Altice Portugal

Towards an Active Cybersecurity Doctrine

Our ACTIVE DOCTRINE consists of a set of fundamental principles that holistically guide our cyber security investments, resources, and controls to keep our organization cyber-safe. In addition to complying with national and EU regulations, and following the most recommended cyber controls, it must be ACTIVE to tactilely, and very quickly, counter-respond to the ever-changing hacker landscape and tactics. Particularly in the RANSOMWARE threat space For this reason, we have developed an actionable RISK MODEL with a special focus on RANSOMWARE!

Another key aspect of our doctrine, as one of our core beliefs, is to assume upfront what we call the “Mark Twain Trap” – It ain’t what you don’t know that gets you into trouble. It’s what you know for sure that just ain’t so. Our cybersecurity controls DO NOT TRUST HUMAN “BELIEFS”! They are, instead, fully supported by rational and validated metrics! Many attacks succeed around and against the internal cybersecurity team's beliefs that later proved to be wrong. TRUST NO ONE!

Our cybersecurity strategy is centered on a 360º pro-Active Doctrine, with 5 complementary dimensions, focused on continuous cyber defense and improvement: ACTIVE GOVERNANCE, ACTIVE PREVENTION, ACTIVE PROTECTION, ACTIVE DETECTION & COUNTER RESPONSE and, finally, ACTIVE RECOVERABILITY. They are all necessary! None is sufficient by itself!

These dimensions must work together, in a continuous 360º approach, supported by a comprehensive and end-to-end security oversight, by the CISO, based on metrics integrated into a central security analytics platform (CyberWatch) that then feeds our risk management ISO 22301 framework. To support governance attribution and continuous improvement.

Without proper ACTIVE GOVERNANCE, it is not possible to have a sound and effective cybersecurity strategy and execution. This is key to guaranteeing full and continuous support from top management, including necessary and rational budgeting! Another key vector is to guarantee, by the CISO, the end-to-end oversight of the state of cyber risk in the organization based on an approved corporate cyber risk model. Finally, there isn’t a proper ACTIVE GOVERNANCE without a comprehensive and effective cyber training program for all employees and users, particularly with respect to properly handling illicit emails and messaging.

ACTIVE PREVENTION and ACTIVE PROTECTION are INHIBITORs. They exist to reduce the probability of security incidents materializing or propagating, respectively.

ACTIVE PREVENTION is a top priority since it is the main INHIBITOR to viable attacks! It must cover all 4 attack surfaces in an organization: External or Internet-facing, Internal systems, 3rd Party Dependencies, and Users/People.

ACTIVE PROTECTION should follow best practices in security in-depth, but with special and additional attention on the cyber resilience of our critical assets like the Corporate Active Directory (AD) and the Corporate Backup/Restore Infrastructure. These are primary targets of hackers! Additionally, a special emphasis should be put on robust and universal 2FA/MFA in all external accesses (VPN, Citrix, Office365, …) and on a robust Privileged Access Management (PAM) solution to additionally control all accesses to privileged accounts.

ACTIVE DETECTION & COUNTER RESPONSE must guarantee that early security warnings are effectively detected, and counter-responded in useful time! Most recent cyber-attacks were only detected, by the internal security teams, after the fact. And that is not acceptable! We must guarantee the ability to detect early warnings (“security smells”, as we call them) to allow for a counter-response in useful time. And, with the current state of technology, this is only viable with integrated state-of-the-art solutions for Extended Detection and Response (XDR) / Endpoint Detection and Response (EDR), User and Entity Behavioral Analytics (UEBA) to detect suspicious behaviors, particularly around the most critical ecosystems like the AD, and SOAR playbooks for fast effective counter-response. Of course, nothing will really work at top level without trained and motivated cyber analysts. 

Finally, a critical dimension is to assure ACTIVE RECOVERABILITY! The main idea here is to guarantee that the hypercritical systems and infrastructures (i.e., the corporate Active Directory and corporate BACKUP/RESTORE infrastructure), that are required to quickly recover an organization from a nasty cyber-attack, are treated by the doctrine in a special way, receiving special oversight from the CISO. And, in addition to top cyber resilience, investments must be made to guarantee fast recoverability. Particularly for the Corporate AD infrastructure. Fortunately, there are now a few solutions that address, for example, the recoverability of a Corporate Active Directory Forest in about two hours or less (e.g., SEMPERIS). In the case of the Corporate BACKPUP/RESTORE infrastructures start by adopting a different Operating System from the common base in your organization. To isolate from potential zero-day attacks on the common base. Additionally, guarantee a second level and air-gapped backup of the most critical information required to quickly recover your essential IT infrastructure. It is crucial to guarantee ransomware-resistant backups of the most critical data.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.