How to Use Threat Intelligence Before Incidents

96 views
August 22, 2022
by
RSAC Cybersecurity
YouTube video player
How to Use Threat Intelligence Before Incidents

TL;DR

Effective threat intelligence depends on public-private collaboration that combines government visibility, industry data, and expert experience to reduce unknowns before incidents occur. Organizations must also maintain basic defenses because social engineering, phishing, password reuse, and techniques that bypass multi-factor authentication can undermine otherwise advanced security measures.

Transcript

Welcome, everybody. Um, I guess it's good afternoon. My name is- Sure ... Patrick Flynn. I'm the head of the Advanced Programs Group and Intelligence Organization with Trellix Labs. We're based out of Columbia, Maryland, um, and we, we provide that sort of, uh, keep, keep everybody left of boom type, uh, support from our company. It's so good to be... Read More

Key Insights

  • Public-private collaboration is a core part of NSA’s evolving cybersecurity mission. The Cybersecurity Collaboration Center brings government organizations together with defense industrial base, communications, and IT partners to share information, combine expertise, and remove unknowns from common security problems.
  • The Enduring Security Framework is an NSA-led collaborative effort involving government and industry partners. It gives experts and leaders a forum to identify a security problem, contribute their respective capabilities and perspectives, and work jointly toward a solution.
  • The Joint Cyber Defense Collaborative is designed to move cooperation beyond building trust and exchanging information. CISA uses the initiative to improve federal visibility into threat actors and vulnerability activity while drawing on private-sector technology, tools, and operational capabilities.
  • Industry contributes more than endpoint data to threat intelligence collaboration. Its experienced practitioners bring shared knowledge developed through direct work in the field, which complements information available through government sources such as signals intelligence.
  • Security basics remain essential even when organizations deploy advanced defensive technology. The panel notes that password reuse and social engineering contributed to major breaches, showing that sophisticated controls cannot compensate fully for weaknesses in foundational practices or user behavior.
  • Social engineering works by creating urgency and narrowing a victim’s attention. In the FBI example, an attacker impersonated human resources, alleged racist social-media activity, and persuaded an employee to permit remote access, after which millions of pieces of customer PII were stolen.
  • Multi-factor authentication changes attacker behavior without eliminating account compromise. As MFA becomes more widely adopted, criminals increasingly rely on social engineering and SIM swapping to bypass two-factor protections instead of attacking those controls directly.
  • Phishing remains a high-volume threat according to the FBI panelist. More than 324,000 phishing attempts were reported to the FBI in 2021, reinforcing the need for layered defenses, effective reporting, employee awareness, and strong control of passwords and remote access.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How should organizations use threat intelligence before incidents occur?

Organizations should use threat intelligence through sustained collaboration that combines government visibility, private-sector data, technical capabilities, and expert experience. The objective is to remove unknowns, identify threat-actor and vulnerability activity, and provide useful watch and warning information. Intelligence becomes strategically valuable when it helps enterprises prepare mitigations before potential issues develop into incidents.

Q: What is the purpose of the Joint Cyber Defense Collaborative?

The Joint Cyber Defense Collaborative seeks to take public-private cybersecurity cooperation beyond trust building and routine information sharing. CISA uses it to expand the federal government’s visibility into threat actors and vulnerability activity. It also draws on private-sector tools, technology, and capabilities to improve understanding of the broader ecosystem and support national cybersecurity guidance, watch, and warning.

Q: How does NSA collaborate with private-sector cybersecurity partners?

NSA collaborates through its Cybersecurity Collaboration Center and initiatives such as the Enduring Security Framework. Experts and leaders from the defense industrial base, communications sector, IT sector, and government identify common problems and work together on solutions. Participants share information, data, operational experience, and capabilities because reducing unknowns requires contributions that no single organization possesses alone.

Q: What does industry contribute to government threat intelligence efforts?

Industry contributes endpoint observations, tools, technology, operational capabilities, and the experience of professionals who work directly in the cybersecurity field. The panel emphasizes that data is valuable, but shared human experience also matters. When industry expertise is combined with government information, including signals intelligence, partners gain a more complete basis for understanding and addressing security problems.

Q: Why are basic security practices still important with advanced defenses?

Basic security practices remain important because attackers can bypass advanced controls by exploiting people, reused passwords, and weak processes. The FBI panelist notes that major breaches stemmed from password reuse and social engineering used to defeat multi-factor authentication. Security therefore requires a layered approach in which advanced technology is supported by strong foundational controls and informed user behavior.

Q: How can social engineering bypass multi-factor authentication?

Social engineering can bypass multi-factor authentication by persuading a user to provide access or cooperate with an attacker. In the panel’s example, someone impersonating human resources created anxiety with an allegation about racist social-media posts, then asked the employee to click a link and permit remote access. The deception succeeded without directly defeating the authentication technology itself.

Q: What social engineering tactics were used in the FBI example?

The attacker impersonated a human resources representative and alleged that the target had posted racist statements on social media. That accusation created urgency and caused the victim to focus on correcting an apparent mistake. The attacker then presented remote computer access as a routine investigation step. Five hours later, the company discovered the deception after customer PII had been taken.

Q: What cyber threats did the FBI panelist identify as major concerns?

The FBI panelist identified ransomware as a threat that had expanded greatly over several years, while emphasizing more basic compromise methods as persistent concerns. These included phishing, social engineering, SIM swapping, password reuse, and attempts to bypass multi-factor authentication. More than 324,000 phishing attempts were reported to the FBI in 2021, illustrating the scale of the problem.

Summary & Key Takeaways

  • NSA’s Cybersecurity Collaboration Center brings government and industry experts together to address shared security problems. Through efforts such as the Enduring Security Framework, participants from the defense industrial base, communications, and IT sectors combine information, experience, and capabilities to reduce unknowns and strengthen collective cybersecurity work.

  • CISA’s Joint Cyber Defense Collaborative seeks to advance public-private cooperation beyond trust building and information sharing. Its objectives include expanding federal visibility into threat actors and vulnerability activity, using private-sector tools and capabilities to understand the cybersecurity ecosystem, and supporting national watch, warning, and best-practice communication.

  • The FBI perspective emphasizes that advanced security controls do not eliminate basic attack paths. Criminals use social engineering, phishing, SIM swapping, and password reuse to bypass protections such as multi-factor authentication. Organizations therefore need layered security while ensuring that foundational controls and employee awareness remain consistently effective.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚