Mandiant kicked off its Cyber Defense Summit event with two new software-as-a-service products — Active Breach and Intel Monitoring, and Ransomware Defense Validation — and a name change from FireEye (back) to Mandiant, or what CEO Kevin Mandia called “Mandiant part deux” during his opening keynote.
Last year was a tough year to be a CISO, Mandia said. “And I remember thinking this is the hardest year to be a chief information security officer,” he added during his keynote. “But 2021 is just as hard.”
FireEye itself experienced a breach at the end of 2020 when Russian state-sponsored hackers inserted malicious code into a SolarWinds software update, Mandia noted. And he said this type of “implant” threat, where the attackers implant malicious code into the software build process, remains a top-three concern for CISOs. “So, bottom line, implants are fair game. You’re going to see them again because they’re fair game for cyber espionage.”
Zero-day exploits and ransomware comprise the other two top threats, according to Mandia.
“We’re seeing more zero days in 2021 than the last two years combined,” he added.
In, 2019 Mandiant recorded 32 zero-day attacks exploited in the wild. These are never-before-seen attacks where there’s no patch available to fix the vulnerability. In 2020, the number decreased slightly to 30. So far in 2021, Mandiant documented 64 zero-day exploits.
“There’s a whole market for zero days, and the amount of profit you can make breaking in right now is so high that it used to be zero days were the providence of nations,” Mandia said. These nation-state attackers “developed them, or they bought them, and they used them. Now we’re seeing far more criminal activity using zero-day attacks because of the amount of dollars” they can make off of these attacks.
Of course, ransomware is another attack method in which criminal gangs have seen skyrocketing profits. “It’s the No. 1 board topic,” Mandia said. “It’s changing how we do business, but quite frankly it means: Don’t be the low-hanging fruit at your organizations. Figure out how to bolster your security.”
Ransomware Defense ValidationOne of the new SaaS products Mandiant launched this week directly addresses the threat of ransomware. And both are designed to bolster Mandiant’s multi-vendor extended detection and response (XDR) platform, called Mandiant Advantage, and will be generally available in early 2022.
Ransomware Defense Validation lets organizations test their security controls against prevalent ransomware, determine which attacks they are vulnerable to, and then fix those flaws in their defenses so they don’t get hit by an attack. It’s powered by Mandiant’s threat intelligence on active ransomware groups.
“We have a large library of these groups, it’s updated continuously based on what we are seeing in our incident response, and when we start engaging with a customer we pick the top five for that customer profile,” Chief Product Officer Chris Key said in an interview with SDxCentral, adding that it’s a dynamic threat assessment.
“As we’re working with the customer, what’s being tested is changing based upon that customer profile and what we’re seeing as the most active threats in the wild,” he explained.
The product gives customers proactive protection against ransomware instead of waiting for Mandiant or another incident response team to come in and clean up after an attack. It’s unique in that it provides organizations with quantifiable information about which ransomware strains they aren’t protected against, Key said.
“Most of the security control vendors’ products on the market will say they’re protecting a customer against ransomware, but they’re not providing any quantifiable information,” he said. “Additionally, most of the time that we go into a customer’s environment after they’ve been breached and had a ransomware event, they have controls that they thought would protect them that were not set up correctly or just aren’t capable. So there’s a false sense of security that you can get from a control vendor that’s not quantifying the security.”
Ransomware Defense Validation tests the organizations security controls using real ransomware “so we can tell you with 100% certainty what your environment will do when that ransomware happens and if your controls detected and prevented it or not,” Key said.
As ransomware attacks increase, organizations’ security posture has moved to a board-level discussion. CISOs need to be able to answer what will happen to the business in the event of a Darkside or REvil ransomware attack, Key added.
Usually, the answer is: “We think we’re going to be OK. We’ve bought a lot of stuff,” he said. Mandiant’s new ransomware prevention product, however, “is empiric data on what’s going to take place.”
Active Breach and Intel MonitoringMandiant’s second new product, Active Breach and Intel Monitoring, identifies relevant indicators of compromise (IOC) within an organizations’ IT environments. It’s based on the real-time information from Mandiant’s global incident response team’s breach investigations and threat intelligence research.
Using this data, the security module searches customers’ data for IOC matches going back 30 days. It prioritizes IOC matches using a data science-based score and contextual factors such as direction of travel and indicator type so that security teams can more efficiently respond to high-priority threats.
Customers see headlines about the SolarWinds breach or the Colonial Pipeline ransomware attack, and “one of the things that constantly hear from customers is: How do we know if that breach is happening in our environment or not? And what Active Breach and Intel Monitoring does is it connects a customer’s security data with what our incident responders are finding on the frontlines,” Key said.
It’s worth noting that the Mandiant incident response team responded to both Colonial Pipeline and SolarWinds, and its threat hunters initially discovered the SolarWinds breach.
From Mandiant to FireEye to Mandiant (Again)In addition to hosting a Cyber Defense Summit in Washington, DC and launching two SaaS products this week, Mandiant also finalized its name change.
FireEye originally acquired Mandiant for about $1 billion in 2014, and later moved Mandia, who founded Mandiant, into the CEO role. The name change back to Mandiant is a result of the sale of FireEye’s products business to private equity firm Symphony Technology Group (STG).
In June, FireEye said it would sell its products business to STG for $1.2 billion and reposition its Mandiant threat intelligence and incident response arm as an independent company.
A couple months before acquiring FireEye’s product business, STG paid $4 billion for McAfee’s enterprise security business, and last year STG bought security vendor RSA from Dell Technologies for a little over $2 billion.
The name change back to Mandiant is significant because it puts the emphasis back on the company’s work at the frontlines of cybersecurity, Key said. Mandiant spends more than 200,000 hours a year responding to breaches, he added. “It’s about 23 years of IR every 2 months. And that gives us an immense knowledge about [what] the attackers are doing literally right now and powerful expertise on how to defend against it,” Key said.
“What we see is that the market has continued to spend more money on security, purchase more and more controls, and throw more and more bodies at the problem, but it hasn’t increased security effectiveness,” he added.
This is because effective security isn’t based on controls and products deployed in an IT environment, Key said. But rather, it’s based on the expertise and intelligence behind the security controls.
Most attacks use years-old vulnerabilities to breach organizations, he added.
“And if we look at broad supply-chain attacks like SolarWinds: every major control vendor product was involved, and still 18,000 customers got bad binaries that SolarWinds was able to leverage,” Key said. “Only one team was able to find that [breach] based upon our expertise and ability to track that down. If we could scale that expertise and intelligence, we can make the industry much more effective.”
This is why Mandiant launched its XDR platform and wanted to become an independent company: “To address these challenges, not by focusing on controls, but by making those controls more effective and more efficient,” he said.
Comments