EP177 Cloud Incident Confessions: Top 5 Mistakes Leading to Breaches from Mandiant
Jun 17, 2024
auto_awesome
Mandiant consultants discuss top 5 mistakes in cloud incidents, challenges in securing hybrid environments, attack surface evaluation, IAM importance, and incident preparedness for organizations transitioning to the cloud.
Proper identity management and strong multi-factor authentication are crucial for cloud security.
Understanding attack surfaces goes beyond network vulnerabilities, focusing on privileged accounts and identity controls.
Deep dives
Importance of Identity Management in Cloud Security
Ensuring proper identity management, particularly segregating privileged accounts, enforcing strong multi-factor authentication methods such as FIDO2 security keys, and restricting password reset and MFA method modifications are essential for bolstering cloud security. Identity management plays a pivotal role in preventing unauthorized access and potential security breaches.
Expansion of Attack Surface Awareness
Organizations should broaden their understanding of attack surfaces beyond network perspectives. Apart from network vulnerabilities, focusing on trusted service infrastructure tools that deploy scripts across endpoints and maintaining visibility and controls over identity, endpoints, and privileged accounts are crucial in reducing security risks.
Role of Endpoint Security in Comprehensive Security Programs
Endpoint security, often overlooked, is a vital pillar in cloud security. Establishing robust controls, such as hardening devices, enforcing strong configuration settings like disabling WDigest on legacy Windows systems, and segmenting privileged accounts, are effective strategies to enhance security posture and prevent endpoint compromises.
Recommendations for Incident Preparedness
To enhance incident preparedness in cloud environments, maintain an updated inventory of logs with investigative value, enable necessary logs for effective detection, utilize comprehensive security tools that cover specific processes in the infrastructure, and establish predefined playbooks to respond promptly to security alerts. Proactive measures like efficient MFA and continuous monitoring can significantly mitigate security incidents.
Most organizations you see use both cloud and on-premise environments. What are the most common challenges organizations face in securing their hybrid cloud environments?
You do IR so in your experience, what are top 5 mistakes organizations make that lead to cloud incidents?
How and why do organizations get the attack surface wrong? Are there pillars of attack surface?
We talk a lot about how IAM matters in the cloud. Is that true that AD is what gets you in many cases even for other clouds?
What is your best cloud incident preparedness advice for organizations that are new to cloud and still use on-prem as well?