E-Book, Englisch, 584 Seiten
Rains / Youngblood Cybersecurity Threats, Malware Trends, and Strategies
2. Auflage 2024
ISBN: 978-1-80461-895-0
Verlag: De Gruyter
Format: EPUB
Kopierschutz: 0 - No protection
Discover risk mitigation strategies for modern threats to your organization
E-Book, Englisch, 584 Seiten
ISBN: 978-1-80461-895-0
Verlag: De Gruyter
Format: EPUB
Kopierschutz: 0 - No protection
Tim Rains is Microsoft's former Global Chief Security Advisor and Amazon Web Services' former Global Security Leader for Worldwide Public Sector. He has spent the last two decades advising private and public sector organizations all over the world on cybersecurity strategies.
Cybersecurity Threats, Malware Trends, and Strategies, Second Edition builds upon the success of the first edition that has helped so many aspiring CISOs, and cybersecurity professionals understand and develop effective data-driven cybersecurity strategies for their organizations. In this edition, you'll examine long-term trends in vulnerability disclosures and exploitation, regional differences in malware infections and the socio-economic factors that underpin them, and how ransomware evolved from an obscure threat to the most feared threat in cybersecurity. You'll also gain valuable insights into the roles that governments play in cybersecurity, including their role as threat actors, and how to mitigate government access to data. The book concludes with a deep dive into modern approaches to cybersecurity using the cloud.
By the end of this book, you will have a better understanding of the threat landscape, how to recognize good Cyber Threat Intelligence, and how to measure the effectiveness of your organization's cybersecurity strategy.
Fachgebiete
Weitere Infos & Material
Table of Contents - Introduction
- What to Know About Threat Intelligence
- Using Vulnerability Trends to Reduce Risk and Costs
- The Evolution of Malware
- Internet-Based Threats
- The Roles Governments Play in Cybersecurity
- Government access to data
- Ingredients for a Successful Cybersecurity Strategy
- Cybersecurity Strategies
- Strategy Implementation
- Measuring Performance and Effectiveness
- Modern Approaches to Security and Compliance
Preface
Imagine you are in a submarine submerged hundreds of feet below the surface surrounded by dark, freezing water. The hull of the submarine is under constant immense pressure from all directions. A single mistake in the design, construction, or operation of the submarine spells disaster for it and its entire crew.
This is analogous to the challenge that Chief Information Security Officers (CISOs) and their teams face today. Their organizations are surrounded on the Internet by badness that is constantly probing for ways to penetrate and compromise their IT infrastructures. The people in their organizations receive wave after wave of social engineering attacks designed to trick them into making poor trust decisions that will undermine the controls that their security teams have implemented. The specters of ransomware and data breaches continue to haunt CISOs, Chief Information Officers (CIOs), and Chief Technology Officers (CTOs) of the most sophisticated organizations in the world.
After conducting hundreds of incident response investigations for Microsoft’s enterprise customers, publishing thousands of pages of threat intelligence, and assisting some of Amazon Web Services’ (AWS) largest customers, I have had the opportunity to learn from and advise literally thousands of businesses and public sector organizations in almost every country around the world. I wrote this book to share some of the insights and lessons I’ve learned during this extraordinary journey.
The views and opinions expressed in this book are my own personal opinions and not those of my current or past employers.
Who this book is for
Chief Information Security Officers (CISOs) and aspiring CISOs, Chief Security Officers (CSOs), Chief Technology Officers (CTOs), Chief Information Officers (CIOs), cybersecurity professionals, compliance and audit professionals, senior IT management with cybersecurity responsibilities, vendors’ cybersecurity professional services consultants and salespeople, computer hobbyists with an interest in cybersecurity, and university level students aspiring to become cybersecurity professionals would all benefit from reading this book.
Readers should have basic knowledge of Information Technology (IT), with some insight into IT challenges in large-scale, complex enterprise IT environments. Intermediate knowledge of networking (TCP/IP networks) and software development principles, people management experience and insights into how enterprise scale organizations generally operate, and knowledge of basic cybersecurity concepts would all be useful as well.
What this book covers
, , discusses the most common ways that enterprise IT environments get initially compromised and how to mitigate them. This will prepare you to evaluate cybersecurity strategies that are designed to mitigate intrusion attempts (covered in later chapters).
, , explains what threat intelligence is, how to determine good intelligence from bad, and how enterprise cybersecurity teams use it.
, , covers what security vulnerabilities are, how they are scored, and the long-term industry disclosure trends across major vendors, operating systems, and browsers. This chapter also provides tips and tricks for running an enterprise vulnerability management program and how threat intelligence (covered in , ) can be integrated.
, , provides a unique data-driven perspective of how malware has evolved around the world over the past 10+ years. This will help you understand the types of malware threats you face, and which malware threats are most and least prevalent.
This chapter also provides a deep dive into the evolution of ransomware – the most feared threat for security teams.
, , examines some of the ways that attackers have been using the Internet and how these methods have evolved over time. Several types of threats are examined including phishing attacks, drive-by download attacks, malware hosting sites, and Distributed Denial of Service (DDoS) attacks.
, , explains that many CISOs rely on governments to help them achieve their objectives by setting and regulating industry security standards, while others look to governments as a source of threat intelligence and guidance, while yet other CISOs view governments as threats to their organizations. What role do governments really play in cybersecurity? This chapter explores this question and help you decide whether to treat governments as threats.
, , many CISOs and security teams view governments as threats to their organizations’ data. This is especially true of organizations based outside of the United States. Why is this and what do they know that you don’t? This chapter will examine the threat of government access to data and how to mitigate it.
, , discusses developing a cybersecurity strategy, which is necessary, but not a guarantee of success by itself. There are several other ingredients that are necessary for a successful cybersecurity program. This chapter describes each of these ingredients in detail. This will give you the best chance of success for their own cybersecurity strategy.
, , critically evaluates the major cybersecurity strategies that have been employed in the industry over the past 20 years, including Zero Trust. This chapter shows you how to evaluate the effectiveness of cybersecurity strategies.
, , provides an example of how to implement one of the best cybersecurity strategies. This chapter illustrates how an attack-centric strategy that leverages the intrusion kill chain and MITRE ATT&CK® can be implemented.
, , examines one of the challenges that CISOs and security teams have always had: how to measure the effectiveness of their cybersecurity programs. It’s hard to prove that something bad didn’t happen because of the work of the cybersecurity team - this chapter provides guidance on how to measure the performance and effectiveness of cybersecurity strategies.
, , provides insights into how the cloud is the great cybersecurity talent amplifier. This chapter describes how Application Programming Interfaces (APIs) and automation can be leveraged to support a highly effective cybersecurity strategy.
To get the most out of this book
- You’ll already understand basic IT concepts and have some experience of using, implementing, and/or operating IT systems and applications.
- Possessing some knowledge of basic cybersecurity concepts will make this book an easier read.
- Experience of managing enterprise IT, compliance, and/or cybersecurity teams will be helpful, but is not strictly required.
- You’ll bring curiosity and the desire to learn about key aspects of cybersecurity that CISOs and CSOs of large organizations manage in the course of doing their jobs.
Download the color images
We also provide a PDF file that has color images of the screenshots/diagrams used in this book. You can download it here: https://packt.link/INq4w.
Conventions used
There are a number of text conventions used throughout this book.
: Indicates code words in text, database table names, folder names, filenames, file extensions, pathnames, dummy URLs, user input, and Twitter handles. For example: “Attackers could be registering and using domain names in this ccTLD to catch web browser users that type instead of .”
Any code snippet is written as follows:
Bold: Indicates a new term, an important word, or words that you see on the screen. For instance, words in menus or dialog boxes appear in the text like this. For example: “DevOps typically includes concepts like continuous testing, Continuous Integration (CI), Continuous Delivery (CD), continuous deployment, and continuous performance monitoring.”
Warnings or important notes appear like this.
Tips and tricks appear like this.
Get in touch
Feedback from our readers is always welcome.
General feedback: Email and mention the book’s title in the subject of your message. If you have questions about any aspect of this book, please email us at...




