After participating in a simulation of managing post-breach response, Gregory Touhill, deputy assistant secretary for cybersecurity and communications at the Department of Homeland Security, gave a succinct overview of the threats coming at federal agencies and the best practices for defending the network.
Watch the video above for the six kinds of cyberattacks and find Touhill’s five tips for defense below.
CYBERCON 2015:Sign up now for CyberCon 2015 to learn how best to protect your agency’s networks
“In the aftermath of a lot of these breaches we’ve been dealing with in the public and private sector, we’ve given what we believe are the top five best practices out there — not only in the office but at home, as well,” he said during a panel discussion after the simulation, which was hosted by Deloitte.
Two-Factor Authentication
“Multifactor authentication is even better,” Touhill said.
Passwords are a dying breed, mostly because a single point of verification is easily cracked by savvy hackers. Sophisticated social engineering and other tactics make it imperative that agencies have more than one layer of authentication to ensure the user on the network is the person who is supposed to be there.
In the wake of the breaches at the Office of Personnel Management, the Office of Management and Budget instituted a 30-day cyber sprint with the prime goal of increasing two-factor authentication deployment across government.
Network Segmentation
Don’t make it easy for the adversary to move around once they’ve breached the network.
By segmenting data and applications and limiting the pathways for those segments to interact, a minor intrusion might not turn into a major catastrophe.
In the mock breach used during the simulation, a compromise of a third-party payroll management vendor was used to steal proprietary information about the fake company, including data on pricing and distribution contracts. If that network had been properly segmented, the attackers would have gotten payroll data but would have been prevented from getting anything else.
Control Privileged Access
Once the network is properly segmented, restrict users from moving between those areas unless it’s critical to their job function. Make sure authorized users can only access the areas they need.
“Control how much privileged access you give,” Touhill said, noting this goes hand-in-hand with segmentation in preventing large-scale data exfiltration.
Whitelist Apps
“Make sure you have application whitelisting so that if you click on that link, even by mistake,” any potential malware is blocked and doesn’t infect the system, he said.
Even the best cybersecurity postures are tested regularly by the users themselves. Advancements in spear-phishing techniques and social engineering have made it dangerous to click on even trusted emails.
Contract with Security in Mind
Touhill stressed the importance of establishing who is responsible for every aspect of security before signing a contract with a vendor.
“You’ve got to guard that backdoor with those trusted third-party vendors,” he said. “Make sure that you have solid contractual relationships; that you have the ability to audit to make sure that you’re … protected with all the folks you’re doing business with.”
For the remaining 0.56 percent that might get past those defenses, understanding the kinds of attacks and motivations behind them will greatly improve the response. Watch the video at the top for more on that.




