Change Your Cyberscurity Risk Calculation Mindset: Horizon3.AI Executive

"We have limited resources," said Anthony Pillitiere, CTO and co-founder of Horizon3.ai.

Samara Lynn
clock • 2 min read
Change Your Cyberscurity Risk Calculation Mindset: Horizon3.AI Executive

"Why am I wasting my time?" Anthony Pillitiere, CTO and co-founder, Horizon3.ai, said he once asked himself while working in IT operations while analyzing cybersecurity risk. 

"We have limited resources," Pillitiere told the audience during his presentation at the Midsize Enterprise Summit IT Security 2024, hosted by MES Computing parent The Channel Company.

Pillitiere offered ways organizations can tweak their cybersecurity strategy to become more secure and efficient in calculating risk.

Many organizations, he said, have a flawed risk calculation methodology which is "likelihood times impact." He said that thinking is incorrect. 

"The data that we are using to perform that calculation is off," he said. "We look at the CVSS [common vulnerability scoring system] score and that tells us likelihood, but does it really tell us likelihood in the context of our environment?" 

Pillitiere expounded on that thought with an example.

"If I [as a threat actor] land on a printer and I can't get to anything [in the network] there's no value to me as an attacker," he explained. "Is that really valuable for you to fix?" 

Attackers, he said, also have "margins" and want to attack as efficiently as possible. 

"So that was printer A. If I go to printer B and it's connected to a domain controller and it has cached credentials on it and I can dump those credentials, now I can use those credentials somewhere else. Printer B – that changes the likelihood and impact [of a compromise] … What is possible after I get exploitation, what is the impact? What am I actually calculating when I'm calculating this?" he added. 

Organizations tend to calculate risk in less granular ways, Pillitiere said, and not within the context of their environments. 

"How do we be more efficient by calculating risk level?" He urged organizations to adopt an offense-to-inform defense strategy and an offense-to-inform defense philosophy.

That means not having a false sense of security. The worst thing than risk, is risk you were confident was known and you took steps to mitigate. You don't really know your risks unless you are actively taking an offense strategy, he explained.

"If you think about how many different permutations of [security] tools that you have … the average number I believe is like 25 … you don't have enough people to manage and understand the intricacies of all of your security tools. How do you understand if they are doing what they're supposed to be doing if you're not sending an attacker at them to trigger those alerts?" 

Pillitiere said there is no longer any perimeter. Bad actors are coming from the outside and landing on the inside. Prioritizing what is critical to secure is paramount, as is being more efficient in fixing things that are actually going "to move the needle." 

"Otherwise, you're wasting time [on] risk calculation," he said. 

 

You may also like
Midmarket Reacts, Recovers From CrowdStrike Outage

Software

Needless to say, the outage placed additional burden on IT departments, particularly those in the midmarket where budgets and team sizes can be limited.

clock 07-23-2024 • 5 min read
SolarWinds Patches Eight Critical Flaws In Access Rights Manager Software

Security

The latest revelation comes as a U.S. district judge last week dismissed most of a lawsuit that accused SolarWinds of misleading investors.

clock 07-22-2024 • 3 min read
Access Point: Weekly News Roundup For IT Executives – July 19, 2024

Column

Access Point is a weekly roundup of major tech news for IT executives on the go. This edition covers July 15-July 19.

clock 07-19-2024 • 1 min read

More on Security

SolarWinds Patches Eight Critical Flaws In Access Rights Manager Software

SolarWinds Patches Eight Critical Flaws In Access Rights Manager Software

The latest revelation comes as a U.S. district judge last week dismissed most of a lawsuit that accused SolarWinds of misleading investors.

clock 07-22-2024 • 3 min read
Protect AI Releases 'Bug Bounty' Report On July Vulnerabilities

Protect AI Releases 'Bug Bounty' Report On July Vulnerabilities

The vulnerabilities involve tools used to build machine language models that fuel artificial intelligence applications.

Samara Lynn
clock 07-18-2024 • 3 min read
Kaspersky Exiting US Market After Ban: What To Know If You're Running Its Software

Kaspersky Exiting US Market After Ban: What To Know If You're Running Its Software

Experts offer guidance for midmarket IT leaders on navigating their organizations through the government's Kaspersky ban and the company's move to shutter its U.S. operations.

Samara Lynn
clock 07-18-2024 • 8 min read