This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Incident Response Lessons Learned From the Front Lines

Download resources

About this session

Dan Wiley, who leads incident response at Check Point Software Technologies, reports on the cases his team worked through 2020, a year in which incident volume roughly doubled from about 2,000 to a projected 4,000. He describes remote access as the dominant entry vector, with attackers hammering RDP, VPN appliances and Citrix, and warns that once inside they move laterally within minutes, often stealing domain admin credentials with Mimikatz. He devotes most of the talk to ransomware, tracing its escalation from simple encryption to data theft, public shaming and pressure on suppliers and customers, and notes that cyber insurers increasingly decide to pay. His strongest recommendation is to secure Active Directory, deploy next-generation EDR or MDR, keep offsite backups and retire legacy Windows XP. He then covers Office 365 attacks and layered email defence, a sharp rise in ransom DDoS, and closes on brand-targeting social media threats and the mental toll of major incidents on responders.

At any moment, day or night, your organization can be victimized by devastating cybercrime. You can’t predict when cyberattacks will happen, but you can use proactive incident response to quickly mitigate its effects or prevent them altogether. It's essential to have an effective security program which includes incident response to protect your organization.

How prepared are you?

Information security success relies on people, policy, process and product however, we are only as strong as our weakest link.

Please join this session to hear from Daniel Wiley our Head of Incident Response where we will discuss lessons learned from the front lines and how you can prepare, respond, and mitigate risks. 

Key takeaways

  • Harden every remote access path (RDP, VPN, Citrix) with multi-factor authentication, fast patching, logging and something layered in front of exposed appliances.
  • Make securing Active Directory a standing program, since it is the common thread attackers use for lateral movement and privilege escalation in nearly every ransomware case.
  • Run next-generation EDR or MDR rather than legacy antivirus, and keep offsite backups so you can restore without paying a ransom.
  • Layer email defence on top of Office 365 (external MTA filtering, MFA, CASB) and routinely audit mailbox forwarding rules for attacker-added redirects.
  • Plan ahead for ransom DDoS with your ISP or a cloud scrubbing provider, and prepare responders and management for the stress of a major incident.

Speakers

Daniel Wiley
Daniel Wiley
Head of Threat Management and Chief Security Advisor · Check Point

Resources

Tags

More from GoSec 2020

Also from Daniel Wiley

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.