Forget Security Compliance, prioritise Threat Mitigation
CIOREVIEW >> Compliance >> NEWS

GSK

Steve Williamson, Audit Account Director, Information Security and Data Privacy

Forget Security Compliance, prioritise Threat Mitigation

Steve Williamson, Audit Account Director, Information Security and Data Privacy
Steve Williamson, Audit Account Director, Information Security and Data Privacy, GSK

There are few organisations that do not have a strategy to digitise, automate and become more data driven. This is enabled through cloud services, such as Azure, AWS and GCP, each providing a rich software toolbox to enable this transformation and deliver business value with greater speed than would be possible through on-pemises infrastructure.

Cloud services are key to achieving digital transformation as they enable the rapid build and deployment of business solutions.  They provide a range of technology options and services far beyond what a typical end-user organisation can maintain on-premises. For example, if we need data storage, we have the option of SQL databases, nonSQL databases, object storage, file systems, cache storage. We also have the freedom to lift and shift long-standing technologies such as Oracle databases. This all means more distributed processing, a broader range of technologies and exponential data growth.

As cyber defenders, it is our job to protect our digital assets whilst keeping abreast of the threat landscape and rapidly changing attack surface. Traditionally, we would adopt an industry standard control framework (e.g. CIS, NIST, ISO), implement it, monitor for deviations and measure maturity. This approach has served our industry well but scaling up to cover our diverse attack surface is becoming impractical.  Factor in budget constraints, stakeholder demands and more regulation, and even the most sophisticated security professionals are feeling overwhelmed.

An understanding of the threats and their consequences (i.e. cost to the organisation) should drive the modern-day security programme.  Investments in new or improved security safeguards should be prioritised based on how much risk reduction benefit can be achieved.  Risk management methodologies, such as Factor Analysis of Information Risk (FAIR) provide techniques for achieving this. 

FAIR provides the structure and methods to help us identify high likelihood threats and effective safeguards. Following a threat-based approach, cyber defenders would:

1. Identify the most valuable digital assets (Crown Jewels)

2. Build a Threat Profile

3. Assess Threat Likelihood

4. Assess the effectiveness of existing safeguards against the most likely threats

5. As necessary, implement new safeguards (people, process, technology)

An example threat profile is presented in the table below. It starts with the Threat Actor Community (TCom), together with their motives, capabilities, likely targets, and entry point into the organisation.

The next steps involve assessing threat likelihood and the effectiveness of the existing control environment. One may find that some existing controls are ineffective against a specific class of threat. For example, encryption of data at rest and 2 factor authentication are strong controls for protecting against external bad actors, but they are irrelevant against insider threats.

Assessing threat likelihood builds on this threat profile by identifying the specific actions the threat actor needs to perform to achieve their goal. In many cases, multiple exploits make up a threat scenario.  Two example threat scenarios are below. As is apparent, one is significantly more complicated than the other. That is why motivation and capability of threat action are important considerations in any threat analysis. 

Example Threat Scenarios

● Criminal threat actor gains a foothold in the network through a set of phishing emails, he downloads malware, cracks weak credentials, elevates privileges, gains access to a service account, etc, etc. queries the database, exfiltrates customer data and holds the organisation to ransom

● A Privileged User with access to the data lake downloads thousands of customer records into spreadsheets, emails these to his personal account and holds the organisation to ransom

Fleshing out threat scenarios without informed guidance or reliable breach data can be subjective, with different experts having differing views. Industry resources to assist in this exercise include the MITRE Att&ck matrix, which outlines common attack paths.  Similarly, publications such as Verizon Data Breach Investigation Report provide useful data on attack paths and their frequency.

A threat-based approach uses the same security controls as a compliance-based approach.  A threat-based approach is more targeted and drives risk-based prioritisation. In the above example, we may conclude that our biggest threat is privileged insiders, and we would prioritise detection controls, such as monitoring, alerting and data loss prevention.

In conclusion, most organisations have a diverse and distributed attack surface. Business processes increasingly rely on digital solutions and data volumes are growing exponentially. The traditional approach of applying an industry standard broadly across the digital landscape is time consuming and expensive.  A threat-based approach to security focusses on protecting the most valuable assets from most likely threats and success is measured by risk reduction.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.