<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Thomas Vo-Dinh, Auteur</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/author/thomas-vo-dinh/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/author/thomas-vo-dinh/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Wed, 06 Nov 2024 22:09:02 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>Thomas Vo-Dinh, Auteur</title>
	<link>https://www.riskinsight-wavestone.com/author/thomas-vo-dinh/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Cracking the recipe: making employees hungry for more cyber awareness activities</title>
		<link>https://www.riskinsight-wavestone.com/en/2023/01/cracking-the-recipe-making-employees-hungry-for-more-cyber-awareness-activities/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2023/01/cracking-the-recipe-making-employees-hungry-for-more-cyber-awareness-activities/#respond</comments>
		
		<dc:creator><![CDATA[Thomas Vo-Dinh]]></dc:creator>
		<pubDate>Mon, 23 Jan 2023 09:00:00 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[EscapeGame]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=19509</guid>

					<description><![CDATA[<p>Who would have known that locking your employees in a room for 15 minutes could become their new favorite way to learn about cybersecurity?  In a never-ending quest to find innovative ways to raise awareness on cybersecurity topics, the Wavestone team...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/01/cracking-the-recipe-making-employees-hungry-for-more-cyber-awareness-activities/">Cracking the recipe: making employees hungry for more cyber awareness activities</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="reader-text-block__paragraph" style="text-align: justify;">Who would have known that locking your employees in a room for 15 minutes could become their new favorite way to learn about cybersecurity? </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">In a never-ending quest to find innovative ways to raise awareness on cybersecurity topics, the Wavestone team might have very well unearthed the new golden nugget.</p>
<p class="reader-text-block__paragraph" style="text-align: justify;">Tested and approved by hundreds of our clients&#8217; employees, <strong>read on to find out the secret recipe that makes cybersecurity best practices so easy to digest. </strong></p>
<p><img fetchpriority="high" decoding="async" class="aligncenter wp-image-24559 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-1-1.png" alt="Cyber escape game as a secret recipe for maximizing awareness-raising efforts" width="1002" height="318" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-1-1.png 1002w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-1-1-437x139.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-1-1-71x23.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-1-1-768x244.png 768w" sizes="(max-width: 1002px) 100vw, 1002px" /></p>
<div class="reader-image-block reader-image-block--full-width" style="text-align: justify;">
<figure class="reader-image-block__figure">
<div class="ivm-image-view-model   ">
<div class="ivm-view-attr__img-wrapper ivm-view-attr__img-wrapper--use-img-tag display-flex
    
    "> </div>
<div> </div>
<div class="ivm-view-attr__img-wrapper ivm-view-attr__img-wrapper--use-img-tag display-flex
    
    "><span style="font-size: revert; color: initial;">The concept, inspired by a beloved leisure activity, is </span><strong style="font-size: revert; color: initial;">simple, yet mightily potent. </strong></div>
</div>
</figure>
</div>
<p class="reader-text-block__paragraph" style="text-align: justify;">Employees are assembled into teams of four or five participants. </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">The mission starts with a 10-minute briefing where they receive a lightning-fast training to become agents, and step into the shoes of hackers to perform their mission &#8211; should they accept it. </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">They are then given 15 minutes to uncover as many confidential documents as they will find in their fictional target&#8217;s office. The game elaborately weaves in clues of varying difficulty level related to key security topics, including <strong>passwords, physical security, and social engineering</strong> to name a few. </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">Finally, participants come out of their adventure eyes bright and laughing, enthusiastic to move on to a 15-minute debriefing, where best cybersecurity practices are explained. </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">In the end, <strong>the activity mobilizes employees for a mere 40 minutes, which pass by in a flash, and leaves them motivated to implement concrete actions to protect their organization</strong>.</p>
<p><img decoding="async" class="aligncenter size-full wp-image-24561" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-2.png" alt="What sets the cyber game apart?" width="966" height="325" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-2.png 966w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-2-437x147.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-2-71x24.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-2-768x258.png 768w" sizes="(max-width: 966px) 100vw, 966px" /></p>
<div class="reader-image-block reader-image-block--full-width" style="text-align: justify;">
<figure class="reader-image-block__figure">
<div class="ivm-image-view-model   ">
<h2 class="ivm-view-attr__img-wrapper ivm-view-attr__img-wrapper--use-img-tag display-flex
    
    "> </h2>
</div>
</figure>
</div>
<h2 class="reader-text-block__heading2" style="text-align: justify;">Gamification never disappoints  </h2>
<p class="reader-text-block__paragraph" style="text-align: justify;">Quite a few years might have passed since you and the members of your organization ran around your school&#8217;s playground, but one thing remains the same: <strong>games are still a unanimously popular way to learn. </strong></p>
<p class="reader-text-block__paragraph" style="text-align: justify;">Through gamification, <strong>people become actors, instead of spectators</strong>, of the learning process and embody the principles that you aim to instill in them. Keeping in mind that <strong>practice makes up 70% of the learning process</strong>, that is an opportunity that is hard to pass by.</p>
<p class="reader-text-block__paragraph" style="text-align: justify;">When adopting an active posture, participants get immersed in the activity, and they do not even realize that they are <strong>acquiring precious skills that will serve them and their organization&#8217;s security well for years to come. </strong></p>
<h2 class="reader-text-block__heading2" style="text-align: justify;">Spice it up with competition </h2>
<p class="reader-text-block__paragraph" style="text-align: justify;">What do football, chess, and Monopoly have in common? Besides the fact that they are all games, they also include an element of competition. </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">In the context of a challenge, <strong>competition acts as a strong motivator and a driver to perform</strong>. Add a fun and safe environment to the mix, and you have yourself a perfect combination to tremendously boost engagement. </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">Our cyber escape game includes a <strong>smart scoring system</strong>, so teams feel driven to reach the highest score, and you can gather information on overall performance. That&#8217;s what we call a win-win. </p>
<figure id="attachment_19496" aria-describedby="caption-attachment-19496" style="width: 872px" class="wp-caption aligncenter"><img decoding="async" class="size-full wp-image-19496" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-1.png" alt="Example of scoring sheet for the cybersecurity escape game" width="872" height="637" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-1.png 872w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-1-261x191.png 261w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-1-53x39.png 53w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-1-768x561.png 768w" sizes="(max-width: 872px) 100vw, 872px" /><figcaption id="caption-attachment-19496" class="wp-caption-text"><em>Example of scoring sheet</em></figcaption></figure>
<div class="reader-image-block reader-image-block--resize" style="text-align: center;">
<figure class="reader-image-block__figure">
<div class="ivm-image-view-model   ">
<div class="ivm-view-attr__img-wrapper ivm-view-attr__img-wrapper--use-img-tag display-flex
    
    "> </div>
</div>
<figcaption class="display-block mt2 full-width text-body-small-open t-sans text-align-center t-black--light"></figcaption>
</figure>
</div>
<h2 class="reader-text-block__heading2" style="text-align: justify;">The more the merrier </h2>
<p class="reader-text-block__paragraph" style="text-align: justify;">When faced with a puzzle to solve, who would be against a little bit of help? </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">Indeed, completing an exercise on one&#8217;s own can be daunting, if not just plain lonely.  </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">As part of a cyber escape game, people are encouraged to collaborate to solve clues. <strong>Teamwork then makes the challenge even more fun</strong> as creative ideas to break codes burst and are implemented, rendering their success all the more rewarding. </p>
<figure id="attachment_19498" aria-describedby="caption-attachment-19498" style="width: 1024px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-19498" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-2.jpg" alt="Briefing session in Krakow" width="1024" height="768" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-2.jpg 1024w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-2-255x191.jpg 255w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-2-52x39.jpg 52w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-2-768x576.jpg 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-2-600x450.jpg 600w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption id="caption-attachment-19498" class="wp-caption-text"><em>Briefing before the escape game</em></figcaption></figure>
<div class="reader-image-block reader-image-block--resize" style="text-align: center;">
<figure class="reader-image-block__figure">
<div class="ivm-image-view-model   ">
<div class="ivm-view-attr__img-wrapper ivm-view-attr__img-wrapper--use-img-tag display-flex
    
    "> </div>
</div>
<figcaption class="display-block mt2 full-width text-body-small-open t-sans text-align-center t-black--light"></figcaption>
</figure>
</div>
<h2 class="reader-text-block__heading2" style="text-align: justify;">Bring the human touch to learning experiences </h2>
<p class="reader-text-block__paragraph" style="text-align: justify;">To complement online training initiatives, providing staff with a way to <strong>engage in-person with cybersecurity experts</strong> allows to go the extra mile in accompanying them on their learning journey. </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">Indeed, this format promotes live discussions and gives people the opportunity to receive personalized answers to their specific questions related to security.</p>
<p class="reader-text-block__paragraph" style="text-align: justify;">The result? Employees coming out of the activity with <strong>advice that precisely solves their pain points</strong>. </p>
<figure id="attachment_19500" aria-describedby="caption-attachment-19500" style="width: 1395px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-19500" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-3.png" alt="Positive feedback from the cybersecurity escape game" width="1395" height="919" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-3.png 1395w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-3-290x191.png 290w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-3-59x39.png 59w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-3-768x506.png 768w" sizes="auto, (max-width: 1395px) 100vw, 1395px" /><figcaption id="caption-attachment-19500" class="wp-caption-text"><em>Feedback from participants of our latest session</em></figcaption></figure>
<div class="reader-image-block reader-image-block--resize" style="text-align: center;">
<figure class="reader-image-block__figure">
<div class="ivm-image-view-model   ">
<div class="ivm-view-attr__img-wrapper ivm-view-attr__img-wrapper--use-img-tag display-flex
    
    "> </div>
</div>
<figcaption class="display-block mt2 full-width text-body-small-open t-sans text-align-center t-black--light"><em><br /><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-24563" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-3.png" alt="Make it happen" width="1004" height="320" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-3.png 1004w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-3-437x139.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-3-71x23.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-3-768x245.png 768w" sizes="auto, (max-width: 1004px) 100vw, 1004px" /></em></figcaption>
</figure>
</div>
<p class="reader-text-block__paragraph" style="text-align: justify;">Not only is the format of the cyber escape game particularly appreciated by employees, it also presents multiple advantages for your organization in terms of implementation. </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">Take it from the Wavestone team !</p>
<p class="reader-text-block__paragraph" style="text-align: justify;">Over the course of the month of October 2022, <a href="https://www.linkedin.com/company/wavestone/" data-entity-hovercard-id="urn:li:fs_miniCompany:10133" data-entity-type="MINI_COMPANY">Wavestone</a> Belgium carried out +100 cyber escape games sessions with +400 players across 6 countries.  </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">As training sessions last 40 minutes each,<strong> up to 45 collaborators can be trained in one day</strong>, maximizing time-efficiency. </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">Further, <strong>customization </strong>is at the core of our approach, with a debriefing that exposes concrete ways to <strong>apply the best security practices that are most crucial to your organization</strong>.</p>
<p class="reader-text-block__paragraph" style="text-align: justify;">Although we could keep on enumerating the benefits that a cyber escape game can bring to an entity&#8217;s security, a game is still worth a thousand words.</p>
<p class="reader-text-block__paragraph" style="text-align: justify;">Curious to understand how the cyber escape game leaves employees asking for another serving of awareness activities? <strong>Get in touch with our expert </strong><a href="https://www.linkedin.com/in/thomasvodinh?miniProfileUrn=urn%3Ali%3Afs_miniProfile%3AACoAABXDa2gB3uuIfNKDhMbmEedA2haY2hHz1UA" data-entity-hovercard-id="urn:li:fs_miniProfile:ACoAABXDa2gB3uuIfNKDhMbmEedA2haY2hHz1UA" data-entity-type="MINI_PROFILE">Thomas Vo Dinh</a><strong> to organize a free session.</strong></p>
<p class="reader-text-block__paragraph" style="text-align: justify;">See you on the other side, agent <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/01/cracking-the-recipe-making-employees-hungry-for-more-cyber-awareness-activities/">Cracking the recipe: making employees hungry for more cyber awareness activities</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2023/01/cracking-the-recipe-making-employees-hungry-for-more-cyber-awareness-activities/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Adapting your detection strategy to the multi-cloud without getting lost in the cloud</title>
		<link>https://www.riskinsight-wavestone.com/en/2021/10/adapting-your-detection-strategy-to-the-multi-cloud-without-getting-lost-in-the-cloud/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2021/10/adapting-your-detection-strategy-to-the-multi-cloud-without-getting-lost-in-the-cloud/#respond</comments>
		
		<dc:creator><![CDATA[Thomas Vo-Dinh]]></dc:creator>
		<pubDate>Mon, 18 Oct 2021 12:54:00 +0000</pubDate>
				<category><![CDATA[Cloud & Next-Gen IT Security]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[SOC]]></category>
		<category><![CDATA[Transformation]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=17051</guid>

					<description><![CDATA[<p>  If 10 years ago, building your SOC meant asking yourself which scenarios to monitor, which log sources to collect and which SIEM to choose, recent developments in the IS have brought new challenges: how to set up monitoring in...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/10/adapting-your-detection-strategy-to-the-multi-cloud-without-getting-lost-in-the-cloud/">Adapting your detection strategy to the multi-cloud without getting lost in the cloud</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p> </p>
<p>If 10 years ago, building your SOC meant asking yourself which scenarios to monitor, which log sources to collect and which SIEM to choose, recent developments in the IS have brought new challenges: how to set up monitoring in a partially on-premise and/or multi-cloud environment? Indeed, in 2021, having an IS hosted by several IaaS providers is closer to being the rule than the exception; and while AWS remains the most popular player, Azure and GCP offerings are of increasing interest to IT teams.</p>
<p>How to build a detection strategy? Where to position the SIEM? How to centralize logs and alerts? In fact, do we need logs or alerts? And how to take advantage of the managed solutions offered by cloud providers?</p>
<p>In this article, we will discuss best practices: using a bottom-up detection strategy, optimizing via the choice of the most relevant cloud native services, simplifying the collection architecture; always based on feedback from building multi-cloud monitoring strategies.</p>
<h2><strong>(Re)thinking your detection strategy for the multicloud</strong></h2>
<p>The first question the SOC team should ask itself is the detection strategy. In other words, what scenarios will be monitored?</p>
<p>A good cyber reflex is to use a &#8220;top-down&#8221; approach: start with a risk analysis to identify the alerts to prioritize, formalize them and then translate them technically into the SIEM. In practice, three factors demonstrate that this approach is insufficient:</p>
<ul>
<li>Few teams have risk analyses that are sufficiently exhaustive, up to date and pragmatic to allow the breakdown of threat scenarios into monitorable scenarios, especially for complex scopes such as the public cloud;</li>
<li>There is no guarantee that the scenarios obtained by this method can actually be put under supervision, whether the limitations are related to the solutions deployed or to the need for SOC teams to have business knowledge.</li>
<li>This approach defines some attack paths according to the criticality of the assets but does not cover all the attack paths that an attacker could take.</li>
</ul>
<p>Therefore, an efficient multi-cloud detection strategy will be obtained by completing the risk-based approach with a &#8220;bottom-up&#8221; approach: starting from the logging capabilities of the solutions available to identify the alerts that the SIEM will have to raise, and finally prioritize based on their interest in terms of risk coverage. Starting with the existing solutions guarantees the pragmatism and efficiency of the approach.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-17067 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/10/EN-image-1-multicloud.png" alt="" width="1162" height="732" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/10/EN-image-1-multicloud.png 1162w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/10/EN-image-1-multicloud-303x191.png 303w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/10/EN-image-1-multicloud-62x39.png 62w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/10/EN-image-1-multicloud-768x484.png 768w" sizes="auto, (max-width: 1162px) 100vw, 1162px" /></p>
<p>At Wavestone, we are increasingly solicited by clients who want to be supported in this new approach. The scope concerns the main solutions used in multicloud: Microsoft 365 (SaaS) and the managed solutions of the IaaS offers of the 3 main market players: Amazon Web Services, Microsoft Azure and Google Cloud Platform.</p>
<h2><strong>Set up the supervision of the Microsoft 365 infrastructure</strong></h2>
<p>On paper, the SOC team has all the keys in hand to monitor its cloud infrastructure:</p>
<p>&#8211; Raw logs for Office 365 services (Teams, SharePoint Online, Exchange Online, etc.)</p>
<p>&#8211; Raw logs, security reports, alerts and Identity Secure Score for Azure AD</p>
<p>&#8211; Raw logs, alerts, Microsoft Secure Score and Azure recommendations for security tools like ATP, AAD Identity Protection, Intune, AIP, etc.</p>
<p>In practice, navigating between the logs and all the tools available (and their consoles) can quickly become a headache. And if we regularly hear that there are too many logs or administration interfaces to master, in the field the difficulties are accentuated:</p>
<p>&#8211; By the poor customization capabilities of the native tools offered,</p>
<p>&#8211; By the lack of scenarios available with the purchased license,</p>
<p>&#8211; By the 90-day retention period for logs,</p>
<p>&#8211; By the general lack of Office 365 or AzureAD skills in the SOC teams.</p>
<p>To avoid getting lost, we recommend simplifying the playing field as much as possible. The best practices consist in thinking about alerts, not logs collection, and then centralizing their management in the SIEM using connectors like those of Security Graph API. As an example, it is possible to arrive at a model like the one given below:</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-17074 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/10/EN-image-2-multicloud.png" alt="" width="1202" height="803" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/10/EN-image-2-multicloud.png 1202w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/10/EN-image-2-multicloud-286x191.png 286w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/10/EN-image-2-multicloud-58x39.png 58w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/10/EN-image-2-multicloud-768x513.png 768w" sizes="auto, (max-width: 1202px) 100vw, 1202px" /></p>
<p>Once the architecture has been identified, configure a log retention period adapted to your needs (within Azure or outside) and start adapting the SOC processes to the specificities of M365 according to the choices made in the previous step.</p>
<h2><strong>Set up the supervision of other clouds in IaaS</strong></h2>
<p>To draw the architecture of collection on these clouds, it is necessary to distinguish the different types of logs made available by the CSPs.</p>
<h3><strong>System logs</strong></h3>
<p>The case of system logs generated by VMs and network flows can be dealt with first; it is possible to collect them in the same way as on-premise, with syslog agents, for example. CSP infrastructures provide building blocks such as Log Analytics in Azure to facilitate reporting.</p>
<h3><strong>Infrastructure administration logs</strong></h3>
<p>It is also possible to supervise the administration of &#8220;sensitive&#8221; infrastructure components (VPN, FW, vulnerability scanners, etc.) in the same way as on-premise solutions. Indeed, most of these solutions have their IaaS counterpart in the cloud providers: they can be obtained via the Marketplace and have a web administration console or interface directly with the CSP&#8217;s management console (this is the case for the Qualys scanner appliance, for example).</p>
<h3><strong>API call logs</strong></h3>
<p>Finally, API calls made by processes/accounts on the cloud infrastructure and by administration operations generate logs that are easily retrievable via the following managed services:</p>
<p>&#8211; CloudTrail at AWS</p>
<p>&#8211; Activity Log &amp; Monitor at Azure</p>
<p>&#8211; Audit Logging at GCP</p>
<p>To avoid getting lost, let&#8217;s learn the lesson: &#8220;Use and abuse cloud-native services”. After all, who better than the provider to offer services that are adapted and integrated into the environment? In practice, we see that implementing log management and cloud alerts in an on-premise SIEM is expensive (even if we try to limit storage costs in the monitoring solution) and time-consuming.</p>
<p>The use of the cloud implies a shift to the cloud philosophy: let&#8217;s adopt its codes and tame its services and tools. This is an opportunity to strengthen the synergies between the cloud teams and the SOC!</p>
<p>In summary, an example of monitoring architecture on AWS is proposed below. It shows several ways to perform monitoring, using native services for logs and alerts (NB: all flows to S3 and other services have not been shown for readability reasons).</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-17085 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/10/EN-image-3-multicloud.png" alt="" width="1233" height="732" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/10/EN-image-3-multicloud.png 1233w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/10/EN-image-3-multicloud-322x191.png 322w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/10/EN-image-3-multicloud-66x39.png 66w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/10/EN-image-3-multicloud-120x70.png 120w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/10/EN-image-3-multicloud-768x456.png 768w" sizes="auto, (max-width: 1233px) 100vw, 1233px" /></p>
<h2><strong>Define the architecture for centralizing multi-cloud alerts</strong></h2>
<p>This is one of the questions we are asked the most: what SIEM architecture should be considered in the multi-cloud? While each context is different, because each IT infrastructure has its own legacy and history, the presence of so many resources and tools should lead an SOC team to consider adopting a central cloud SIEM (such as Azure Sentinel, Splunk SaaS, etc.; AWS and Google&#8217;s Chronicle do not offer an equivalent solution to date).</p>
<p>To help SOC teams choose the right scenario, our recommendations are as follows:</p>
<p>&#8211; Prefer the scenario with a single central SIEM</p>
<p>&#8211; Limit the number of cloud monitoring consoles as much as possible</p>
<p>&#8211; Maximize the number of alerts that have already been analyzed by the native services studied above</p>
<p>&#8211; Take advantage of possible synergies between products from the same supplier: Azure Sentinel for monitoring Microsoft 365 infrastructure, for example</p>
<p>&#8211; Take advantage of the numerous connectors made available by cloud SIEM providers</p>
<p>&#8211; Study the impact of each scenario on the organization of the SOC (team size, technological skills, etc.) and the associated costs (necessary developments, volume and ingestion costs, etc.)</p>
<p>An example of an architecture that includes all the recommendations of this article is proposed below, it uses Azure Sentinel as a central cloud SIEM.</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-17087 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/10/EN-image-4-multicloud.png" alt="" width="1244" height="635" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/10/EN-image-4-multicloud.png 1244w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/10/EN-image-4-multicloud-374x191.png 374w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/10/EN-image-4-multicloud-71x36.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/10/EN-image-4-multicloud-768x392.png 768w" sizes="auto, (max-width: 1244px) 100vw, 1244px" /></p>
<h2><strong>Summary: Key principles to keep your head above the clouds</strong></h2>
<p>In summary, the SOC team wanting to adapt its detection strategy to the multicloud should:</p>
<p>&#8211; Complement its classic top-down approach with the bottom-up approach, which is particularly well-suited to the complex context of the multicloud,</p>
<p>&#8211; Use native services provided by vendors whenever possible to take full advantage of the cloud,</p>
<p>&#8211; Simplify the collection architecture and centralize as much as possible the alerts pre-analyzed by the cloud native services,</p>
<p>Once the head is out of the cloud, the strategy formalized and the collection architecture deployed, the SOC is back in its place as the IS control tower: the proliferation of services in the cloud no longer scares it!</p>
<p>The next steps may be to look at automation possibilities, with the implementation of a SOAR, for example. We will be sure to discuss this topic in a future article.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/10/adapting-your-detection-strategy-to-the-multi-cloud-without-getting-lost-in-the-cloud/">Adapting your detection strategy to the multi-cloud without getting lost in the cloud</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2021/10/adapting-your-detection-strategy-to-the-multi-cloud-without-getting-lost-in-the-cloud/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Wavestone publishes its 2020 Belgian Cybersecurity Startup Radar</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/07/wavestone-publishes-its-2020-belgian-cybersecurity-startup-radar/</link>
		
		<dc:creator><![CDATA[Thomas Vo-Dinh]]></dc:creator>
		<pubDate>Mon, 20 Jul 2020 09:00:01 +0000</pubDate>
				<category><![CDATA[Cloud & Next-Gen IT Security]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Sections]]></category>
		<category><![CDATA[2020]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[belgian]]></category>
		<category><![CDATA[belgium]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[identity management]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[startups]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=13924</guid>

					<description><![CDATA[<p>For several years now, Wavestone&#8217;s different offices have been periodically identifying startups active in the field of cybersecurity. Wavestone Brussels office has therefore carried out its very first census in this field: the 2020 Belgian Cybersecurity Startup Radar. &#160; A proven...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/07/wavestone-publishes-its-2020-belgian-cybersecurity-startup-radar/">Wavestone publishes its 2020 Belgian Cybersecurity Startup Radar</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div id="ember73" class="ember-view">
<div class="reader-article-content" dir="ltr">
<p>For several years now, Wavestone&#8217;s different offices have been periodically identifying startups active in the field of cybersecurity. Wavestone Brussels office has therefore carried out its very first census in this field: <strong>the 2020 Belgian Cybersecurity Startup Radar</strong>.</p>
<p>&nbsp;</p>
<h2>A proven and pragmatic methodology</h2>
<p>This study starts with a global overview of the Belgian cybersecurity ecosystem based on a first mapping of companies active in this field. To that end, we consulted <strong>3 main sources</strong>. The first one are <strong>databases</strong> specialized in the identification of startups, then <strong>co-working spaces &amp; incubators</strong> and finally <strong>organizations &amp; associations</strong> supporting cybersecurity startups.</p>
<p>Only companies marketing a product (application, platform, hardware, etc.) were retained. Consulting companies are out of scope.</p>
<p>The purpose of this first step is to establish a list of actors in order to then apply the <strong>selection criteria</strong> of the <a href="https://fr.wavestone.com/fr/insight/radar-2020-startups-cybersecurite-francaises/" target="_blank" rel="nofollow noopener noreferrer">Wavestone radar</a>. Those criteria allow us to establish the perimeter of the radar in accordance with those already carried out previously by our others offices.</p>
<p>The criteria we select to map out the companies are <strong>the age</strong>, <strong>the location</strong> and <strong>the size</strong>:</p>
</div>
</div>
<p>&nbsp;</p>
<figure id="post-14257 media-14257" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-14257 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-1-8.png" alt="" width="1126" height="549" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-1-8.png 1126w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-1-8-392x191.png 392w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-1-8-71x35.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-1-8-768x374.png 768w" sizes="auto, (max-width: 1126px) 100vw, 1126px" /></figure>
<p>&nbsp;</p>
<div id="ember73" class="ember-view">
<div class="reader-article-content" dir="ltr">
<h2>The result of our 2020 Belgian cybersecurity startup radar</h2>
<p>After having drawn up a list of companies active in Belgium and offering a product, we apply our 3 criteria. The first census identified 30 companies, <strong>11</strong> of which met our criteria.</p>
</div>
</div>
<p>&nbsp;</p>
<figure id="post-14259 media-14259" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-14259 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-2-7.png" alt="" width="676" height="543" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-2-7.png 676w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-2-7-238x191.png 238w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-2-7-49x39.png 49w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-2-7-155x125.png 155w" sizes="auto, (max-width: 676px) 100vw, 676px" /></figure>
<div id="ember73" class="ember-view">
<div class="reader-article-content" dir="ltr">
<p>&nbsp;</p>
<p>The results of our study allow us to identify certain <strong>trends </strong>for the Belgian ecosystem. The typical Belgian cybersecurity startup is extra small, working in Brussels in the field of IAM.</p>
<h3>More than 1/3 of the identified startups works in the field of IAM</h3>
<div></div>
</div>
</div>
<div class="slate-resizable-image-embed slate-image-embed__resize-full-width"></div>
<div>
<figure id="post-14261 media-14261" class="align-none"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-14261" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-3-3.png" alt="" width="1141" height="432" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-3-3.png 1141w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-3-3-437x165.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-3-3-71x27.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-3-3-768x291.png 768w" sizes="auto, (max-width: 1141px) 100vw, 1141px" /></figure>
</div>
<div></div>
<div id="ember73" class="ember-view">
<div class="reader-article-content" dir="ltr">
<p><strong>Identity and Access Management</strong> (IAM) and <strong>Application Security</strong>, which groups &#8220;Vulnerabilities&#8221;, &#8220;E-mail security&#8221; and &#8220;Surveillance&#8221; categories, are the two most important areas of activity and represent more than <strong>60% of the cyber ecosystem</strong>. The figure reveals also that the IAM seems to be the most mature sector in this ecosystem, echoing the figures from the <a href="https://fr.wavestone.com/fr/insight/radar-2020-startups-cybersecurite-francaises/" target="_blank" rel="nofollow noopener noreferrer">French</a>, <a href="https://www.wavestone.com/en/insight/2019-uk-cybersecurity-start-up-radar/" target="_blank" rel="nofollow noopener noreferrer">English</a> or <a href="https://www.linkedin.com/posts/wavestone-switzerland_cybersecurity-wavestone-switzerland-activity-6626401160091705344-2v2-" target="_blank" rel="noopener noreferrer">Swiss</a> startup radars, which show a similar trend.</p>
<p>&nbsp;</p>
<h3>More than 80% of the startups surveyed have less than 10 employees</h3>
</div>
</div>
<p>&nbsp;</p>
<figure id="post-14263 media-14263" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-14263 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-4-3.png" alt="" width="799" height="517" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-4-3.png 799w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-4-3-295x191.png 295w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-4-3-60x39.png 60w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-4-3-768x497.png 768w" sizes="auto, (max-width: 799px) 100vw, 799px" /></figure>
<p>&nbsp;</p>
<div id="ember73" class="ember-view">
<div class="reader-article-content" dir="ltr">
<p>The majority of the startups on our radar have few employees: <strong>more than 80%</strong> have less than 10 employees and none have more than 35 employees.</p>
<p>In Belgium it is the <strong>extra small</strong> startup that predominates compared to the other radars of the group that see the medium-sized startups more numerous.</p>
<p>&nbsp;</p>
<h3>The cyber ecosystem is mainly concentrated in Brussels Region with almost 60% of startups, followed by Leuven and Antwerp by far</h3>
</div>
</div>
<p>&nbsp;</p>
<figure id="post-14265 media-14265" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-14265 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-5-5.png" alt="" width="298" height="258" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-5-5.png 298w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-5-5-221x191.png 221w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-5-5-45x39.png 45w" sizes="auto, (max-width: 298px) 100vw, 298px" /></figure>
<p>&nbsp;</p>
<div id="ember73" class="ember-view">
<div class="reader-article-content" dir="ltr">
<p>The majority of startups are located in <strong>Brussels</strong>. No wonder, given that Brussels is the capital and one of the most dynamic economic centers in the country.</p>
<p>&nbsp;</p>
<h3>Focus on the analysis of the degree of innovation of startups</h3>
<p>The next step in the analysis is to estimate the <strong>level of innovation</strong> of the companies on the radar. To do this, it is necessary to estimate a &#8220;degree of innovation&#8221; whether:</p>
<p>• The company imagines a completely new security solution</p>
<p>• The company reinvents an existing security solution</p>
<p>• The company secures already existing uses (IoT, Cloud, etc.)</p>
<p>Most Belgian startups are reinventing existing solutions or providing a tool to secure new uses.</p>
<p>Quite logically, few startups work on a totally innovative project. This is also a trend observed in other international Wavestone radars, where the degrees of innovation are more or less the same as in Belgium.</p>
</div>
</div>
<p>&nbsp;</p>
<figure id="post-14267 media-14267" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-14267 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-6-5.png" alt="" width="1029" height="577" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-6-5.png 1029w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-6-5-341x191.png 341w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-6-5-71x39.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-6-5-768x431.png 768w" sizes="auto, (max-width: 1029px) 100vw, 1029px" /></figure>
<div id="ember73" class="ember-view">
<div class="reader-article-content" dir="ltr">
<div></div>
<p>The other trend is the low (or even non-existent) presence of startups active in the fields of &#8220;data security&#8221;, &#8220;network security&#8221; and &#8220;cloud security&#8221;. Several actors and employees of the startups met during this study confirmed the firm&#8217;s convictions on the subject.</p>
<p>Firstly, the cyber market only rings the bell for <strong>experts </strong>or <strong>insiders</strong>, which can repel investors. Then, cybersecurity is a complex field that often requires <strong>special IT expertise</strong> and <strong>specific support</strong>. Finally, the current maturity of the market does not facilitate startups to find their customers.</p>
<p>These observations may also explain why few contacted incubators support IT startups, and by extension the cyber field.</p>
<p>&nbsp;</p>
<h2>Conclusion</h2>
<p>The 2020 Belgian Cybersecurity Startup Radar shows that the vast majority of <strong>startups are located in Brussels, have less than 10 employees and work in the IAM sector</strong>. This study also reveals that the Belgian cybersecurity market is still in its infancy. Most of the startups encountered are either looking for financing, customers or are still in the testing phase.</p>
<p>The objective of Wavestone is to follow the <strong>evolution of this ecosystem</strong> through new editions: new startups appearing during the year, possible disappearance, etc.</p>
<p>In order to prepare these next versions, and for the purpose of improving and enriching this study, please do not hesitate to <strong>contact us</strong> if you know any company that might join our radar.</p>
</div>
</div>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/07/wavestone-publishes-its-2020-belgian-cybersecurity-startup-radar/">Wavestone publishes its 2020 Belgian Cybersecurity Startup Radar</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
