<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Axel Petersen, Auteur</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/author/axel-petersen/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/author/axel-petersen/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Wed, 06 May 2026 14:56:17 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>Axel Petersen, Auteur</title>
	<link>https://www.riskinsight-wavestone.com/author/axel-petersen/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Backups: The Last Line of Defense Against Ransomware Part 2 </title>
		<link>https://www.riskinsight-wavestone.com/en/2026/05/backups-the-last-line-of-defense-against-ransomware-part-2/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2026/05/backups-the-last-line-of-defense-against-ransomware-part-2/#respond</comments>
		
		<dc:creator><![CDATA[Axel Petersen]]></dc:creator>
		<pubDate>Wed, 06 May 2026 14:56:14 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[air gapping]]></category>
		<category><![CDATA[Immutability]]></category>
		<category><![CDATA[Protecting Backups]]></category>
		<category><![CDATA[Risk-Based approach]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=29921</guid>

					<description><![CDATA[<p>This article is structured around four complementary approaches aimed at strengthening end‑to‑end backup security. After addressing, in Part 1, backup usability (1) and the security of the backup infrastructure (2), this second part focuses on the last two approaches: protecting...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/05/backups-the-last-line-of-defense-against-ransomware-part-2/">Backups: The Last Line of Defense Against Ransomware Part 2 </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;"><span style="color: #000000;">This article is structured around four complementary approaches aimed at strengthening end‑to‑end backup security. After addressing, in Part 1, backup usability (1) and the security of the backup infrastructure (2), this second part focuses on the last two approaches: protecting backups against logical destruction (3) and identifying the residual risks associated with the measures implemented (4). </span></p>
<p style="text-align: justify;"><span style="color: #000000;" data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1 style="text-align: justify;"><span style="color: #000000;"><b>3. Protecting backups against logical destruction</b> </span></h1>
<p style="text-align: justify;"><span style="color: #000000;">As part of a defense‑in‑depth approach to backup protection, and in light of the threat landscape observed, the assumption of an illegitimate takeover of components within the storage and backup infrastructure must be considered. </span></p>
<p style="text-align: justify;"><span style="color: #000000;">More generally, in order to effectively reduce the risk of data loss, best practice dictates ensuring that backups are not exposed to the same risks (cyber or otherwise) as the stored data. This approach is notably based on diversifying backup media, implementing physical or logical segregation, and maintaining at least one isolated copy that is both offline and off‑site. </span></p>
<p style="text-align: justify;"><span style="color: #000000;">The use of mechanisms designed to prevent the alteration or deletion of backed‑up data,even in the event of a successful attack on the storage and backup infrastructure, should therefore be considered. </span></p>
<p style="text-align: justify;"><span style="color: #000000;"><i>Immutability</i> and <i>air gapping</i> represent the two main approaches in this area. While these concepts are widely promoted by vendors, the solutions available and the residual risks associated with their implementation vary. It is therefore essential to fully understand the underlying mechanisms of these solutions in order to select the one that best addresses the required risk coverage. </span></p>
<p style="text-align: justify;"><span style="color: #000000;"><i>According to the Cyber Benchmark conducted by Wavestone, nearly 65% of organizations implement immutability or air</i>‑<i>gapping mechanisms, at least for critical functions, and 21% apply them across all of their backups.</i> </span></p>
<p style="text-align: justify;"><span style="color: #000000;" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559740&quot;:259}"> </span></p>
<h2 style="text-align: justify;"><span style="color: #000000;"><b>Backup Immutability, an Increasingly Adopted Technique</b> </span></h2>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span style="color: #000000;">&#8220;Data immutability means that data can be written but cannot be modified or deleted” (NIST). </span></p>
<p style="text-align: justify;"><span style="color: #000000;">Far from being uniform, its implementation relies on a variety of technical approaches whose robustness varies depending on whether they are based on hardware or software mechanisms. </span></p>
<p style="text-align: justify;"><span style="color: #000000;"><strong>a. Purely Hardware-Based Mechanisms </strong></span></p>
<ul style="text-align: justify;">
<li><span style="color: #000000;"><b>LTO WORM cartridges (with compatible hardware/firmware)</b> </span><br /><span style="color: #000000;">These magnetic tape cartridges allow data to be written once, preventing any subsequent modification or deletion, provided that the hardware and firmware support WORM (Write Once, Read Many) mode. </span></li>
</ul>
<p style="text-align: justify;"><span style="color: #000000;">     For more specific use cases : </span></p>
<ul style="text-align: justify;">
<li><span style="color: #000000;"><b>Blu</b>‑<b>ray jukeboxes</b> </span><br /><span style="color: #000000;">This robotic system uses WORM Blu‑ray discs to permanently store data, rendering it physically unalterable once written. </span></li>
<li><span style="color: #000000;"><b>Flash storage with WORM controller (firmware / e</b>‑<b>Fuse bit)</b> </span><br /><span style="color: #000000;">Some flash storage devices incorporate a controller with dedicated firmware or hardware mechanisms such as e‑Fuse bits, enabling data to be permanently locked after being written. </span></li>
</ul>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span style="color: #000000;"><strong>b. Software-Based Mechanisms, Embedded or Appliance-Based </strong></span></p>
<ul style="text-align: justify;">
<li><span style="color: #000000;"><b>Hardware appliance with local management</b> </span><br /><span style="color: #000000;">This is a backup‑dedicated appliance, locally configured to enforce immutability policies, often through software locks or non‑modifiable retention periods. </span></li>
<li><span style="color: #000000;"><b>Hardware appliance with online management</b> </span><br /><span style="color: #000000;">This type of appliance enables remote management, sometimes via an out‑of‑band channel, ensuring that immutability policies cannot be altered even if the primary network is compromised. </span></li>
<li><span style="color: #000000;"><b>Software installed on the organization’s operating systems</b> </span><br /><span style="color: #000000;">Some software solutions allow immutability rules to be defined directly at the operating system level. However, this approach may be less robust, as it can be vulnerable if the host system is compromised. </span></li>
<li><span style="color: #000000;"><b>Cloud capabilities (e.g., Amazon S3 Glacier / Azure Blob Storage)</b> </span><br /><span style="color: #000000;">Cloud storage services offer immutability features through retention policies or WORM locks, ensuring that stored objects cannot be modified or deleted for a defined period. </span></li>
</ul>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span style="color: #000000;">It should be noted that the level of immutability can be adjusted based on the nature of the data concerned, in order to optimize the balance between security requirements and operational constraints. </span></p>
<p style="text-align: justify;"><span style="color: #000000;">Immutability is increasingly observed as a mechanism deployed within backup protection strategies and remains more commonly implemented than air gapping. </span></p>
<p style="text-align: justify;"><span style="color: #000000;" data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 style="text-align: justify;"><span style="color: #000000;"><b>Backup Air Gapping : A Technique Observed but Less Optimized</b> </span></h2>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span style="color: #000000;">An air gap<i>4</i> is defined as “an interface between two systems in which (a) the systems are not physically connected and (b) any logical connection is not automated (i.e., data is transferred across the interface only manually, under human control).” </span></p>
<p style="text-align: justify;"><span style="color: #000000;">Like immutability, air gapping can be implemented in various ways, including: </span></p>
<p style="text-align: justify;"><span style="color: #000000;"><strong>Physical implementations  :</strong></span></p>
<ol style="text-align: justify;">
<li><span style="color: #000000;"><b>Offline, protected tape storage (primarily at a remote site)</b> </span><br /><span style="color: #000000;">Magnetic tapes are removed from the active backup system and stored in a physically separate location, preventing any network or automated access. </span></li>
<li><span style="color: #000000;"><b>Tapes stored in a backup robot</b> </span><br /><span style="color: #000000;">Although physically connected, certain backup robot configurations allow tapes to be logically disconnected when not in use, thereby limiting the risk of unauthorized access. </span></li>
<li><span style="color: #000000;"><b>Other removable storage media such as disks (stored offline)</b> </span><br /><span style="color: #000000;">Hard drives or SSDs can be used to transfer data, then physically disconnected and stored in a secure environment, ensuring full isolation. </span></li>
<li><span style="color: #000000;"><b>Optical data diode transfer gateways</b> </span><br /><span style="color: #000000;">These devices enable one‑way data transfer, physically preventing any return flow of information or commands to the source system and providing a certain level of separation. When native support is not provided by backup software vendors, third‑party software agents enabling unidirectional transfer must be used in addition. </span></li>
</ol>
<p style="text-align: justify;"><span style="color: #000000;" data-ccp-props="{&quot;335559685&quot;:1080}"> </span></p>
<p style="text-align: justify;"><span style="color: #000000;"><strong>Logical Air‑Gap Implementations (Departing from Physical Isolation) :</strong></span></p>
<ol style="text-align: justify;">
<li><span style="color: #000000;"><b>“Saloon door” network ports opened only during synchronization</b> </span><br /><span style="color: #000000;">Network connections are temporarily enabled to allow data synchronization and then automatically disabled, thereby limiting the exposure window and requiring strict controls to ensure that only legitimate replication traffic is authorized. </span></li>
<li><span style="color: #000000;"><b>Isolation through access control and encryption capabilities</b> </span><br /><span style="color: #000000;">Strict access control mechanisms combined with encryption make it possible to restrict access to backups to precisely defined users and time windows. </span></li>
<li><span style="color: #000000;"><b>Backup as a Service (isolated private cloud / third</b>‑<b>party cloud)</b> </span><br /><span style="color: #000000;">Some externalized backup offerings provide full logical isolation by segregating customer environments and limiting network interactions to strictly controlled channels. However, the risk of compromise is not null, as illustrated by a successful attack in 2025 against an online backup service targeting firewall configurations. </span></li>
</ol>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span style="color: #000000;">Subject to a risk analysis, particularly when relying on logical solutions, implementing data immutability should generally be prioritized over air gapping. </span></p>
<p style="text-align: justify;"><span style="color: #000000;">While immutability and air gapping constitute effective safeguards to preserve the integrity, and even the confidentiality, of traditional backups against risks of modification or exfiltration, other approaches that are more focused on operational optimization also warrant consideration. </span></p>
<p style="text-align: justify;"><span style="color: #000000;">In this context, the objective is no longer to secure full data copies, but rather to rely on alternative mechanisms enabling rapid and large‑scale restoration, often at the cost of certain trade‑offs. This is notably the case with snapshots, which have emerged as a preferred technical solution in environments where recovery performance takes precedence over backup completeness or robustness. </span></p>
<p style="text-align: justify;"><span style="color: #000000;" data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 style="text-align: justify;"><span style="color: #000000;"><strong>Snapshots: A Fast Recovery Solution, but Not a Full-Fledged Backup </strong></span></h2>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span style="color: #000000;">To better understand what the concept of a snapshot technically entails, it is useful to refer to the definition provided by NIST: “A record of the state of a running image, typically captured as the differences between a reference image and the current state.” </span></p>
<p style="text-align: justify;"><span style="color: #000000;">In other words, a snapshot represents an instantaneous capture of the state of a file system or data volume at a given point in time. Unlike a full backup, it records only the blocks or files that have changed since the reference state. This mechanism, which is fast and resource‑efficient, is particularly well suited to environments where rapid recovery is a priority. It is therefore widely used in virtualized and cloud infrastructures. </span></p>
<p style="text-align: justify;"><span style="color: #000000;">However, this operational efficiency comes with notable trade‑offs in terms of backup quality. Snapshots do not constitute independent copies of data; they depend on the integrity of the host system. In the event of corruption of the primary volume, snapshots may become unusable. In addition, their lifecycle management (rotation, retention, application consistency) requires particular rigor to avoid operational drift. </span></p>
<p style="text-align: justify;"><span style="color: #000000;">While effective in accelerating business recovery, snapshots cannot replace a true backup strategy. They should be considered as a complement to more robust mechanisms that ensure long‑term data durability and integrity. </span></p>
<p style="text-align: justify;"><span style="color: #000000;">Whether dealing with snapshots or traditional backups, their integration into a protection architecture requires a thorough risk analysis, including the identification of residual vulnerabilities. </span></p>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;"><span style="color: #000000;">4. <b style="font-size: revert;">Risk-Based approach and identification of residual risks</b><span style="font-size: revert; font-weight: revert;" data-ccp-props="{&quot;201341983&quot;:0,&quot;335559685&quot;:720,&quot;335559740&quot;:259,&quot;335559991&quot;:360}"> </span></span></h1>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span style="color: #000000;">Given the stakes associated with irreversible data loss and/or prolonged disruption of critical business activities, risk analysis applied to backup mechanisms is not an optional step but rather a fundamental pillar of a consistent and well‑controlled backup strategy. </span></p>
<p style="text-align: justify;"><span style="color: #000000;" data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 style="text-align: justify;"><span style="color: #000000;"><b>Embedding Risk Analysis at the Core of Backup Management</b> </span></h2>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span style="color: #000000;">Whether or not it is part of a formal certification or authorization process, conducting a risk analysis of backup mechanisms aims to ensure that the controls in place are aligned with identified threats and business continuity requirements. </span></p>
<p style="text-align: justify;"><span style="color: #000000;">In this context, a risk analysis applied to backups, based, for example, on the EBIOS Risk Manager (EBIOS‑RM) methodology proposed by ANSSI, makes it possible to assess existing controls, identify plausible attack scenarios such as compromise of the backup server or data tampering, and evaluate their likelihood. This approach helps prioritize security measures according to their potential impact on business activities, while ensuring that residual risks remain acceptable with regard to business objectives. </span></p>
<p style="text-align: justify;"><span style="color: #000000;">Monitoring residual risks, those that persist despite the implementation of protection measures, is a natural extension of the risk analysis process. It is therefore essential to identify, document, and integrate them into an ongoing security risk management strategy. By way of illustration, such residual risks may include: </span></p>
<ul style="text-align: justify;">
<li><span style="color: #000000;"><b>Insider threat :</b> A malicious administrator or an employee with privileged access may intentionally alter or delete backups. </span></li>
<li><span style="color: #000000;"><b>Compromise of the cloud backup service provider :</b> A compromise of the cloud provider, for example through the exploitation of non‑public vulnerabilities, could allow an attacker to access or manipulate backups while bypassing customer‑side security mechanisms. </span></li>
<li><span style="color: #000000;"><b>Compromise of customer (tenant) accounts :</b> Unauthorized access to customer accounts may result in loss of control over backups, including their deletion or alteration. </span></li>
<li><span style="color: #000000;"><b>Destruction of backup solution assets :</b> If the backup infrastructure is destroyed (physically or logically), restoring backups may become difficult or even impossible in the event of the loss of critical resources such as: </span>
<ul>
<li><span style="color: #000000;">Backup catalogs / backup tool databases </span></li>
<li><span style="color: #000000;">Secrets such as decryption keys </span></li>
</ul>
</li>
<li><span style="color: #000000;"><b>Technical compromise of the backup tool :</b> An attacker may render backups unusable by exploiting technical vulnerabilities in the backup software or the host system, including via low‑level out‑of‑band access mechanisms such as iLO or iDRAC. </span></li>
<li><span style="color: #000000;"><b>Compromise of administrative accounts :</b> Even with immutability mechanisms in place, functional compromise of administrative accounts may allow an attacker to disable or bypass protections before, and in some cases after, data is written (retention periods, time‑management mechanisms, etc.). </span></li>
<li><span style="color: #000000;"><b>Compromise of the backup tool’s cybersecurity controls :</b> If an attacker tampers with backup protection settings, such as encryption parameters (e.g., <i>encryption_secret</i>), backups may remain unusable.  </span></li>
</ul>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;"><span style="color: #000000;"><b>Once a secure backup solution is implemented, complement the analysis with periodic audits, Including Red Team Exercises</b> </span></h2>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span style="color: #000000;">In addition to theoretical risk analysis and residual risk monitoring, periodic audits help identify vulnerabilities related to the implementation of the backup solution. Among the possible audit types, Red Team exercises aim to reproduce the behavior of an attacker seeking to destroy backups. These exercises also serve to test the effectiveness of the technical and human measures in place for protection, detection, and response to an attack. </span></p>
<p style="text-align: justify;"><span style="color: #000000;" data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:2,&quot;335559740&quot;:300}"> </span></p>
<h1 style="text-align: justify;"><span style="color: #000000;"><b>Conclusion</b> </span></h1>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span style="color: #000000;">Protecting backups against ransomware relies on a holistic approach rather than a purely “product‑based” one : </span></p>
<ul style="text-align: justify;">
<li><span style="color: #000000;">Continuously verifying the reliability of backups to ensure effective reconstruction of the information system; </span></li>
<li><span style="color: #000000;">Securing the backup infrastructure by reducing its attack surface; </span></li>
<li><span style="color: #000000;">Protecting backed‑up data, with immutability as a priority; </span></li>
<li><span style="color: #000000;">Adopting a cross‑functional, risk‑driven approach to security management. </span></li>
</ul>
<p style="text-align: justify;"><span style="color: #000000;">The level of rigor required for backup security will continue to increase as attackers refine their techniques and strengthen their capabilities.  </span></p>
<p style="text-align: justify;"><span style="color: #000000;">Continuous vigilance and adaptation to the evolving threat landscape therefore remain the strongest allies of a resilient backup strategy. </span></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/05/backups-the-last-line-of-defense-against-ransomware-part-2/">Backups: The Last Line of Defense Against Ransomware Part 2 </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2026/05/backups-the-last-line-of-defense-against-ransomware-part-2/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Backups : The Last Line of Defense Against Ransomware &#8211; Part 1 </title>
		<link>https://www.riskinsight-wavestone.com/en/2026/04/backups-the-last-line-of-defense-against-ransomware-part-1/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2026/04/backups-the-last-line-of-defense-against-ransomware-part-1/#respond</comments>
		
		<dc:creator><![CDATA[Axel Petersen]]></dc:creator>
		<pubDate>Thu, 02 Apr 2026 06:36:52 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[cybercriminality]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[ransomware]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=29548</guid>

					<description><![CDATA[<p>In 2025, ransomware attacks remained a persistent threat and increasingly targeted backup systems (21% of attacks targeted backups in 2021, compared with 90% in 2025 [1] ). Protecting backups,&#160;now also subject to strengthened regulatory requirements such as NIS 2,&#160;has therefore...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/04/backups-the-last-line-of-defense-against-ransomware-part-1/">Backups : The Last Line of Defense Against Ransomware &#8211; Part 1 </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;"><span data-contrast="auto">In 2025, ransomware attacks remained a persistent threat and increasingly targeted backup systems (21% of attacks targeted backups in 2021, compared with 90% in 2025 [</span><span data-contrast="auto">1] </span><span data-contrast="auto">). Protecting backups,&nbsp;now also subject to strengthened regulatory requirements such as NIS 2,&nbsp;has therefore become a top priority in addressing this threat.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:360}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">This article presents four complementary approaches to strengthening end-to-end backup security:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<ol>
<li><strong>Continuously ensuring the availability of usable backups&nbsp;</strong></li>
<li><strong>Strengthening the security of the backup infrastructure against attacker takeover&nbsp;</strong></li>
<li><strong>Protecting backups against logical destruction&nbsp;</strong></li>
<li><strong>Identifying&nbsp;residual risks&nbsp;in light of&nbsp;the measures implemented&nbsp;</strong></li>
</ol>
<p>&nbsp;</p>
<p style="text-align: justify;"><span data-contrast="auto">This article is published in two parts: the first focuses on approaches 1 and 2, followed by a second publication covering approaches 3 and 4.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">The recommendations presented do not replace those set out in ANSSI guidelines, which define the fundamental principles of backup [</span><span data-contrast="auto">2]</span><span data-contrast="auto">&nbsp;practices.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> <img fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-29535" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/image.png" alt="Renforcer la sécurisation des sauvegardes par 4 approches" width="579" height="519" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/image.png 579w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/image-213x191.png 213w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/image-44x39.png 44w" sizes="(max-width: 579px) 100vw, 579px" /></span></p>
<p style="text-align: center;"><em>Figure 1: Strengthening Backup Security Through Four Approaches&nbsp;</em></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559685&quot;:720}">&nbsp;</span></p>
<h1><b><span data-contrast="none">1. Continuously ensuring the availability of usable backups</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559685&quot;:1080,&quot;335559740&quot;:259,&quot;335559991&quot;:360}">&nbsp;</span></h1>
<p style="text-align: justify;"><span data-contrast="auto">To guarantee the availability of usable backups, it is essential to apply fundamental best practices.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<h2><b><span data-contrast="none">Ensuring backup completeness and consistency</span></b><span data-ccp-props="{}">&nbsp;</span></h2>
<p>&nbsp;</p>
<p style="text-align: justify;"><span data-contrast="auto">In the context of a ransomware attack, the primary&nbsp;objective&nbsp;of backups is to provide a reliable data source enabling the reconstruction of the information system. Backups are truly effective only if they&nbsp;contain&nbsp;all the elements&nbsp;required&nbsp;for full recovery. This notably includes&nbsp;businesscritical&nbsp;data, configurations of business applications and systems, installation sources, as well as critical operational data such as password vaults, licenses, and operational documentation.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">Backup completeness alone is not sufficient. The need for data&nbsp;consistency&nbsp;points across backups originating from different sources (e.g., a document management system (DMS) database and its associated files) must also be&nbsp;taken into account. Conducting a preliminary analysis helps&nbsp;facilitate&nbsp;data resynchronization across different repositories during the recovery phase.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">In addition, it is necessary to&nbsp;maintain&nbsp;backups of the&nbsp;infrastructure itself&nbsp;to enable identical reconstruction. These backups must include the backup catalog, software installation sources, encryption keys, and all other required secrets. A copy of configuration parameters should be stored in a separate location,&nbsp;such as an offline environment,&nbsp;distinct from the primary infrastructure,&nbsp;in order to&nbsp;limit the risk of a shared compromise.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p>&nbsp;</p>
<p style="text-align: justify;"><i><span data-contrast="none">According to the Cyber Benchmark conducted by Wavestone across more than 170 assessed organizations, approximately </span></i><b><i><span data-contrast="none">90%</span></i></b><i><span data-contrast="none">&nbsp;of the&nbsp;organizations&nbsp;observed&nbsp;perform&nbsp;regular&nbsp;data backups.</span></i>&nbsp;<br><i><span data-contrast="none">Among&nbsp;organizations&nbsp;that&nbsp;perform&nbsp;regular&nbsp;backups:</span></i><span data-ccp-props="{&quot;335559685&quot;:0}">&nbsp;</span></p>
<ul>
<li><i><span data-contrast="none">Approximately&nbsp;</span></i><b><i><span data-contrast="none">65%</span></i></b><i><span data-contrast="none">&nbsp;conduct&nbsp;</span></i><b><i><span data-contrast="none">restoration&nbsp;tests</span></i></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></li>
<li><i><span data-contrast="none">Approximately&nbsp;</span></i><b><i><span data-contrast="none">20%</span></i></b><i><span data-contrast="none">&nbsp;perform&nbsp;</span></i><b><i><span data-contrast="none">business data&nbsp;consistency&nbsp;checks</span></i></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></li>
</ul>
<p style="text-align: justify;"><span data-contrast="auto">In this context, various controls must be defined and implemented on a regular basis.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<h2><b><span data-contrast="none">Testing Backup Reliability Through Regular Controls</span></b><span data-ccp-props="{}">&nbsp;</span></h2>
<p>&nbsp;</p>
<p style="text-align: justify;"><span data-contrast="auto">A first&nbsp;level of control aims to ensure that backups are effectively performed and remain usable. This can be based on the application of daily verification procedures relying on evidence such as reports, logs, and alerts. These checks may be manual or (semi)&nbsp;automated. However, an&nbsp;additional&nbsp;human review&nbsp;remains&nbsp;necessary to ensure that indicators and alerts are not misleading,&nbsp;particularly&nbsp;in the event that&nbsp;monitoring&nbsp;and control mechanisms have been compromised or disabled by an attacker.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">This first level also includes periodic restoration tests, carried out on representative scopes,&nbsp;in order to&nbsp;verify,&nbsp;where possible with the involvement of application or business subject-matter experts,&nbsp;the integrity and completeness of the data&nbsp;required&nbsp;for business recovery.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">The second level consists&nbsp;in&nbsp;ensuring that first-level checks are properly applied. It relies on independent controls or formalized processes. Dashboards may be used to centralize confidence-level indicators by correlating the results of daily operational checks with restoration test outcomes.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">Once the reliability of backups has been&nbsp;established, restoration processes should be&nbsp;optimized&nbsp;by regularly testing them and ensuring their effectiveness.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<h2><b><span data-contrast="none">Industrializing Restoration Processes to Optimize Recovery Time&nbsp;in the Event of&nbsp;a Compromise</span></b><span data-ccp-props="{}">&nbsp;</span></h2>
<p>&nbsp;</p>
<p style="text-align: justify;"><span data-contrast="auto">To reduce recovery time following a compromise, it is essential to industrialize restoration&nbsp;processes at&nbsp;scale&nbsp;in order to&nbsp;support mass recoveries. This requires preparing these processes in advance, testing them regularly, and adapting them to different destruction scenarios.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">As the restoration phase of an information system may extend over several weeks,&nbsp;or even several months,&nbsp;it is necessary to increase backup retention periods for the data to be restored,&nbsp;in order to&nbsp;prevent their loss through overwriting or premature deletion.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">Restoration processes must also include mechanisms to rapidly assess the state of&nbsp;backedup&nbsp;data by&nbsp;identifying,&nbsp;based on indicators of compromise,&nbsp;data that has been compromised,&nbsp;modified, or corrupted,&nbsp;so as to&nbsp;effectively target the&nbsp;appropriate restoration&nbsp;points.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<h2><b><span data-contrast="none">Integrating the Risk of Backup Compromise into the Restoration Strategy</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:259}">&nbsp;</span></h2>
<p>&nbsp;</p>
<p style="text-align: justify;"><span data-contrast="auto">To ensure reliable recovery following a compromise, it is essential to account, within the overall restoration strategy, for the risk of alteration or manipulation of&nbsp;backedup&nbsp;data. This involves addressing the risk of data alteration or manipulation occurring upstream of backup processing by the backup agent, for example:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<ul>
<li><span data-contrast="auto">Being able to rely on full backups created prior to the attacker’s intrusion, as&nbsp;identified&nbsp;during the&nbsp;initial&nbsp;investigations. In such cases, the&nbsp;backedup&nbsp;data can be considered uncompromised and used to rebuild systems and applications.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></li>
</ul>
<p style="text-align: justify;"><span data-contrast="auto">When restoring unaltered application or system components that are not reinstalled from trusted sources, the restoration process must also include the application of security patches and hardening measures to prevent any&nbsp;subsequent&nbsp;compromise.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">The backup process alone cannot prevent potential data compromise before the data is handed over to it. Depending on the context,&nbsp;additional&nbsp;measures may be implemented, such as:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<ul>
<li><span data-contrast="auto">Protecting data integrity through system-level mechanisms and/or cryptographic&nbsp;means;</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></li>
<li><span data-contrast="auto">Detecting data alteration through application-level validation,&nbsp;monitoring&nbsp;of “canary&nbsp;files” data, or the use of an EDR (Endpoint Detection and Response) solution.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></li>
</ul>
<p style="text-align: justify;"><span data-contrast="auto">These topics must be addressed in addition to backup protection measures.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<h2><b><span data-contrast="none">Extending Backup and Restoration Best Practices to Cloud Environments</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:259}">&nbsp;</span></h2>
<p>&nbsp;</p>
<p style="text-align: justify;"><span data-contrast="auto">Finally, the backup rules defined for&nbsp;onpremises&nbsp;environments must be replicated and adapted to cloud environments.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><i><span data-contrast="none">According to the Cyber Benchmark conducted by Wavestone, approximately 25% of the organizations observed have a regularly reviewed and updated backup policy covering both onpremises and cloud environments.</span></i><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559740&quot;:259}">&nbsp;</span></p>
<p style="text-align: justify;"><i><span data-contrast="none">In addition,&nbsp;around&nbsp;29% of&nbsp;organizations&nbsp;externalize&nbsp;a backup of&nbsp;their&nbsp;cloud data to&nbsp;another&nbsp;region&nbsp;or to an&nbsp;onpremises&nbsp;environment,&nbsp;ensuring&nbsp;resilience&nbsp;against&nbsp;cyberattacks&nbsp;and&nbsp;regularly&nbsp;testing&nbsp;this&nbsp;process.</span></i><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559740&quot;:259}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">Beyond the usability of backups, securing the infrastructure that hosts them&nbsp;represents&nbsp;an equally critical challenge,&nbsp;one that is sometimes insufficiently addressed.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<h1><b><span data-contrast="none">2. Strengthening the security of the backup infrastructure against attacker takeover</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:259}">&nbsp;</span></h1>
<p>&nbsp;</p>
<p style="text-align: justify;"><span data-contrast="auto">Before considering more advanced mechanisms, it&nbsp;is important to recall that effective backup protection first relies on best practices for securing the backup infrastructure, notably those documented by ANSSI</span><span data-contrast="auto">3</span><span data-contrast="auto">. A compromise of this infrastructure could indeed result in the alteration of backups (encryption, destruction, etc.).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p>&nbsp;</p>
<h2><b><span data-contrast="none">Ensuring Defense in Depth for the Backup Infrastructure</span></b><span data-ccp-props="{}">&nbsp;</span></h2>
<p>&nbsp;</p>
<p style="text-align: justify;"><span data-contrast="auto">These best practices include segregating production and backup environments, using dedicated administrative accounts, and hardening infrastructure components,&nbsp;particularly through the application of ANSSI hardening guides applicable to Windows, Linux, and other systems. They also apply to backup agents, which may&nbsp;constitute&nbsp;a propagation vector toward production systems.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">In addition to hardening measures, the backup infrastructure must be subject to both technical and cybersecurity monitoring.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<h2><b><span data-contrast="none">Implementing technical and cyber monitoring of backup infrastructures</span></b><span data-ccp-props="{}">&nbsp;</span></h2>
<p>&nbsp;</p>
<p style="text-align: justify;"><span data-contrast="auto">Technical monitoring of backup infrastructures helps ensure&nbsp;their proper&nbsp;operation and detect any anomalies. The effective handling of detected anomalies must be regularly reviewed.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">Cybersecurity monitoring of the backup infrastructure relies on&nbsp;appropriate logging&nbsp;and traffic analysis. It must be capable of detecting the main attack techniques&nbsp;observed&nbsp;in the wild.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<h2><b><span data-contrast="none">Maintaining&nbsp;Threat Intelligence Focused on Backup Systems</span></b><span data-ccp-props="{}">&nbsp;</span></h2>
<p>&nbsp;</p>
<p style="text-align: justify;"><span data-contrast="auto">Threat intelligence specifically targeting backup systems must be&nbsp;maintained, beyond the technical vulnerability monitoring performed as part of&nbsp;maintaining&nbsp;the backup infrastructure in a secure operating condition. This&nbsp;threat&nbsp;intelligence should cover attack techniques and tactics used against backup infrastructures,&nbsp;in order to&nbsp;anticipate&nbsp;potential attacks and adapt protection, detection, and response capabilities accordingly.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">Despite the measures implemented to prevent the compromise of backup infrastructures, the risk of logical destruction&nbsp;remains&nbsp;and must be&nbsp;anticipated.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p>&nbsp;</p>
<h1>Reference</h1>
<p>[1] Wavestone, <a href="https://www.wavestone.com/en/insight/2024-wavestone-cert-report/">CERT</a></p>
<p>[2] ANSSI, <a href="https://messervices.cyber.gouv.fr/guides/fondamentaux-sauvegarde-systemes-dinformation">Sauvegarde des systèmes d&#8217;information</a></p>
<p>[3] ANSSI, <a href="https://messervices.cyber.gouv.fr/guides/fondamentaux-sauvegarde-systemes-dinformation">Sauvegarde des systèmes d&#8217;information</a></p>






<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/04/backups-the-last-line-of-defense-against-ransomware-part-1/">Backups : The Last Line of Defense Against Ransomware &#8211; Part 1 </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2026/04/backups-the-last-line-of-defense-against-ransomware-part-1/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title> « Compromise by design » or how to anticipate a destructive cyber attack</title>
		<link>https://www.riskinsight-wavestone.com/en/2023/07/compromise-by-design-or-how-to-anticipate-a-destructive-cyber-attack/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2023/07/compromise-by-design-or-how-to-anticipate-a-destructive-cyber-attack/#respond</comments>
		
		<dc:creator><![CDATA[Axel Petersen]]></dc:creator>
		<pubDate>Thu, 06 Jul 2023 15:00:00 +0000</pubDate>
				<category><![CDATA[Cloud & Next-Gen IT Security]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[cyberresilience]]></category>
		<category><![CDATA[Recovery]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=20845</guid>

					<description><![CDATA[<p>Most organisations are still insufficiently prepared for a possible compromise of their Information System, leading to its destruction. Taking this risk into account right from the project design stage will enable them to significantly strengthen their resilience capabilities.    On...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/07/compromise-by-design-or-how-to-anticipate-a-destructive-cyber-attack/"> « Compromise by design » or how to anticipate a destructive cyber attack</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[


<p style="text-align: justify;"><i><span data-contrast="auto">Most </span></i><i><span data-contrast="auto">organisations</span></i><i><span data-contrast="auto"> are still insufficiently prepared for a possible compromise of their Information System, leading to its destruction. Taking this risk into account right from the project design stage will enable them to significantly strengthen their resilience capabilities.</span></i><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559740&quot;:259}"> </span></p>
<p><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">On 17 April, the </span><b><span data-contrast="auto">ANSSI</span></b><span data-contrast="auto"> published the </span><b><span data-contrast="auto">first doctrinal documents</span></b><span data-contrast="auto"> concerning </span><b><span data-contrast="auto">remediation</span></b><span data-contrast="auto">, which is defined as the project to regain control of a compromised information system. These documents are the fruit of the Agency&#8217;s experience in supporting victims of security incidents.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">This corpus consists of three sections: strategic section, an </span><span data-contrast="auto">organisational</span><span data-contrast="auto"> section, and a technical section. Currently, the technical section focuses on the remediation of tier 0 of the Active Directory</span><span data-contrast="auto">1</span><span data-contrast="auto">, or core of trust. This section will be supplemented with </span><b><span data-contrast="auto">additional documents in the future</span></b><span data-contrast="auto"> to enhance its content. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">The approach proposed by ANSSI (E3R) is divided into 3 stages:</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<ol>
<li data-leveltext="%1." data-font="Calibri" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,1],&quot;469777803&quot;:&quot;right&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Containment</span><span data-contrast="auto"> of the </span><span data-contrast="auto">attacker</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="%1." data-font="Calibri" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,1],&quot;469777803&quot;:&quot;right&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Evicting the intruder from the heart of the IS</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="%1." data-font="Calibri" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,1],&quot;469777803&quot;:&quot;right&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Eradicating</span><span data-contrast="auto"> the </span><span data-contrast="auto">adversary&#8217;s</span> <span data-contrast="auto">strongholds</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
</ol>
<p style="text-align: justify;"><span data-contrast="auto">These stages are illustrated by </span><b><span data-contrast="auto">3 typical remediation scenarios</span></b><span data-contrast="auto">, each with increasing ambition levels based on the </span><b><span data-contrast="auto">urgency of the restart</span></b><span data-contrast="auto"> and the </span><b><span data-contrast="auto">costs incurred</span></b><span data-contrast="auto"> by the long-term damage resulting from the attack:</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<ol>
<li data-leveltext="%1." data-font="Calibri" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Restore vital services as quickly as possible</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="%1." data-font="Calibri" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Regain control of the IS</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="%1." data-font="Calibri" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Seize the opportunity to prepare for long-term control of the IS</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
</ol>
<p style="text-align: justify;"><span data-contrast="auto">The publication of this corpus is a timely step in the </span><b><span data-contrast="auto">reflections and projects currently being carried out</span></b><span data-contrast="auto"> by </span><b><span data-contrast="auto">many public and private players</span></b><span data-contrast="auto">, with a view to </span><b><span data-contrast="auto">strengthening their resilience</span></b><span data-contrast="auto"> in the face of a </span><b><span data-contrast="auto">successful cyber-attack</span></b><span data-contrast="auto"> that would compromise or </span><b><span data-contrast="auto">even destroy their Information System on a massive scale</span></b><span data-contrast="auto">.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">In practice, the time required to establish a proven remediation system extends over several years for most players, rather than just months. This timeframe may be out of sync with the evolving threat landscape and the regulatory deadlines imposed on certain entities. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">There are several reasons for this, which vary from one player to another. </span><span data-contrast="auto">However, there are three key factors which contribute to this variation: </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<ol>
<li style="text-align: justify;" data-leveltext="%1." data-font="Calibri" data-listid="5" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="auto">Awareness of cyber risk is growing</span></b><span data-contrast="auto">; however, many </span><b><span data-contrast="auto">decision-makers</span></b><span data-contrast="auto"> still </span><b><span data-contrast="auto">lack</span></b><span data-contrast="auto"> adequate understanding. Balancing immediate priorities with long- term preparation in the face of potential compromises often leads to difficult decisions regarding the allocation of valuable human and financial resources. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li style="text-align: justify;" data-leveltext="%1." data-font="Calibri" data-listid="5" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">The interruption of an </span><span data-contrast="auto">organisation&#8217;s</span><span data-contrast="auto"> activities following an IT disaster has historically been dealt with using </span><b><span data-contrast="auto">Disaster Recovery Plans</span></b><span data-contrast="auto">. Their advantages and limitations in terms of remediation are still poorly understood within </span><span data-contrast="auto">organisations</span><span data-contrast="auto">:</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span>
<ol style="list-style-type: lower-alpha;">
<li data-leveltext="%1." data-font="Calibri" data-listid="5" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Depending on the recovery principles adopted, they may offer </span><b><span data-contrast="auto">advantages in terms of IS recovery sequencing know-how </span></b><span data-contrast="auto">(similar to an electrical shutdown/restart), capabilities for unitary and grouped reconstruction, restored data </span><span data-contrast="auto">resynchronisation</span><span data-contrast="auto"> and reconciliation, among others.</span></li>
<li data-leveltext="%1." data-font="Calibri" data-listid="5" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1">Remediation efforts can leverage this know-how, provided it has not been lost because of the adoption of new solutions (e.g., active/active backup) or when a <b style="font-size: revert; color: initial;"><span data-contrast="auto">&#8216;debt&#8217;</span></b><span style="font-size: revert; color: initial;" data-contrast="auto"> in terms of maintaining operational conditions and </span><b style="font-size: revert; color: initial;"><span data-contrast="auto">DRP exercises</span></b><span style="font-size: revert; color: initial;" data-contrast="auto"> has built up.</span><span style="font-size: revert; color: initial;" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:1440,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
</ol>
</li>
</ol>
<p style="text-align: justify;"><span data-contrast="auto">Nonetheless, these plans also have </span><b><span data-contrast="auto">significant limitations</span></b><span data-contrast="auto">. Their architecture relies on technical interconnections and data replication with backup infrastructures, which can inadvertently </span><b><span data-contrast="auto">propagate compromises</span></b><span data-contrast="auto">. Furthermore, while their relevance is proven in a deterministic context (where a given disaster corresponds to a given solution and plan), their effectiveness becomes much less certain when confronted with the diverse characteristics and possibilities of </span><b><span data-contrast="auto">evolving cyber attacks</span></b><span data-contrast="auto"> </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">This calls for a </span><b><span data-contrast="auto">hybrid approach</span></b><span data-contrast="auto"> involving operational, </span><b><span data-contrast="auto">DRP and cyber resilience players</span></b><span data-contrast="auto">. This can be facilitated or hindered depending on the </span><b><span data-contrast="auto">governance</span></b><span data-contrast="auto"> that has been put in place between these populations.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">To </span><b><span data-contrast="auto">accelerate the necessary rise in maturity</span></b><span data-contrast="auto"> of players on the subject of IS remediation following a cyber-attack, </span><b><span data-contrast="auto">several approach</span></b><span data-contrast="auto"> can be considered. Outlined below are </span><i><span data-contrast="auto">four potential strategies</span></i><span data-contrast="auto">, and the subsequent information will provide a more detailed explanation and elaboration for each approach.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<ol>
<li data-leveltext="%1." data-font="Calibri" data-listid="16" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Helping decision-makers to understand the specific nature of cyber risk;</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="%1." data-font="Calibri" data-listid="16" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Anchoring &#8220;compromise by design&#8221; in everyday life;</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="%1." data-font="Calibri" data-listid="16" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Have several remedial options at your disposal;</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="%1." data-font="Calibri" data-listid="16" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Sharing and </span><span data-contrast="auto">capitalising</span><span data-contrast="auto"> on feedback.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
</ol>
<p><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:720,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> <img decoding="async" class="aligncenter wp-image-20848 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/07/Schema-article-recovery-VE.jpg" alt="Is remediation : 4 way to accelerate its mutation" width="1280" height="720" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/07/Schema-article-recovery-VE.jpg 1280w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/07/Schema-article-recovery-VE-340x191.jpg 340w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/07/Schema-article-recovery-VE-69x39.jpg 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/07/Schema-article-recovery-VE-768x432.jpg 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/07/Schema-article-recovery-VE-800x450.jpg 800w" sizes="(max-width: 1280px) 100vw, 1280px" /></span></p>
<p><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:720,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<h2><span data-contrast="none">Helping decision-makers understand the specific nature of cyber risk</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:40,&quot;335559739&quot;:0,&quot;335559740&quot;:259}"> </span></h2>
<p style="text-align: justify;"><span data-contrast="auto"> The </span><b><span data-contrast="auto">vast majority of players</span></b><span data-contrast="auto"> do not totally rule out the </span><b><span data-contrast="auto">possibility of being vulnerable</span></b><span data-contrast="auto"> to a successful cyber-attack that would </span><span data-contrast="auto">paralyse</span><span data-contrast="auto"> their activities through the </span><b><span data-contrast="auto">logical destruction of their IT assets</span></b><span data-contrast="auto">.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">On the other hand, a significant proportion of players have not yet grasped the fact that their existing IT backup resources are </span><b><span data-contrast="auto">rarely adapted</span></b><span data-contrast="auto"> to the specific characteristics of this type of attack. A cyber-attack can </span><b><span data-contrast="auto">jeopardise</span></b><b><span data-contrast="auto"> the availability</span></b><span data-contrast="auto"> and non-compromise of operating and administrative </span><b><span data-contrast="auto">resources</span></b><span data-contrast="auto">, right down to the </span><b><span data-contrast="auto">workstations of those involved in IS recovery</span></b><span data-contrast="auto">. The timeframe for remediating an Information System (IS) that has suffered extensive destruction due to a cyber-attack is typically considerably longer compared to the recovery time communicated to the business in the event of a physical disaster.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">A number of players have not yet fully assessed the impact of the </span><b><span data-contrast="auto">cyber threat on their ecosystems</span></b><span data-contrast="auto">, for example:</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<ul>
<li style="text-align: justify;" data-leveltext="" data-font="Symbol" data-listid="8" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">If their </span><b><span data-contrast="auto">first-tier IT</span></b> <b><span data-contrast="auto">service providers</span></b><span data-contrast="auto"> (outsourcer, cloud service provider, etc.), or even </span><b><span data-contrast="auto">higher-tier</span></b><span data-contrast="auto"> providers, are themselves </span><b><span data-contrast="auto">affected by a successful destructive attack</span></b><span data-contrast="auto">;</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li style="text-align: justify;" data-leveltext="" data-font="Symbol" data-listid="8" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">If a player is the </span><b><span data-contrast="auto">victim of a cyber-attack</span></b><span data-contrast="auto">, whether proven successful or not, its </span><b><span data-contrast="auto">partners</span></b><span data-contrast="auto"> who have knowledge of the attack will be able to </span><b><span data-contrast="auto">isolate it unilaterally</span></b><span data-contrast="auto"> for protection purposes.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
</ul>
<p style="text-align: justify;"><span data-contrast="auto">The awareness of an </span><span data-contrast="auto">organisation&#8217;s</span><span data-contrast="auto"> decision-makers of the cyber risk, its systemic implications and the impact on its business must be developed. In the financial sector, the </span><b><span data-contrast="auto">DORA</span></b><span data-contrast="auto"> regulations, or their equivalents in certain non-European countries, as well as the </span><b><span data-contrast="auto">stress tests</span></b><span data-contrast="auto"> announced by the European Central Bank for </span><b><span data-contrast="auto">2024</span></b><span data-contrast="auto">, should contribute to this.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">For many decision-makers, </span><b><span data-contrast="auto">too many technical words</span></b><span data-contrast="auto"> are used to describe the </span><b><span data-contrast="auto">risk of cyber destruction</span></b><span data-contrast="auto">. Unlike compliance issues such as the RGPD, which can be understood by the uninitiated, this risk is </span><b><span data-contrast="auto">perceived as a matter for technical experts</span></b><span data-contrast="auto">. Nevertheless, the subject is increasingly being addressed at executive committee level, for example through the presence of the CISO on the Executive Committee and/or through external speakers with experience in acculturating senior management.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p> </p>
<h2 style="text-align: justify;"><span data-contrast="none">Anchoring &#8220;compromise by design&#8221; in everyday life</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:40,&quot;335559739&quot;:0,&quot;335559740&quot;:259}"> </span></h2>
<p><span data-contrast="auto">By considering the possibility of an IS compromise that could result in its destruction and incorporating this perspective </span><b><span data-contrast="auto">from project design to operational activities</span></b><span data-contrast="auto">, the resilience capabilities of the IS can be significantly bolstered. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">From the earliest stages of a project, the business units can be called upon to </span><b><span data-contrast="auto">identify and evaluate</span></b><span data-contrast="auto">, with the support of the technical teams, </span><b><span data-contrast="auto">cyber-resilient design solutions</span></b><span data-contrast="auto">. </span><span data-contrast="auto">These</span> <span data-contrast="auto">may</span> <span data-contrast="auto">include</span><span data-contrast="auto">:</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<ul>
<li style="text-align: justify;" data-leveltext="" data-font="Symbol" data-listid="9" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">To use suppliers of </span><b><span data-contrast="auto">nominal solutions</span></b><span data-contrast="auto"> that are </span><b><span data-contrast="auto">technically independent</span></b><span data-contrast="auto"> of the </span><span data-contrast="auto">organisation&#8217;s</span><span data-contrast="auto"> IS, so that its activities are not based exclusively on it’s IS;</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li style="text-align: justify;" data-leveltext="" data-font="Symbol" data-listid="9" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">To host and operate </span><b><span data-contrast="auto">backup solutions</span></b><span data-contrast="auto"> outside the </span><span data-contrast="auto">organisation&#8217;s</span><span data-contrast="auto"> IS;</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li style="text-align: justify;" data-leveltext="" data-font="Symbol" data-listid="9" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Use </span><b><span data-contrast="auto">cyber-resilient architecture models</span></b><span data-contrast="auto"> based on an on-premises catalogue or hosted in the Cloud. They are also designed to allow their resilience to be tested while limiting the impact of tests on production;</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="9" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Designing projects that enable operation in </span><b><span data-contrast="auto">degraded mode</span></b><span data-contrast="auto"> via :</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span>
<ul>
<li style="text-align: justify;" data-leveltext="" data-font="Symbol" data-listid="9" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Periodic extraction of business data in office format, outsourced and protected in an external file storage service;</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li style="text-align: justify;" data-leveltext="" data-font="Symbol" data-listid="9" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">The ability for applications (and services such as restoration) to operate without certain cross-functional services such as the AD authentication repositories via local backup accounts, etc; </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
</ul>
</li>
<li style="text-align: justify;" data-leveltext="" data-font="Symbol" data-listid="9" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Drawing up </span><b><span data-contrast="auto">downgraded business procedures</span></b><span data-contrast="auto"> based on downgraded IS resources such as those defined above.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
</ul>
<p style="text-align: justify;"><span data-contrast="auto">In addition, the appropriateness of certain practices, although incompatible with the objectives of </span><span data-contrast="auto">standardisation</span><span data-contrast="auto"> and </span><span data-contrast="auto">industrialisation</span><span data-contrast="auto">, can be considered at the technical design stage, in particular:</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<ul>
<li style="text-align: justify;" data-leveltext="" data-font="Symbol" data-listid="10" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Encouraging </span><b><span data-contrast="auto">diversity of technologies</span></b><span data-contrast="auto"> to limit the exploitation of a vulnerability.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li style="text-align: justify;" data-leveltext="" data-font="Symbol" data-listid="10" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><b><span data-contrast="auto">Limiting the dependency</span></b><span data-contrast="auto"> of applications on </span><b><span data-contrast="auto">cross-functional information systems</span></b><span data-contrast="auto">, so that they can be </span><b><span data-contrast="auto">rebuilt</span></b><span data-contrast="auto"> and made operational more quickly.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
</ul>
<p style="text-align: justify;"><span data-contrast="auto">During the </span><b><span data-contrast="auto">acceptance phase</span></b><span data-contrast="auto">, business operations in </span><b><span data-contrast="auto">degraded mode</span></b><span data-contrast="auto"> and the ability to </span><b><span data-contrast="auto">rebuild</span></b><span data-contrast="auto"> an application can be </span><b><span data-contrast="auto">systematically tested</span></b><span data-contrast="auto"> before going into production. This test can be </span><b><span data-contrast="auto">reviewed </span></b><span data-contrast="auto">if necessary for each major change. It should be reiterated periodically through exercises that will enable remediation capabilities to be tested and </span><b><span data-contrast="auto">enhance the skills</span></b><span data-contrast="auto"> of the various operational players.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">Moving </span><b><span data-contrast="auto">beyond the project phase</span></b><span data-contrast="auto">, the integration of asset </span><b><span data-contrast="auto">reconstruction</span></b><span data-contrast="auto"> practices into Business As Usual (BAU) operations enables better mastery of these practices. This, in turn, benefits a larger number of participants in the event of remediation, for example;</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<ul>
<li style="text-align: justify;" data-leveltext="" data-font="Symbol" data-listid="11" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:768,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="auto">Reconstruction</span></b><span data-contrast="auto">, once or twice a year, using non-IS resources (e.g., Cloud services or off-line resources), of </span><b><span data-contrast="auto">workstations</span></b><span data-contrast="auto"> used for </span><b><span data-contrast="auto">administrative tasks and/or critical activities</span></b><span data-contrast="auto">;</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li style="text-align: justify;" data-leveltext="" data-font="Symbol" data-listid="11" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:768,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><b><span data-contrast="auto">Reconstruction</span></b><span data-contrast="auto">, once a year, of </span><b><span data-contrast="auto">infrastructures essential</span></b><span data-contrast="auto"> to the recovery of the IS (e.g., restoration infrastructures, core of trust, </span><span data-contrast="auto">virtualisation</span><span data-contrast="auto"> base, etc.), to be determined on the basis of the threat and risk analysis;</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li style="text-align: justify;" data-leveltext="" data-font="Symbol" data-listid="11" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:768,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Development of </span><b><span data-contrast="auto">CI/CD practices</span></b><span data-contrast="auto"> on a daily basis, particularly in Cloud environments, in order to automate the </span><b><span data-contrast="auto">recreation of servers</span></b><span data-contrast="auto"> to apply changes to them, such as version upgrades or patches.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
</ul>
<p style="text-align: justify;"><span data-contrast="auto">Finally, keeping the </span><b><span data-contrast="auto">IS map</span></b><span data-contrast="auto"> (including its interconnections with partners and the Internet) and its </span><b><span data-contrast="auto">interdependencies up to date</span></b><span data-contrast="auto"> daily is a key factor in remediation, which must be supported by appropriate processes, tools (cyber-resilience) and controls.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p> </p>
<h2><span data-contrast="none">Having several remediation options at your disposal</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:40,&quot;335559739&quot;:0,&quot;335559740&quot;:259}"> </span></h2>
<p style="text-align: justify;"><span data-contrast="auto">Given the difficulty of predicting the course of a cyber-attack and the evolution of its impact in advance, the preparation of a plan requires a balance to be struck between two excesses:</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<ul>
<li style="text-align: justify;" data-leveltext="%1." data-font="Calibri" data-listid="12" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Developing reconstruction solutions tailored to </span><b><span data-contrast="auto">too few attack scenarios</span></b><span data-contrast="auto">, with the inherent risk of </span><b><span data-contrast="auto">deadlock</span></b><span data-contrast="auto">,</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li style="text-align: justify;" data-leveltext="%1." data-font="Calibri" data-listid="12" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Or, on the contrary, seek to cover </span><b><span data-contrast="auto">all possible scenarios</span></b><span data-contrast="auto">, at the cost of a </span><b><span data-contrast="auto">significant loss of efficiency</span></b><span data-contrast="auto">.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
</ul>
<p style="text-align: justify;"><span data-contrast="auto">An </span><b><span data-contrast="auto">updated risk analysis</span></b><span data-contrast="auto"> of possible attack scenarios, based on a </span><b><span data-contrast="auto">threat watch</span></b><span data-contrast="auto">, makes it possible to </span><b><span data-contrast="auto">prioritise</span></b><span data-contrast="auto"> those to be covered, such as those with the highest probability of success and the greatest impact in the context of the </span><span data-contrast="auto">organisation</span><span data-contrast="auto">. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">This analysis makes it easier to </span><b><span data-contrast="auto">identify the assumptions</span></b><span data-contrast="auto"> that will be used as inputs to the development of plans. </span><span data-contrast="auto">For example ;</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<ul>
<li style="text-align: justify;" data-leveltext="" data-font="Symbol" data-listid="17" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Just a year ago, planning for the </span><b><span data-contrast="auto">industrialised</span></b><b><span data-contrast="auto"> reconstruction of the </span></b><b><span data-contrast="auto">virtualisation</span></b><span data-contrast="auto"> layer of physical servers did not appear to be a necessity for most players, but it has now been identified as essential.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li style="text-align: justify;" data-leveltext="" data-font="Symbol" data-listid="17" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">The destruction of Cloud resources through the </span><b><span data-contrast="auto">compromise of access to the tenant</span></b><span data-contrast="auto"> (master accounts or API access) or even the </span><b><span data-contrast="auto">compromise of the Cloud provider</span></b><span data-contrast="auto"> itself, appears to be a new risk that needs to be considered in the Cloud resilience strategy of several players.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
</ul>
<p style="text-align: justify;"><span data-contrast="auto">Once the </span><b><span data-contrast="auto">working hypotheses have been chosen or ruled out</span></b><span data-contrast="auto"> (e.g., the types of components and technologies impacted, the residual capacities of the malicious code once its means of interacting with the attacker have been cut off, etc.), it is possible to </span><b><span data-contrast="auto">assess the relevance of the various possible means of reconstruction</span></b><span data-contrast="auto"> and to </span><b><span data-contrast="auto">prioritise</span></b><b><span data-contrast="auto"> the work</span></b><span data-contrast="auto"> more effectively. The following are possible means of reconstruction. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<ul>
<li style="text-align: justify;" data-leveltext="%1)" data-font="Calibri" data-listid="14" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,4],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1)&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="auto">Restore</span></b><span data-contrast="auto"> systems and/or business data from backups, if necessary, in an isolated environment (e.g., from snapshots, offline or &#8220;immutable&#8221; backups);</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li style="text-align: justify;" data-leveltext="%1)" data-font="Calibri" data-listid="14" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,4],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1)&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><b><span data-contrast="auto">Cleaning up</span></b><span data-contrast="auto"> restored environments that may have already been compromised when they were backed up (e.g., Using antivirus software for office files and systems that may have been compromised, using an EDR on systems that have been restarted in an isolated environment, or using solutions that can clean up the backed-up image of a virtual server directly);</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li style="text-align: justify;" data-leveltext="%1)" data-font="Calibri" data-listid="14" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,4],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1)&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"><b><span data-contrast="auto">Reinstallation</span></b><span data-contrast="auto"> of compromised technical layers (e.g., OS, middleware, etc.);</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li style="text-align: justify;" data-leveltext="%1)" data-font="Calibri" data-listid="14" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,4],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1)&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"><b><span data-contrast="auto">Replenishment</span></b><span data-contrast="auto"> of virtual infrastructures (e.g., Terraform, etc.);</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li style="text-align: justify;" data-leveltext="%1)" data-font="Calibri" data-listid="14" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,4],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1)&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">Strategies and solutions that can cover both the risk of a conventional disaster and a cyber disaster (e.g., a backup IS that is independent of the nominal IS, with business data refreshed by a device that maintains technical watertightness).</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
</ul>
<p style="text-align: justify;"><span data-contrast="auto">This assessment should lead to the development of a &#8220;</span><b><span data-contrast="auto">catalogue</span></b><span data-contrast="auto">&#8221; of </span><b><span data-contrast="auto">remediation methods</span></b><span data-contrast="auto">, the application of which should be </span><span data-contrast="auto">contextualised</span><span data-contrast="auto"> at the time of the attack. As a complement to each reconstruction solution in the catalogue, the </span><b><span data-contrast="auto">identification of an alternative</span></b><span data-contrast="auto"> &#8211; perhaps less </span><span data-contrast="auto">industrialised</span><span data-contrast="auto"> &#8211; solution will </span><b><span data-contrast="auto">enable us to deal more effectively with the vagaries of the attack context</span></b><span data-contrast="auto">.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p> </p>
<h2><span data-contrast="none">Sharing and capitalising on feedback</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:40,&quot;335559739&quot;:0,&quot;335559740&quot;:259}"> </span></h2>
<p style="text-align: justify;"><span data-contrast="auto">To gain maturity and efficiency in remediation more quickly, market players benefit from </span><span data-contrast="auto">capitalising</span><span data-contrast="auto"> on the experience of others.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">This may involve </span><span data-contrast="auto">capitalising</span><span data-contrast="auto"> on:</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="18" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Studies, such as the </span><b><span data-contrast="auto">body of doctrine published by ANSSI</span></b><span data-contrast="auto">;</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="18" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><b><span data-contrast="auto">Direct exchanges</span></b><span data-contrast="auto"> with </span><b><span data-contrast="auto">peers</span></b><span data-contrast="auto"> or </span><b><span data-contrast="auto">via third parties</span></b><span data-contrast="auto">;</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="18" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"><b><span data-contrast="auto">Working groups</span></b><span data-contrast="auto"> in which its ecosystem of partners will be represented if possible.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
</ul>
<p style="text-align: justify;"><span data-contrast="auto">The feedback to be sought can relate to the specificity of the cyber context in remediation but also to more traditional aspects linked to the reconstruction of an IS such as:</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="15" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">The methods and approaches used;</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="15" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Proven</span> <span data-contrast="auto">market</span><span data-contrast="auto"> solutions (</span><span data-contrast="auto">beyond</span><span data-contrast="auto"> promises); </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="15" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Performance </span><span data-contrast="auto">achieved</span><span data-contrast="auto"> (reconstruction times) </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="15" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Costs</span><span data-contrast="auto">; </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="15" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Logistical and HR aspects (similar to crisis management); </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="15" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">More functional aspects such as data reconciliation, following different restoration points and lost flows with third parties.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
</ul>
<p><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p> </p>
<h3>Other articles on the subject of remediation :</h3>
<p><a href="https://www.riskinsight-wavestone.com/en/2023/06/surviving-an-active-directory-compromise-key-lessons-to-improve-the-reconstruction-process/">Surviving an Active Directory compromise: key lessons for improving the rebuilding process</a></p>
<p><a href="https://www.riskinsight-wavestone.com/en/2021/11/cyber-attacks-what-are-the-risks-for-backups-and-how-to-protect-yourself/">Cyber-attacks: what are the risks for backups and how can you protect yourself?</a></p>
<p><a href="https://www.riskinsight-wavestone.com/en/2023/02/approaches-to-quick-active-directory-recovery/">Active Directory rebuild: approaches to quick Active Directory recovery</a></p>
<p><span data-contrast="auto">Next on </span><a href="https://www.riskinsight-wavestone.com/"><span data-contrast="none">https://www.riskinsight-wavestone.com/</span></a><span data-contrast="auto"> : workstation remediation</span></p>
<p><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/07/compromise-by-design-or-how-to-anticipate-a-destructive-cyber-attack/"> « Compromise by design » or how to anticipate a destructive cyber attack</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2023/07/compromise-by-design-or-how-to-anticipate-a-destructive-cyber-attack/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>OSINT or Intelligence 2.0</title>
		<link>https://www.riskinsight-wavestone.com/en/2022/11/osint-or-intelligence-2-0/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2022/11/osint-or-intelligence-2-0/#respond</comments>
		
		<dc:creator><![CDATA[Axel Petersen]]></dc:creator>
		<pubDate>Fri, 25 Nov 2022 09:00:00 +0000</pubDate>
				<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[OSINT]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=19074</guid>

					<description><![CDATA[<p>During protests in Philadelphia towards the end of May 2020, two police vehicles were set on fire. Photos of the event posted on Instagram and cross-referencing of aliases, visible on Etsy, Poshmark and LinkedIn, will lead[1] an FBI investigator to...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2022/11/osint-or-intelligence-2-0/">OSINT or Intelligence 2.0</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;">During protests in Philadelphia towards the end of May 2020, two police vehicles were set on fire. Photos of the event posted on Instagram and cross-referencing of aliases, visible on Etsy, Poshmark and LinkedIn, will lead<a href="#_ftn1" name="_ftnref1">[1]</a> an FBI investigator to suspect a person who will later be convicted.</p>
<ul style="text-align: justify;">
<li>In this case, FBI used <em>Open-Source INTelligence</em> (OSINT) techniques.</li>
</ul>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;">Overview and use cases</h1>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">Behind the myriad of acronyms related to OSINT (SOCMINT, GEOINT and so on) lies a single methodology: identify and consolidate a variety of information related to a target, using publicly available tools and services. Similar to technical audit activities, the underlying approach will be iterative, with its share of false positives and dead ends.</p>
<p style="text-align: justify;">Regardless of the information sought, the techniques used can range from complete passivity (search without being authenticated, without leaving any trace) to a much stronger interactivity (sending emails, subscriptions, or interaction on social networks &#8230;).</p>
<p style="text-align: justify;">Although this specific field of cyber is rapidly evolving, the constants will be:</p>
<ul style="text-align: justify;">
<li>Remain humble and critical about the quality of the sources and information retrieved.</li>
<li>Be aware of the traces generated and left as a result of our research.</li>
<li>Consider legal aspects, including research and retention of personal data.</li>
</ul>
<p style="text-align: justify;">At present, the possibilities offered by OSINT methods and tools make it possible to consolidate information in various fields:</p>
<ul style="text-align: justify;">
<li>On the organizational and human side, it will be mainly financial investigations, obtaining a consolidated view of the competition, headhunters, or lawyers.</li>
<li>On the technical side, the objective may be to conduct a proactive watch on actors and threats, or to obtain an overview of an organization&#8217;s exposure on the Internet, looking for technical entry points or leaked data.</li>
</ul>
<p style="text-align: justify;">In both cases, attackers deploy similar methodologies to achieve their goals, whether it&#8217;s doxing, blackmail, fraud, or simply the reconnaissance phase of a larger cyber attack.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><img decoding="async" class="aligncenter wp-image-19076 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/11/Before-OSING-Market.png" alt="" width="1557" height="885" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/11/Before-OSING-Market.png 1557w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/11/Before-OSING-Market-336x191.png 336w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/11/Before-OSING-Market-69x39.png 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/11/Before-OSING-Market-768x437.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/11/Before-OSING-Market-1536x873.png 1536w" sizes="(max-width: 1557px) 100vw, 1557px" /></p>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;"><strong>What market for OSINT?</strong></h1>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">The OSINT market is growing rapidly (+20 to +25% per year on average according to studies<a href="#_ftn2" name="_ftnref2">[2]</a>).</p>
<p style="text-align: justify;">These include players related to marketing solutions, business intelligence and homeland security; as well as players related to cyber threat intelligence or the provision of more OSINT-specific solutions.</p>
<ul style="text-align: justify;">
<li>Marketing intelligence platforms, such as Brandwatch, Cikisi or Digimind, which are able to analyze what is being said about a brand on social networks.</li>
<li>Players specialized in consulting and investigations in the field of economic intelligence, such as Avisa partners/CEIS, ADIT or Axis&amp;Co.</li>
<li>Homeland security oriented solutions, with players:
<ul>
<li>French, such as Thales with OSINTLab used by the Gendarmerie Nationale or Airbus ;</li>
<li>foreign, such as the American Palantir, used temporarily by French governmental administrations, while waiting for a sovereign alternative encouraged by the public authorities<a href="#_ftn3" name="_ftnref1">[3]</a>.</li>
</ul>
</li>
<li>Cyber threat intelligence actors:
<ul>
<li>working more classically on attacker groups, trends, vulnerabilities, such as Sekoia and Tehtris;</li>
<li>having the ability to automate searches, such as information leaks based on keywords (e.g., CybelAngel) or the digital footprint of a set of people (e.g. AnozrWay).</li>
</ul>
</li>
<li>Providers of specific commercial solutions, used in particular for:
<ul>
<li>automated monitoring of Web data sources, or even the Darknet, such as Fivecast Onyx or Aleph Networks;</li>
<li>transcription/indexation of speech from videos posted online, such as Chapvision and natural language processing, such as expert.ai;</li>
<li>investigation assistance, such as Maltego or Osidian.</li>
</ul>
</li>
</ul>
<h1 style="text-align: justify;">Tools</h1>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">The panel of essential OSINT tools is constantly changing and can be largely adapted according to the objectives set. We mainly count the following typologies:</p>
<ul style="text-align: justify;">
<li>Public tools, such as major search engines (Google, Yandex, Bing &#8230;) and their reverse lookup services, storage and archive sites (Pastebeen, WaybackMachine &#8230;), tracking services (airplanes, boats &#8230;) as well as some social networks.</li>
<li>Specialized SaaS services, often with trial offers or free versions, but which often limit the quantity and quality of the information presented. The use cases can be oriented towards people search (Lusha, Kaspr, Anywho, Hunter.io &#8230;), face search (TinEye, PimEyes), technical information search (Shodan, IntelX.io, Onyphe, BinaryEdge), or even leak search (HaveIbeenpwnd, DeHashed &#8230;).</li>
</ul>
<p style="text-align: justify;">Various toolkits, including complete frameworks (Maltego, Lampyre), as well as a large number of open-source tools and scripts (GHunt, Maigret, Phoneinfoga &#8230;). Most of these tools will be based on automation via Selenium and will be confronted with the API limitations and possible countermeasures of the targeted services.</p>
<p style="text-align: justify;">Within the framework of an investigation, the key will be to position our needs on the triptych Quality of information / Price of information / Simplicity of access (speed, specific developments&#8230;), and to adapt the choice of tools accordingly, given the time and financial means deployed.</p>
<p style="text-align: justify;">The legal framework surrounding OSINT activities is often vague and may depend on the country or geographical area, the durability of certain tools and platforms is never guaranteed. This is why it is useful to have a redundant toolbox and to update it regularly. As an example, the technical information search site Spyse, mainly hosted in Ukraine, has seen its services interrupted since March 2022.</p>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;">How to protect yourself from malicious use of OSINT?</h1>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">Three pieces of advice can be given to actors wishing to limit the exposure of their digital footprint:</p>
<p style="text-align: justify;">1/ (Have) your digital footprint searched on the Internet and clean up what can be cleaned up (close unnecessary accounts, do not expose unwanted information &#8211; especially using privacy settings).</p>
<p style="text-align: justify;">2/ Diversify and hide your logins and passwords (e.g. avoid leaving information that can be linked to your identity in the accounts you choose or that are offered to you by default).</p>
<p style="text-align: justify;">3/ Before posting public content, think about whether its content could be exploited against you; talk about this subject with your friends and family, reminding them that the Internet does not forget.</p>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;">What regulatory framework applies to OSINT?</h1>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">There is no specific regulatory framework applicable to OSINT in France, which is also generally the case abroad. The existing legal framework is however applicable, in particular:</p>
<ul style="text-align: justify;">
<li>The Godefrain law, which will repress the fact of accessing, fraudulently remaining in an information system, extracting, holding, or fraudulently reproducing its information. The fraudulent character can in some cases consist in bypassing a simple security mechanism or in downloading files exposed by mistake. It is assessed, on a case-by-case basis, by judges whose level of familiarity with digital technology may vary.</li>
<li>The General Data Protection Regulation (GDPR). For example, the CNIL condemned in October 2022 the company ClearView AI, champion of the indexing of face photos on the Internet. Clearview announced a target of 100 billion indexed photos, which was 10 times more than in 2020.</li>
</ul>
<p style="text-align: justify;">In addition to the regulatory framework applicable to the countries concerned, whose jurisprudence may diverge, it is desirable that the players conducting OSINT activities adhere to a framework of good practices. In this respect, we can mention the Berkeley Protocol, even if it is more specifically oriented towards investigations.       </p>
<p style="text-align: justify;">      </p>
<h1 style="text-align: justify;">What can OSINT concretely bring to cybersecurity?</h1>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">The proliferation of OSINT techniques and tools accessible to the greatest number of people can facilitate its use and its industrialization for offensive purposes, with regard to information systems, people and organizations.</p>
<p style="text-align: justify;">Putting oneself in the shoes of an attacker, by using OSINT as he does, is a way to better protect oneself. This is how OSINT finds its place in certain risk analyses, awareness-raising initiatives for people at risk, or RedTeam missions. But always within a legal and ethical framework to which the attacker will not adhere.</p>
<p style="text-align: justify;">_________________________________</p>
<p style="text-align: justify;"><a href="#_ftnref1" name="_ftn1">[1]</a> Detail of the report <a href="https://heavy.com/wp-content/uploads/2020/06/merged_87745_-1-1592492707.pdf"><em>https://heavy.com/wp-content/uploads/2020/06/merged_87745_-1-1592492707.pdf</em></a></p>
<p style="text-align: justify;"><a href="#_ftnref2" name="_ftn2">[2]</a> Including Open-Source Intelligence (OSINT) Market by GMInsights <a href="https://www.gminsights.com/industry-analysis/open-source-intelligence-osint-market"><em>https://www.gminsights.com/industry-analysis/open-source-intelligence-osint-market</em></a><em> and Open-Source Intelligence (OSINT) Market by Market Research Future </em><a href="https://www.marketresearchfuture.com/reports/open-source-intelligence-market-4545"><em>https://www.marketresearchfuture.com/reports/open-source-intelligence-market-4545</em></a></p>
<p style="text-align: justify;"><a href="#_ftnref3" name="_ftn3">[3]</a> &#8220;Chapsvision annonce l’acquisition d’Ockham Solutions après avoir finalisé celle de Deveryware&#8221; <a href="https://www.aefinfo.fr/depeche/680407">https://www.aefinfo.fr/depeche/680407</a>  and &#8220;Une alternative française au logiciel d&#8217;analyse de données de Palantir est possible, d&#8217;après Thales&#8221; <a href="https://www.usine-digitale.fr/article/une-alternative-francaise-au-logiciel-d-analyse-de-donnees-de-palantir-est-possible-d-apres-thales.N1020429">https://www.usine-digitale.fr/article/une-alternative-francaise-au-logiciel-d-analyse-de-donnees-de-palantir-est-possible-d-apres-thales.N1020429</a></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2022/11/osint-or-intelligence-2-0/">OSINT or Intelligence 2.0</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2022/11/osint-or-intelligence-2-0/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Dorking &#8211; exploiting search engine capabilities to discover security gaps</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/01/dorking-exploiting-search-engine-capabilities-discover-security-gaps/</link>
		
		<dc:creator><![CDATA[Axel Petersen]]></dc:creator>
		<pubDate>Fri, 31 Jan 2020 15:25:03 +0000</pubDate>
				<category><![CDATA[Cloud & Next-Gen IT Security]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Dorking]]></category>
		<category><![CDATA[google hacking]]></category>
		<category><![CDATA[search engines]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=12602</guid>

					<description><![CDATA[<p>Search engines, such as public ones like Google or companies’ internal intranet search tools, are typically used so one can find information about a topic that they are interested in.  However, a more nefarious way to use these tools has...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/01/dorking-exploiting-search-engine-capabilities-discover-security-gaps/">Dorking &#8211; exploiting search engine capabilities to discover security gaps</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><strong>Search engines</strong>, such as public ones like Google or companies’ internal intranet search tools, are typically used so one can find information about a topic that they are interested in.  However, a more nefarious way to use these tools has recently gained prominence.  Cybercriminals are hunting for sensitive information hidden in publically-accessible information by using search terms called “dorks”.  <strong>This technique is referred to as both “Google hacking” or “Google dorking”.</strong></p>
<figure id="post-12603 media-12603" class="align-none"><img loading="lazy" decoding="async" class="wp-image-12603 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/01/Capture.png" alt="" width="541" height="302" /></figure>
<p>Typically, <strong>one would use key words to find out information about a topic they are interested in.</strong>  For example, if one wanted to improve their tennis serve, they would probably search for “tennis serve tips”, which would give a number of links to articles based upon the terms provided. Search engines archive information collected throughout the internet, indexing information so it is readily available to comb through. A user will provide a keyword which the engine will then find throughout its indexes, returning results based upon relevance and algorithms. Search engines store all publicly accessible information in a website, like things hidden in the code that are not secured.  <strong>In addition to searching for key terms, search engines provide a number of more advanced operators to take advantage of, which is exactly what Google dorking takes advantage of.</strong> For example, the operator ‘site’ will focus a search on a specific website instead of every site indexed by the search engine.</p>
<p>Wide scale security events using Google dorking has occurred recently and has been widely reported on.   Two notable examples include the data leak of a <strong>French political party’s data</strong>, which was found on the site of its webhost using “dorks” of the type “Index of /” and <strong>the discovery of numerous websites used by the CIA for communication</strong>, leading to numerous executions of agents working for the US.</p>
<p>To give an example of a specific search that uses Google dorking, the inquiry “inurl: files intext:nationality filetype: xls intext: &lt;first name or last name type&gt;”is likely to find Excel files that contain individuals’ information with columns displaying  name and nationality. At the same time, a <strong>single well-chosen keyword</strong>—for example, the name of <strong>an enterprise application</strong> searched on the Internet or the word “<strong>salary</strong>” searched on the company intranet—c<strong>an be enough to find highly sensitive information.</strong></p>
<figure id="post-12607 media-12607" class="align-none"><img loading="lazy" decoding="async" class=" wp-image-12607 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/01/Capture-2.png" alt="" width="406" height="360" /></figure>
<p>Search engines internal to certain websites can also be exploited.  For example, <strong>websites containing application source codes</strong> (e.g. GitHub), <strong>technical forums</strong> for software publishers, or <strong>job posting websites</strong> containing descriptions of sensitive technical environments can be ripe for using Google dorking to find exploitable information</p>
<p>Google dorking has reached an apex of public accessibility because of numerous tutorials postedonline, specialized, private search engines (e.g. startpage.com) and websites listing thousands of “dorks” (e.g. Google Hacking Database) listed by specific use case (e.g. finding files containing passwords).</p>
<p>Google dorking is <strong>typically performed manually but able to be automated with “dork scanners”</strong> such as “Zeus-scanner” or with the help of PowerShell tools (PnP-PowerShell) for searches in Office365.</p>
<p><strong>To guard against exploitation of internal search engines</strong>, organizations can:</p>
<ul>
<li><strong>Use Data Loss Prevention software and services</strong> to detect data leakage of sensitive information, including tools that search non-indexed websites, like the Dark Web.</li>
<li><strong>Implement Data Classification and Governance procedures</strong>, including oversight of how data is shared, like withOffice365 Groups, starting with data that is most critical to business operation and would lead to the largest risk events (e.g. sensitive trade groups, client data, HR information, etc.)</li>
<li><strong>Appropriately oversee outsourced activities with a Security Assurance Plan</strong> and raise providers’ awareness of the importance of the adequate protection and nondisclosure of the information accessible to them. When possible, require evidence of data destruction after a contract has expired</li>
<li><strong>Supervise the transfer of sensitive information</strong> to parties that do not always possess Synchronous Serial Interface (SSI) protection capabilities (on their company intranet or on the Internet) equivalent to the organization’s own capabilities</li>
</ul>
<p>Organizations can also take <strong>measures to limit the impact of a known data leak:</strong></p>
<ul>
<li><strong>Develop a process for managing identified leaks</strong>, including actions to be taken for search engines and websites that have indexed the leak (e.g. Google search engine optimization (SEO) management)</li>
<li><strong>Have procedures for security incident management including data breach</strong> (with regards to GDPR) and crisis management activities,  noting the potential need for notification of regulatory authorities and impacted individuals.</li>
<li><strong>Have a monitoring procedure and tools in place for social media networks</strong>, developing prepared responses for engaging with individuals on these platforms when dealing with a crisis</li>
</ul>
<p>Google dorking can be leveraged by an organization <strong>to test out the security of its own systems,</strong> such as during, security audits or Red Team activities that aim at thinking from a malicious agent’s perspective to discover—before the agent—the gaps that could be exploited to cause harm to an organization.  <strong>Google dorking is a powerful technique bad actors are using</strong> to exploit rarely seen gaps in an organization’s architecture, and the possibility of this technique’s use should be kept in mind when assessing an organization’s information security risk.  It is one of the many examples of ways cybercriminals continue to evolve in their activities today, and highlights the need for an organization’s continuous evolution in how it handles security.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/01/dorking-exploiting-search-engine-capabilities-discover-security-gaps/">Dorking &#8211; exploiting search engine capabilities to discover security gaps</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Le Dorking ou la pêche aux informations sensibles via les moteurs de recherche</title>
		<link>https://www.riskinsight-wavestone.com/en/2019/08/le-dorking-ou-la-peche-aux-informations-sensibles-via-les-moteurs-de-recherche/</link>
		
		<dc:creator><![CDATA[Axel Petersen]]></dc:creator>
		<pubDate>Sat, 31 Aug 2019 08:48:07 +0000</pubDate>
				<category><![CDATA[Cloud & Next-Gen IT Security]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[données]]></category>
		<category><![CDATA[Dorking]]></category>
		<category><![CDATA[moteur de recherche]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=12050</guid>

					<description><![CDATA[<p>Les moteurs de recherche publics ou internes aux organisations offrent un moyen de « pêcher » des informations sensibles et techniquement accessibles à tous via des mots clefs bien choisis – les « Dorks ». Deux actes médiatisés ces dernières...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2019/08/le-dorking-ou-la-peche-aux-informations-sensibles-via-les-moteurs-de-recherche/">Le Dorking ou la pêche aux informations sensibles via les moteurs de recherche</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Les <strong>moteurs de recherche publics ou internes </strong>aux organisations offrent un moyen de « pêcher » des <strong>informations sensibles et techniquement accessibles à tous</strong> via des <strong>mots clefs bien choisis</strong> – les « <strong>Dorks</strong> ».</p>
<figure id="post-12055 media-12055" class="align-center"><img loading="lazy" decoding="async" class="aligncenter wp-image-12055" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/Image-1.png" alt="" width="335" height="196" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/Image-1.png 774w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/Image-1-120x70.png 120w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/Image-1-326x191.png 326w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/Image-1-768x449.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/Image-1-67x39.png 67w" sizes="auto, (max-width: 335px) 100vw, 335px" /></figure>
<p>Deux actes médiatisés ces dernières années l’illustrent parmi bien d’autres : la fuite des <strong>données d’un parti politique français </strong>retrouvées sur le site de son hébergeur, en utilisant un Dork du type « <em>Index of /</em>», ou la découverte, par des services de contre-espionnage, de <strong>sites internet servant pour la communication entre une agence étatique et ses informateurs</strong>, entraînant la mort de plusieurs dizaines d’entre eux.</p>
<p>Sur Internet, la pêche aux « Dorks » s’exerce via des <strong>moteurs de recherche tels que Google et Bing</strong> mais également sur <strong>des moteurs hors US/EU</strong> qui, tout comme les <strong>sites d’archivage </strong>de pages web, sont<strong> susceptibles de conserver des informations retirées </strong>des bases d’index <strong>des moteurs de recherche classiques</strong>.</p>
<p>A titre illustratif, la recherche suivante : « <em>inurl:files intext:nationalité filetype:xls intext:&lt;un prénom ou un nom de famille type&gt;</em> » entrée sur un moteur de recherche largement utilisé, est susceptible de retrouver des fichiers Excel où figurent des informations nominatives mentionnant la nationalité de personnes. Cependant <strong>un seul mot bien choisi</strong>, par exemple le nom d’une <strong>application métier </strong>recherché sur Internet ou le mot « <strong>salaire</strong> » recherché sur l’intranet, peut <strong>suffire à</strong> <strong>pêcher des informations très sensibles</strong>.</p>
<figure id="post-12057 media-12057" class="align-center"><img loading="lazy" decoding="async" class="aligncenter wp-image-12057" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image-2.png" alt="" width="201" height="173" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image-2.png 604w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image-2-222x191.png 222w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image-2-45x39.png 45w" sizes="auto, (max-width: 201px) 100vw, 201px" /></figure>
<p>Les moteurs de recherche internes à certains sites peuvent être également exploités. C’est le cas, par exemple, <strong>des sites spécialisés dans la mise en ligne de codes sources</strong> (ex : GitHub) ou de <strong>morceaux de textes</strong> (ex : PasteBin), des sites de <strong>forums techniques</strong> d’éditeurs de logiciels, ou de <strong>sites de CV </strong>en ligne contenant des descriptions parfois très précises sur des environnements techniques sensibles.</p>
<p>Le « <strong>Dorking</strong> » est <strong>à la portée du plus grand nombre</strong>, grâce aux nombreux <strong>tutoriels</strong> accessibles sur Internet, aux <strong>formulaires de recherches étendues</strong> (ex : celui de startpage.com) et surtout aux <strong>sites référençant des milliers de Dorks</strong> (ex : Google Hacking Database) organisés en fonction de l’usage attendu tel que retrouver des « Fichiers contenant des mots de passe ».</p>
<p>Le Dorking s’effectue plus communément à l’aide de <strong>recherches manuelles</strong> mais est susceptible d’être <strong>industrialisé</strong> grâce à des « <strong>Dork scanners</strong> » comme Zeus-scanner ou à l’aide d<strong>’outils PowerShell</strong> (PnP-PowerShell) pour les recherches dans Office365.</p>
<p>Pour <strong>se prémunir de l’exploitation malveillante du Dorking</strong>, les organisations peuvent notamment :</p>
<ul>
<li>Être en capacité de <strong>détecter les fuites d’informations</strong> sensibles sur le SI interne ou sur Internet, en examinant par exemple l’opportunité de recourir sur le SI interne à des <strong>produits de type DLP</strong> et sur internet à un <strong>service de veille des fuites d’informations</strong>, qui pourra également surveiller l’<strong>internet non-indexé</strong>, voire<strong> le Dark-Web</strong>.</li>
<li>Mettre en place une <strong>classification des données et une gouvernance des partages internes</strong> (ex : les Groups Office 365) en commençant par les activités les plus sensibles (ex : groupes métiers sensibles, données clients, RH…).</li>
<li><strong>Encadrer contractuellement et opérationnellement</strong> les missions confiées aux <strong>prestataires</strong> via un <strong>Plan d’Assurance Sécurité</strong> et les sensibiliser à la protection et à la non-divulgation des informations auxquelles ils peuvent accéder ; lorsque c’est possible, prévoir un <strong>PV de destruction de données</strong>.</li>
<li>Encadrer la communication d’informations sensibles aux partenaires sociaux, aux associations, etc. qui ne disposent pas toujours sur leur SI et sites Internet dédiés, de moyens de protection SSI équivalents à ceux de l’organisation ou de l’entreprise à laquelle ils sont liés.</li>
</ul>
<p>Les organisations peuvent également prendre des <strong>mesures</strong> visant à <strong>limiter l’impact d’une fuite de données</strong> avérée :</p>
<ul>
<li>Disposer d’une <strong>fiche réflexe </strong>pour traiter la fuite, incluant la <strong>conduite à tenir vis-à-vis des moteurs de recherche </strong>et des sites l’ayant indexée (ex : gestion du référencement Google, etc …)</li>
<li>Disposer d’un processus de gestion des incidents de sécurité, de <strong>data-breach</strong> (GDPR), de gestion de crise… incluant la <strong>notification potentielle aux autorités et personnes concernées</strong>.</li>
<li>Disposer d’un processus et d’outils de <strong>veille sur les réseaux sociaux </strong>et media avec des réponses préparées.</li>
</ul>
<p>Cette prévention peut en outre conduire à <strong>recourir à la technique du Dorking à des fins éthiques</strong>, tels que des <strong>audits de sécurité</strong>, ou des <strong>activités « Red Team »</strong> qui visent à se mettre à la place d’un acteur malveillant pour découvrir – avant lui – les failles et les informations qui permettraient de porter atteinte à l’organisation. Néanmoins, en fonction du contexte, il peut être préférable de <strong>bien encadrer en amont la communication des résultats de la mise en œuvre de techniques de Dorking</strong>, lesquelles peuvent donner lieu à la <strong>découverte d’informations personnelles ou/et sensibles</strong>, sur des ressources <strong>liées à l’entreprise ou à des acteurs externes</strong>.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2019/08/le-dorking-ou-la-peche-aux-informations-sensibles-via-les-moteurs-de-recherche/">Le Dorking ou la pêche aux informations sensibles via les moteurs de recherche</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>L&#8217;habit ne fait pas le moine &#8211; Ou l&#8217;importance du facteur humain dans la maîtrise du risque USB</title>
		<link>https://www.riskinsight-wavestone.com/en/2017/07/facteur-humain-maitrise-du-risque-usb/</link>
		
		<dc:creator><![CDATA[Axel Petersen]]></dc:creator>
		<pubDate>Thu, 13 Jul 2017 15:12:24 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Cyberattaque]]></category>
		<category><![CDATA[facteur humain]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[Risque]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=9882/</guid>

					<description><![CDATA[<p>L&#8217;USB est quasiment incontournable. L&#8217;interconnexion non maîtrisée des dispositifs avec le SI est facilitée par les comportements humains. Les moyens d&#8217;attaques se perfectionnent et le risque s&#8217;accroît, notamment vis-à-vis des attaques ciblées. Une vigilance toute particulière doit être accordée à...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2017/07/facteur-humain-maitrise-du-risque-usb/">L&#8217;habit ne fait pas le moine &#8211; Ou l&#8217;importance du facteur humain dans la maîtrise du risque USB</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>L&#8217;USB est quasiment incontournable. L&#8217;interconnexion non maîtrisée des dispositifs avec le SI est facilitée par les comportements humains.<br />
</em><em>Les moyens d&#8217;attaques se perfectionnent et le risque s&#8217;accroît, notamment vis-à-vis des attaques ciblées.<br />
</em><em>Une vigilance toute particulière doit être accordée à son usage sur les périmètres les plus sensibles, du SI et des populations utilisatrices.<br />
</em><em>La prise en compte du facteur humain via une sensibilisation adaptée est une mesure essentielle ; les solutions techniques restent un complément d&#8217;efficacité variable.</em></p>
<p>&nbsp;</p>
<h2>L&#8217;IMPORTANCE DU FACTEUR HUMAIN</h2>
<p style="margin: 0cm; margin-bottom: .0001pt;">Selon la légende, un homme déguisé en moine pénétra sans attirer la méfiance dans une forteresse du sud-est de la France (actuel Monaco), une nuit de janvier 1297. Il put ainsi ouvrir à des soldats qui s&#8217;en emparèrent facilement. Il en va de même pour des attaques perpétrées à l&#8217;aide de dispositifs USB familiers, que l&#8217;utilisateur branche en tout confiance sur le port d&#8217;une machine.</p>
<p style="margin: 0cm; margin-bottom: .0001pt;">Une étude publiée au Blackhat USA en 2016 a montré que<b> 45% des 297 clefs USB disséminées</b> sur un campus universitaire ont été <b>connectées à des ordinateurs et leurs fichiers ouverts</b>. Cette étude illustre bien la capacité à mener des attaques efficaces via des clefs USB et pour un coût minime.</p>
<p style="margin: 0cm; margin-bottom: .0001pt;">Par ailleurs qui n&#8217;a jamais laissé un téléphone portable se recharger sur l&#8217;un des ports USB de son PC ?</p>
<p style="margin: 0cm; margin-bottom: .0001pt;">Si la connexion au réseau fait le plus souvent l&#8217;objet de nombreuses mesures de sécurité, les autres portes que constituent les ports USB font, généralement, l&#8217;objet d&#8217;une attention moindre, sur les serveurs, les postes de travail et désormais les tablettes et smartphones qui intègrent la technologie USB On-The-Go.</p>
<p style="margin: 0cm; margin-bottom: .0001pt;"><b>Les dispositifs USB sont présents partout</b>, tirant partie de l&#8217;interopérabilité de l&#8217;<b><u>U</u></b><u>niversal </u><b>S</b>erial Bus.</p>
<p>Le revers de la médaille de ce développement historique et de sa compatibilité descendante, est qu&#8217;il n&#8217;a <b>pas été techniquement conçu &#8220;security by design&#8221;</b> et que ces dispositifs offrent une large surface d&#8217;attaque.</p>
<figure id="post-9883 media-9883"><a href="https://www.youtube.com/attribution_link?a=yXIKuk59k6ynP4nP&amp;u=/watch?v%3Dyjc_xvlwMa8%26feature%3Dem-share_video_user"><img loading="lazy" decoding="async" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2017/07/image-1.jpg" alt="" width="320" height="180" /></a></figure>
<p><em>Figure -Vidéo illustrative de sensibilisation sur la sécurité des clefs USB</em></p>
<p>&nbsp;</p>
<h2 style="margin: 0cm; margin-bottom: .0001pt;">UN LARGE PANEL D&#8217;ATTAQUES RENDUES POSSIBLES PAR L&#8217;USAGE (PRESQUE) INCONTOURNABLE DES DISPOSITIFS USB ET AU MANQUE INTRINSÈQUE DE SÉCURITÉ DES STANDARDS HISTORIQUES</h2>
<p>Les périphériques de stockage amovibles, clefs ou disques USB, peuvent servir de vecteur à la propagation d&#8217;un code malicieux. D&#8217;autres types de périphériques USB (ex : webcam, clef 4G) peuvent également intégrer une fonction de stockage amovible, par exemple pour faciliter l&#8217;installation du pilote logiciel du périphérique.</p>
<p><strong>La</strong> <strong>provenance légitime d&#8217;une clef USB ne peut garantir entièrement son innocuité</strong>, si celle-ci a été compromise en usine ou avant l&#8217;envoi aux clients, comme cela a pu arriver récemment à un fournisseur de systèmes de stockage.</p>
<p>Par ailleurs, <strong>un périphérique USB d&#8217;apparence banale, peut avoir été reprogrammé ou modifié physiquement</strong> pour compromettre ou endommager le système sur lequel il est branché, par exemple :</p>
<ul>
<li>En se <a href="http://usbrubberducky.com">faisant passer pour <strong>un clavier</strong> et envoyer des commandes au système hôte</a>, lesquelles vont par exemple permettre sa prise de contrôle à distance. Il est à cet effet possible de reprogrammer une clef USB du commerce (voir cas d&#8217;usage illustratif dans la vidéo ci-dessus) ou d&#8217;utiliser un dispositif ayant l&#8217;apparence d&#8217;une clef USB classique ;</li>
<li>En <a href="https://samy.pl/poisontap/">se faisant passer pour <strong>une interface réseau</strong> </a>et un serveur DHCP/DNS, afin notamment d&#8217;intercepter le trafic de l&#8217;utilisateur, d&#8217;introduire des portes dérobées sur le poste de l&#8217;utilisateur, de faire exécuter par son navigateur des codes malveillants sur des sites sur lesquels il est autorisé à se connecter, voire d&#8217;exposer un  routeur interne ;</li>
<li>Pour <strong>détruire le système hôte</strong> en <a href="https://www.usbkill.com">délivrant au connecteur des tensions élevées</a>.</li>
</ul>
<p>Une clef USB peut également être utilisée pour attaquer des <a href="https://wikileaks.org/vault7/document/Emotional_Simian-v2_3-User_Guide/Emotional_Simian-v2_3-User_Guide.pdf"><strong>équipements sensibles déconnectés </strong></a>du réseau de l&#8217;entreprise, par exemple des équipements industriels, lorsque celle-ci est utilisée en &#8220;navette&#8221; avec des postes connectés internet, donc à un attaquant externe potentiel.</p>
<p>Il est également possible de tirer parti du <a href="http://cyber.bgu.ac.il/blog/can-we-rely-air-gap-secure-our-critical-systems">rayonnement électromagnétique </a>qui peut se produire au travers d&#8217;un périphérique/câble USB, d&#8217;un <strong>poste isolé de tout réseau</strong>, pour permettre à un code malicieux, introduit via le dispositif USB, d&#8217;exfiltrer des informations à quelques mètres.</p>
<p>Les attaques consécutives à la modification de périphériques USB restent encore limitées, assez ciblées et potentiellement très efficaces (ex : Stuxnet en milieu industriel). La <strong>mise au point</strong> de certaines de ces attaques est <strong>facilitée par les sources d&#8217;informations</strong>, les tutoriels et les outils librement accessibles sur Internet.</p>
<p>L&#8217;arrivée de l&#8217;<strong>USB-C</strong>, également <strong>utilisé comme alimentation électrique</strong> des nouveaux ordinateurs portables, peut contribuer à <strong>augmenter un peu plus la surface d&#8217;attaque</strong> (chargeurs, packs de batterie), tant que la compatibilité avec des standards non sécurisés devra être maintenue pour des raisons de compatibilité descendante avec les autres versions d’USB et dans l&#8217;attente de la généralisation de futurs chargeurs sécurisés.</p>
<p>&nbsp;</p>
<h2>LES CONTRE-MESURES DOIVENT ÊTRE CIBLÉES SUR LES RISQUES LES PLUS ÉLEVÉS (ET DONC ÉGALEMENT SUR L&#8217;HUMAIN)</h2>
<p>L&#8217;évaluation des risques liés aux dispositifs USB doit permettre d&#8217;identifier les périmètres du SI et les populations vers lesquels <strong>cibler en priorité les contre-mesures</strong> :</p>
<ul>
<li>Sensibilité des populations (VIP, mainteneurs, administrateurs systèmes …) ;</li>
<li>Sensibilité de l&#8217;équipement sur lequel il est possible de connecter un dispositif USB (poste utilisateur, poste sensible déconnecté du réseau, station d&#8217;administration, serveur, équipement industriel …).</li>
</ul>
<p>La connexion d&#8217;un périphérique USB à un équipement passe par un <strong>choix humain</strong>. Il est donc essentiel de <strong>sensibiliser les acteurs</strong>, <strong>y compris leur management opérationne</strong>l, par des actions classiques (supports de communication des risques et des bonnes pratiques, …) voire plus innovantes (ex : disperser des <strong>clefs USB témoins</strong> remontant une alerte une fois connectées à un poste de travail, effectuer des <strong>démonstrations</strong>, organiser des <strong>jeux de plateau</strong> pour <strong>entraîner</strong> des populations plus ciblées à évaluer certaines prises de risque, …).</p>
<p>Les contre-mesures techniques sont un complément. Leur efficacité demeure toutefois variable.</p>
<ul>
<li>Un <strong>antivirus</strong> pourra le plus souvent détecter un fichier infecté sur un périphérique de stockage USB avec la <strong>même efficacité que si ce fichier se trouvait sur un autre espace de stockage</strong>. Certains produits pourront <strong>n&#8217;autoriser la lecture du contenu d&#8217;un stockage amovible</strong>, que si celui-ci a préalablement été chiffré <strong>avec une clef</strong> permettant d&#8217;y accéder seulement depuis des postes de l&#8217;entreprise ;</li>
<li>Des équipements de <strong>&#8216;sas&#8217; de décontamination</strong> peuvent également être utilisés pour sécuriser les échanges de fichiers entre une clef USB et le SI de l&#8217;entreprise ;</li>
<li>Des solutions logicielles permettent de <strong>contrôler la connexion</strong> d&#8217;un dispositif USB à des groupes de postes ou serveurs, <strong>en fonction de caractéristiques annoncées lors de son branchement</strong>. Il s&#8217;agit du moyen le plus répandu pour maîtriser la connexion des dispositifs USB. Cependant, un dispositif USB modifié peut dans certains cas arriver à tromper cette protection logicielle ;</li>
<li>Le marché propose également des clefs USB avec un <strong>micrologiciel sécurisé</strong>, qui permettent de s&#8217;assurer que celui-ci n&#8217;a pas été reprogrammé. Néanmoins, il reste toutefois possible d&#8217;introduire dans l&#8217;entreprise des dispositifs piégés reprenant ou imitant le packaging extérieur de clefs USB sécurisées ;</li>
<li>La <strong>neutralisation ou le blocage physique des ports USB</strong>, en particulier sur les postes les plus sensibles, tels que des stations d&#8217;administration ou des stations de conduite dans le milieu industriel, reste toutefois une solution assez efficace pour des périmètres spécifiques.</li>
</ul>
<p>Nous devrons attendre encore un peu avant de pouvoir pleinement bénéficier d&#8217;une <strong>sécurité efficace portée par de nouveaux standards USB</strong>. En attendant, le parc non sécurisé et le risque s&#8217;accroissent. Pour y faire face, <strong>ne comptons pas uniquement sur des réponses techniques et ne négligeons pas le facteur humain</strong>.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2017/07/facteur-humain-maitrise-du-risque-usb/">L&#8217;habit ne fait pas le moine &#8211; Ou l&#8217;importance du facteur humain dans la maîtrise du risque USB</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
