IT Hygiene - Cyber Security Landscape

The first post of the IT Hygiene series goes to Cyber Security and for a good reason I will explain.
I have been close to this domain for the last 15 years: it started with attending and graduating from a Master's degree in Information Security, then with a role as a Cyber Security Engineer for a government agency where I got to write my first encryption application for top secret content that was certified nationally, and then as an engineer and then IT leader always focused on cyber security.
Over the last 15 years, the cyber landscape has changed significantly: back then it was more about cryptography, secure protocols, networks, databases and applications. Although all this education was done with a Threat Actor in mind, that Threat Actor was less present. In the last 5 years, cyber security attacks have become easier to execute by Threat Actors with various services such as ransomware as a service, DDOS as a service and the Dark Web, thus reducing the entry barrier and making it available for many. The consequence of this is that attacks and specifically ransomware attacks have become more frequent and damaging: average payout these days is around $6M and they can infiltrate a company in under 2 hours. And while I have presented these facts and the current state of play in many exec and board meetings, until it hits you, you have no idea what it really means. It's like we all have a plan until we get punched in the face, and it felt exactly that way when it happened to me.
There are a lot of topics to cover here so I will break the Cyber Security Hygiene into multiple posts for each topic:
- identity: https://blog.askalex.how/it-hygiene-cyber-security-identity/
- cloud: https://blog.askalex.how/cyber-security-hygiene-the-cloud/
- endpoints: https://blog.askalex.how/cyber-security-hygiene-endpoints/
- software applications:
You can subscribe if you'd like to stay up to date and receive emails when new content is published. If you'd like to work together on your IT posture, here is how I can help: askalex.how.