Part four of Play Your Position, a Cyberleaf series on the lessons in Ken Dryden's The Game. This one takes on the defender's mindset from the security operations side.
Our team has spent September working through lessons from Ken Dryden, the goaltender who died a year ago this month. The one I was handed is the defender's mindset. Jeff Buss wrote the piece that started it, and one of his lines was that you can only shoot a puck so many ways, and how this carries over to cyber.
The metaphor works as an opposing example because hockey is a fixed environment. The physics of the game have not changed since the game was first played on a frozen pond. Cybersecurity, by contrast, operates in a man-made domain where the underlying conditions are constantly changing. You step onto what you think is a rink, take your shot, and suddenly the ice turns to mud, the puck changes shape mid-flight, and the goal doubles in size. That is what an unanticipated vulnerability, such as a zero-day exploit, does to a control you were counting on. Or, likewise, what an out-of-cycle patch does to a previously reliable exploit in an offensive cyber operations plan. In a deeply hypothetical sense, the number of possible paths into an environment is nearly limitless.
You could respond by trying to prepare for everything, but that is both daunting and impractical. There are simply too many possibilities to account for, and trying to do so often leads to analysis paralysis.
Instead, we use intelligence to narrow the list of likely adversaries and their TTPs. Like defenders, cyber criminals and nation-state actors operate under constraints of time, budget, and talent. They are creative, but they are not omnipotent. They must prioritize their efforts to maximize returns, which means we are not facing every threat group, just the ones who have a reason to target the organizations we protect. An intelligence program helps us identify those groups, their tools, and techniques.
Intelligence is not fortune-telling. It is a reasoned assessment of what we are most likely to encounter, based on who or what we are defending. Most of our customers are small and mid-sized businesses, making financially motivated criminal actors the more likely threat. Our defense industrial base customers represent a smaller subset where that assessment often shifts toward nation-state attackers. Once we understand whose tradecraft we are facing, we can prioritize our sensor alignment on the most relevant tactics, techniques, and procedures and prepare accordingly. In military terms, this is intelligence-driven operations, and I believe it is indispensable to the defender's mindset.
Then there is the question of what an adversary does after gaining access. Initial access is often unprivileged, and no attacker gains access simply for the sake of gaining access. The next stage usually involves deploying additional tools, executing code, or expanding control within the environment. That creates opportunities for detection. We narrow the avenues of approach and focus on the choke points where adversary behavior must surface. Frequently, we catch the second stage: the malware that follows the initial compromise, the download that delivers the real payload, or the account that suddenly begins interacting with a cloud environment in ways that have no legitimate business purpose.
The defender's mindset is not about anticipating every possible move. It is about understanding the adversaries most likely to matter, recognizing the behaviors that must occur for them to succeed, and positioning ourselves to detect and disrupt those behaviors. The environment may be constantly changing, but disciplined, intelligence-driven defense allows us to focus on what is probable instead of becoming overwhelmed by what is merely possible.
– Nikita
Originally published on LinkedIn by Nikita Belikov, Director of SOC Services at Cyberleaf.