Cyber Deterrence: Beyond Cyber Defense

No ratings

Presented at ArabSecurityConference 2020 by

We don't know for sure who said "Attack is the best for of defense"; was it Sun Tsu or Napoleion Bonaparte? It really doesn't matter because this saying indeed worked for every single commander who used it no matter what his nationality is ... Today this concept is coming to the cyber space because the fact security operation has been always focused in the past on monitoring/detection of offenses and responding to it through containment, investigation and recovery is simply no more enough. Why? Because this approach forcu on the attack rather than the attacker and turn the institution/enterprise to a punching bag that is continiously beaten and the best it can do is to be strong enough in order not to be blow in pieces by the punches ... But what if ... Just what if we start focusing on the attacker rather than the attack? What if we follow a preventive/pre-emptive approach to cyber security rather than the current reactive approach? Welcome to the "Cyber Deterence" approach increasingly being adopted by both private and public sectors.Cyber deterence will be implemented through next generation of cyber security operation centers which has to cover 3 distinct areas through all of them cyber deterence will be delivered:- Cyber Defense: with proper detection, monitoring & response tools,- Cyber Offense: with proper deception & attack tools,- Cyber Inteligence: with proper actionable intelligence, sources, brand visibility & Authorities connection.The value expected from NG-CSOC today is the same value expected from military and police display of power: make a threat actor think twice at least or not think at all at best of performing an attack because he knows the institution is not a punching bag: It will hit back. For this to happen legislation has to change, an executive cyber security bodies has to exist, coordination mechanisms between public & private sector NG-CSOC and cyber security executive bodies has to be put in place, cyber alliances with other nations has to be belt, thechnologies such as honeypots, traffic generators, vulnerability management, threat intelligence, SIEM, SOAR, EDR, needs to be covered as well as processes and organization as previously explained.