All modern enterprises have security tools in place that alert them to potential threats.

The problem is that, too often, those alerts go unheeded, and the hackers get in anyway.

This is due to “passive security” methods: Organizations aren’t blocking threat actors from the start.

But this paradigm must be flipped, says Nick Biasini, head of outreach for Cisco Talos Intelligence Group. To survive in 2024 and beyond, organizations have to take an active security approach.

“Technology is running passively, meaning it doesn’t take an active response, it just alerts when it sees something that is bad,” said Biasini. He pointed out that, “it's 2024; running passive security is a recipe for disaster.”

The argument for active security

In his role, Biasini runs a team of threat hunters tasked with identifying new novel threats coming from all sides — from ransomware gangs, to mercenary spyware to state-sponsored groups.

He describes himself as “someone who sits on the threat side of things,” meaning he sees adversaries’ increased level of sophistication. On the flip side, enterprises are constantly in defense mode and they face significant staffing challenges.

The “constant theme,” Biasini said, is that security technologies are in place, yet they fail to deter attacks. This is because many enterprises don’t have their security tools configured to actively block malicious activity, particularly when it comes to their endpoints.

“We see far too many passive approaches to security, still,” said Biasini. “It’s 2024, vulnerabilities are weaponized in a matter of hours. We don’t move fast enough as people to be relying on passive technology.”

It’s a contentious debate, though: As long as active blocking has existed, there have been strong arguments against it, he pointed out. Ten to 15 years ago naysayers may have had a sound argument, he conceded, as emerging technologies can deliver false-positives. However, “in today's threat landscape, it's asking for trouble.”

Simply put, threat actors are good at what they do, and not actively blocking their activity is a mistake, Biasini contends.

But, sometimes active just isn’t feasible

Sitting on the defender side, his colleague, Cisco’s head of advisory Chief information security officer (CISO) Wendy Nather, respectfully disagrees.

In some scenarios, “you can’t just block everything in a class across the board,” she said. Due to increasingly complex IT infrastructures, “it’s just not that easy to do.”

Not to mention, automating more and more blocking doesn’t work in specific instances (say, healthcare, where doctors must have access, on demand, whenever they need it), she pointed out.

“There are some things you cannot get around,” said Nather.

Furthermore, regulation issues are a complication for CISO, as is the increasingly complex security supply chain. If security leaders are looking to implement active measures, they must look at everything they rely on, Nather said.

Then there’s just the internal plumbing — today’s infrastructure is so complicated that organizations are afraid of implementing blocking. “For them, blocking is breaking,” she said.

For instance, Nather once worked for an organization that hadn’t been patched in two years because its leaders were terrified of what might happen when they did. “Part of it is psychological.”

Instead, reluctant organizations can train their employees to work alongside automation.

“Can you replace people with automation? No you can’t,” said Nather. “But you can raise skill levels and capabilities.”

Like patching, active blocking will simply become everyday practice

Still, Biasini said, there might be an argument to be made for a passive approach if you’re running a 24/7/365 security operations center (SOC). Analysts can stay on top of attacks and threats when they come in at, say, 3 a.m. when everyone is otherwise asleep.

In reality, though, most organizations don’t have SOCs (or the budgets to implement and maintain them). As such, they are “blind” during big chunks of the day. Biasini emphasized that, “adversaries do not follow your work schedule.”

He added that existing security teams are over-extended, leaving little time to address alerts as they are generated. “Alerting infrastructure is only as good as people actually responding to it.”

With active blocking, however, security professionals can home in on events impacting servers or databases, he pointed out — instead of triaging every single thing that comes along.

Biasini drew parallels between active security and patching. Looking back five to 10 years, patching was either not done at all or was required to be ‘baked in’ for 3 to 6 months for testing purposes.

Today? Patches have become so stable that they are rolled out regularly without issue, and are automatically applied to home users, too.

Yes, passive methods have their time and place, Biasini conceded, but “the issue comes when organizations run the majority, if not all, of their security technologies in passive mode, most critically on the endpoint.”

Moving from passive to active (if only halfway)

In incorporating automation, CISO should follow guidelines that incorporate certainty, precision, transparency and commitment, said Nather.

Certainty means they need to be absolutely sure that it will work. “They can’t say, ‘well sometimes, it depends, not in this case,’” she said.

Precision means security leaders know what actions they want to see taken, and that automation can successfully perform them. Transparency is critical so that everyone who relies on automation understands what might trigger alerts and what to look for.

Finally, commitment means organizations “need to be able to leave [automation] in place,” she said.

Biasini agreed that it’s important to strike a balance to make the most of automation as well as human talent.

“Start small, start slow, start piecemealing,” he said. Build on strengths, “let them cook for a while” and continuously look for ways to expand and get better.

“It’s definitely a process, it’s going to take time,” he said.

Ultimately, Nather emphasized that, “our joint goal from both the attacker and defender side is ‘How can we make things better?”