I work in the field of ai and cybersecurity at a small startup so can only speak from the experience of helping others solve some of these challenges. I think it comes down to setting guardrails (e.g you must have MFA to access X system), having the right monitoring in place (e.g automated scanners), and strongly leaning into ai-native tooling because ultimately machine-scale attacks and telemetry can only be countered with machine-scale defense.
Hire a CISO and let them build a team empowered to improve your security. Don't depend on a decentralized approach.
The most important aspect in my opinion is locking down permissions so that no one has access to everything and each team only has access to the components they need access to. Then one hack doesn't take down the whole company.
I find that having someone pen-testing your application in the early stages gets you the best results.
It also helps to build on top a strong foundation, resilient.
I thought I knew what I was doing with cybersecurity, then I got some formal training and certs. Cybersecurity is a career field for a reason. It can’t be a side gig for the devs.
I'm a I've been a malware researcher, lead security engineer, software engineer, and pentester. Correct me if I'm wrong here, but this post seems to contain two different types of security concerns:
1. The security of your product, aka Product Security (you mentioned "users", MFA, the dev team, etc...)
2. The security of your internal company networks, endpoints, etc used by employees and systems to operate the business, often called Information Security (you mentioned "non-tech folks in the company", pwned passwords etc...
The biggest thing that comes to mind that you've not mentioned here is security training for both the Information Security side of things (e.g. all employees), and the software developers (technical training about the various vulnerabilities, secure coding best practices, supply chain attacks and how to mitigate them, etc...). I used to teach security training courses for past employers to software engineers and other colleagues, and we did see improvement from those who were trained. Many organizations will have that 1-2 people who just won't cooperate, listen, or play dumb and unfortunately click that link, or do something untoward that puts the whole org at risk, but this sort of thing can also be partially mitigated by proper network segmentation and in the case of product security, proper security controls in the CI/CD and build & release pipelines, amongst other things. Unfortunately, there is no way to achieve "perfect security" and I've found that as a business grows and brings more people into the mix, the likelihood of something getting lost in translation and going unnoticed grows as well.
Another big point - You can't secure what you don't know about. The first thing a pentester will do is scan your entire domains and pages for other domains and pages, and we will build a big list... So for example if you have employeehub.yourcompany.com, I'm going to scan and dig up like 50 other subdomains, and if I find dev1.employeehub.yourcompany.com, I'm going to go there and see what's exposed to the public... Maybe your team forgot that was left up and exposed, and maybe since it was supposed to be a temporary or a test endpoint, it has less security features than employeehub.yourcompany.com does and it may be a way in, etc... So, a pentesting firm will provide you with all of this recon information about your site in addition to trying to actively find and exploit vulnerabilities on it. Certain security companies also offer whats called "Attack Surface Management" which is software that helps you to identify your assets and the attack surface as well... Those are often quite large dashboards with many options, but as a pentester, I can get a list of practically your entire attack surface in a matter of seconds using some of my tools. The point is, you have to inventory everything you expose externally, internally, and in your products. Your products and dependencies should also have SBOMs and vulnerable dependencies should be patched, etc... I don't know the size of your business, you may not need a CISO, but at least one proficient engineer who can handle much of this depending on the size.
8 comments
[ 2.5 ms ] story [ 40.4 ms ] thread1. The security of your product, aka Product Security (you mentioned "users", MFA, the dev team, etc...) 2. The security of your internal company networks, endpoints, etc used by employees and systems to operate the business, often called Information Security (you mentioned "non-tech folks in the company", pwned passwords etc...
The biggest thing that comes to mind that you've not mentioned here is security training for both the Information Security side of things (e.g. all employees), and the software developers (technical training about the various vulnerabilities, secure coding best practices, supply chain attacks and how to mitigate them, etc...). I used to teach security training courses for past employers to software engineers and other colleagues, and we did see improvement from those who were trained. Many organizations will have that 1-2 people who just won't cooperate, listen, or play dumb and unfortunately click that link, or do something untoward that puts the whole org at risk, but this sort of thing can also be partially mitigated by proper network segmentation and in the case of product security, proper security controls in the CI/CD and build & release pipelines, amongst other things. Unfortunately, there is no way to achieve "perfect security" and I've found that as a business grows and brings more people into the mix, the likelihood of something getting lost in translation and going unnoticed grows as well.
Another big point - You can't secure what you don't know about. The first thing a pentester will do is scan your entire domains and pages for other domains and pages, and we will build a big list... So for example if you have employeehub.yourcompany.com, I'm going to scan and dig up like 50 other subdomains, and if I find dev1.employeehub.yourcompany.com, I'm going to go there and see what's exposed to the public... Maybe your team forgot that was left up and exposed, and maybe since it was supposed to be a temporary or a test endpoint, it has less security features than employeehub.yourcompany.com does and it may be a way in, etc... So, a pentesting firm will provide you with all of this recon information about your site in addition to trying to actively find and exploit vulnerabilities on it. Certain security companies also offer whats called "Attack Surface Management" which is software that helps you to identify your assets and the attack surface as well... Those are often quite large dashboards with many options, but as a pentester, I can get a list of practically your entire attack surface in a matter of seconds using some of my tools. The point is, you have to inventory everything you expose externally, internally, and in your products. Your products and dependencies should also have SBOMs and vulnerable dependencies should be patched, etc... I don't know the size of your business, you may not need a CISO, but at least one proficient engineer who can handle much of this depending on the size.