Deloitte's Email Breach (Sept 2017): An Admin Account Without MFA
In September 2017, The Guardian reported that Deloitte, one of the world's largest accounting and consulting firms, had suffered a breach of its global...
Insights
Articles in Retrospectives.
In September 2017, The Guardian reported that Deloitte, one of the world's largest accounting and consulting firms, had suffered a breach of its global...
Global Administrators can change every setting, read every mailbox and create new admins in Microsoft 365. Protecting those accounts is the highest-value...
Compromised administrator accounts give attackers control of an entire Microsoft 365 tenant. Detecting unusual admin behavior early is one of the...
The short version: Deloitte's 2017 email breach reportedly started with one administrator account protected only by a password. Admin accounts are the keys...
In August 2017, AWS launched Amazon Macie, a service that used machine learning to discover, classify and protect sensitive data stored in Amazon S3. It...
Amazon Macie scans S3 buckets for sensitive data such as names, financial information and credentials. Here is how to run it effectively without a surprise...
Use this checklist before and after enabling Amazon Macie to get value quickly while keeping costs predictable.
The short version: In 2017, AWS released Macie, a tool that finds sensitive data like customer records hidden in cloud storage. Its premise is simple and...
In July 2017, UpGuard researchers reported that records belonging to millions of Verizon customers were sitting in a publicly accessible Amazon S3 bucket....
Bucket policies decide who can access data in Amazon S3. Written loosely, they leak data; written tightly, they make many attacks impossible. Here is how to...
Overly broad bucket policies are a frequent root cause of S3 exposures. Detecting policy changes that widen access — and catching risky policies already in...
The short version: In 2017, a Verizon vendor exposed customer records — including account PINs used for phone support — in a cloud storage folder anyone...
In July 2017, Microsoft announced Microsoft 365: a single subscription bundling Office 365, Windows 10 Enterprise and Enterprise Mobility + Security. For...
Microsoft 365 E3 and E5 both include significant security capabilities, but they are packaged differently and named inconsistently over the years. Here is...
New and long-neglected Microsoft 365 tenants share the same weaknesses. This checklist covers the baseline settings that stop the most common attacks. Treat...
The short version: Microsoft 365 E3 includes solid security basics. E5 adds advanced threat protection, risk-based identity controls and stronger compliance...
On June 27, 2017, a malware outbreak later called NotPetya began in Ukraine and spread to multinational companies within hours. Shipping giant Maersk had to...
NotPetya spread by stealing administrator credentials from memory and reusing them across the network. Tiering your Active Directory admin accounts stops...
NotPetya combined credential theft with legitimate admin tools to move across networks. Detecting that pattern early is one of the most effective ways to...
The short version: NotPetya, in 2017, entered companies through a trusted software update and then spread using administrator passwords stolen from one...
In June 2017, researcher Chris Vickery of UpGuard found an Amazon S3 bucket containing personal data on about 198 million American voters. It belonged to...
Public S3 buckets were behind dozens of data leaks in 2017. AWS has since made buckets private by default, but older accounts, older buckets and deliberate...
The best time to catch a public S3 bucket is the moment it becomes public. Detection rules on configuration changes close the window between a mistake and...
The short version: In 2017, a data company working for the Republican National Committee left personal details on 198 million voters in an unprotected cloud...