NetWorks Group Blog

Modeling an effective threat detection and response program

Posted by NetWorks Group on Dec 19, 2017 10:35:41 AM

Modeling an effective threat detection and response program

Know Your Enemy

Read More

Topics: Managed Detection & Response, Information Security, Threat Hunting, Threat Management

The Impact of Cybersecurity Breaches in the Healthcare Industry

Posted by Jyothish Varma on Dec 14, 2017 10:16:05 AM

Cybersecurity breaches reached unprecedented levels in 2017. Few were spared as businesses and government entities alike -- including Equifax, the British National Health Service and even the U.S. National Security Agency, as well as dozens of others -- were hit with data breaches. While frequent targets like the financial sector and retail industries experienced their fair share of attacks, the healthcare sector is now the primary target of hackers, accounting for 25 percent of all data breaches. Understanding why this is happening and the consequences of it will help you improve your company's cybersecurity defenses and mitigate future threats.

Read More

Topics: Managed Detection & Response, Information Security, Threat Management, Healthcare, HIPAA

Why You Should Be Concerned About HIPAA Security Rules Enforcement

Posted by David Howard on Dec 6, 2017 10:18:17 AM

With data breaches in the healthcare industry increasing exponentially, it's critical for those in leadership positions to get serious about HIPAA security and enforcement. You need to understand not only why HIPAA is important but how the rule enforcement process works and the penalties that can be implemented.

Read More

Topics: Information Security, Compliance, Healthcare, HIPAA

3 Common-Sense Ways to Prevent Phishing Attempts

Posted by Jyothish Varma on Nov 30, 2017 3:28:04 PM
Today, phishing is one of the most dangerous forms of online threats. In the fourth quarter of 2016 alone, social media-based phishing attempts increased 500 percent As if that weren't enough, a recent 2017 report found that the average business user comes across at least one phishing attempt via email each day.  Luckily, you can reduce the risk of phishing (and ensure you're protecting your endpoints) by recognizing the signals of phishing and taking proactive steps to prevent attacks.

What Is a Phishing Attack?

Phishing attacks take place when a hacker or thief attempts to steal sensitive information through electronic communications. This information includes but is not limited to passwords, usernames and credit card information, by sending electronic communications that look like they are from a trustworthy source. Each year, successful phishing attempts claim more than $5 billion from US consumers and businesses.
Read More

Topics: Ethical Hacking, Information Security, Threat Management

Protect. Detect. Respond: The Case for Managed Detection and Response

Posted by NetWorks Group on Nov 27, 2017 10:49:18 AM

Cyber security is on the mind of every business executive in the world. Modern security challenges are not easy to fix or even identify, and despite some misleading advertising from vendors, there is no one-size-fits-all solution. We frequently observe large visibility gaps in existing security implementations, providing even obvious red flags to slip under the radar. Firewalls and traditional antivirus software are important, but only react to known threats. Too many organizations rely on passive preventative technology for network security. Good attackers employ stealth and polymorphic tools that defy signature-based detection, allowing them to bypass these technologies all together. We must assume that threats will get in, and no system is impenetrable.  

Read More

Topics: Security Monitoring, Managed Detection & Response, Information Security, Threat Hunting, Threat Management

Active Directory Password Filters: The Missing Windows Feature

Posted by Aaron Pohl on Oct 23, 2017 11:28:38 AM

As penetration testers, we get a lot of joy out of compromising Windows networks. They are basically our favorite targets because of how insecure they are by default. Microsoft has always favored backward compatibility over security, and while it is possible to really lock down an AD (Active Directory) environment, it takes a lot of effort. While setting up an organization’s network in the first place, many admins take the stance of, “Let’s just get it working, and then we’ll add security on afterwards.” Nine times out of ten, they never go back and enable the security features until after there is an incident.

Read More

Topics: Ethical Hacking, Information Security, Penetration Testing, Threat Management

Threat Detection - Logs, Log Sources and Analysis Make All the Difference

Posted by Matt Warner on Oct 10, 2017 9:25:00 AM

Threat detection has grown to a complex and messy activity in organizations. Many utilize Security Information and Event Management systems which can play a critical role in today's enterprise.  In order to do their job, SIEMs depend on the logs generated by the enterprise's various systems. Sounds simple enough. However, in a typical Fortune 500 company scenario, an astounding amount of log data is generated. It's not at all unusual to see 10 Terabytes of plain text per month. Fact is, there can be hundreds, even thousands of sources of log data in the typical enterprise. Even small and medium sized businesses will be overwhelmed trying to collect, analyze, and store their log data. The questions are, then, “Can you collect AND analyze them all? Should you? Will the the infrastructure support storage and ongoing detection? Do you have the expertise in place to analyze logs and maintain the infrastructure to do so?”  

Read More

Topics: Security Monitoring, Managed Detection & Response, Information Security, Threat Hunting, Threat Management

Discussing Cybersecurity in the Boardroom

Posted by Jyothish Varma on Sep 20, 2017 12:55:41 PM

Discussing Cybersecurity in the Boardroom

Cyber warfare is a very real and present danger, with more companies finding themselves on the losing end of the battle. Statistics from security monitoring services show that in a single hour alone, there are about 184,188 recorded cyber security breaches. This should be a wake-up call to key stakeholders, the majority of whom assume that cybersecurity is simply an IT problem and responsibility.

Read More

Topics: Information Security, Threat Management

Equifax breach: A learning opportunity to get ahead of the constant threats

Posted by Amanda Berlin on Sep 8, 2017 12:10:43 PM

If you haven’t heard already, Equifax one of the “big-three” U.S. credit bureaus has announced a data breach that may have affected 143 million Americans, including consumer Social Security numbers, birth dates, addresses and some driver’s license numbers. For a good rundown of what has transpired so far, Krebs on Security has a solid in-depth article on it here. Every time there is a breach in the news, most other outlets swarm to a few different types of articles. Some popular directions are attribution, defense advice, or sensationalist journalism.

Read More

Topics: Managed Detection & Response, Ethical Hacking, Information Security, Threat Advisory

The Importance of Cybersecurity in Healthcare

Posted by David Howard on Sep 5, 2017 10:19:00 AM
Healthcare data theft totaled more than 112 million records in 2015, according to the Office of Civil Rights. Moreover, 42.5 percent of all data breaches have occurred in the healthcare industry in the last three years, and 91 percent of healthcare organizations have reported at least one breach in the last two years. Hackers, unauthorized access from staff, improper disposal, data loss — all of these factors contributed to large-scale data breaches in hospitals and medical facilities across the United States. Now, more IT managers and administrators are investing in cybersecurity to safeguard patient data.
Read More

Topics: Managed Detection & Response, Information Security, Vulnerability Management, Compliance, Healthcare

Subscribe to our blog!