SolarWinds bolsters its security response capabilities following hack

The company is in the process of 'creating a new, highly-secure environment based upon the latest practices'

SolarWinds has revealed that it is in the process of bolstering its cyber security response and monitoring capabilities, seven weeks after a “highly sophisticated” cyber attack on its IT management systems.

The software provider is working on expanding teams, techniques, and processes responsible for monitoring, responding, and “hunting” for threat actors such as those who coordinated December’s attack.

In a webcast hosted by the company, SolarWinds' security advisor and former Facebook CSO Alex Stamos said that enterprises should not only invest in appropriate security tools, but also “embrace the inevitability” that they, too, could be hacked.

“The unfortunate truth is when you go against one of these adversaries of this level, you're dealing with people that have a huge amount of time and motivation to break into your company,” he said. 

“People that have dedicated research teams that are looking for zero-day in the products you use, dedicated development teams who are building new tools and new command and control systems to break in, that are not going to be caught by existing antivirus, and that come in every day with their job to break into your company.

Related Resource

Improving cyber security for remote working

13 recommendations for security from any location

Download now

Stamos recommended that, instead of focusing solely on preventing the initial compromise, enterprises must take into consideration their detection, monitoring, alerting, and response strategies and tools on every step of the cyber kill chain.

He also advised companies to measure the effectiveness of their response by using red team and tabletop exercises, as well as employing “trusted third parties” to handle the top two percentile of activity, leaving the 98% for internal teams.

Stamos was taken on by SolarWinds last month in order to help manage the software provider’s recovery from December’s cyber attack, alongside former CISA head Chris Krebs. Krebs and Stamos have recently formed a security consulting business, of which expertise SolarWinds is expected to benefit from.

During the webcast, the company also announced that it has secured its existing build environment and is in the process of “creating a new, highly-secure environment based upon the latest practices”, which includes integrating a systems development life cycle in all the environments concerned with product development.

Featured Resources

BCDR buyer's guide for MSPs

How to choose a business continuity and disaster recovery solution

Download now

The definitive guide to IT security

Protecting your MSP and your customers

Download now

Cost of a data breach report 2020

Find out what factors help mitigate breach costs

Download now

The complete guide to changing your phone system provider

Optimise your phone system for better business results

Download now

Recommended

Google’s about to push everyone into two-factor authentication
Security

Google’s about to push everyone into two-factor authentication

6 May 2021
Defense Dept. expands vulnerability disclosure program to all publicly accessible defense systems
ethical hacking

Defense Dept. expands vulnerability disclosure program to all publicly accessible defense systems

5 May 2021
Security researchers take control of a Tesla via drone
ethical hacking

Security researchers take control of a Tesla via drone

5 May 2021
Best free malware removal tools 2021
Security

Best free malware removal tools 2021

5 May 2021

Most Popular

KPMG offers staff 'four-day fortnight' in hybrid work plans
flexible working

KPMG offers staff 'four-day fortnight' in hybrid work plans

6 May 2021
Dell patches vulnerability affecting hundreds of computer models worldwide
cyber security

Dell patches vulnerability affecting hundreds of computer models worldwide

5 May 2021
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

29 Apr 2021