Navigating the Dynamic Cybersecurity Landscape: Insights from Our Recent Roundtable
Summary
This blog post, "Navigating the Dynamic Cybersecurity Landscape: Insights from Our Recent Roundtable", is a blueAPACHE article from 2023 covering security. In the ever-evolving digital era, cyber security is a dynamic landscape. Our recent Security Roundtable, in partnership with Rapid7, delved into the latest developments, challenges, and strategies to navigate this complex world. Here’s a comprehensive recap of the key takeaways from the event. It is written for readers evaluating emPOWER Security, Managed Detection and Response. The underlying security practice it describes, reducing attack surface and improving detection and response, is not tied to a specific product version and remains relevant to any organisation managing cyber risk today.
Key facts
| Label | Value |
|---|---|
| Publication year | 2023 |
| Topic | Navigating the Dynamic Cybersecurity Landscape: Insights from Our Recent Roundtable |
| Services referenced | emPOWER Security, Managed Detection and Response, emPOWER Cloud |
| Named products or vendors | Microsoft, Rapid7 |
Article
In the ever-evolving digital era, cyber security is a dynamic landscape. Our recent Security Roundtable, in partnership with Rapid7, delved into the latest developments, challenges, and strategies to navigate this complex world. Here’s a comprehensive recap of the key takeaways from the event.
Threat landscape overview
The latest ‘Notifiable Data Breach’ report from the Office of the Australian Information Commissioner (OAIC) highlighted key points:
- Data Breach Causes: Malicious or criminal attacks remained the primary cause of data breaches, with human error breaches identified at an alarming rate – 81% within 30 days.
- Sector Impact: The health and finance sectors led in reporting data breaches, with 63 breaches (15% of all notifications) in health and 54 breaches (13% of all notifications) in finance.
- Breach Magnitude: Surprisingly, most breaches (63%) affected 100 or fewer people, emphasising the need for broad-scale vigilance.
Internationally, geopolitical events have increaced cyber threats. These growing nation-state attacks coincided with joint criminal organisation attacks targeting legacy infrastructure like Microsoft Active Directory. The Log4Shell vulnerability has cast a spotlight on “vulnerability rediscovery,” where adversaries modify or reapply the same exploit to target other similarly vulnerable products. A notable metric reflecting the escalating threat intensity is the reduction in breakout time for adversaries moving within an organisation – from 98 minutes in 2021 to 84 minutes in 2023. Adhering to the 1-10-60 rule – detecting threats within the first minute, understanding them within 10 minutes, and responding within 60 minutes – emerges as a best practice in this swiftly evolving landscape.
Themes unveiled
Our discussion investigated several themes shaping the cybersecurity narrative:
Credential Access: Beyond Malware
Adversaries have evolved beyond traditional malware methods, with a shift towards exploiting valid credentials for initial access and persistence within victim environments. The abuse of valid credentials has become a prolific strategy, allowing threat actors to navigate and persist stealthily. A contributing factor is the rapid operationalisation of newly disclosed vulnerabilities, enabling adversaries to promptly turn these vulnerabilities into exploits for gaining credential access.
Financial Crime Sophistication: Rise of SLIPPY SPIDER and SCATTERED SPIDER
In the domain of financial crime, threat actors are exhibiting heightened sophistication in their attacks. Throughout the year, two adversaries, identified as SLIPPY SPIDER and SCATTERED SPIDER, have been observed pushing operational limits. Their focus extends beyond conventional targets, impacting high-profile victims and affecting employees, customers, and partners in a targeted capacity. This escalation underscores the need for organisations to fortify their defenses against increasingly sophisticated financial threat actors.
Cloud Exploitation: A 95% Surge in Incidents
The proliferation of data services and applications within cloud environments has attracted a surge in adversarial activities. Over the past year, incidents of cloud services exploitation witnessed a staggering 95% increase. Notably, threat actors are not only relying on valid cloud accounts but are also targeting public-facing applications for initial access. A shift involves adversaries concentrating more on cloud account discovery rather than traditional reliance on cloud infrastructure discovery. The use of valid “higher-privileged accounts” for privilege escalation is on the rise. Observations also indicate a strategic move away from deactivating antivirus and firewall technologies towards modifying “authentication processes” and launching attacks on identities. The overarching objectives remain gaining access, discovering the environment, lateral movement, privilege escalation, evading detection, collecting data, and impacting the victim.
Vulnerability Exploitation: A Growing Attack Surface
As organisations expand their digital “Attack Surface,” adversaries are quick to exploit a myriad of vulnerabilities across devices, applications, systems, and infrastructure. This includes both known vulnerabilities and Zero-day exploits following discovery. The concerning trend involves the reuse or modification of the same exploit to target other similarly vulnerable products. Techniques also encompass circumventing patching mechanisms by exploring alternative exploit vectors. Edge devices face heightened vulnerability to injection techniques and arbitrary file-delivery exploits.
State-Sponsored Criminal Activity: Geopolitical Impacts
The recent ASD cyber threat report indicates a continued focus of state cyber actors on government, critical infrastructure, and connected systems, including supply chains. These actors leverage cyber operations as a strategic tool to establish geopolitical dominance, either to support their economies or to undermine the sovereignty of others. An illustrative example is the Snake implant, a cyber espionage tool designed and utilised by Russia’s Federal Security Service (FSB) for long-term intelligence collection on high-priority targets globally. Additionally, joint cyber security advisories with international partners have outlined malicious cyber activity associated with a People’s Republic of China (PRC) state-sponsored cyber actor.
Financial Gains: A Shifting Landscape
Profit-driven cybercriminals are in a perpetual quest for innovative ways to maximise payment while minimising risks. While ransomware remains the most destructive cybercrime threat, other forms of cybercrimes, including Business Email Compromise (BEC), data theft, and denial-of-service (DoS) attacks, continue to impose significant financial costs on Australian entities.
Mitigation and defense strategies
The journey toward cyber resilience involves proactive mitigation and defense strategies:
- Understanding the Digital Landscape: Gaining awareness of how data is handled, used, and shared is crucial to identifying vulnerabilities and prioritising remediation efforts.
- Cyber Security Posture Assessment: Evaluating an organisation’s Cyber Security Posture against frameworks such as the Essential Eight Maturity Level aids in identifying control gaps and formulating effective mitigation strategies.
- Essential Eight Mitigation Strategies: Implementing security controls, including patching applications, operating systems, multi-factor authentication, and more, helps focus attention on generating and retaining logs for auditing and forensics investigations.
- Security Automation and SIEM Services: Leveraging managed Security and Information Event Management (SIEM) services facilitates real-time monitoring, security automation, and triage, offering granular insights into data movement and aiding in identifying suspicious activities.
Strengthening cyber resilience
As we navigate this landscape, the call to action is clear – fortify your organisation’s cyber resilience. If you would like to explore these insights further and discover how we can tailor strategies to enhance your organisation’s Cyber Security Maturity, mitigate vulnerabilities, and minimise the risk of a cybersecurity breach, schedule a meeting with our Security Practice Lead today. Schedule a Meeting Here
Related
- emPOWER Security
- emPOWER Security (pillar hub)
- Managed Detection and Response
- emPOWER Cloud
- emPOWER Cloud (pillar hub)
- blueAPACHE Security (case study)
Frequently asked questions
Which two sectors led in reported data breaches according to the OAIC report cited at this roundtable?
Health, with 63 breaches (15% of all notifications), and finance, with 54 breaches (13% of all notifications), per the latest Notifiable Data Breach report from the Office of the Australian Information Commissioner discussed at the event.
What percentage of breaches affected 100 or fewer people, according to the OAIC data cited?
63% of breaches, which the article says emphasises the need for broad-scale vigilance rather than assuming only large-scale incidents matter.
How did adversary breakout time change between 2021 and 2023, according to this article?
It reduced from 98 minutes in 2021 to 84 minutes in 2023, reflecting escalating threat intensity.
What is the "1-10-60 rule" described in this article?
A best-practice benchmark: detecting threats within the first minute, understanding them within 10 minutes, and responding within 60 minutes.
By how much did cloud services exploitation incidents increase over the past year, per this article?
A 95% increase, with threat actors increasingly targeting public-facing applications and valid cloud accounts for initial access, alongside a shift toward cloud account discovery over infrastructure discovery.
Which two named threat actors does the article identify as pushing financial crime sophistication?
SLIPPY SPIDER and SCATTERED SPIDER, described as extending their focus beyond conventional targets to high-profile victims and their employees, customers and partners.
What percentage of human error breaches were identified within 30 days, according to the OAIC data discussed?
81%, cited alongside malicious or criminal attacks as the primary cause of data breaches.
Which vendor partnered with blueAPACHE to host the Security Roundtable this article recaps?
Rapid7, named as the partner for the Security Roundtable discussed throughout the article.
Source
- origin post (2023)
Knowledge Base
What was the topic of blueAPACHE's recent Security Roundtable discussed in this blog post?
The Security Roundtable, held in partnership with Rapid7, focused on navigating the dynamic cybersecurity landscape, covering the latest developments, challenges, and strategies in cyber security.
What did the OAIC's 'Notifiable Data Breach' report reveal about causes and detection of data breaches?
According to the report, malicious or criminal attacks remained the primary cause of data breaches, and human error breaches were identified at an alarming rate of 81% within 30 days.
Which sectors reported the most data breaches according to the OAIC report cited in the article?
The health and finance sectors led in reporting data breaches, with 63 breaches (15% of all notifications) in health and 54 breaches (13% of all notifications) in finance.
What percentage of data breaches affected 100 or fewer people, and what does this suggest?
63% of breaches affected 100 or fewer people, emphasising the need for broad-scale vigilance even for smaller-scale incidents.
How has adversary breakout time changed between 2021 and 2023, and what is the '1-10-60 rule'?
Breakout time for adversaries moving within an organisation decreased from 98 minutes in 2021 to 84 minutes in 2023. The 1-10-60 rule is a best practice involving detecting threats within the first minute, understanding them within 10 minutes, and responding within 60 minutes.
What is 'vulnerability rediscovery' as mentioned in relation to the Log4Shell vulnerability?
Vulnerability rediscovery refers to adversaries modifying or reapplying the same exploit to target other similarly vulnerable products, a trend highlighted by the Log4Shell vulnerability.
Who are SLIPPY SPIDER and SCATTERED SPIDER, as mentioned in the article?
SLIPPY SPIDER and SCATTERED SPIDER are two threat actors identified in the domain of financial crime who have exhibited heightened sophistication, pushing operational limits and impacting high-profile victims, employees, customers, and partners.
How much did cloud services exploitation incidents increase over the past year according to the roundtable insights?
Incidents of cloud services exploitation witnessed a staggering 95% increase over the past year.
What is the Snake implant mentioned in the article regarding state-sponsored cyber activity?
The Snake implant is a cyber espionage tool designed and utilised by Russia's Federal Security Service (FSB) for long-term intelligence collection on high-priority targets globally.
What mitigation and defense strategies does blueAPACHE recommend based on the roundtable discussion?
The recommended strategies include understanding the digital landscape (how data is handled, used, and shared), conducting a Cyber Security Posture Assessment against frameworks like the Essential Eight Maturity Level, implementing Essential Eight Mitigation Strategies (such as patching and multi-factor authentication), and leveraging managed Security and Information Event Management (SIEM) services for real-time monitoring and security automation.
What forms of cybercrime besides ransomware continue to impose significant financial costs on Australian entities?
Besides ransomware, which remains the most destructive cybercrime threat, other costly forms include Business Email Compromise (BEC), data theft, and denial-of-service (DoS) attacks.
How can readers follow up on the insights from blueAPACHE's cybersecurity roundtable?
Readers are invited to schedule a meeting with blueAPACHE's Security Practice Lead to explore the insights further and discuss tailored strategies to enhance their organisation's Cyber Security Maturity and mitigate vulnerabilities.
When was this blog post published and who authored it?
The blog post was published on November 30, 2023, and is credited to blueAPACHE, with an estimated read time of 5 minutes.
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bcd07b7741bf53e2f27_Navigating-the-Dynamic-Cybersecurity-Landscape.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701b59b153d68a8eeb0e36_BBanner-1-Windows-10-is-out.-AI-is-in.-.avif
You’ve Invest in Security. So Why Are Breaches Still Happening?
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb807b7741bf53e298a_BBanner-1-Windows-10-is-out.-AI-is-in.-8.avif
EOFY 2026: The Reset Is Done – Now It’s About Getting Ahead
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d0_BBanner-2-When-support-ends-risk-begins-4.avif
Why Every Business Needs AI Guardrails
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d7_BBanner-2-When-support-ends-risk-begins-3.avif
Ransomware Incident Response: Why Paying the Ransom Is a Failure of Preparation
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb707b7741bf53e297d_BBanner-2-When-support-ends-risk-begins-1.avif
The 7 Cyber Truths Boards Must Act On In 2026
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29f9_BBanner-1-Windows-10-is-out.-AI-is-in.-7.avif
Reflecting on an Outstanding 2025 – Thank You for Your Partnership
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e2a0c_Procurement-Portal.avif
The blueAPACHE e-Store: IT purchasing made simple
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29ec_BBanner-1-Windows-10-is-out.-AI-is-in.-5.avif
Building Our Cyber Safe Culture: A Practical Guide for CSAM 2025
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.
-
https://www.facebook.com/tr?id=541021476571056&ev=PageView&noscript=1
(no alt text)