Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Gov Sec conference: Don’t just monitor, do protective monitoring

by The Gurus
October 14, 2020
in Editor's News
Share on FacebookShare on Twitter

Monitoring is a key part of a cyber security approach, but look at what could be achieved with protective monitoring.

Speaking at the Government IT Security and risk management conference in London, Pankaj Mistry, head of IT Security and IT security office at the Department of Work and Pensions, said that while monitoring is one of the “ten steps to cyber security”, what should be done is proactive monitoring.

“Monitoring is about looking at network traffic to detect unusual activity and attacks, and if you design and develop it well, it will help in other areas too,” he said. “You can monitor remote workers and it may help to understand and get data you may have missed and help prevent incidents happening again in future.

“From a malware protection point of view, you can make sure it is doing what it is supposed to do and, with the information you get, it can help with information risk management and understand what you are working on as often we are too focused on alerts and events and not the underlying risk.”

However Mistry said that with the evolution of threats, monitoring is often not enough. “It is based on signatures so it will not tell you when authorised users do unusual activity, so we looked at protective monitoring,” he said.

“You may be able to pool information and see what else you can find out from it. I am sure you understand threats and vulnerabilities and you can look to CERTs for advice, but if you bring it all together and look at it together than in isolation, and by putting it all together you will see the information.”

Mistry said that putting a monitoring system in is important, but it is what you do with alerts that is crucial, and where you get the value.

“Protective monitoring gets wrapped into the security operations centre which is based on a military model with their eyes on the glass, and where you aim is down to you; but we try to do it in small steps to get confidence in the way we are doing it as with hundreds of systems it could end up as a data bunker,” he said.

“You need a sound base and we do need to change the data model as we are accountable for assurance. You need to say to your business that you are well protected.”

Mistry said that upon implementing protective monitoring, it was able to find changes being made that were not harmful, but had visibility of what was being done. He said: “We are improving our security posture and where does monitoring stop and start? Once you in the cloud, how do you get access to the logs you want and if you leave it to them [cloud provider], you will not get a full picture.

“We do think we need to embrace Big Data from an analytics point of view and we cannot afford to get some data on what going on in new infrastructure when it is not owned by us.”

Tags: Cyber SecurityGov Secinfo securityit securityprotective monitoring
ShareTweet
Previous Post

Former White House CIO to keynote ISACA Ireland

Next Post

Gov Sec conference – HMRC to begin fight back on phishing

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol