{"id":2456,"date":"2018-11-08T17:47:00","date_gmt":"2018-11-08T17:47:00","guid":{"rendered":"https:\/\/www.clockwork.com\/?p=2456"},"modified":"2022-11-21T22:21:24","modified_gmt":"2022-11-21T22:21:24","slug":"changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma","status":"publish","type":"post","link":"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/","title":{"rendered":"Changing how we think about cybersecurity: Creating the attacker\u2019s dilemma"},"content":{"rendered":"\n<p>I was at a conference recently at which Tim Crothers&nbsp;delivered the keynote. Tim has worked as a breach investigator for the better part of his career. He joined Target after their 2013 breach and currently leads their cyber security team. I got to hear him flip an information security paradigm on its head.<\/p>\n\n\n\n<p><em>\u201cThe <\/em><a href=\"https:\/\/www.rand.org\/pubs\/research_reports\/RR1024.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><em>defender\u2019s dilemma<\/em><\/a><em> states that breaches are inevitable because defenders have to be right 100% of the time whereas attackers only have to be right once.\u201d<\/em><\/p>\n\n\n\n<p>That\u2019s not empowering. As someone that advises clients, that\u2019s not how I want them to approach their security. As a consumer, it\u2019s not how I want organizations to think about securing my own personal data.<\/p>\n\n\n\n<p>There is another way, and it starts by understanding what a breach means. A breach happens when data, from an individual or organization, is illegally copied. That\u2019s known as exfiltration. It\u2019s only possible when an attacker gets a foothold on a system. <strong>And that open window, between the foothold and exfiltration, is where the true failure happens.<\/strong><\/p>\n\n\n\n<p>Organizations tend to focus their spend on prevention. While prevention can be effective at mitigating known vulnerabilities, it\u2019s the unknown vulnerabilities that should be of most concern. Since 2013, the Carbanak FIN7 syndicate has been connected to almost every major breach in the banking, hospitality, and retail industries.&nbsp;They\u2019re professionals, persistent, and creative&nbsp;\u2013 they use attack vectors that no one has ever thought.<\/p>\n\n\n\n<p>When an organization is not aware of prevention failures, it\u2019s a sign that there\u2019s a lack of detection capabilities. That\u2019s evident with the time attacker\u2019s have had in the breaches we\u2019re seeing today. Tim said that it\u2019s likely many breaches have gone unreported over the years. And only with the introduction of disclosure laws have we started to understand the wide-scale magnitude of breaches.<\/p>\n\n\n\n<p><strong>My big takeaway:&nbsp;Prevention protects you from what you know, but not from what you <em>don\u2019t<\/em> know.<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Creating the attacker\u2019s dilemma<\/h2>\n\n\n\n<p>If an organization is to deal with risk and uncertainty, it shouldn\u2019t have to adopt a defeatist mentality. It can start by weaving cyber security awareness into the company culture, earmarking an appropriate budget, striving for continuous improvement, adopting a mindset that emboldens.<\/p>\n\n\n\n<p>Creating the attacker\u2019s dilemma starts by asking this question: \u201cHow might we quickly detect prevention failures so that we can minimize the window that a foothold can be exploited?\u201c<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The new paradigm:<\/h3>\n\n\n\n<p><em>\u201cAttacker&#8217;s dilemma forces an attacker to exfiltrate data without tripping a single detection instrument.&#8221;<\/em><\/p>\n\n\n\n<p>What I love about reframing the defender\u2019s dilemma is that it assumes prevention failures will happen. That\u2019s more realistic because it\u2019s already happening. Imagine having a detection net that sends timely alerts on prevention failures. The game turns into response, containment, and engaging attackers head-on.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The approach to creating the attacker\u2019s dilemma<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Focus on an attacker\u2019s activities rather than the tools and exploits<\/li><li>Use the attacker&#8217;s needs and techniques against them<\/li><li>Balance prevention, detection, and response appropriately<\/li><li>Invest in people over tools<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Focus on an cyber attacker\u2019s activities rather than the tools and exploits<\/h3>\n\n\n\n<p>Attackers seek entry points into an organization so that a foothold can be established. That involves social engineering, usually through spear-phishing, and compromising Internet-facing systems like web applications, vendor platforms or remote access. Given these threats, it\u2019s common to focus efforts on multi-factor authentication, encryption, monitoring, and vulnerability scanning. Yet, attackers assume that those safeguards are in place. That\u2019s why attacks are asymmetrical, ones that bypass or sabotage a defender\u2019s strengths while targeting their vulnerabilities. Using cyber security attack frameworks like <a href=\"https:\/\/attack.mitre.org\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">MITRE ATT&amp;CK<\/a> or <a href=\"https:\/\/www.ibm.com\/security\/services\/ibm-x-force-incident-response-and-intelligence?ce=ISM0484&amp;ct=SWG&amp;cmp=IBMSocial&amp;cm=h&amp;cr=Security&amp;ccy=US&amp;cm_mc_uid=60175497123015415428014&amp;cm_mc_sid_50200000=68845521541560357279&amp;cm_mc_sid_52640000=49889921541560357285\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">IBM X-Force Incident Response and Intelligence Services (IRIS)<\/a> helps an organization identify gaps in prevention and detection.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Use the attacker&#8217;s needs and techniques against them<\/h3>\n\n\n\n<p>Attackers need access, intelligence, and targets. Use that against them by creating a detection net that uses deception, automation, and escalation. The concept is to create a lure that, when accessed, sends an alert to first responders. Here are some ideas that are just the tip of the iceberg:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Use <a href=\"https:\/\/en.wikipedia.org\/wiki\/Honeypot_(computing)\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">honeypots<\/a> in every part of your tech stack. Even better if you can deploy a honeynet.<\/li><li>Embed fake API keys on a public Github repository. Have a developer that has worked with your organization post it.<\/li><li>Create fake admin accounts to be cached on a local machine.<\/li><li>Use fake user accounts to respond to phishing attacks.<\/li><li>Post fake traceable data on an internal wiki.<\/li><li>Reuse breached credentials for fake accounts.<\/li><li>Deploy an internet appliance with default credentials.<\/li><li>Increase awareness in your organization by simulating phishing campaigns. Foster a positive security-aware culture.<\/li><li>Develop meaningful cyber security metrics.<\/li><li>Invest in deep web intelligence to understand who may be attacking you and why.<\/li><li>Use automation to dynamically restrict privileges based on escalating activities that would be considered adversarial.<\/li><li>Create infrastructure in an immutable fashion and alert on any filesystem modifications.<\/li><li>Invest in a security orchestration and automation framework to bolster your detection net.<\/li><\/ul>\n\n\n\n<p>This approach is like the dark side of a customer journey map \u2014 determining the attackers \u201chappy path\u201d and inserting lures that can lead to better detection and response. Most of these can be implemented by a team of any size, as long as they have DevOps capabilities.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Balance cyber security prevention, detection, and response appropriately<\/h3>\n\n\n\n<p>Organizations should determine the right level of prevention for themselves and then focus the remaining budget on detection and response. This balance can be tough since prevention feels like the right strategy because <em>most<\/em> attacks can be prevented, and yet it\u2019s what we don\u2019t know that is actually the most dangerous.<\/p>\n\n\n\n<p>That\u2019s why spending more on detection makes sense. It has a higher return on investment because it empowers you to identify prevention failures and respond to them just-in-time.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Invest in people over technology tools<\/h3>\n\n\n\n<p>Cyber security is just as much a people problem as it is a tool problem. Vulnerability scanning puts organizations into a defender\u2019s mindset. There are limits with vulnerability scanning on immutable infrastructure and the attack surface is incredibly large. Tools tend to be rigid and cannot always adapt to rapidly changing situations, whereas people can. And when properly inspired, people can be endlessly inventive.<\/p>\n\n\n\n<p>With an appropriate budget, a team can deploy a detection net, respond to prevention failures, and work with outside vendors. Since cyber security professionals are in-demand, level-up your team by sending them to an immersive security bootcamp \u2013 one that encourages students to get to root. Partner with a vendor that can do a blend of manual and automated penetration testing at a high frequency (e.g. bi-weekly to monthly).<\/p>\n\n\n\n<p>Adopt Agile as a way of working. It\u2019s a proven approach in software development for managing change, risk, and uncertainty. A framework like scrum equips an organization with the agility to respond to prevention failures. It also encourages constant iteration through the principles of transparency, inspection, and adaptation.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Final thoughts<\/h2>\n\n\n\n<p>As an ethical hacker and someone that values information security, I think creating the attacker&#8217;s dilemma is a mindset worth adopting. This way of thinking is more proactive, expands your toolset, and puts you in a more offensive position.<\/p>\n\n\n\n<p><a href=\"mailto:vince@clockwork.com\">Email me<\/a> to talk more about cybersecurity.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"1024\" src=\"https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/vince-1024x1024.jpeg\" alt=\"Vincent Cabansag\" class=\"wp-image-2476\" srcset=\"https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/vince-1024x1024.jpeg 1024w, https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/vince-300x300.jpeg 300w, https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/vince-150x150.jpeg 150w, https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/vince-768x768.jpeg 768w, https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/vince-1536x1536.jpeg 1536w, https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/vince-1080x1080.jpeg 1080w, https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/vince-720x720.jpeg 720w, https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/vince-360x360.jpeg 360w, https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/vince.jpeg 1839w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>Vince Cabansag<br>VP, Technology and Delivery<\/figcaption><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>I was at a conference recently at which Tim Crothers&nbsp;delivered the keynote. Tim has worked as a breach investigator for the better part of his career. He joined Target after their 2013 breach and currently leads their cyber security team. I got to hear him flip an information security paradigm on its head. \u201cThe defender\u2019s [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":2457,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","footnotes":""},"categories":[118,56,25],"tags":[],"coauthors":[86],"class_list":["post-2456","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-how-we-work","category-strategy","category-technology"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v23.2 (Yoast SEO v25.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Changing how we think about cybersecurity: Creating the attacker\u2019s dilemma<\/title>\n<meta name=\"description\" content=\"Creating the attacker\u2019s dilemma starts by asking this question: \u201cHow might we quickly detect prevention failures so that we can minimize the window that a foothold can be exploited?\u201c\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Changing how we think about cybersecurity: Creating the attacker\u2019s dilemma\" \/>\n<meta property=\"og:description\" content=\"Creating the attacker\u2019s dilemma starts by asking this question: \u201cHow might we quickly detect prevention failures so that we can minimize the window that a foothold can be exploited?\u201c\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/\" \/>\n<meta property=\"og:site_name\" content=\"Clockwork\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/clockworkactivemedia\" \/>\n<meta property=\"article:published_time\" content=\"2018-11-08T17:47:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-11-21T22:21:24+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/cmdr-shane-610506-unsplash-scaled.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1672\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Vince Cabansag\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Changing how we think about cybersecurity: Creating the attacker\u2019s dilemma\" \/>\n<meta name=\"twitter:description\" content=\"Creating the attacker\u2019s dilemma starts by asking this question: \u201cHow might we quickly detect prevention failures so that we can minimize the window that a foothold can be exploited?\u201c\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/cmdr-shane-610506-unsplash-scaled.jpeg\" \/>\n<meta name=\"twitter:creator\" content=\"@Clockwork_Tweet\" \/>\n<meta name=\"twitter:site\" content=\"@Clockwork_Tweet\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/\"},\"author\":{\"name\":\"Vince Cabansag\",\"@id\":\"https:\/\/www.clockwork.com\/#\/schema\/person\/58b7f89753076f01a5ef569d5cea6132\"},\"headline\":\"Changing how we think about cybersecurity: Creating the attacker\u2019s dilemma\",\"datePublished\":\"2018-11-08T17:47:00+00:00\",\"dateModified\":\"2022-11-21T22:21:24+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/\"},\"wordCount\":1236,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.clockwork.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/cmdr-shane-610506-unsplash-scaled.jpeg\",\"articleSection\":[\"CW POV: How we work\",\"Strategy\",\"Technology\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/\",\"url\":\"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/\",\"name\":\"Changing how we think about cybersecurity: Creating the attacker\u2019s dilemma\",\"isPartOf\":{\"@id\":\"https:\/\/www.clockwork.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/cmdr-shane-610506-unsplash-scaled.jpeg\",\"datePublished\":\"2018-11-08T17:47:00+00:00\",\"dateModified\":\"2022-11-21T22:21:24+00:00\",\"description\":\"Creating the attacker\u2019s dilemma starts by asking this question: \u201cHow might we quickly detect prevention failures so that we can minimize the window that a foothold can be exploited?\u201c\",\"breadcrumb\":{\"@id\":\"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/#primaryimage\",\"url\":\"https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/cmdr-shane-610506-unsplash-scaled.jpeg\",\"contentUrl\":\"https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/cmdr-shane-610506-unsplash-scaled.jpeg\",\"width\":2560,\"height\":1672,\"caption\":\"photo of Key in hand\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.clockwork.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Topics\",\"item\":\"https:\/\/www.clockwork.com\/insights\/category\/topics\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Strategy\",\"item\":\"https:\/\/www.clockwork.com\/insights\/category\/topics\/strategy\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Changing how we think about cybersecurity: Creating the attacker\u2019s dilemma\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.clockwork.com\/#website\",\"url\":\"https:\/\/www.clockwork.com\/\",\"name\":\"Clockwork\",\"description\":\"We create human-centered digital experiences.\",\"publisher\":{\"@id\":\"https:\/\/www.clockwork.com\/#organization\"},\"alternateName\":\"Clockwork: Custom Software Solutions & Experience Design\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.clockwork.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.clockwork.com\/#organization\",\"name\":\"Clockwork\",\"url\":\"https:\/\/www.clockwork.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.clockwork.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/clockwork.svg\",\"contentUrl\":\"https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/clockwork.svg\",\"width\":93,\"height\":48,\"caption\":\"Clockwork\"},\"image\":{\"@id\":\"https:\/\/www.clockwork.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/clockworkactivemedia\",\"https:\/\/x.com\/Clockwork_Tweet\",\"https:\/\/www.linkedin.com\/company\/clockwork-active-media-systems\"],\"description\":\"Experience design & technology consultancy. We build enterprise websites, software platforms, and mobile apps with a human-centered approach.\",\"legalName\":\"Clockwork\",\"foundingDate\":\"2001-01-01\",\"naics\":\"541511\",\"numberOfEmployees\":{\"@type\":\"QuantitativeValue\",\"minValue\":\"51\",\"maxValue\":\"200\"},\"actionableFeedbackPolicy\":\"https:\/\/www.clockwork.com\/accessibility-statement\/\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.clockwork.com\/#\/schema\/person\/58b7f89753076f01a5ef569d5cea6132\",\"name\":\"Vince Cabansag\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Changing how we think about cybersecurity: Creating the attacker\u2019s dilemma","description":"Creating the attacker\u2019s dilemma starts by asking this question: \u201cHow might we quickly detect prevention failures so that we can minimize the window that a foothold can be exploited?\u201c","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/","og_locale":"en_US","og_type":"article","og_title":"Changing how we think about cybersecurity: Creating the attacker\u2019s dilemma","og_description":"Creating the attacker\u2019s dilemma starts by asking this question: \u201cHow might we quickly detect prevention failures so that we can minimize the window that a foothold can be exploited?\u201c","og_url":"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/","og_site_name":"Clockwork","article_publisher":"https:\/\/www.facebook.com\/clockworkactivemedia","article_published_time":"2018-11-08T17:47:00+00:00","article_modified_time":"2022-11-21T22:21:24+00:00","og_image":[{"width":2560,"height":1672,"url":"https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/cmdr-shane-610506-unsplash-scaled.jpeg","type":"image\/jpeg"}],"author":"Vince Cabansag","twitter_card":"summary_large_image","twitter_title":"Changing how we think about cybersecurity: Creating the attacker\u2019s dilemma","twitter_description":"Creating the attacker\u2019s dilemma starts by asking this question: \u201cHow might we quickly detect prevention failures so that we can minimize the window that a foothold can be exploited?\u201c","twitter_image":"https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/cmdr-shane-610506-unsplash-scaled.jpeg","twitter_creator":"@Clockwork_Tweet","twitter_site":"@Clockwork_Tweet","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/#article","isPartOf":{"@id":"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/"},"author":{"name":"Vince Cabansag","@id":"https:\/\/www.clockwork.com\/#\/schema\/person\/58b7f89753076f01a5ef569d5cea6132"},"headline":"Changing how we think about cybersecurity: Creating the attacker\u2019s dilemma","datePublished":"2018-11-08T17:47:00+00:00","dateModified":"2022-11-21T22:21:24+00:00","mainEntityOfPage":{"@id":"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/"},"wordCount":1236,"commentCount":0,"publisher":{"@id":"https:\/\/www.clockwork.com\/#organization"},"image":{"@id":"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/#primaryimage"},"thumbnailUrl":"https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/cmdr-shane-610506-unsplash-scaled.jpeg","articleSection":["CW POV: How we work","Strategy","Technology"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/","url":"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/","name":"Changing how we think about cybersecurity: Creating the attacker\u2019s dilemma","isPartOf":{"@id":"https:\/\/www.clockwork.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/#primaryimage"},"image":{"@id":"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/#primaryimage"},"thumbnailUrl":"https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/cmdr-shane-610506-unsplash-scaled.jpeg","datePublished":"2018-11-08T17:47:00+00:00","dateModified":"2022-11-21T22:21:24+00:00","description":"Creating the attacker\u2019s dilemma starts by asking this question: \u201cHow might we quickly detect prevention failures so that we can minimize the window that a foothold can be exploited?\u201c","breadcrumb":{"@id":"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/#primaryimage","url":"https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/cmdr-shane-610506-unsplash-scaled.jpeg","contentUrl":"https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/cmdr-shane-610506-unsplash-scaled.jpeg","width":2560,"height":1672,"caption":"photo of Key in hand"},{"@type":"BreadcrumbList","@id":"https:\/\/www.clockwork.com\/insights\/changing-how-we-think-about-cybersecurity-creating-the-attackers-dilemma\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.clockwork.com\/"},{"@type":"ListItem","position":2,"name":"Topics","item":"https:\/\/www.clockwork.com\/insights\/category\/topics\/"},{"@type":"ListItem","position":3,"name":"Strategy","item":"https:\/\/www.clockwork.com\/insights\/category\/topics\/strategy\/"},{"@type":"ListItem","position":4,"name":"Changing how we think about cybersecurity: Creating the attacker\u2019s dilemma"}]},{"@type":"WebSite","@id":"https:\/\/www.clockwork.com\/#website","url":"https:\/\/www.clockwork.com\/","name":"Clockwork","description":"We create human-centered digital experiences.","publisher":{"@id":"https:\/\/www.clockwork.com\/#organization"},"alternateName":"Clockwork: Custom Software Solutions & Experience Design","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.clockwork.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.clockwork.com\/#organization","name":"Clockwork","url":"https:\/\/www.clockwork.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.clockwork.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/clockwork.svg","contentUrl":"https:\/\/www.clockwork.com\/wp-content\/uploads\/2022\/07\/clockwork.svg","width":93,"height":48,"caption":"Clockwork"},"image":{"@id":"https:\/\/www.clockwork.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/clockworkactivemedia","https:\/\/x.com\/Clockwork_Tweet","https:\/\/www.linkedin.com\/company\/clockwork-active-media-systems"],"description":"Experience design & technology consultancy. We build enterprise websites, software platforms, and mobile apps with a human-centered approach.","legalName":"Clockwork","foundingDate":"2001-01-01","naics":"541511","numberOfEmployees":{"@type":"QuantitativeValue","minValue":"51","maxValue":"200"},"actionableFeedbackPolicy":"https:\/\/www.clockwork.com\/accessibility-statement\/"},{"@type":"Person","@id":"https:\/\/www.clockwork.com\/#\/schema\/person\/58b7f89753076f01a5ef569d5cea6132","name":"Vince Cabansag"}]}},"_links":{"self":[{"href":"https:\/\/www.clockwork.com\/wp-json\/wp\/v2\/posts\/2456","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.clockwork.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.clockwork.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.clockwork.com\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/www.clockwork.com\/wp-json\/wp\/v2\/comments?post=2456"}],"version-history":[{"count":2,"href":"https:\/\/www.clockwork.com\/wp-json\/wp\/v2\/posts\/2456\/revisions"}],"predecessor-version":[{"id":4516,"href":"https:\/\/www.clockwork.com\/wp-json\/wp\/v2\/posts\/2456\/revisions\/4516"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.clockwork.com\/wp-json\/wp\/v2\/media\/2457"}],"wp:attachment":[{"href":"https:\/\/www.clockwork.com\/wp-json\/wp\/v2\/media?parent=2456"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.clockwork.com\/wp-json\/wp\/v2\/categories?post=2456"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.clockwork.com\/wp-json\/wp\/v2\/tags?post=2456"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.clockwork.com\/wp-json\/wp\/v2\/coauthors?post=2456"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}