South African organisations are trying to secure environments that change by the hour, while AI is reducing the time between vulnerability discovery and exploitation.
Arctic Wolf’s Andre den Hond and Jason Oehley explain why security teams need to know what they have before they can decide what to protect.
An employee may connect a new laptop to the company network, a contractor could plug in a system that nobody knows is there, or a business unit might create its own cloud environment. An acquisition can also introduce unfamiliar infrastructure, while shadow IT allows new services to be created without the security team’s knowledge.
Each action adds to an attack surface that is continuously growing and changing. Arctic Wolf’s research indicates that 33% of IT assets lack critical security controls, exposing the scale of a problem many organisations may not realise they have.
“An asset is anything on the network,” explains Den Hond. “It could be a desktop, a virtual machine, a firewall or a storage array. It is literally anything that has an IP address and is contactable on the network.”
Maintaining an accurate view becomes difficult because most enterprise environments are dynamic, especially when they extend into the cloud. Instances are brought up and taken down, users join and leave the organisation, and different parts of the environment may be managed by different teams.
“It is the dynamic nature of IT,” Den Hond continues. “In large organisations, users are being hired or leaving, organisations are being acquired, and new infrastructure is coming into the environment. It is very hard to get an accurate, live view of what your asset base looks like.”
Security teams have too much to do
Many security teams have more tools and responsibilities than they can realistically manage. As the environment changes, they may not have the time or insight to identify every new or unprotected asset. There are simply “too many tools and too much to do,” Oehley believes.
This pressure is particularly relevant to South Africa’s small and mid-market businesses, where dedicated security teams or security operations centres may not exist. Public-sector organisations may also be working with older technology and security approaches that have not kept pace with changes in their environments.
Even organisations that have invested substantially in cybersecurity may have devices that are missing essential controls. One laptop may not have endpoint protection installed, while another asset could be missing patch or configuration management. Unless security teams can correlate the information held across their existing tools, they may never see the gap.
“You can’t protect what you can’t see,” says Oehley.
Unknown assets create easy ways in
Den Hond recalls an organisation where a threat actor gained access to its environment by exploiting a weakness in an unknown firewall. Because the security team had not been made aware of the firewall, it was not being monitored.
Had the organisation known about the firewall, it could have been monitored correctly and flagged for an update. Preventing that initial access would also have been far less disruptive and costly than responding after the environment had been compromised.
Threat actors often target these known weaknesses because they tend to do what works. Unpatched systems, missing controls and forgotten infrastructure can give them an easy way into an organisation.
AI is shrinking the time available
As AI automates the attack process, criminals no longer need the same level of technical skill to target an organisation. This will accelerate the number of cyberattacks and reduce the time defenders have to act.
“The time from vulnerability identification to exploitation is shrinking drastically,” warns Den Hond. “Organisations are going to get to a point where they cannot patch systems fast enough because AI is going to exploit vulnerabilities faster than they can patch them.”
With so many vulnerabilities to address, security teams cannot patch systems willy-nilly and hope they reach the right ones first. Den Hond believes organisations need to know exactly where to focus their exposure reduction efforts because the time available to find and close every gap is disappearing.
Attack surface management provides the starting point: an accurate view of the assets within the environment and the security controls associated with them. From there, teams can identify missing controls and focus their efforts where they make sense for the business.
What should leaders ask?
Business leaders do not need to become cybersecurity experts, but they should expect clear answers to some direct questions:
Do we know what our attack surface looks like?
How many assets do we have under management, and is that figure accurate?
Which assets are missing security controls?
Where should we focus our exposure reduction efforts first?
“An organisation may establish an accurate view of its risk only to find that, a week down the line, everything changes,” says Oehley. “This is why security posture improvement needs to happen all the time, supported by a live view of what is happening across the environment.”
He feels that organisations need to start looking at security differently because the traditional approach no longer works. Those without the internal capacity to assess, prioritise and resolve risk should work with a specialist partner rather than trying to do everything themselves.
“When you buy a car, you send it to somebody who knows how to service it. So why are you doing security on your own?” he asks.
Cybersecurity may still be treated as a grudge purchase or a cost to the business, but Den Hond believes leaders need to understand what a cyber incident could mean for the organisation’s ability to continue operating.
“Security is still seen as a cost to the business rather than something that can fundamentally affect that business moving forward,” Den Hond says. “Organisations need to understand the potential impact, because cyber risk doesn’t discriminate at all.”