Posts

Showing posts with the label Risk Management

Vendor Diversity and Monoculture Risk: When Two Vendors Beat One

Vendor diversity means deliberately using products from more than one supplier for a given function. The argument is that a vulnerability or failure in one vendor's product does not affect everything at once. The counter-argument is that complexity is itself a source of failure. Both are true, and the exam expects you to weigh them rather than pick a side. Monoculture risk The term comes from agriculture, where a field of genetically identical plants falls to a single disease. The computing analogue is direct: an estate where every endpoint runs the same operating system, every firewall is the same model and every server the same distribution has one set of vulnerabilities, and a flaw in any of them applies everywhere simultaneously. It compounds with automation. A configuration management system that pushes the same change to ten thousand identical machines is an efficiency until the change is wrong, at which point it is an outage delivered at scale. Supply chain concentratio...

Quantitative Risk Assessment: SLE, ARO and ALE Worked Through

Quantitative risk assessment attaches monetary values to risk so that control spending can be compared against expected loss. The formulas are simple, they appear on the exam as calculations, and knowing where their inputs come from matters as much as the arithmetic. The formulas Asset Value (AV) — what the asset is worth, including replacement, lost revenue during unavailability, and the cost of consequences such as notification and regulatory penalty. Exposure Factor (EF) — the proportion of the asset's value lost in a single occurrence, expressed as a percentage. A fire destroying a building outright is 100 percent; a disk failure in a redundant array may be 5 percent. Single Loss Expectancy (SLE) = AV × EF — the cost of one occurrence. Annualized Rate of Occurrence (ARO) — how many times per year it is expected. Once every four years is 0.25; three times a year is 3. Annualized Loss Expectancy (ALE) = SLE × ARO — the expected ann...

Preparing for a SOC 2 Audit: Readiness, Evidence and the Common Gaps

Reading a SOC 2 report is one skill; producing one is another. This is the producer's side — what an organization actually does to get through an audit, and where the work concentrates. If you need the consumer's perspective, the report types and how to read one are under SOC 1, SOC 2 and SOC 3 . Scoping first Two decisions shape everything else, and both are frequently made badly under sales pressure. Which systems are in scope. Narrow scope means less work and a report customers may find inadequate. Broad scope means a stronger report and substantially more effort. Scope the service customers actually buy, and be able to describe the boundary clearly — auditors ask, and a vague boundary produces findings. The boundary depends on an accurate inventory, which is why organizations discover during scoping that they do not have one. That work is upstream of the audit, not part of it, and it is the same dependency described under CMDB . Which trust services criteria. Sec...

Supply Chain Security: Software, Hardware, and Service Provider Risk

A supply chain attack compromises something you trust in order to reach you. The economics are what make it attractive: one successful compromise of a widely used software vendor, hardware component, or managed service reaches every one of their customers at once, and it arrives through a channel every one of those customers has explicitly decided to trust. Three attack surfaces Software. The build pipeline is the highest-value target, because code inserted there is signed by the legitimate vendor and distributed through the legitimate update mechanism. Nothing downstream looks wrong. Below that sit dependency attacks — a compromised maintainer account, a typosquatted package name, or a malicious version published to a public registry — and update channels that can be hijacked where signature verification is weak. Hardware. Counterfeit components, firmware implanted during manufacturing or in transit, and devices shipping with backdoored management interfaces. Hardware...

MSSP vs MDR vs In-House SOC: Choosing a Monitoring Model

A Managed Security Service Provider operates security controls and monitoring on your behalf. The reason the category exists is arithmetic: continuous coverage requires enough analysts to staff nights, weekends, holidays, vacations, and turnover, and most organizations cannot justify that headcount for their own environment alone. A provider spreads the same team across many customers. What a provider typically runs The core offering is monitoring and alert triage against your log and telemetry sources, usually through a SIEM the provider operates. Around that sit device management for firewalls, proxies, and endpoint tooling; vulnerability scanning with reporting; and compliance evidence gathering. The value is continuous coverage and the pattern recognition that comes from seeing the same attack technique across a customer base. A campaign that hits one client at 2 a.m. can inform detections for the rest before morning. MSSP, MDR, and an internal SOC These three are distingui...

OCTAVE: Asset-Driven Risk Assessment and How It Compares to STRIDE

OCTAVE is a risk assessment method built on one premise: the people who know which assets matter are the business, not the security team. It works from critical assets and business impact toward technical controls, which is the opposite direction from most technical threat modelling, and that difference is what the exam is testing when it appears. What makes it different Most technical methods start with a system and enumerate what could go wrong with it. OCTAVE starts by asking the organization which handful of assets it genuinely could not operate without, then works out what threatens those. It is self-directed — run by an internal team drawn from across the business rather than by outside consultants — and it is operationally focused , concerned with organizational risk and practice rather than with a vulnerability list. The output is a protection strategy and mitigation plans, not a scan report. The self-direction is deliberate. An external assessment produces a d...

DREAD Risk Scoring: How It Works and Why It Fell Out of Favour

DREAD is a scoring model for ranking threats, originally paired with STRIDE at Microsoft. STRIDE identifies what could go wrong; DREAD ranks what to fix first. It is worth knowing both because it still appears on exams and because the reasons it was abandoned teach something about risk scoring generally. The five categories Each is rated on a scale — commonly 1 to 10, sometimes 1 to 3 — and the ratings are combined. Damage — how bad is the outcome if this is exploited? Data destruction or full system compromise scores high; minor information disclosure scores low. Reproducibility — how reliably does the attack work? Something that works every time scores high; something requiring a narrow race condition scores low. Exploitability — how much skill, time and access does it take? A single unauthenticated request scores high; a chain requiring physical access and custom tooling scores low. Affected users — what proportion of users or systems ar...

Computer Misuse Law and Authorization: Why Everything Needs It in Writing

Computer misuse legislation exists in some form in most jurisdictions, and the concept every version turns on is authorization . Accessing a system without it, or exceeding what was granted, is the offence — and that single concept is why documented permission is the first artefact in any security engagement. This is general context rather than legal advice; specifics vary by jurisdiction and a lawyer is the right source for a real situation. Authorization is the hinge The technical act is frequently identical on both sides of the line. Sending a request to a web server is either ordinary use or the start of an offence, depending entirely on whether the sender was permitted. That is why intent and skill are not the determining factors people expect. A researcher who finds a flaw, reports it responsibly and profits in no way has still accessed a system without authorization if they had none, and jurisdictions differ considerably in how sympathetically that is treated. "Exceed...

Physical Lock Bypass: Why a Lock Is a Delay, Not a Barrier

Physical security assessments consistently find that locks are trusted far beyond what they deliver. A lock is a delay mechanism — it buys time, measured against an attacker's skill and tolerance for being noticed. Treating it as a barrier is the mistake, and designing around the delay is the correct response. How a pin tumbler lock works A cylinder contains stacked pin pairs. The correct key lifts each pair so the gap between them aligns exactly with the shear line between the rotating plug and the fixed housing, and the plug turns. The weakness is manufacturing tolerance. The pin chambers are not perfectly aligned, so when rotational pressure is applied, one pin binds first. Set that pin at the shear line and the next binds. Working through them one at a time defeats the lock, and this is the basis of picking. Single pin picking does exactly that, deliberately and quietly. Raking scrubs a toothed pick across all pins while applying tension, hoping several set at once ...

Choosing a Penetration Testing Provider: Accreditation, Scope, and Rules

Buying a penetration test is a procurement problem before it is a technical one. Two providers quoting the same engagement can differ by a factor of five in price and by rather more in what you actually receive. Accreditation and scoping are the two levers that decide which you get. What accreditation signals CREST is an accreditation body for penetration testing and incident response providers, widely recognized in the UK, Europe, Asia-Pacific, and increasingly elsewhere. It accredits organizations against assessed standards for methodology, data handling, personnel vetting, quality assurance, and complaints handling, and it certifies individual testers by examination at several levels. The organizational accreditation is the part buyers underuse. It says the company has documented processes, that reports go through review, that testers are background checked, and that there is a route to escalate when something goes wrong. Individual certification says a named person passed a pra...

Vulnerability Scan, Penetration Test or Red Team: Choosing the Right Exercise

Four exercises get used interchangeably in procurement conversations and answer completely different questions. Buying the wrong one is the most common way organizations spend a security budget and learn nothing, so the distinction is worth being precise about. Vulnerability scanning: what is wrong Automated, broad and shallow. A scanner enumerates hosts and services, identifies software and versions, and reports known vulnerabilities and misconfigurations. It answers "what known weaknesses exist across the estate," runs continuously, and costs very little per asset. It does not confirm anything is exploitable, does not chain findings, and produces false positives and negatives — the matching problems described under CPE . Authenticated scanning finds substantially more than unauthenticated, and running it is the baseline hygiene that should be in place before anything else is purchased. Penetration testing: what is exploitable Manual, scoped and deep. A tester attemp...

Physical and Environmental Attacks: Power, Cooling, RF, and Tampering

Most security discussion assumes the attacker arrives over the network. Physical and environmental attacks do not. They target the conditions a system needs in order to run — electricity, temperature, radio spectrum, physical integrity — and they almost always aim at the availability leg of the CIA triad rather than at confidentiality. Power attacks Cutting power stops everything, and the ways to do it range from pulling a breaker to cutting a feeder outside the building. More subtle versions do damage rather than causing an outage: deliberately induced surges, brownouts that stress power supplies, or repeated cycling that shortens hardware life and corrupts filesystems. The defenses are layered and familiar. Uninterruptible power supplies carry the load through short interruptions and, more importantly, provide the window in which generators start. Generators handle extended outages, with a fuel contract that has actually been tested. Redundant utility feeds from separa...

COBIT: IT Governance, and How It Differs From a Security Framework

COBIT is a governance framework for enterprise IT, published by ISACA. It is not a security framework, and the difference is the thing exam questions test: COBIT answers who decides, who is accountable, and how do we know IT is delivering value , while security frameworks answer what controls should exist . Governance versus management COBIT draws a hard line between the two, and it is the framework's central idea. Governance is the board's responsibility: evaluating options, directing the organization, and monitoring whether direction is being followed. It sets objectives and decides risk appetite. Management is the executive team's responsibility: planning, building, running and monitoring activities within the direction governance has set. Most organizations conflate them, and the practical symptom is a board being asked to approve technical decisions it cannot evaluate, or an IT function setting its own risk appetite by default. Separating the two is what COBIT ...

Dependency Governance: Choosing, Updating and Retiring Open Source Components

Scanning dependencies for known vulnerabilities tells you about problems that already have a CVE number. Governance is the upstream question: which components you take on in the first place, how you keep them current, and how you get rid of the ones that become liabilities. It is the part that prevents findings rather than reporting them. Evaluating a dependency before adopting it Adding a library is a long-term commitment to someone else's code and someone else's maintenance. A short check before the first import costs minutes and saves years. Maintenance signals. When was the last release, and how quickly do security issues get fixed? A project with an eighteen-month gap since its last commit is not maintained, whatever its popularity. Bus factor. How many people can merge changes? A great deal of critical infrastructure is maintained by one unpaid person, which is a supply chain risk and a burnout risk simultaneously. Dependency weight. A package pulling in forty tr...

Fail-Open vs Fail-Closed: Choosing Which Way a Control Breaks

Every control fails eventually, and it fails in one of two directions. Fail-open means access is permitted when the control stops working — availability is preserved, security is lost. Fail-closed , or fail-secure, means access is denied — security is preserved, availability is lost. Choosing is a business decision, and defaults frequently choose for you. The general principle and its exception Security controls should generally fail closed. A control that stops enforcing when it breaks provides an attacker with an obvious strategy: break the control. An authentication system that admits everyone when its database is unreachable is not an authentication system. The exception is life safety , and it overrides everything. Doors on emergency exit routes must unlock when power or control fails, because people trapped in a burning building is a worse outcome than an unauthorized entry. Fire codes require this and they are not negotiable — a security design that conflic...

Data Protection Roles and Principles: Controller, Processor and Lawful Basis

Data protection law appears on security exams as vocabulary and accountability rather than as legal detail. The terms are consistent across regimes even where the specifics differ, and knowing who is responsible for what is the part that affects how systems are built. Controller and processor The distinction everything else hangs on. A controller determines the purposes and means of processing — why the data is collected and how it will be used. The controller is accountable for compliance and is who a regulator and a data subject deal with. A processor processes data on the controller's behalf, following instructions. A cloud provider hosting a customer's database is typically a processor; the customer is the controller. The exam point: accountability does not transfer to the processor. Engaging a processor does not move responsibility, which is the same reasoning as under the cloud shared responsibility model and under supply chain security . A controller must contr...

Security Metrics That Survive a Board Meeting

Security programmes are asked to prove their value with numbers, and most of the numbers reported are the wrong ones. The test for any metric is simple and rarely applied: if this number moved, would anyone do anything differently? A number that cannot change a decision is decoration. Vanity metrics These get reported constantly because they are easy to produce and they look impressive. Attacks blocked, emails filtered, and alerts generated are volume counts driven almost entirely by the internet's background noise. They rise and fall with attacker activity you do not control, and a large number proves only that you have a perimeter, not that it is effective. Training completion percentage measures attendance, not behaviour. Total vulnerabilities is a count without context — a thousand low-severity findings on isolated systems matters less than three critical findings on an internet-facing one. Patch counts have the same problem. None of these are useless as operational tel...

Single Pane of Glass: What Consolidation Buys, and What It Costs

"Single pane of glass" is a vendor phrase for one console showing everything, and it is sold as the answer to a real problem. The problem is genuine; the answer is partial, and knowing which parts it solves is more useful than the slogan. The problem it addresses A mid-sized security team commonly operates a dozen or more products, each with its own console, its own alert queue, its own terminology and its own login. The cost is not the licensing. It is that an analyst investigating one alert has to visit five consoles to gather context, that the same host is called different things in each, that nobody knows which queues are unworked, and that correlation across products is performed by a human holding several browser tabs open. That manual assembly is where the time goes, and it is the work described under alert enrichment . Coverage gaps follow from the same fragmentation. When each tool reports on its own domain, nobody can answer how many endpoints lack a working ag...