📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

CYBER SECURITY explained in 8 Minutes

Mad Hat8:09

Transcription

Cyber security makes no sense. You have all these computers talking to each other over the internet, and somehow hackers can turn this into free money or chaos if they really want to. Meanwhile, your IT budget, it's a Post-It note and a pack of gum. Let's talk about how badly protected everything is, and how that posit is somehow supposed to keep the entire castle safe.

The problem with cyber security. Cyber security isn't just about computers; it's about mitigating attack vectors. While management says, "What's a vector?" And when breaches happen, it's not an incident; it's an opportunity for growth. Spoiler: your security tools will not be growing.

The history of cyber security. Arpet, the alpha stage of the internet, hit us in the 70s, and it was fine until the Morris worm showed up in 1988, taking down 10% of what was then considered the internet. Entered TCP wrappers and firewalls. Fixed that. Today, we have SIEMs and EDR, but your old IDS is still chugging along because it works fine. Encryption: AES, RSA, TLS. All these tools encrypt data, but you're still stuck with an old SSL certificate because renewing it would mean breaking something. And don't even ask about quantum-resistant cryptography; it's a pipe dream when half the org uses FTP.

Authentication: passwords, fingerprints, your dog's birthday, anything to prove you're you. Who are you? Who are you? LDAP for centralized authentication, great in theory, until someone forgets to disable an ex-employee's account. And MFA? "It's inconvenient," says upper management. "You want people to use two passwords? That sounds like overkill." Meanwhile, hackers are brute-forcing through your exposed RDP with password123.

Password management. Passwords are a necessary evil. Let's just use password managers. Problem solved. Until someone forgets the master password. Force complex passwords with GPOs, but users still write them on sticky notes. "Password1!" gets flagged, but "Password!" spelled with special characters, somehow that's acceptable. Passwords need to expire. Passwords no longer need to expire. Welcome to entropy theater.

Authorization. Role-based access control versus attribute-based access control. Sounds fancy, but in practice, everyone's in the admin group because it's easier. Pro tip: it's not easier when the intern accidentally formats a production database.

Networking. IPv6 adoption? Maybe next year. BGP security? We trust our ISP. Meanwhile, your gateway rules look like spaghetti, and half the ACLs have "permit any" at the end. VLANs, subnetting, and micro-segmentation with software-defined networking sounds nice until you realize the entire network is still one big broadcast domain because nobody wants to deal with DHCP relay.

Firewalls and ACLs. Stateless versus stateful firewalls. Stateless is fast; stateful is secure. So, of course, you're running a hybrid with ACLs that haven't been updated since the birth of IPv4. Oh, and why is port 3389 open to the world? Because Carl in accounting needed it last year.

Intrusion detection and prevention systems. IDS/IPS solutions like Snort or Suricata alert you to possible intrusion, but without fine-tuning, every alert is a false positive. Meanwhile, the real threat sneaks through your flat network because segmentation was too expensive and too much work.

Endpoint protection. EDR tools like CrowdStrike and SentinelOne provide threat hunting, but Sharon's BYOD device does not support them. Is there a BYOD policy in place? Yes, but we haven't implemented it yet. My disappointment is immeasurable. And don't forget IoT, because your smart fridge is now a pivot point.

Malware. Portable executable files, obfuscated PowerShell scripts, and zero-click exploits packaged into viruses, worms, and ransomware. Your AV flags them as unknown threats, and your response? Hoping Windows Defender catches it while the C2 server exfiltrates your data. Oh, [expletive]. Windows Defender was in audit mode.

Zero-day exploits. Leverage unpatched vulnerabilities in CVEs (Common Vulnerabilities and Exposures). You'd patch, but there's a change freeze because it's quarter-end. Guess who's manually blocking traffic at the edge router?

Phishing. Spear phishing, whaling, and smashing. No, these aren't news sports; they're tailored email or SMS attacks. Your SPF, DKIM, and DMARC email security not configured properly according to the latest pentest.

Incident response. Playbooks, runbooks, and incident response plans are essential, unless they're in SharePoint, which is down because of the incident. So you're relying on Slack messages and memory to coordinate. Good luck.

Vulnerability scanning. Security teams constantly scan for vulnerabilities. It's like looking for cracks in a dam, except the dam is miles long, and every crack requires a different type of glue. Nessus, Qualys, OpenVAS churn out reports with hundreds of CVEs, but management only approves fixes for critical vulnerabilities because who cares about high ones? No one cares until they do.

Log analysis. Splunk, ElasticSearch, Logstash, Kibana, and Graylog parse terabytes of logs, but your budget is firmly at "Can't we do this in Excel?" Meanwhile, the real attacker is buried under a thousand benign DNS queries.

Change management. You mean the whiteboard in the break room? "Tell change management best practices in place?" Sure, but only urgent changes bypass the Change Advisory Board, and when something breaks, we'll document it later.

Documentation. Runbooks, workbooks, playbooks, topology diagrams, and standard operating procedures. None of which are ever up to date. When something breaks, you're reverse-engineering configs while management asks, "Why wasn't this documented?"

Careers in cyber security. Penetration testers, hackers for hire. They find vulnerabilities while management asks, "Do we really need to pay them this much?" Probably use Metasploit, Burp Suite, and custom scripts while executives follow up with questions like, "Can we just run Nessus ourselves?" Yes, yes, you can, but that's not the point. Security analysts parse volatile memory dumps and netflow logs while drinking cold coffee. Either burnt out or still in the honeymoon phase of a new job. There's no in-between. Security engineers configure all the security tools while praying nothing breaks. Get blamed when something breaks. Do they juggle budgets, compliance, and board presentations? They approve your tools after 3/4 of meetings. That's if you don't get a new CISO before it's approved.

The human factor. Humans click phishing links. Humans disable User Account Control. Humans reuse passwords. No security awareness training will fix Carl clicking "Free iPad Giveaway."

Artificial intelligence and cyber security. Machine learning and User and Entity Behavior Analytics promises to detect anomalies. Real anomaly detected: user logged in from Starbucks. Meanwhile, hackers' AI. Sounds great until it flags everything as suspicious. Now you're stuck explaining to management why the tool they spent six figures on is freaking out over normal traffic.

Quantum computing. Post-quantum cryptography standards are still in draft, while RSA 2048 encryption trembles. But management says, "Let's wait for the Gartner report."

Global cyber warfare. Nation-states are hacking each other. Your company is caught in the crossfire because someone thought it was a good idea to host critical systems in the cloud without redundancy. APT groups target OT systems that make up public infrastructure. Your industrial control systems still running Windows XP because it works.

To sum it up, cyber security isn't a job; it's a lifestyle of patching, logging, and arguing with Finance over why the security tool licensing is too expensive. And yet, somehow, Carl still has access.

[Music] How play.