Book Image

The Cybersecurity Playbook for Modern Enterprises

By : Jeremy Wittkop
Book Image

The Cybersecurity Playbook for Modern Enterprises

By: Jeremy Wittkop

Overview of this book

Security is everyone's responsibility and for any organization, the focus should be to educate their employees about the different types of security attacks and how to ensure that security is not compromised. This cybersecurity book starts by defining the modern security and regulatory landscape, helping you understand the challenges related to human behavior and how attacks take place. You'll then see how to build effective cybersecurity awareness and modern information security programs. Once you've learned about the challenges in securing a modern enterprise, the book will take you through solutions or alternative approaches to overcome those issues and explain the importance of technologies such as cloud access security brokers, identity and access management solutions, and endpoint security platforms. As you advance, you'll discover how automation plays an important role in solving some key challenges and controlling long-term costs while building a maturing program. Toward the end, you'll also find tips and tricks to keep yourself and your loved ones safe from an increasingly dangerous digital world. By the end of this book, you'll have gained a holistic understanding of cybersecurity and how it evolves to meet the challenges of today and tomorrow.
Table of Contents (15 chapters)
1
Section 1 – Modern Security Challenges
5
Section 2 – Building an Effective Program
9
Section 3 – Solutions to Common Problems

Understanding the risk from targeted attacks

As we discussed in Chapter 2, The Human Side of Cybersecurity, all cyber attacks are people attacking people. Understanding the people behind the attacks helps defenders prioritize their investments to protect themselves appropriately. It is not economically feasible for a company to defend itself from every potential attack.

The first threat actor group we will explore are organized criminals. The term organized is used loosely in this context because these actors range from sophisticated groups with defined hierarchies to informal cooperatives of people who have never met outside of dark web forums. While there are multiple types of threat actors, what unites all threat actors are their motivations and tactics. In the following sections, we will learn about the various types of threat actors and the common tactics they use to attack victims.

Organized crime

Organized criminals in cyberspace are no different from organized criminals...