<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>I Told You So, Volume 1 - verizon-dbir</title>
    <subtitle>Archive, Volume 1: conference talks and papers on security and risk, 2010 to 2018.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://blog.itys.net/vol1/tags/verizon-dbir/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2015-05-07T00:00:00+00:00</updated>
    <id>https://blog.itys.net/vol1/tags/verizon-dbir/atom.xml</id>
    <entry xml:lang="en">
        <title>State of Cyber Security</title>
        <published>2015-05-07T00:00:00+00:00</published>
        <updated>2015-05-07T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/fuel-pan/"/>
        <id>https://blog.itys.net/vol1/posts/fuel-pan/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/fuel-pan/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The Minneapolis Chapter Palo Alto Networks Fuel Users Group Meeting on May 7,
2015, opened with a sobering overview entitled State of Cyber Security,
underscoring that breaches are not a question of if but when. Drawing on
cultural touchstones from Sesame Streets Oscar the Grouch to BBCs Moriartyi the
presenter highlights that even simple lapses (like exposed post-it note
credentials) can enable attackers and that motivated adversaries will exploit
both technical and human weaknesses.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;hard-data&quot;&gt;Hard Data&lt;&#x2F;h2&gt;
&lt;p&gt;The bulk of the talk reviewed hard data from the 2015 Verizon Data Breach
Investigations Report, detailing 2014s most significant incidentsranging from
Neiman Marcuss 350,000 records to JP Morgan Chases 76 million households and
cataloged threat sources, attack vectors, and time-to-compromise metrics. This
context stressed that organizations must evolve beyond perimeter defenses and
adopt proactive monitoring, rapid patching, and layered controls to limit dwell
time and impact.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;information-sharing&quot;&gt;Information sharing&lt;&#x2F;h2&gt;
&lt;p&gt;In response to these challenges, the presentation pivoted to the power of shared
intelligence. It outlined the founding of the NorSec ISAO under recent executive
orders, described opensource feeds (APTnotes, ShadowServer, REN-ISAC CIF), and
defined Indicators of Compromisefrom DNS hosts to file hashesemphasizing that
crowd-sourced, expert-vetted threat data is essential for timely detection.
Finally, it showcased Palo Alto Networks solutions WildFire for sandbox analysis
and Traps for endpoint exploit preventionas integral tools for automating IoC
blocking and closing the gap between discovery and defense.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;57149_2015-05-07-FUEL_PAN_UG.pdf&quot;&gt;State of Cyber Security 2015&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
