By Juliet Umeh
Recorgnising the fact that cyber-attack is easy to conduct, industry experts have alluded that this makes it difficult for security personnel to deal with.
But, the experts stated that with Attivo’s cyber security deception solution, the security professional can easily gain the knowledge of what the attacker was coming to do.
This was the thrust of a day event organized by a Nigerian tech firm, InfoData Professional Services, in collaboration with a cyber security detection services provider, Attivo Networks in Lagos recently.
Speaking, the Head of Security Operations Centre at the Central Bank of Nigeria, CBN, Mr. Ifeanyi Jude Muonagor said the bank’s deployment of cyber deception solution in 2017, has yielded positive results.
While speaking on the topic: ‘Importance of deception technology and identity security,’ he said: “Eighty percent of system breaches have been linked to compromised credentials.
“In 2017, CBN identified the need for cyber deception technology and we moved with a particular solution. I will not mention names because I am not campaigning for any particular vendor. But we found out that there were fewer activities because of the deployment model.”
Also the Lead System Engineer at Attivo Networks, Mr Osama Al-Shatnawi, said cyber-attacks do more damage than conventional warfare.
He said: “Everything can be done literally. A single bank lost $70 million dollars through a cyber-attack. I can tell you about electricity companies. Just look at what happened to Ukraine. Any damage can happen due to cyber-attacks and that is why we need to take security seriously.”
Al-Shatnawi said based on different market analysis that have been done by different entities using Attivo with other solutions in place, their detection and protection capability has enhanced by 42 per cent.
Similarly, the Territory Manager at Attivo Networks, Wayne Forsman, explained why cyber security breaches were on the increase.
According to Forsma, “Conventionally, we set up a wall around our network, web security, email, next generation firewalls. But effectively, by not protecting Active Directory (a Microsoft tool used to access networks and other applications), you have left the door open.
“In order to secure something, you really need to know about it. First we have Active Directory assessor which gives you full visibility into Active Directory. It will give you all the vulnerability and mitigation steps to effectively make Active Directory more secure.
“However, you also need to protect your information, the various profiles created for a user to have rights to a system – passwords, username. You need to protect that information. As for the current gaps, no solution is protecting the information on the Active Directory, which is the gap Attivo has closed.”
According to the President of Infodata Professional Services Global, Mr Chuks Udensi; “Our commitment to delivering security solutions that are intuitive, intelligent and relevant to the realities of today’s business critical infrastructure is further bolstered by our partnership with Attivo Networks.”
He said Solutions such as identity detection and response, IDR, IEV and others within the Attivo ThreatDefend Platform gives users the ability to deploy decoy and deception technologies as well as an expanded portfolio of solutions that address the challenges of increased attack destructiveness for a global distributed workforce as cloud based solutions drive enterprise business productivity, profitability and efficiencies.
“We will continue to build , adopt and develop resources and solutions that ensure that our customer’s enterprise infrastructure are stable , secure, predictive and adaptive to the realities of today’s global constantly-evolving threat landscape.”
On his own, Info Data Regional Solutions Manager, Mr Eze Osiago, explained the reason for the partnership.
He said: “Attivo deceptive solution is one of its kind. We have EDRs that do prevention but scenarios where the attacker is already inside, we currently do not have solutions that will detect the malicious insider or the attacker who is already inside. So, Attivo is that missing gap that comes in to say let’s do a scan around and spot anomalies to spot people who are misusing privileges,” he said.
Among the participants at the event were security professionals for various Nigerian financial institutions and other firms.
Disclaimer
Comments expressed here do not reflect the opinions of Vanguard newspapers or any employee thereof.