious is that phishing emails is skyrocket. I've heard, you know, increases of like 600% or so since the beginning of the year. And so, you know, unfortunately, the attackers are exploited in the situation.

You know, they're definitely trying to get people to, you know, click on things that they shouldn't. Attackers are clearly going to target this VPN infrastructure as a new attack vector. And it's been an existing one, but now the opportunity is exponentially greater. The other thing that we're seeing is going to be called that attackers being very cunning and very patient.

And so they're using these opportunities as well to get access into things. So if they can get a man in the middle attack to steal credentials and theft, if they can do some active directory reconnaissance by using these tasks to get into the organization, we're definitely seeing that. And while putting an increase in ransomware attacks against the healthcare and research communities, it's very unfortunate and essentially in the word of criminal that they're doing that. But again, any time that they think they can modify something, they're going to target it.

So unfortunately, those ransomware attacks have dramatically increased as well. Well, let's talk about deception technology then. In this landscape, how are you seeing deception used to mitigate some of these new risks? Well, and it's interesting, we have always had detection as an obvious use case and even some things around VPN and fast credentials being a part of the product and solution.

And so part of the process was first talking to customers and making sure that they were using the full functionality of the solution. And then the second was going out to organizations that may be new to deception and helping them understand how we can help with that network reconnaissance detection in the middle of the way to get to text those credentials in transit theft. And then also fast credential modeling monitoring is another thing that deception platforms can be. So that's a very basic level.

And what makes that piece interesting is a lot of that can be a completely cloud-based offering because one of the other challenges we're finding is, hey, I can't take on any new equipment. I don't even have people in my offices right now. So how do I deploy new layers of security that I don't need to go on premise to do? And so the things that I just talked about, there are things that people can do all remotely as far as the deployment of operating within the cloud.

And then for others that are able to do a little bit more sophistication, they can enhance their input protection by putting in a VPN credentials, deploy fast credentials, public cloud credentials. And then they can also do some really interesting things around redirecting or misdirecting active directory attacks where it can actually feed them that fake AD information that only leads them back into a weekly environment. And so a couple of different layers are depths of security that organizations can add in. But these will definitely help reduce the risk associated to us to remote looking.

Karone made a very good point a few minutes ago when you talked about the growing realization that this could be more long-term than we might have initially thought. So as you look at the weeks ahead, perhaps the months ahead, what are some of the trends that you're going to be paying particular attention to? Yeah. So we're all tracking the number of attacks, especially those that are coming from a compromised remote system.

So how much of a reality is this going to be for increasing our risk? And it'll help companies understand, is it something that they can say with what they have? Or do they really need to make some changes sooner than later? They need to take a look at their current security controls and do an assessment, right?

Just even if you were using things like this or my attack framework and you have everything all mapped out, did you really map it out sufficiently when it comes to your remote workers and making sure that if there is any sale or bypass that happens there are the right controls in place to be able to detect early? And early is a big piece, because if you can catch them early, you're going to stop a bigger mess that will have to be cleaned up afterwards to make sure you've threatened to eradicate and prevent it from being able to come back. Other things that I think we're looking out for are ransomware attacks against the healthcare and research community. Obviously, there's an opportunity to get a quick ransomware payout if people want to go and restore quickly back to operations.

Or if they feel like they can get a jump on any of this new research coming out and monetize that, we know that the criminals are other looking for opportunities to do this. So we'll obviously be watching these face lines and trends. We will as a company also be looking at ways that our technology is being used to make sure we share those use cases and to make it easy for people to be able to adopt into them so that they can be up and running quickly. We mentioned before, reception can be up and running in an hour for companies and many times that's enough to get them by to at least give them more time to complete a more extent for the assessment of their security controls and then over time continue to close those gaps.

Well, Seth, Carol and I always enjoy talking with you. Thank you so much for taking time to share some of your observations today. Oh, thank you again. Our role right now is really to help educate people on what they can do to reduce their risk, you know, in this change climate of remote workers.

And so anything that we can do with a company to keep the cyber criminals at pay, what we want to do. So happy to help out in the way we can. Excellent. Thank you so much.

Again, I've been talking with Carolyn Crandell. She's chief deception officer and CMO with the TVO Networks for information security media group. I'm Tom Field. Thank you very much.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on April 6, 2020.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!