I had an excellent time in Copenhagen presenting Building an organization attackers hate to attack at SANS Copenhagen. Great crowd, great questions, and a topic I genuinely love talking about: how to make your organization such a frustrating target that attackers give up and move on.
The talk covers four themes:
- The good old best practices. None of the fancy stuff matters if the fundamentals are missing. Patching, hardening, least privilege, and asset management are not glamorous, but they are what removes the easy wins attackers rely on.
- Infrastructure as code. When your environment is defined in code, it is reviewable, repeatable, and rebuildable. Configuration drift disappears, and recovering from compromise becomes redeploying from a known-good state instead of praying over backups.
- Knowing you’re getting hacked. Assume the breach will happen and invest in actually noticing it. Visibility, logging, and detection turn an attacker’s months of free reign into a short and stressful visit.
- A sprinkle of cyber deception. Canaries, honeytokens, and decoys are cheap to deploy and brutal for attackers: every step they take might be the one that gives them away. Few things flip the asymmetry of attack and defense as effectively.
You can grab the full presentation here: Download the slides (PDF).
Thanks to everyone who came, and to SANS for hosting. If you saw the talk and want to discuss how to make your organization a target attackers hate, reach out.