SolarWinds bolsters its security response capabilities following hack
The company is in the process of 'creating a new, highly-secure environment based upon the latest practices'
SolarWinds has revealed that it is in the process of bolstering its cyber security response and monitoring capabilities, seven weeks after a “highly sophisticated” cyber attack on its IT management systems.
The software provider is working on expanding teams, techniques, and processes responsible for monitoring, responding, and “hunting” for threat actors such as those who coordinated December’s attack.
In a webcast hosted by the company, SolarWinds' security advisor and former Facebook CSO Alex Stamos said that enterprises should not only invest in appropriate security tools, but also “embrace the inevitability” that they, too, could be hacked.
“The unfortunate truth is when you go against one of these adversaries of this level, you're dealing with people that have a huge amount of time and motivation to break into your company,” he said.
“People that have dedicated research teams that are looking for zero-day in the products you use, dedicated development teams who are building new tools and new command and control systems to break in, that are not going to be caught by existing antivirus, and that come in every day with their job to break into your company.
RELATED RESOURCE
How to improve cyber security for remote working
13 recommendations for security from any location
Stamos recommended that, instead of focusing solely on preventing the initial compromise, enterprises must take into consideration their detection, monitoring, alerting, and response strategies and tools on every step of the cyber kill chain.
He also advised companies to measure the effectiveness of their response by using red team and tabletop exercises, as well as employing “trusted third parties” to handle the top two percentile of activity, leaving the 98% for internal teams.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Stamos was taken on by SolarWinds last month in order to help manage the software provider’s recovery from December’s cyber attack, alongside former CISA head Chris Krebs. Krebs and Stamos have recently formed a security consulting business, of which expertise SolarWinds is expected to benefit from.
During the webcast, the company also announced that it has secured its existing build environment and is in the process of “creating a new, highly-secure environment based upon the latest practices”, which includes integrating a systems development life cycle in all the environments concerned with product development.
Having only graduated from City University in 2019, Sabina has already demonstrated her abilities as a keen writer and effective journalist. Currently a content writer for Drapers, Sabina spent a number of years writing for ITPro, specialising in networking and telecommunications, as well as charting the efforts of technology companies to improve their inclusion and diversity strategies, a topic close to her heart.
Sabina has also held a number of editorial roles at Harper's Bazaar, Cube Collective, and HighClouds.
-
How channel-supported smart decisions can pay off now and in the futureIndustry Insights How can partners help retailers make smarter IT investments this Black Friday?
-
BenQ PV3200U monitor reviewReviews A £699 32-inch 4K monitor for video editing – but it needs a few cuts to appeal to its target audience
-
JD Sports details cyber security revamp following January attackNews It hopes a multi-vendor approach will substantially improve its cyber resilience
-
96% of CISOs without necessary support to maintain cyber securityNews Security professionals are leaving due to stress, and called out lack of understanding from co-workers
-
Employees behaving badly?Whitepaper Why awareness training matters
-
Freshworks CISO Jason Loomis embraces the ‘shift left’ amid surging supply chain threatsCase Studies Fewer than 100 days in the role, Jason Loomis reveals his plans for the future of security at Freshworks, and discusses the rising threat of API vulnerablities
-
CISOs reveal secrets to pandemic success in critical organisationsNews The pandemic presented unique challenges for every business, but organisations tasked with delivering critical services may have worked the hardest
-
Almost 70% of CISOs expect a ransomware attackNews Many companies are willing to make ransomware payments in the face of the growing threat
-
CISOs aren’t leading by example when it comes to cyber securityNews Cyber security leaders engage in risky online behavior, according to a survey
-
Panel Profile: Moonpig head of cyber security Tash NorrisIT Pro Panel We get face-to-face with one of the IT Pro Panellists
