How to Detect a Hack

There are two types of companies: those that have been hacked, and those who don’t know they have been hacked.  

            – John T. Chambers, Former Cisco CEO 

He said it, not me🤷 but I will back up his point by pointing this out –>

5 cyber security laws:

1. If there is a vulnerability, it will be exploited

2. Everything is vulnerable in some way

3. Humans trust even when they shouldn’t

4. With innovation comes opportunity for exploitation

5. When in doubt, see law number 1

Endpoint Detection

Today’s theme centers around how you would even know you’ve been hacked- given its inevitable for most. Would be nice to know, huh?  Enter Endpoint detection and response (EDR).  Before we dive into this measure, let’s cover Endpoints. Endpoints: A.K.A. laptops, phones, devices, etc. There are so many devices across a network that can vulnerable to breach, how can you possibly keep a pulse on everything? 

What Does EDR Do for me?

EDR is a measure that monitors your company’s endpoints. While EDR alone is not necessarily going to directly stop an attack, it will alert you to potential threats or breaches. In other words, with EDR, you will officially know there’s an issue. This combined with other layers (anti-virus, VPN, MFA, etc.) in your defense in depth strategy displays a good cyber secure posture.

Now, EDR is great for alerting you of threats but what do you do if something is detected? Is it 9-1-1? Incident response team? Chuck your laptop? This is where we would ideally be thumbing through the incident response plan that is established ahead of time. This is your playbook, your bible, your north star for how to navigate a cyber attack or potential attack. This will have outlined key contacts, specific responsibilities and more. 

Managed Detection and Response

So you have a response plan but you are still not 100% sure what to do or maybe you’re worried about catching the EDR notification in the first place. There is a solution for that. Meet MDR: Managed Detection and Response. It’s similar to EDR but adds the crucial element of a qualified person monitoring it. This solution helps you find and track security events from different sources, watch for threats 24/7, investigate threats, and fix problems quickly. So with MDR you are essentially outsourcing the team that is going to recognize the threat and respond so that you don’t have to! Not a bad option. 

If what John said up above is true, we should all be taking steps to be vigilant and know exactly when an attack may be unfolding. When it comes to mitigating damages from a cyber attack, time is everything, speed matters. In order to be aware and respond swiftly we need to have EDR and/or MDR software and monitoring. 

Leave a Reply

Spam-free subscription, we guarantee. This is just a friendly ping when new content is out.

← Back

Thank you for your response. ✨

Discover more from Cyber Survival Guide

Subscribe now to keep reading and get access to the full archive.

Continue reading