Chapter 1. Introduction
Technology development and digitalization have expanded the attack surface and introduced new attack vectors. Today’s organization has a broader scope of concern due to factors like globalization, supply chain, and digital assets. A significant transformation in cybersecurity has been notable over the past few years—different stakeholders are heavily investing in finding new technologies to defeat cyber threats. Nonetheless, there is news daily about security breaches arising worldwide, so the question is, why is this happening to even the most defended institutions?
Chances are high that you will be affected by data breaches without your being aware or there being any public information about the breaches. One scenario could be that your credentials get sold on the dark web. Although you may not be a primary target, you risk becoming an entry point for the threat actor, jeopardizing the security of those connected to you. During the reconnaissance phase (see Chapter 4), an adversary will covertly discover and collect information about the target, sometimes investigating individuals that are not directly associated with the organization. Examples of this can be a family member or an organization that supplies the target with a relevant service or product. Then, through infiltration processes, threat actors will access the network and propagate until their goals are achieved. A couple of years ago, I got a call from one of my friends who was stressed because ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access