Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

What you don’t know, won’t scare you

by The Gurus
July 7, 2015
in This Week's Gurus
Share on FacebookShare on Twitter

What you don’t know, won’t scare you

By Matthias Maier, Product Marketing Manager at Splunk

Insider Threats, Advanced Persistent Threats, Spear Phishing: these terms are enough to keep CISOs awake at night. In days gone by, you could identify malware, add it to a threat list and eliminate. But the new generation of security threats is much harder to find: they’re new every time and often tailored to the victim.
As a result, a new Quocirca report shows that the more visibility businesses have into these new security threats, the more concerned about them they become. ‘Master of Machines II: Conquering complexity with operational intelligence’ asked European organisations about their top technology concerns, and their ability to capture machine data. Some of the top concerns – such as down time and managing data chaos – were reduced with greater operational intelligence. The odd one out is security. Companies with higher levels of operational intelligence (the ability to draw intelligence from machine data) are actually more concerned about security threats.
Those with the maximum level of operational intelligence had an average concern rating of 3.88 for security. The average for the research was 2.58. Those with very low operational intelligence, rated security 2.09, suggesting that perhaps they have their heads in the sand.
However, while the general view applies across Europe, the national level of security focus does cause variance country-by-country. France, for instance, has the highest level of operational intelligence (2.04). That doesn’t make them the most concerned about security however, a phenomenon that exists in the UK (3.27).
So are we in a worse position?
The increased concern comes from the fact that there is more visibility and awareness of what’s actually going on. The scale and severity of the threats is more apparent; those with their heads in the sand do not have this awareness, resulting in a complacent approach to the modern threat landscape.
“There are those who’ve been hacked…and those who don’t know” – John Chambers, CEO of Cisco at the World Economic Forum
But this is the crucial benefit as well. Insider threats, spear phishers and APTs all leave anomalies in the network, through activity and communication trails happening. Companies will not detect these anomalies unless they have two things:
1 – A knowledge of what normal activity looks like
2 – The analytics to detect any variation from normal
Understanding the baseline of what’s normal is easier said than done. The whole network needs to be seen and understood in a ‘normal’ environment – and how often does that really exist?
It’s too much for one person – and difficult for many technology tools to achieve. You need every byte of log data collected together to set up that baseline. You then need to compare every byte of new information against it…in near real-time.
The nature of some threats is that they will cause small anomalies and then sit dormant in the network for weeks and months. They’re hard to spot at this point, it’s only their entrance that causes a ripple.
Additional visibility and insight also helps to protect against socially engineered attacks. If genuine user credentials have been obtained by hackers, they will look like the real thing. However, their intentions will be more malicious; at some point they will access a server, or print documents that they are not expected to or they come from a source that was not expected to. These anomalies can trigger action to tackle the “authorised” threat.
It’s a complex and changing environment of challenges. The next generation of threats, whether they come through on-the-ground social engineering or other methods such as spear phishing, are real, dangerous and difficult to pick up. Organisations need to be taking an analytics-based approach if they are to establish what ‘normal’ looks like and stand a chance at identifying the very faint fingerprints of an advanced threat.

Tags: APTsCISOcyber secutityinformation securityinfosecinfosecurityinsider threatsit securityMalwarePhishingQuocircaSplunk
ShareTweet
Previous Post

Nearly 5,000 new Android malware strains are discovered everyday

Next Post

UK small businesses in the dark about cyber security, with over half not prepared for data breaches

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol