By Andy Hornegold, Product Lead at Intruder
Maybe cybercriminals will find their moral centre this year! Or not. Far more likely, they’ll be busier than ever. So, unless we want to risk our organizations ending up in the news for all the wrong reasons, cybersecurity should be high on our list of priorities in 2023.
Here are four of the most important digital doors to lock.
1. Web applications
While SaaS applications are fantastic digital tools that have revolutionized the way we work, they can also hold some of our most sensitive data. And information, as we know, is power. The more valuable or critical it is (such as customer data or patient information), the more it plays into extortion tactics.
Now, because SaaS applications are usually multi-tenanted, there are hidden doors we need to be wary of. We need to ask ourselves: which level of access are we allowing our SaaS partners, and who has access to our partner’s platform? For example, one customer might have access to another customer’s data, meaning they can easily take advantage of injection flaws, logic flaws, and access control weaknesses.
To combat these threats, we need a combination of regular pen-testing and an automated vulnerability scanner that can be integrated into our existing environment. That way, vulnerabilities can be caught when they’re introduced during the development lifecycle.
2. Misconfigurations
Compliance with industry security laws and company policies usually falls to CTOs and developers. But because they are in charge of everything from securing settings, user roles, and permissions, misconfigurations can be difficult to fix and detect manually, especially with all the other responsibilities on their plate. Gartner reports that these vulnerabilities are responsible for 80% of breaches in data security – and they predict that up to 99% of cloud environment breaches will be down to manual mistakes.
To sort this, we need visibility of our attack surface to spot mistakes and other weaknesses. To achieve visibility, we need network monitoring that can uncover vulnerabilities and misconfigurations for us, combined with a pen-test solution that can reveal risks in our cloud infrastructure. The latter process will help us spot openings such as excessively permissive firewalls, accounts, and misconfigured S3 buckets.
If we want to solve this manually, it can be wise to include tools to assist us with aspects of that process. Alternatively, we should seek out automated solutions to ensure that only the services that need the internet to function are accessible.
3. Software and patches
We know this isn’t breaking news, but weaknesses in these areas remain a widespread issue for SaaS companies – and everyone else, for that matter. But when we host an application ourselves, the name of the game is to make sure we apply security patches to the OS and library when we release them. Every time. Unfortunately, cybersecurity professionals will reveal that weaknesses in the OS and library applications are some of the most common vulnerabilities they find.
Fortunately, there are options. We can adopt DevOps practices, which facilitate continuous communication, collaboration, integration, and transparency between our application development teams and our IT operations team (hence the name). This can help us ensure that our services are always patched before release, but it’s not watertight. We still need to keep our eyes open for new weaknesses in-between releases.
Another option is free or paid Serverless and Platform as a Service (PaaS) solutions. These can run on our applications in a container and therefore do the patching work for us. But, again, we still need to ensure the up-to-date security of our libraries.
4. Internal security policies and practices
Since corporations and large organisations have been victims of organised cyberattacks for a long time, most of them have gotten serious about security. As a result, cybercriminals are shifting their malicious attention to medium-sized and smaller organizations. And the SaaS industry is no exception. With a million competing priorities, security is often sacrificed to the lower ends of the list, leaving us vulnerable.
Luckily, a few simple solutions will go a long way:
- A password manager – this will help us keep our passwords secure (assuming the provider is taking security seriously as well).
- Two-factor or multi-factor authentication (2FA/MFA) – we’ll need to pass another check in addition to our password, but it’s well worth it. The best option is a hardware security key, but an OTP with a timer is also excellent. Alternatively, an OTP without a timer.
- Simple security training – we must teach each other how to practice proper cyber hygiene. Just learning to recognize what phishing looks like and how it works can do wonders, and it’s also important to share it internally when we notice an actual attempt.
The conclusion?
As with so much else, our cyber security investments will ultimately depend on the ROI. While it can be frustrating to spend money to protect against something that might never happen anyway, it can help to think of it as investing in traffic safety; we might drive our entire lives without a scratch, but it only takes one crash to make a disaster.
And when our businesses start picking up speed, when our teams and revenues really get going, so does the risk of crashing.
Stay safe!
##
ABOUT THE AUTHOR
Andy has a long career in cyber security including a decade in threat simulation and consulting. He’s worked with some of the largest organizations and brands across most industries and sectors, advising how to defend themselves against advanced threat actors and resolve vulnerabilities.
Career highlights include being the Assurance Regional Lead at one of the UK’s leading cyber security consultancies, managing a team of 30 cyber security consultants, and helping critical national infrastructure providers stay secure.
Most recently, Andy was the EU Red Team Operations Lead at Mandiant, building out and leading the security team to deliver high quality intelligence-led threat simulations. As the Product Lead at Intruder, he’s bringing this knowledge and experience to help thousands of customers at once.
In tune with everyone at Intruder and its company values, Andy believes in making cyber security as accessible as possible for everyone by reducing the complexity of cyber security and helping customers focus on what matters.






