This guide is part of a 3 part Getting Started series:
This guide aims to help you further enhance your cyber security posture by providing strategies on how to deeply integrate Secure60 into your applications / services / infrastructure.
Completion of this guide will enable the follow benefits across your business:
In this guide we will provide strategies and implementation samples on how to deeply integrate Secure60 into a wide range of scenarios that you may have in your business.
Once you have completed this guide you will have achieved a significant improvement in cyber risk and protection across your most critical IT components.
For deeper guidence we recommend a Threat Modelling process (A great example is available from UK Government NCSC)
Before embarking on a deep integration project you should firstly understand which parts of your business are the most critical and also the most likely to need advanced protection.
This information may come from a range of participants:
Once you have a clear set of business or application areas to focus on you can then craft strategies to mitigate cyber risk.
Every application or service has several layers, and each needs to be analysed and integrated for coverage across the whole service.
The following list is a starting point of considerations to improve your cyber security posture:
NetworkNetwork telemetry establishes how data moves between systems and where it leaves the organisation. Without it, an intrusion can be detected but not traced.
Key detection areas to focus on:
Operating SystemOS logs record authentication, process execution and configuration change on the host itself. They are the layer that establishes what an attacker did after gaining access.
Key detection areas to focus on:
ApplicationApplication logs record what happened to the business data itself: transactions, record access, and application-layer attacks such as SQL injection. This is the layer network and OS telemetry cannot see.
Key detection areas to focus on:
AccessAccess telemetry attributes activity to an identity: authentication attempts, privilege escalation and permission changes. Without it, events have no actor attached and insider activity is indistinguishable from normal use.
Key detection areas to focus on:
Endpoint SecurityEndpoints — laptops, desktops, servers and mobile devices — are where most intrusions begin. EDR and antivirus detections forwarded into Secure60 join the same entity timeline as everything else.
Key detection areas to focus on:
Cloud SecurityCloud control-plane events record who changed the infrastructure, when, and with which credential. Across hybrid and multi-cloud estates this is frequently the only record of a configuration change.
Key detection areas to focus on:
There are a number of ways to improve coverage inside Secure60 of the above components:
For further questions, contact support@secure60.io.