Between the perception of cyber threats and the reality on the ground, a gap persists. Cyber publishers must put themselves in the shoes of hackers to better counter developments in their attack methods.
Faced with the rapid evolution of cyber threats observed in recent years, operational experience has never been as decisive as today in the design of effective cybersecurity solutions. Without immersion in crisis management and the hacker ecosystem, it becomes difficult to develop tools truly capable of countering attacks that have become sophisticated, industrialized and opportunistic.
Being in contact with victims to understand behind the scenes
For fear of reputational impact, many companies do not always disclose the true circumstances of a compromise. Phishing is frequently mentioned as an entry point even though the majority of organizations today have effective filtering solutions. In reality, a single fraudulent email alone is rarely enough to compromise the systems of large organizations.
A study points out that 30% of attacks result from the exploitation of vulnerabilities on servers exposed to the Internet, while 25% rely on the use of compromised credentials. In the context of ransomware attacks, feedback from cyber negotiators indicates an equivalent split between password theft and exploitation of unpatched vulnerabilities.
In fact, two attack vectors dominate: the purchase of stolen credentials, often collected via infostealer malware, and the exploitation of network vulnerabilities. It is this operational reality that must guide cyber defense strategies.
Feed on the enemy to better anticipate him
Direct and regular contact with attackers constitutes a source of strategic information. It makes it possible to identify weak signals, anticipate changes in operating methods and better understand the structure of the cybercriminal ecosystem. Some cybersecurity players thus integrate active observation approaches: presence on specialized forums, analysis of clandestine marketplaces, monitoring of exchanges on the darknet. Conducted in a controlled setting, these interactions provide valuable visibility into the compromised data, the tools used, the business models and the intentions of malicious groups. A strategy unfortunately little or not enough adopted by publishers of cyber solutions.
Design solutions aligned with the reality of organizations
According to a study, 65% of organizations believe they have too many security tools and 53% say their tools are not interoperable. For 77% of them, these two issues slow down the detection and remediation of threats. Indeed, the lack of interconnection between different cyber solutions and their proliferation complicates the detection and response to incidents, creating blind spots that can be exploited by attackers.
Cybercriminals take advantage of the fragmentation of defense systems to prioritize the least mature organizations or the least equipped in terms of supervision and remediation. Publishers have a role to play here. An approach based on continuous observation of threats, combined with a detailed understanding of business environments, makes it possible to design solutions that are effective, interoperable and adapted to uses.
At a time when cyber threats are evolving at a rapid pace, publishers can no longer be satisfied with a theoretical approach. Developing detailed and up-to-date knowledge of adverse practices makes it possible to develop effective solutions, ensuring both the protection of organizations and the competitiveness of publishers.