This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Navigating Cybersecurity’s New Frontiers and Understanding the Modern Threat actor

Download resources

About this session

Peter Smetny-Sowa, regional VP of systems engineering at Fortinet, maps today's threat-actor landscape from opportunistic script kiddies through hacktivists, structured cybercriminal groups and well-funded nation-state operators, then walks through several recent breaches: a socially engineered casino intrusion that spread from stolen credentials to physical door systems and cost over 100 million dollars, a SaaS password manager compromised through an engineer's vulnerable personal software, a file-transfer supply-chain breach that hit tens of millions of users, and a CI/CD pipeline breach used to tamper with a build script, showing identity, cloud misconfiguration and supply chains as recurring root causes. He covers how generative AI cuts both ways, sharpening phishing and deepfake fraud for attackers while speeding malware classification and alert triage for defenders, and argues for threat-informed defense: map ATT&CK techniques against real CVEs and prioritize patching with EPSS exploit-likelihood scores rather than CVSS alone. He closes on resilience moves: harden the fundamentals highlighted by CIS, layer zero trust checks beyond credentials, deploy deception assets to slow lateral movement, and monitor dark-web forums for exposed corporate credentials.

CISOs face a cybersecurity landscape characterized by evolving challenges and transformative opportunities. Meanwhile threat actors have been evolving their adversarial toolkits and techniques to circumvent existing security controls. So how can CISO ensure the security of their organizations? Whether balancing the risks and rewards of innovation, investing in proactive threat prevention and automation, or adopting nimble security models that reduce attack surfaces – the right strategy can bolster cyber-resilient organizations that navigate today’s dynamic environment and help protect against the modern threat actor. In this session we will dive into the threat actors and their motivation as well as strategies we can use to bolster the security of our organizations from these actors.

Key takeaways

  • Audit MFA and helpdesk reset processes; several major breaches in the talk began with social engineering that bypassed multi-factor authentication rather than a technical exploit.
  • Prioritize patches with an exploit-likelihood score such as EPSS instead of CVSS severity alone, since it can cut the patch list roughly in half for the same coverage.
  • Map your detections against a technique framework like MITRE ATT&CK to find where an attack would evade your current tools before an incident, not after.
  • Extend zero trust checks beyond the password: evaluate device posture, location, timing and typical application use before granting or renewing access.
  • Deploy deception assets (decoys) on the path to high-value systems so lateral movement burns attacker time and reveals its own techniques.

Speakers

Peter Smetny-Sowa
Peter Smetny-Sowa
Regional Vice President, Systems Engineering · Fortinet
Peter Smetny-Sowa is a seasoned cybersecurity expert renowned for his expertise in protecting organizations from cyber threats and ensuring the confidentiality, integrity, and availability of critical digital assets. Currently serving as the Vice… Read moreRead less

Peter Smetny-Sowa is a seasoned cybersecurity expert renowned for his expertise in protecting organizations from cyber threats and ensuring the confidentiality, integrity, and availability of critical digital assets. Currently serving as the Vice President of Systems Engineering at Fortinet in Ottawa, Peter collaborates with Federal Government departments and large enterprises, offering guidance on the design, deployment, and operation of cybersecurity solutions. His extensive experience includes working with national carriers and service providers to secure their infrastructures and develop security service offerings.

Resources

Tags

More from GoSec 2024

Also from Peter Smetny-Sowa

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.