Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Why To Think Like an Attacker, You Need to See Like an Attacker

by The Gurus
December 19, 2016
in This Week's Gurus
Hacker sinister threat
Share on FacebookShare on Twitter

Social media, mobile computing, cloud services and the Internet of Things (IoT) have changed the way we do business. Adversaries have changed too and are no longer merely watching networks and endpoints to determine how they will attack. Instead, they have a lot of information that they can use to their advantage and are capitalising on the fact that as we take advantage of new technologies we leave behind a digital footprint – an electronic trail of activities.
Not all digital footprints are bad – indeed a good online reputation is hugely positive. However there is a subset of a digital footprint referred to as a digital shadow which can reveal exposed personal, technical or organisational information that is often highly confidential, sensitive or proprietary. This is what adversaries are looking out for and many actively survey the digital shadows that organisations unknowingly cast and use this information to their advantage – seeing vulnerabilities and launching attacks.
To truly understand which threat actors pose a viable threat to your assets and business operations, as a security professional you need to a better understanding of your organisation’s attack surface and own set of unique threats. You need an attacker’s eye view.
While organisations have relied on cyber threat intelligence (CTI) to gain a better understanding of threats and threat actors, we need to do more. Data feeds, vulnerability feeds, indicators of compromise (IOCs) and profiles of threats and research reports will continue to be pertinent. But what’s lacking is cyber situational awareness that provides a more holistic and specific view of threats and vulnerabilities relevant to your organisation. With this view, you can think like an attacker and more effectively address potential threats, instances of sensitive data loss or compromised brand integrity.
So how do you move your security practices in this direction? This three-staged approach can help. And at each stage you’ll see real benefits.
Stage 1: Perception – Building on the internal information and CTI feeds you already gather to understand threats, the focus of this first stage is to understand how you are perceived by hostile threats. By knowing where key information assets, employee credentials and sensitive documents are being exposed online, you can understand where it is likely to be most vulnerable. Information is gathered by examining millions of social sites, cloud-based file sharing sites and other points of compromise across a multi-lingual, global environment spanning the visible, dark and deep web. Cyber situational awareness also analyses and provides information on which malicious actors might be targeting an organisation or industry, why and their methods of attack. The perception stage provides the basis for better cyber situational awareness and in and of itself provides significant new insights that you can immediately act upon to address vulnerabilities or behaviors that violate policies.
Stage 2: Comprehension – With data about yourself and your attackers, the next step is to apply context to understand what information is relevant and meaningful to your specific circumstances. You do this by ensuring that the intelligence directly references your organisation’s brands, assets, concerns and weaknesses, systems and defences (i.e., those things most relevant). Through this lens you can identify which threats pose the greatest risk and use this information to guide security investment decisions and strategies.
Stage 3: Projection – The highest level of cyber situational awareness involves making educated and informed assessments about what might be around the corner to reduce uncertainty and determine what action to take to mitigate the threat. Techniques include analysis of past behavior to predict future behavior, identification of trends, geopolitical analysis and understanding pre-cursors of previous attacks.
In the short-term, complete cyber situational awareness can prevent and mitigate harmful events. By gathering the facts about a breach, you can do damage control and close gaps, such as resetting passwords and generating takedown requests from social media and code-sharing sites.  In the longer-term it can be used to help prioritise threat protection investments and policies. For example, an organisation that has been deferring an investment in data loss prevention (DLP) technologies, armed with the understanding of a particular problem with data leaks, can re-prioritise.
Cyber situational awareness doesn’t happen overnight, but with the right approach you can see what an attacker sees, think like an attacker thinks, and better protect against cyber-related incidents today and in the future.

ShareTweet
Previous Post

SVG Ransomware: It’s About Much More than Facebook

Next Post

Trouble ahead for smart cities, predicts Tripwire’s Rekha Shenoy

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol