Skip to content

Davey Winder

delivering award-winning technology journalism since 1991

  • home
  • about me
  • follow me on mastodon
  • privacy policy
  • Toggle search form
ice and fire 'hands' colliding

Enter boardroom, set hair on fire. How not to tackle incident response

Posted on February 22, 2018February 22, 2018 By Davey Winder 4 Comments on Enter boardroom, set hair on fire. How not to tackle incident response

Event anomalies can be an indicator of attack, but they can also rather commonly just be an IT problem too…

The Incident Response Report published today by F-Secure and summarising it’s own investigations, shines light on both attack methodologies and corporate attack reporting. Email inboxes, via the dual whammy of phishing and malicious attachments, are the most common source of breaches (34 percent combined.) The single biggest attack source was the exploitation of Internet-facing service vulnerabilities (21 percent.) Neither of which are exactly surprising statistics to be honest.
That 13 percent of the reported incidents investigated by F-Secure turned out to be false alarms is, perhaps, more so.
The number of such false alarms certainly took Tom Van de Wiele, F-Secure’s principal security consultant, by surprise and reveals an enterprise struggle with detecting what is and isn’t an attack. “Sometimes we’ll investigate and discover an IT problem rather than an attack” Van de Wiele says “which drains resources and distracts everyone from dealing with the real issue.”

 

Click here to read complete article

Analysis Tags:incident response, report

Post navigation

Previous Post: AndroRAT exposes fragmented Android ecosystem vulnerabilities
Next Post: Misconfigured memcached server DDoS threat is too powerful to be ignored

Related Articles

Forget Passwords, This New Tech Is Nearly Hacker-Proof, 1Password Says Analysis
Gmail Hackers Leave Vital Clues Behind—Check These 3 Things Now Analysis
No, 1Password Has Not Just Been Hacked—Your Passwords Are Safe Analysis
New Critical Security Warning For iPhone, iPad, Watch, Mac—Attacks Underway Analysis
New Emergency Chrome Security Update After Critical iOS 16.6.1 Release Analysis
New iPhone iOS 16 Bluetooth Hack Attack—How To Stop It Analysis

Comments (4) on “Enter boardroom, set hair on fire. How not to tackle incident response”

  1. Carole Skein says:
    March 27, 2018 at 8:03 AM

    The headline alone is worth its weight in bitcoin.

  2. Davey Winder says:
    March 29, 2018 at 8:31 AM

    Sadly, I cannot accept the credit for coming up with that. It was all the work of the creative cybersec mind that is Ian Trump. I spoke to Ian about the story, and quoted him within it; the headline was pulled straight out of that conversation. I do, however, agree that it is a blinder!!!

  3. Terry Griffiths says:
    March 29, 2018 at 8:38 AM

    Isn’t dealing with these false positives where AI enters the security response equation?

  4. Davey Winder says:
    March 30, 2018 at 7:20 AM

    AI, or more correctly ML, certainly has a role to play in filtering such alerts. Indeed, it is already playing a part in that role but it is only a matter of filtering so as to be able to send less false positives to the incident response team.

Comments are closed.

Categories

Post Archive

Tags

0day Analysis Android Apple Apps breach bug bounty Business Chrome crime Cybercrime Data Protection Encryption Enterprise Google Government Hackers Hacking Health healthcare industry iOS IoT iPhone Malware Microsoft News NHS Opinion passwords Phishing Privacy ransomware Research Russia Samsung threat intelligence Twitter Update Vulnerabilites vulnerabilities Vulnerability Windows Windows 10 zero-day

Copyright © 2025 Davey Winder .

×
Cookies
We serve cookies. If you think that's ok, just click "Accept all". You can also choose what kind of cookies you want by clicking "Settings". Read our cookie policy
Settings Refuse all Accept all
Cookies
Choose what kind of cookies to accept. Your choice will be saved for one year. Read our cookie policy
  • Necessary
    These cookies are not optional. They are needed for the website to function.
  • Statistics
    In order for us to improve the website's functionality and structure, based on how the website is used.
  • Experience
    In order for our website to perform as well as possible during your visit. If you refuse these cookies, some functionality will disappear from the website.
  • Marketing
    By sharing your interests and behavior as you visit our site, you increase the chance of seeing personalized content and offers.
Save Refuse all Accept all
GDPR Cookie Policy