How Does Intelligence Improve Cybersecurity?

TL;DR
Effective cybersecurity starts by understanding the adversary’s entire campaign and your own organization, rather than matching each isolated threat with a separate defense. Attackers increasingly combine seemingly independent actions, including diversionary DDoS attacks, to exploit overloaded security teams, while complex infrastructure, personal devices, and third-party cloud services make corporate data harder to control.
Transcript
Ladies and gentlemen, please welcome Group President, Enterprise Products and Services, Symantec, Francis D'Souza. A businessman on a trip had his smartphone tampered with and compromised, and the information stolen from his smartphone was used to infiltrate his company's network, and then used as a staging ground to attack a number of government a... Read More
Key Insights
- Modern cyber attacks are campaigns rather than isolated technical events. Defenders gain additional options when they examine the adversary’s objectives, motivations, methods, and supporting activities instead of treating every piece of malware or spam as an independent problem requiring a separate product.
- Symantec’s intelligence network collected forty-two types of security information through probes in more than two hundred countries and territories. It processed between one and a half and three billion security events daily, giving the company a broad view of changing attack behavior.
- Security verdicts were calculated from one point five trillion pieces of data for one hundred and forty-five million domains, URLs, and files. Symantec performed this analysis every six hours to identify patterns and assess activity across its global intelligence network.
- Corporate IT environments are becoming larger, more complex, and more heterogeneous. Organizations must manage varied storage systems, servers, operating systems, hypervisors, and endpoints after an earlier period when the industry emphasized standardized endpoint images and consolidated data centers.
- Bring your own device practices reduce centralized control because employees use personal smartphones and tablets to access corporate assets. Business users also place information in third-party data centers through cloud services and public networks, including salesforce.com, Facebook, and Twitter.
- Organizations are responsible for corporate data even when they do not directly control where it resides. Emerging regulations increase responsibility for data security and privacy while infrastructure complexity, heterogeneous technology, and outside services make consistent protection more difficult.
- Multi-flank attacks are coordinated campaigns in which one adversary launches several seemingly independent attacks against the same target. Some components are deliberately diversionary, drawing defenders toward visible disruption while another operation proceeds at the same time.
- Inattentional blindness is the failure to notice unexpected stimuli while concentrating on a demanding task. Security teams inundated with data can focus narrowly on an expected pattern, allowing attackers to use conspicuous events such as DDoS attacks to conceal less obvious activity.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How does intelligence improve cybersecurity strategy?
Intelligence improves cybersecurity by connecting individual incidents to the larger campaign that produced them. Defenders can examine who the adversary is, what the adversary wants, how several actions relate, and which activity may be diversionary. Intelligence about the organization is also important because effective protection depends on understanding corporate assets, infrastructure complexity, data locations, and the organization’s reduced control over personal devices and third-party services.
Q: What does a modern cyber attack look like?
A modern cyber attack can involve several coordinated actions that initially appear independent. A single adversary may compromise a device, use stolen information to enter a corporate network, establish that network as a staging ground, and attack additional targets. Attackers may also combine a conspicuous disruption with a separate operation, making the visible incident a distraction rather than the campaign’s principal objective.
Q: What is a multi-flank cyber attack?
A multi-flank attack is a campaign in which one adversary launches several seemingly independent attacks against a target. Some attacks may create direct harm, while others exist primarily to divert attention and resources. This structure makes incident-by-incident analysis inadequate because defenders may successfully respond to the most visible event while overlooking the more important operation occurring elsewhere at the same time.
Q: Why can a DDoS attack be used as a diversion?
A DDoS attack can generate obvious disruption and demand immediate attention from security and operations teams. While defenders concentrate on restoring services and interpreting the flood of activity, the same adversary can conduct another attack that is less visible. In this role, DDoS changes from the main blunt-force assault into a sophisticated diversion intended to obscure the campaign’s actual objective.
Q: How does inattentional blindness affect security teams?
Inattentional blindness causes people to miss unexpected events while concentrating on a specific task or familiar pattern. The described awareness test found that fifty percent of observers counting basketball passes failed to notice a gorilla entering the court and dancing. Security teams face a comparable risk when large volumes of data narrow their attention, allowing unusual but important activity to remain unnoticed.
Q: Why are corporate IT environments harder to secure?
Corporate IT environments are harder to secure because they are larger, more complex, and more heterogeneous than before. Teams must manage different storage platforms, servers, operating systems, hypervisors, and endpoints. At the same time, employees introduce personal devices, and business users adopt external cloud services and public networks, reducing the organization’s direct control over systems and data.
Q: How does bring your own device change corporate risk?
Bring your own device changes corporate risk by allowing personal smartphones and tablets to connect with corporate assets. These endpoints are not necessarily standardized or controlled in the same manner as company-issued equipment. A tampered smartphone can expose information that attackers use to infiltrate a corporate network, demonstrating how a compromised personal device can become an entry point into broader organizational systems.
Q: Why should defenders analyze campaigns instead of individual threats?
Campaign analysis reveals relationships that are invisible when each threat is considered separately. Traditional security thinking assigns a corresponding defense to an individual problem, such as antivirus for a virus or anti-spam for spam. Examining the full campaign instead helps defenders identify the adversary, intended outcome, coordinated attack stages, diversions, and alternative opportunities to interrupt the operation before its objective is achieved.
Summary & Key Takeaways
-
Cybersecurity threats were becoming more varied and consequential, affecting smartphones, corporate networks, small businesses, government agencies, and critical infrastructure. Symantec analyzed global security telemetry to investigate what modern attacks look like, which assets attackers target, and which strategic elements organizations need to defend themselves effectively.
-
Corporate IT environments had become larger, more heterogeneous, and less centrally controlled. Employees accessed corporate assets through personal smartphones and tablets, while business teams placed data in public networks and cloud services. Despite reduced operational control, organizations remained responsible for the security and privacy of corporate information wherever it resided.
-
A campaign-centered security model examines the adversary, objectives, methods, and connected stages behind individual incidents. Multi-flank attacks illustrate this approach because one actor may launch several apparently unrelated attacks, using a visible DDoS event as a diversion while conducting a more consequential operation elsewhere in the environment.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator