Focusing on Known Vulnerabilities – Scott Holewinski, Arctic Wolf
Scott Holewinski, senior VP and GM of digital forensics and incident response for Arctic Wolf, explains why cybersecurity teams need to focus on known vulnerabilities.
Transcript
This is texturing TV. Hey guys. Thanks for the throne.
We're here with Scott Holewinski who is senior vice president and general manager for Incident Management at arctic wolf. They are a managed service provider among other things Scott walk on the show. Hey, thanks.
Mike. Good to be here. You guys just published a report talking about how a very large percentage of the security incidents that people in Canada are not surprisingly known vulnerabilities if we know about all these vulnerabilities, how come we're unable to do something about It's a great question.
Yeah, I mean it's it's no mystery that. You know the threat actors like to take advantage and and walk through the easiest stores they can and that tends to still be external facing vulnerabilities. You know, I think.
When we look at, you know this report, we still see some of the vulnerabilities associated with Microsoft Exchange being prevalent and in particular with with vulnerabilities related to systems like email systems. It's not all just laziness where people don't want to or forgetful to patch these things. Sometimes those systems.
It's hard to take them down. You know people people need their email and you know, what's the best time to try and take down an email server and actually patch it so, you know, sometimes it's just operationally it can be difficult and as a result instead of patching it the, you know within a couple weeks of knowing about a vulnerability they need to plan for it. It might have to be at the end of the quarter or something like that.
So some of it's just kind of You know operational necessity to kind of keep some of these systems alive and there just isn't an easy way to apply the patches, you know, there's still plenty though that that can be easily patched and sometimes you know, it might be a smaller organization that simply isn't aware didn't get the notification ignored it, you know, there's a variety of reasons, but you know, I think that for some of the most prevalent ones right now related to exchange there's just some challenges to getting those those updates applied. How long is it before something that is called a zero day vulnerability becomes a known vulnerability and people start exploiting it. What's that kind of lead time?
Do you know I mean it used to be weeks or months. Now, it's hours. You know, it's it's very very quick.
You know, the thread actors are. Doing very so essentially they use free scanning tools that can scan the entire internet and they can come in in the morning and see all right here the 10,000 businesses that have this vulnerability and it's actually it's really interesting. You know, we actually like in it to kind of a sales pipeline, you know, they come in and it's like here's our opportunities.
Um, you know that we convictimize and they start going through it. There was a our team likes to kind of keep track of some of the back Channel Communications through that a lot of the threat actors use and you know, when log4j came out, you know, you know a year ago over a year ago, you know people said this is going to be the new thing everybody's going to be focused on this we're gonna see tons of attacks. A thread actor recently, you know, you know joked and said, we're still trying to get through all the exchange vulnerabilities that are out there.
We haven't even you know started to touch log4j, you know, so they've got there's still 20,000 exposed and vulnerable exchange servers that threat actors are just kind of working their way through so long story short, you know, the the identification of who might be a victim for a particular vulnerability is an automated task for these threat actors and as a result, you know, once it's published in those scanners are updated, you know, they're scanning the internet and that's why like literally within hours they can have a list of victims that they could potentially be going after. I feel like we spend a lot of time trying to figure out how to defend against what would be a very elaborate attack and requires a lot of time and effort when you know, basically we left the front door open. So I mean criminals kind of laughing at us and they're going you know, we're not gonna spend that kind of time and effort.
We're just gonna walk through the front door. Yeah, you know you hear a lot about it in cyber security right people just talk about don't people the lowest hanging fruit and it's true. You know, I think you know, we're still kind of as a you know, Society.
We are not to doing the most basic things when it comes to our basic cyber hygiene, you know, and as a result, yeah, it's still a pretty easy task for these for these threat actors to you know, perpetrate these attacks and make money off of them. So yeah until we start to your point my closing the front door folks are gonna keep walking through so, you know, we'll see it though, you know. When these new vulnerabilities come out and thread actors will hit it and hit it and hit it until they start running those scans and it becomes really hard to find an organization that you know isn't in you know, low-hanging fruit.
So, you know, and then they move on to kind of the new things so I think yeah just generally speaking. We're still a little lackadaisical when it comes to and apathetic when it comes to doing some of these simple things that can make us much more difficult to you know, take advantage of Do you think there's too much emphasis on fear mongering then instead of just thinking about who's the fundamentals of good hygiene? And if we Implement that then maybe we can worry about all this other stuff later.
I do, you know, I think when we look at What are the most effective things you know in terms of preventing these attacks? It's things like educating, you know, your employees and in making sure that that becomes a really consistent part of your culture that you have a secure culture and people like to joke about those those trainings. But if you do it consistently it does make sure that cybersecurity is always top of mind for your employees so that that needs to happen and then you know beyond that it is basic stuff multi-factor authentication, you know, although kind of user driven attacks where it was either, you know, credential harvesting or something else was, you know, certainly not the top of our list last quarter.
It's consistent. It's always there, you know, there's always some element of user air or simple credential harvesting that's being done that leads to you know, a significant number of these attacks. So yeah, we can we can carve off very easily probably 50% of these with very Like basic defenses beyond that.
Yeah, there are sophisticated attacks. There's still targeted attacks that happen but those aren't the attacks that are impacting the vast majority of businesses out there. You know, it's it's really just the Plain Jane simple stuff that you weren't a specific Target you were just an easy target.
do we I'm sort of national cyber security awareness campaign where we're going to go and educate people about the fundamentals and you know much the same way we do for healthcare or any other kind of issue that comes along that has this time cross. Cultural impact. I mean it seems like everybody needs to just spend some time with Cyber security service class or something?
Yeah. No, I mean, I think there's some movement in the right direction on that front. You know, we're still not seeing kind of everybody moving in the same direction.
But you know, there's some new programs coming out, you know for for example, and the defense industrial base. There's a new cybersecurity framework called cmmc that has Different levels to it and what I like about that framework is whereas like a lot of the nist Frameworks. It's like zero to a hundred.
It's very you're either here or here cmmc has some nice levels built in where it's a little more practical and it says hey if you're a smaller business doing this type of work, here are the basic things you should be doing if you're maybe a more sophisticated organization with multiple locations selling into the defense, you know ecosystem. Maybe your level is a little higher and we're starting to see some movement where they're again. There's just more of a practical approach to the framework that may be a business can can use because I do think there's a certain element for for certain businesses where it's overwhelming, you know, if you go and look at like innate this date under dash, you know, whatever.
It's like holy cow. There's 171 things that should be doing. So I do nothing.
Um, you know, so I think part of it is just to your point education around, you know, the right approach is to start moving in a direction of being a more secure organization and you know not getting overwhelmed that you know, you have to have every identity crossed. Like I said earlier some of the really basic stuff around, you know, configure the tools you're already paying for to turn some of those security features on you know, Microsoft Office. There's great security built in for some reason.
It's not all on by default. But you know, you don't even have to pay extra money to turn on MFA in most cases. Most people's, you know base licensed.
So, you know, yeah, there's just needs to be I think education, you know around the basics and maybe not worry so much about some of the more sophisticated defenses that quite honestly in some cases businesses, you know. necessarily need do you think that AI one day will save us from ourselves and maybe we can just automate a lot of this stuff and part of the reason people don't turn stuff on is they think that somebody else is going to turn it on for? Yeah.
No. I mean I think AI can help. You know, I think it were quite a ways out from having Security Solutions being fully automated, you know, but in terms of removing some of the noise from these systems, you know, we're already even within the Arctic Wolf platform seeing the value of machine learning in AI where you know, you can remove some of the human element from from this because that is the other side of this these tools, you know, it's no mystery a lot of them are pretty noisy and you do run into things like alert fatigue, even when you have organizations, you have a security, you know team who is Passed with you know responding to alerts coming from all of these different tools.
It's a lot and you know you end up not paying attention. The number of incidents that you know, our team responds to where there was some tool giving them some indication that something wasn't right is high. You know, it's I would say the majority of our incidents there was some indicator from some tool they were paying for that's something was all right, but you know, was anybody looking at it and was anybody taking action so, you know machine learning and AI can help in some of those situations, but we're a long way from it being completely automated.
And we reached a point where maybe it's just better to rely on a service to secure things for us. And maybe we shouldn't be trying to do this ourselves because I feel like a lot of people who don't have a lot of cybersecurity expertise. Even it people are trying to do things that maybe they should leave to the professionals.
Yeah, I mean it depends, you know your level of this station, you know, or obviously mostly working with businesses and you know, really really large organizations. Maybe they can justify the expense of building out a full blown, you know security team and a sac and everything that goes with it the tooling and upkeep. I would still argue that even with you know, significant resources available.
It can be very difficult to build those teams just from Human perspective it's hard to hire in this space. Turnover is high attrition is high. So, you know keeping a team if you can't go all in and have a really significant team, you know, keeping like a 10-person team kind of moving in the right direction and you know fully staff can be really difficult.
So, you know, I think just from building the team and resourcing the team it can be it can be difficult. But then yeah, I mean You know business has to decide where do they want to be spending their time and energy, you know, is it is it, you know driving there whatever they do in their business forward or is it, you know spending time, you know building out a Security operation. So I think In a lot of cases it does make sense to Outsource components to The Experts who can take advantage of the fact that they're not supporting Just One customer and one environment, they're supporting thousands and that background in those insights can be valuable and you can aggregate some of that data to ultimately offer a better service than maybe a business could offer just focusing alone on their on their business.
So yeah, I think there's a lot of advantage to Outsourcing some of this to experts who do a day in and day out for thousands of businesses. And so once your best advice to folks, what's the one thing you wish more folks were doing so that hey or make your life easier, but maybe a little more secure. Yeah, I mean first and forema.
I mean we talked about a few of them. I mean multifactor authentication turn it on, you know and then patching the systems as fast as you possibly can like again easier said than done in some cases but making sure that you have a robust vulnerability management system in place. You know, I think the good zero days are you know, you know, they're common they pop up and I think the good thing is it's companies are better than they used to be about getting that information out the customers and clients quickly, but make sure you take action, you know, so those are those are the most important things, you know from our perspective incidents still happen.
I mean if you you can do everything right and you know, you can still get hit so, you know again from a tooling perspective if you buying tools and paying for tools simple things like making sure you have the logging turned on and you know, those systems are Eating properly your backup systems are running properly and being checked. You know goes a long way in terms of how quickly our team can jump on it respond and help organizations ultimately recover from from these attacks. So on the preventative side, it's things like MFA and patching on kind of the response side making sure your backup systems are robust and being tested and all of your logging is turned on so our teams can unravel what happened as quickly as possible.
All right, folks you're hurting here. Once again, we have met Our Own Worst Enemy and unfortunately A Lot Like Us. Hey, thanks for being on the show.
Awesome. Thanks for having night. All right back to you guys in the studio.