Getting Started - 3 - Customise

This guide is part of a 3 part Getting Started series:

  1. Enable Data Flow
  2. Enhance Data
  3. Customise

This guide aims to help you further enhance your cyber security posture by providing strategies on how to deeply integrate Secure60 into your applications / services / infrastructure.

Completion of this guide will enable the follow benefits across your business:

  1. Deep integration strategies across:

Overview

In this guide we will provide strategies and implementation samples on how to deeply integrate Secure60 into a wide range of scenarios that you may have in your business.

Once you have completed this guide you will have achieved a significant improvement in cyber risk and protection across your most critical IT components.

For deeper guidence we recommend a Threat Modelling process (A great example is available from UK Government NCSC)

Step 1 - Assess cyber risk and focus areas

Before embarking on a deep integration project you should firstly understand which parts of your business are the most critical and also the most likely to need advanced protection.

This information may come from a range of participants:

Once you have a clear set of business or application areas to focus on you can then craft strategies to mitigate cyber risk.


Step 2 - Examine the target application or service

Every application or service has several layers, and each needs to be analysed and integrated for coverage across the whole service.

The following list is a starting point of considerations to improve your cyber security posture:

Network

Network telemetry establishes how data moves between systems and where it leaves the organisation. Without it, an intrusion can be detected but not traced.

Key detection areas to focus on:

Operating System

OS logs record authentication, process execution and configuration change on the host itself. They are the layer that establishes what an attacker did after gaining access.

Key detection areas to focus on:

Application

Application logs record what happened to the business data itself: transactions, record access, and application-layer attacks such as SQL injection. This is the layer network and OS telemetry cannot see.

Key detection areas to focus on:

Access

Access telemetry attributes activity to an identity: authentication attempts, privilege escalation and permission changes. Without it, events have no actor attached and insider activity is indistinguishable from normal use.

Key detection areas to focus on:

Endpoint Security

Endpoints — laptops, desktops, servers and mobile devices — are where most intrusions begin. EDR and antivirus detections forwarded into Secure60 join the same entity timeline as everything else.

Key detection areas to focus on:

Cloud Security

Cloud control-plane events record who changed the infrastructure, when, and with which credential. Across hybrid and multi-cloud estates this is frequently the only record of a configuration change.

Key detection areas to focus on:


Step 3 - How to implement detections and controls in Secure60

There are a number of ways to improve coverage inside Secure60 of the above components:

  1. Use the built in Managed Rules
  2. Apply Entity Analytics
  3. Extend and create your own Rules and detections

With these layers integrated, Secure60 covers the parts of the business that carry the most risk.

For further questions, contact support@secure60.io.

Back to top