Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Cybersecurity Is an Ever-Changing Battlefield

by The Gurus
June 17, 2020
in This Week's Gurus
Cybersecurity Robustness
Share on FacebookShare on Twitter

Just like in combat operations, cyber operations are changing on a second-to-second basis. To effectively combat an insurgency, organisations must drive to an intelligence-driven operations centre. In this ever-changing battlefield, internal and external threat intel are now crucially important to combating attackers.

Even as a steady drumbeat of headlines keeps the world’s attention focused on cybercrimes, such as ransomware and cryptojacking, in the dark corners of the internet, attackers are busy refining their craft. Cyber attackers are honing their ability to remain undetected inside the enterprises they’ve breached, and evolving their attacks to counter defenders’ response efforts.

Business leaders can no longer get by thinking an attack won’t happen to them. Attacks that were once reserved for sophisticated campaigns have become an everyday reality. Most organisations remain woefully unprepared to combat such attacks, with the majority yet to create and implement proactive incident response plans, continuing instead to lean heavily on outdated legacy antivirus and firewall tools for protection.

IT leaders need to understand the ever-shifting landscape of their environment. In a tactical sense, this can be best facilitated in an automated fashion by collecting and using the proper telemetry and intelligence. A strategic understanding of your environment will be key to driving a winning strategy, starting with these fundamental factors:

  • Time – How much time does your staff have? What is delta on dwell time of the last adversary?
  • Money – What is your security budget? 
  • Equipment – What tools do you have? Are they integrated?
  • Culture – What’s the culture of your organisation?
  • Attackers – How are they attacking you and for what aim?

The war for our systems is now upon us and it’s time we adopt new ways of thinking about and addressing the problem. We need to think less like law enforcement and soldiers and more like an insurgent.

Counterinsurgency in cyberspace manifests shared risk.  We must discreetly observe the adversary and suppress their activity as we force them to become resource constrained.

According to our Quarterly Incident Response Threat Report (QIRTR) counterinsurgency is playing out in a number of ways:

Nearly half (46%) of incident response professionals say they’ve experienced instances of counter incident response, another concerning sign that attackers have become increasingly sophisticated and are initiating longer-term campaigns — as well as a clear signal that incident response must get stealthier.

Nearly 60% of attacks now involve lateral movement, which means attackers aren’t just going after one component of an organisation. They’re getting in, moving around and seeking more targets as they go. Of note, 100% of respondents say they’ve seen PowerShell used for attempted lateral movement.

A growing number of hackers won’t stop at a single network — they’re after your clients’ partner and customer infrastructure as well. A full 36% of our respondents say they see attacks where the victim was primarily used for island hopping.

Intrusion suppression is a viable architectural model whose core tenant lies in can you detect, deceive, divert, contain, and hunt an adversary, unbeknown to the adversary. We must dig at the roots of the insurgencies footprint on our networks and begin the hunt.

As military strategist Sun Tzu advised, “Be extremely subtle, even to the point of formlessness. Be extremely mysterious, even to the point of soundlessness. Thereby you can be the director of the opponent’s fate.”

The commercial cyber equivalent of that would be: identities, data, systems, applications and communications. Ask yourself, “Is my list of identities accurate, how do I ensure no unauthorised identities have been added or privileges have been escalated?” For example, is your list of data updated manually or automatically and how do you know a change has been made?

For too long, we have relied on Lockheed Martin’s Kill Chain to understand and predict attacker behaviour.  This framework does not account for the psychology of the adversary, nor does it truly dig into the tactical phenomenon associated with the phases of attack. We would suggest embracing a new, predictive model, one which takes into account the intent and cognition of a cybercriminal – a framework that studies the threat behaviours a.k.a.- modus operandi of elite hacker crews and allows you, as the defender, to anticipate and suppress the contemporary phases of a cyberattack.

Tags: CybersecurityTechnology
ShareTweet
Previous Post

Malware Loaders Continue to Evolve, Proliferate

Next Post

Five common myths of SMBs when it comes to cyber security and online encryption

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol