Skip to main content
Right of Boom
January 30, 2025

CISA and RVAs

In this video, Ryan Weeks and Andrew discuss the CISA Risk and Vulnerability Assessment (RVA) report and its applicability to Managed Service Providers (MSPs). They delve into the importance of addressing common vulnerabilities, enhancing credential security, and the role of phishing-resistant multi-factor authentication (MFA) in cybersecurity. The discussion provides insights into practical steps MSPs can take to improve security measures and highlights the significance of having a well-structured plan to address these risks.<ul><li>The migration from Crowdcast version 1 to version 2 involved exporting and importing over 6,000 users, causing multiple registration emails to be sent out to users.</li><li>The CISA risk and vulnerability analysis report highlights the importance of credential security, as valid accounts were frequently exploited in cyber attacks.</li><li>MSPs should focus on implementing phishing-resistant MFA and ensuring that security measures align with frameworks like CIS to enhance protection against common cyber threats.</li></ul>

Guests

Andrew Morgan

Video Transcript

Welcome, welcome everybody. This is Crowdcast version 2.0, and I just want to take a moment, uh, and go through a quick, um, uh, few announcements. Number one, um, they are migration path. Let's just talk about the migration path. So first I wanna apologize for the emails that you may have gotten last week. Um, basically their migration path was export all 6,000 plus users out of version one and import them into version two.

And when you do that, everybody got emails, multiple emails, and um, I got an email for every person that registered, by the way, uh, Wes. So, um, my email box had 6,000 plus registers that, um, that was fun. Yeah, it was awesome. There was a bunch of, bunch of different things going on. Um, so again, Maybe they don't charge enough. Maybe if they charge more, they can afford to have a migration tool.

Well, I did set up a call with you, Gary, so they're gonna, I'll Take them through their business model if you want. Um, all right. So, um, see, which I Do everywhere. I can't even go get ice cream without how telling the guy how to reorganize his cues. I'm sure he, I'm sure he or she appreciated. In my defense, he wasn't doing it right. Too funny. Um, the other thing I was just gonna ask everybody, um, I'm gonna put a URL into, um, into chat.

And, um, this is our first, um, attempt to understand what are Gary. This is called a lead funnel. And, um, this is something we hope to help MSPs, you know, with not, not like that we're gonna, you know, become, um, the intent doesn't become a marketing company or anything, but it's really intriguing.

I've been studying a lot about these things, and I think they're things that you all can use to help, uh, develop, you know, your, your ideal customer profile, AKA, what they say is your avatar, your message. Um, so check it out. Um, I'd love your comments and thoughts. Um, if you don't know anything about write a Boom, this would be the way to go find out more about it.

But again, just if you can keep an open mind and let us know what your thoughts are on, on how it flows, and you'll also be able to get the free 2023 threat brief, which our special guest actually, uh, was the author of. It's a really, really good threat brief on, um, uh, black Cat Ransomware, which is our threat actor in 2023. Um, okay. Setting the stage. I like to be there, but we have a conflict. We'll be at right bun, Right bun, Which is, uh, yeah, hot Dogs, hamburgers, brisket.

What happened? Did you tell them how to reorganize their business? And they invited you to that. Um, and then, so, so let me just set the stage. So as you guys know, last week, if you were with us, we, um, had Jason Schiffer on, we were talking about, uh, info stealing malware, which is Ryan, one of Ryan's favorite subjects.

Um, we talked about how, um, the browser really is the new os and we were discussing how these, this info stealing malware really is about looking for information, everything from credentials, credit cards, financial information, P II, PHI, et cetera, and extracting that data and then using it to, um, gain access. And, um, what a better way to kind of lead in today, what I was talking to Ryan Weeks, our special guest who will introduce himself momentarily.

For those that you don't know him, um, were like, He's coming from the, an, he's from like the Antarctic. He's, he's wrapped up Surely where he is. Um, and, um, and, and we were talking about this 2023 cis, a Risk and vulnerability analysis, um, report that they published.

And lo and behold, you're gonna see a lot of dataset similarities between what we've seen from Verizon Data Breach report and, and other threat briefs where still credentials, um, remain Reign Supreme in terms of what threat actors are doing. So that is what we are gonna be talking about today, this assessment report from cisa, and we'll talk about the applicability it has to MSPs along the way. So Ryan, welcome, welcome back to the cyber call. It's awesome to have you with us.

It's been a while. And yeah, uh, for those that may not know that you are once, uh, one of our hosts, tell us a little about yourself and what you up to these days. Yeah, so, uh, in my time as a host, I was, um, the, the CISO at Datto, um, was there for six years, um, then took some time off, um, came back, uh, worked at Kaseya for about four or five, six months.

Um, and then, uh, decided to, to kind of just, yeah, spend some more time with family and, uh, you know, and then kind of went along the way. And in the meantime, um, decided to focus some more energy working with Andrew on, on Write a boom. Um, been involved, uh, with him for, for several years. There actually more, more so in the background. Um, and, uh, you know, the focus for this year for me continues just to be spending time with, with family.

Um, but, uh, and Andrew's been keeping me pretty busy with, with Right of Boom too. Um, and, um, I've, uh, I've been an advisor to, to Cork, um, which is a cyber warranty, um, company that's a startup in the channel.

And, um, it's interesting that the, the needs, uh, that I've been helping fill at Cork and what we do at Write a Boom with the structured content journey all rely on taking these complex threat landscape threat environment reports and distilling them down into something that is a little more accessible and makes a little bit more sense for people to, to kind of plot a course through.

Um, and one of those things was, uh, that came across my desk was the Seesaw RVA report, which I've never seen before. And I was like, and I, you know, kind of, I, I do what I always do, I download it, I load it up, and I take a quick spin through it and I'm like, yo, this actually looks pretty decent. I'm, I kind of wanna kind wanna dig into this.

And then, you know, the, the ensuing weeks poor Andrew gets 5,000 text messages from me, you know, with quotes from the thing and, oh, you know what this means for Ms blah blah. And he's like, you know, what's time to get you back on the cyber call? And I'm like, all I'll do it. So here, we're Glad you're back. Yeah, it's great to have you, Ryan. Alright, Gary. Well, I thought, you know, setting the landscape and the stage here would be really good for, for you to do.

Um, this is a really interesting report. I'll put the URL for everybody momentarily. It is. And it's like, you know what, these last two weeks fit together really well. Yeah, yeah. Fair. Very fair. Um, so Gary, why don't you take it on away there and, uh, dig on in if you would with us. Well, one thing I liked about this report, Ryan, was, uh, even someone with my level of a DD could read it. Were you looking at the infographic, Gary?

No, I felt like it was well done because it was well organized and made sense, and then they went through just every, like logically took you through, uh, you know, the entire kind of vector there. So, um, I know you spent a lot of time, you know, uh, looking at this Mm-Hmm. And we'll get into some of the detail, but, um, when they talk about, um, risk and vulnerability assessments, talk about what, like get us on the fairway, what we're talking about here. Yeah, it sounds really boring, right?

Um, but it, it's actually kind of cool. It's, it's like a, you should think of it like a hybrid red team exercise, um, where they're looking for vulnerabilities, weaknesses in your, in your security program that could lead to intrusion. And they're using, uh, you know, the, the information they see from the broader threat landscape to emulate these behaviors against, um, the, the entities that are in scope for these RVAs.

So it's actually kind of a really neat, um, way to go about doing something like this. It's not sitting there asking questions and then getting answers and then putting together some sort of, you know, um, you know, boring survey of what people think. It's, they actually did some, some real assessments and put together some, some real data, which is why, you know, for me, this is on par and level of interest with the Verizon data breach, uh, investigations report. It's really cool data in here.

Um, and, uh, and yeah, th those assessments are I, I think, more robust than what you might assume just from the name. So really, really, really interesting service. They provide, unfortunately, um, a lot of demand for that service. And there's criteria around who can qualify for those that that service. Um, so they can't do a lot of them, but the data they gleaned from them was, was very insightful. So 121 organizations, mainly critical infrastructure, state and local governments.

Um, can you walk through the methodology a bit in terms of the use of, like, what you started saying, like a little bit more detail, MITRE attack red team, and then, um, how they chose an an adversary? Yeah. So the, they basically, what they say they did is they collect data through remote and onsite actions. Um, so they're doing a remote pen test, they're going on site and they're doing an assessment.

Um, and then they combine information like threat intelligence from national threat and vulnerability sources. One, you know, some of which is their own, right? They have their own known exploitable list, and they're using those techniques, um, to, to do these things. And ultimately they, they don't pick a specific threat actor when they're, they're, they're doing these exercises, is my understanding.

They're more just approaching it from can I, are they able to emulate the, the, the behaviors that the trade craft, the TTPs that threat actors, uh, in, in mass are using regardless of whether they're ransomware or data breach oriented or intellectual property theft oriented, or BEC, they're, they're looking at it from a more macro sense, which, which I actually like, right? Because, you know, we did the black hat brief, um, you know, focusing in really quite heavily on ransomware.

Um, but when you take that approach where you're myopic on a single threat actor, um, you lose, you lose some of the holistic nature of the program build out. So, you know, you lose things on like being business email compromise, which has an entirely different set of TTPs and trade craft. So, um, I I I hit Like 11 outta 14 tactics, right? Yeah. Which is not surprising.

So for those of you that aren't familiar with Mitre, MITRE attack has 14 tactic areas, and with the, within each tactic, there are techniques and sub techniques and TTPs are tactics, techniques, and procedures. The 11 of 14 isn't surprising because CISA can't emulate reconnaissance and resource development because that's pre attack, right? And they're not gonna do the last thing, which is encrypt you. So, you know, those three things give you your net 11.

So they really have emulated the most important portions of the whole attack lifecycle for a broad set of threat actors in this report, which is another reason, you know, uh, I like it. Um, so yeah, hopefully that answers the question. Yeah, it does. Why is it important specifically for MSPs right, to, to number one, to understand these type of exercises, and then what should be maybe some of the action items that they would learn right? As an MSP or in relation to their software vendors?

Yeah, I mean, this is, to me, this RVA Good question. It's, it's, it's a, it's a great question. I think this r these RVAs, if you, if you look into what they are a little bit more, they really are the types of assessments that you really would want your vendors to be doing.

You want your vendors not just to be doing, you know, o os top 10, uh, as SVS level one pen test, but you want the, your vendors to be emulating real attacker tradecraft for a broad set of threat actors against their, uh, their solutions in order to be able to provide you some reasonable assurance. And that's really what the CIS A RVA is. So many MSPs are not gonna qualify for an RVA.

But I think the methodology is interesting both in one, you advocating for it with your third parties, and two for those of you that are providing services, um, maybe you provide pen tests or you provide risk assessments. It's an interesting way to think about how you can level up and differentiate that service by combining those two things together. Um, you know, in the, the security programs I've run in the past, I always call these objective based pen tests.

We're gonna emulate some specific behaviors, and we're gonna try and achieve an objective. I don't necessarily care how we do it, so it's not prescriptive. We don't have to hack web applications if that helps us. Cool. But we can also do social engineering. We can also do use malware. We can also use, you know, whatever we need in order to, uh, to achieve that objective.

And I think that approach, especially when you're, you know, going back channeling my inner Brian Blakely, if you know how your customer makes money and you can tie that objective to the thing that makes them money, it, that really is a differentiated service from what I would say 99% of other people are providing out there. This was a really cool approach to to, to assessing these, uh, these entities. Yeah.

So you think about it, everything you've said, and then I kind of relate it to Wes, what you have said many times, which in order to know what to do or change with customers, it starts with, uh, A BIA, right? We have to understand their business so that we can, you know, really focus on, um, the areas which we can do certain things to lower their risk dramatically with the least amount of work and effort. 'cause we can't eliminate their risk everywhere, right? Yeah. Yeah. That's good.

Yeah, Sure. So, Weston Phillips are gonna get into some details about tactics and mitigation steps, but, um, can you just tell us, like, give us the executive summary of the findings and anything that might have surprised you in the results? Um, I won't say if you read the report as is, I didn't find anything especially surprising in the report, mostly because I do a lot of analysis of reports like this, and I think a lot of themes are consistent.

Where the aha moment for me was, is when I did my second level analysis where I pull all the data out and then I kind of flip it and spin it and look at it different ways. And I think, we'll, we'll get into that. But the, the main findings of the report, which won't surprise anybody, is that most successful attacks happen through common methods. Uh, phishing and default credentials are, uh, unfortunately the, the, the most, the most common. Um, they did say On the phishing, I was surprised.

Yeah. I mean, uh, if you think about it, especially when you're looking at initial access, if you can't get in using a vulnerability, uh, and you can't get in using a credential that you, you've stolen, the next most likely thing you're gonna do is send a phishing email. Um, and I think that that's also true when you include the broader landscape of BEC attacks, which is kinda still in the top three most revenue generating cyber crime.

Uh, you know, um, uh, attack types, phishing being in the most common is not surprising to me from that perspective.

I think when you, again, when you focus a lot on ransomware, you don't necessarily see phishing as much because what's happening is the phishing is happening as part of the, um, credential acquisition as a service model where some initial access brokers going, doing the phishing, stealing the creds, selling them to the ransomware operator, and then the ransomware operator says, you know, their threat profile is they're using ballot accounts.

So it's, it's interesting in that like the ransomware ecosystem has, has compartmentalized so much that you don't necessarily see that tactic or technique talked about when we talk about ransomware, even though it's still a very integral part of the success of that ecosystem. So I actually think this being phishing, being in the top findings here, again, is a more holistic look at the, the, the TTPs that are effective across the board Board. Yeah, that makes sense. Awesome.

Gary, I, the reason I I left Phyllis and Wes to get more of the technical stuff is I figured, you know, you, you've spent so much time on that already doing red teaming this week, so Yes, Exactly. I'm exhausted. Really Good. Yeah. Uh, Wes, I'm gonna hand it over to you Right on Just two more things on the exact summary that I wanna hit real quick. Oh, go ahead.

One, were that most of the organizations that were assessed exhibited the same vulnerabilities, uh, which is, you would expect some variability, but like by and large, the, the same types of vulnerabilities are, are, are able to be exploited. And then third, like the, just through this whole report, if you're paying attention, like you, I swear, like 90% of the pages have the words valid accounts written on them. Um, and that, that really kind of speaks to how important that is.

And, and that's something I wanna get into, um, as, as we talk about the analysis. So yeah, that's your executive summary, not so executive, but Ryan, uh, yeah, Wes, I ask a quick question, Ryan, please. Yeah.

So Ryan, the vulnerabilities that showed up across these, you know, 121 different, uh, organizations, was it the fact that, like, as an example, uh, VPNs or, um, you know, like what, what did you see in common across them that, you know, 'cause you wouldn't think vulnerability, common vulnerabilities other than maybe a human vulnerability of phishing would be one that you see Over?

Yeah, this is an area where they didn't go into a lot of detail, and I wish they would've okay, but the, the kind of only qualification they gave was that it was, um, publicly known vulnerabilities, which should read to you. There's absolutely no reason that these vulnerabilities should have been able to be exploited because they were public. And when things are public, there tends to be known mitigations or workarounds, um, to, to reduce the risk of those things.

So it's basically a call out from them saying, like, you, you guys, these SLTs that were assessed still kind of suck at patching their stuff. Um, which it doesn't surprise anyone here, right? I was gonna say, Philip, what are your, like, you, you know, give us your, your thoughts on that as you, you know, you're the right and your back door there. So, I mean, I think this is, uh, the more things change, the more things stay the same.

I've done blue teams, I've done red teams, I've, I've seen results of everything. What's the number one finding? I mean, keep your, keep your software up to date and patch. Are you patched and are you up to date? These are over and over again, the most common findings you'll see out of any red team, right? Mm-Hmm. And they'll be the highest finding on a blue team. It's always, you know, red teams don't have to do anything fancy schmancy.

It's, Yeah, I gotta say, my guess is that a lot of it, this is just a guess, the report doesn't say this. My guess is that it continues to be a lot of one internet exposed applications, which has its own TTP no matter attack framework.

And that the, the, the, the, I would venture guess that the, the most common ones are web applications with, um, known, uh, CDs, CVSs, uh, uh, scores assigned to them that are probably in the high to critical range, your internet exposed, uh, network appliances like firewalls. There's just another one that came out last week on June os, just Juniper's operating system.

It's another web admin interface for the firewall exposed to the internet problem, which still makes me wanna bash my head into the wall while people are still exposing their admin interfaces to the internet. Just absolutely bonkers because it's like the number one way that these devices are getting popped. You see it all the time with the Fortinet, um, yeah. You know, stuff. So I think those tend to be big. And then, you know, they reference your, your big ones too.

There's a reference here, there to proxy shell and proxy No shell, and there's a reference to log for J in there. And so a lot of these big named ones that, that frankly should be mitigated at this point but aren't. So, you know, it's, it's, it's just a reminder that like you need to do continuous diligence in your environment to make sure that after you've gone through and done your initial mitigation, that these things don't recur in an environment and expose you to risk.

Because it is possible, it can happen. So is inventory passe now, Ryan? No. Inventory is still the number one most important thing you should, you should do, in my opinion, because you can't do anything else well without it. All right, Wes. So yeah, some things don't change, right? That's, uh, and, and you know what you said too, Phyllis, um, you know, just around, like, it's not really, we're not forcing red teams to have to do anything, all that amazing.

It's just what Phil Lwa said from the Verizon DBR when you come on, is like, we haven't, the big outcome to me is that we haven't forced bad guys to innovate by and large, you know, and that's, that's one of the big findings. I, you know, um, it's, well, well said. Um, so let's talk about this, Ryan. Um, one of the things that, uh, I don't think a lot of MSPs know about is the CISA cyber security performance goals or the CPGs. So we can say it easier.

Um, Phyllis and I were riffing in chat just a minute ago about, it's a little, I mean, I get why they did it, right? Because you have, you know, this overarching security framework, but people that are still wanting to follow, you know, csun, federal government guidance are like, well, what matters out of it the most? And CPGs are an easy, measurable, impact driven way for them to do that. I'm a fan of that, right? Mm-Hmm.

I even did a workshop on it just a few, few months ago, um, with my folks over at impasse. So I, I'm, I'm a fan of what they're doing. I wonder too, a little, is there some reinventing the wheel? Um, but, but I guess I'm curious your thoughts. This is the first time I've seen anything directly out of CISA that actually ref references the CPGs as mitigation. So can you kind of walk us through just your high level thoughts around all of that?

Yeah, you would think as a framework nerd, that I would've like really known about this and had it fully internalized. But I also was not familiar with the CPGs until I read this report. Um, and then I spent way more time than I should have looking into them and, and analyzing them. And, um, I think it's, it, I was, I was coming to commenting to Andrew on this as we were reviewing the data.

It's, it's a little surprising to me that you have CISA focusing on, you know, governmental critical infrastructure, SLTT that prescribes a framework for doing cybersecurity things against the NIST framework. But you have CIS that focuses on SLTs and arguably has a, a more, um, prescriptive approach. Uh, you would think that those two things would be leaked, but instead we have a world where CISA maps to NIST and Verizon data breach investigations report maps to CIS.

It's a little backwards, right? Right. Um, and then I went through this exercise trying to figure out, well, how do I map CIS and NIST and, um, MITRE attack mitigations to try and get, like, you know, what's the consensus set of things that need to be done?

Um, and one of the things I realized is that we're, in my opinion, I think these reports, with the exception of Verizon data breach incident investigation support this year, because they actually embedded the CIS things you need to do to subvert those attack patterns directly in the report this year. So you don't need to go off to the CIS community defense model for that. This is the only exception.

A lot of these reports are not really doing a good job of saying, you need to do these three things. I mean, yeah, they link you off to the cpg part of the problem with the CPGs is they're, they're, they're very blurry in their recommendation and looks like a single sentence. This seems super easy, but when you break it down, there may be four or five components in that sentence that could take six to 18 months of work, of work individually. And so, yeah, I think I, I, I like the CPGs.

I'm gonna continue to look at them and see how they fit within the broader framework. And, you know, I like their wording a little bit more than some of the, some of the NIST areas. Um, and I'll say, you know, they initially started off, I think in 2022 with the CPGs, um, and then in 2023 they kinda remapped them. So they have five CPG areas, uh, each CPG area. So one corresponds to identifying this two corresponds to protect, et cetera, et cetera. I really like how they did that.

I think, you know, where, where it's lacking for me is it still doesn't have the specificity, which, especially in our community, and I would argue for s ltts as well, makes it a little bit inaccessible. Like, just tell me what I need to do. And so, yeah, I don't, I don't, I don't know how helpful it is, but I think what I see from CISA is the willingness to adapt those CPGs on a year over year basis.

And, um, you know, I love that Phyllis, LinkedIn, the mapping to CPGs and cis, because I think that really gets you a sense of, you know, if I'm already down a path of CIS, how closely am I, uh, mapped to attaining the cpg? So, you know, I would argue, I don't think we really needed another framework, but I think maybe over time this will be become, um, a little bit more useful.

So it's definitely gonna be something I'm gonna keep an eye on, but potentially redundant to CSF and CIS at this point. We, Wes, can you and Ryan riff just a touch? 'cause there was chat in, in, in chat about MFA, right? And of course, you know, people are, you know, hey, we don't even do business with a company that isn't gonna do MA, but we've, Ryan and Wes, they, they talk now. 'cause MSPs have so many prospects that they can just turn 'em away, The ones that are in true methods.

That's true, Gary. Um, but, but talk about, if you could just riff for a minute on phishing resistant MFA, I mean, and, and what I put context on it, I mean, are we wasting our time if we're gonna try to get somebody on MFA and we haven't yet? Should we just go right to phishing resistant because of the, how ubiquitous credential theft is at this point? Yeah. So I'll provide a little bit more context. Dangerous question, please.

I said ballot, ballot accounts was peppered all throughout this thing. And, uh, the CISA CPGs has an entire basically major section of protect, um, which is, uh, CPG two. A lot of it just goes into like account security stuff. And one of the things recommendation, because again, their report was showing how easy phishing was against some of these SLTs, and their recommendation wasn't due MFA, it was due phishing resistant MFA, which if you recall, is what we were doing a DA two years ago.

We were emulating that attacker, and that's why we went down the route of phishing resistant MFA. And I was on my soapbox on cyber calls all the time talking about this. Um, so I, I think it's really important that they structured that recommendation that way because it, it, they really are showing through the RBA that having SMS based or app-based or push-based, um, MFA still, while it does prevent some sub techniques under ballot accounts, it does not protect against phishing.

And phishing is still one of the major ways that credentials are harvested. So yeah, fishing resistant MFA is absolutely critical. I probably stole all of Wes' Thunder, but I'm sure he'll have something that No, no. You know, to add to that, The whole firestorm in, in, in the chat, the, the thunder is, is all yours, Ryan, it's awesome. Um, I, I don't have anything more to add on that, but I do think that is important to understand.

You know, I think we've always, you know, the, the, the, the folks, okay, let me say it this way. There's a lot of MSPs that are listening today that are like, I don't have the time to do all of this. I don't, I don't like what I, I'm, I'm managing 60 clients. Just tell me what I need to do, right?

So if you tell me I need to think about rethinking MFA and you're telling me that like just buying an MFA like duo off the shelf and pushing off is not good enough, then tell me that and tell me what I should do about it. Tell me how these bad guys are leveraging this and help me understand where the threat is, and then I can do something about that, right? And so I think that's why this conversation is really healthy, because I think it, it gets some practicality.

And maybe, Ryan, I'll just have you lean in just a bit more. If I am one of those MSPs today, and I hear you talking about phishing resistant MFA, what does that practically look like for me as a small mid-size MSP? What should I be doing that I'm not doing? Um, maybe re-ask the question in a, in a, in a different way for me. Yeah. So, so if I'm hearing, if I'm hearing this conversation and I've been doing MFA, I'm pushing duo out to everybody, and that's like what I do to check a box for MFA.

Yeah. Yeah. But now I'm hearing you and Andrew talk a little bit more about phishing resistant MFA and like I'm thinking, am I not doing something right? Should I be doing more than than I'm doing? Yeah. Are there adv adverse areas that are that's kinda what I'm asking. Yeah. So, I mean, duos is interesting. It's, And I'm not picking duo of course, I'm just throwing that out there. Yeah.

But let's say you're using Duo more like an IDP, like an SSO platform or like a single place to manage your identities. Think of it like an Okta or a Azure ad or, you know, whatever your uh, I-D-P-S-S-O choice is, you can still totally botch the configuration of that thing and leave yourself no more secure than you were with bifurcated and decentralized account security. So the configuration of that IDP really matters.

And one of the things that matters is the MFA requirement that you push onto the user just saying users are required. MFA is a step in the right direction, but not all MFAs are phishing resistant. And so you can use a duo, but yeah, if you're not requiring, uh, you know, basically hardware based, um, security keys, um, uh, then you're not phishing resistant.

You are, you are more well protected and you've increased the bar for many of the sub techniques for valid accounts under the Mitre attack framework. But you have not made your organization phishing resistant. And I, and I argue, given the prevalence and the, just the, the momentum that exists in the initial access market, um, you know, initial access is a service and BEC, uh, emails.

And what we're seeing there, um, you know, the Verizon data breach report noted that for the first year, uh, pretexting attacks are, um, uh, you know, eclipsing or on par with phishing, this is only getting worse. Um, and so, yeah, I think if you're not already trying to move your users down this path, you're gonna wanna do it. 'cause I think it's coming. And, you know, you know, government was pushing for zero trust since 2021. We're really starting to see that become more commercially viable.

A lot of new products coming out in the space are seeing that embedded. Um, anytime you're, you see something like this coming from an organization like cisa, you should expect that within 18 to 24 months, it's probably gonna become table stakes, you know, more so from just a, a broad adoption and like consensus. But my argument is like, we've known this for years. Why do we need to wait for everyone else to do the thing that we know is right? Yeah. Can you answer that question? Why?

Listen, like, I, I would say, is this more, again, it's obviously I'm extremely technical, so maybe for some less technical. No, seriously, can you explain, do you think the, the adoption is based on more the overhead on the MS from the MSP side of understanding it, setting it up management? Or is it resistance on the user side? On the customer side? I think there's some resistance on the customer side.

Um, you know, it's kind of like going back to the RSA key FB days, but people don't understand that it's actually become a lot more user friendly. Um, and, um, so I, I think there's an education problem in the market. You need to literally show your users how easy it can be. And it is a bit of a handholding exercise to do the conversion. Um, but you can do it successfully and you can do it successfully in under six months for an organization that's 5,000 people. I know I did it.

So you just, you have to, you, you have to set yourself up for success there. But you know, this is an opportunity to use your qbr. Hey, we're tracking some threat intel from the Verizon data breach investigation support and the CISA RBA for FY 22. There's starting to be a major push in the ecosystem for phishing resistant MFA. Let me tell you why that's important.

Let me show you what that looks like and let's start having a conversation about how we might implement that inside of your business. Um, Mr. Uh, you know, SMB customer or SLTT customer, you gotta start having the conversation. Um, because if anything, what both of those reports show is without it, you still have anywhere from a 20 to 40% attack surface unmitigated. Yeah.

And that's, that's outside of anybody's reasonable risk tolerance, especially if you communicate it to them in terms of their business. Solid. Um, I wanna come back. We, we were just to the CPGs for a minute 'cause we have the director of the CIS controls on. So Phyllis, can I just ask you as well kind of what your thoughts are, um, on the CPGs and, you know, where CIS is at with it and, and just like what that relationship looks like, what it should look like.

Help us navigate those waters from CI s's perspective. Can, can you first call her VP though? Us? Yeah. Doctor and VP Doctor. Um, so yeah, so, you know, we try to work with government a lot. Um, you know, we get a lot of feedback. Hey, we don't need one more framework. It causes confusion in the community, et cetera, et cetera. Not just from SLTs, but from, you know, so many other different organizations.

So Kurt, so Kurt Dukes, who has been on this call, um, he participated with cis a on, you know, the CPGs and you know, he went there and he did his pitch that we always say, you know, let's, we, uh, Tony Seger, um, coined it the fog of more, right? Everyone's buckling under the pressure of, you know, dozens and dozens of, um, regulatory frameworks they have to comply with.

And throwing one more in the mix that doesn't really offer, I will say not much, not anything really unique, um, and is supposed to be common across all sectors, which is great. Um, uh, but like again, then people have to make yet another choice. What should I do? CIS authority is critical infrastructure. You know, you talk about NCSF, we get that question all the time. Why do I, why do I have to do CSF or this, that and the other?

And we're we're always mentioned in legislation side by side, the CSF and, and CIS critical security control. So it does cause some confusion. Um, and we really tried and, and, and we try to work with DHS and GAO and, and all those government or agencies that set those regulations of, Hey, let's just settle on one thing. We don't care what we call it. Just one thing. Like you could call the CPGs and do a little cut and paste. We don't care.

But let's just try to do like one thing to avoid confusion, um, in the marketplace. And, and so we're where we are. Yeah. I will say, you know, CIS relative to CPG, we all know that CIS is more technical controls focused with some, some surrounding people and process stuff that does leave a little bit of a gap in the respond and recovery areas. Yes.

And so I think CISA probably was trying to act on that, but in the op, but what they missed is an opportunity for 80 to 90% of the CPGs to be an overlap with CS and just to fill out those missing areas, right. With, with something Yes. You know, equally actionable as the rest of what you see with cis. So, um, we, We were happy for them to just do a cut and paste and then do their additional kind of like governance and, and all that kind of stuff. We're like, that's fine. Like we don't this.

Yeah, I was gonna say, we know they're gonna have to redo the CPGs next year anyway when N two oh, uh, CSF two oh comes out, we, we add in the, the govern function, right? Yep. They, so yep. So this is all gonna be, you know, over the next year we're gonna see a lot of stuff change. We're gonna see ci IS remapping, you know, maybe in, in a new version. Maybe it's eight one. I don't know. You could so more there if, if, if she's allowed.

But everything is gonna see a little bit of an upheaval next year when two oh comes out and everything needs to be remapped. I think that's also an opportunity for a lot of these organizations to, to re-look at how their frameworks are going against the, the, the most core framework and, and adding in some more detail. So again, I think it's one to keep your eye on, but if you're already all in on this or you're already all in on CIS just keep doing what you're doing.

Um, you know, and it might be worth perusing them on the website. Maybe you like how they've worded something. Maybe you wanna steal that and in inject it into a policy somewhere. Because to me, the CPGs really read more like policy requirements and policy statements than a, Hey actually go implement and do this thing. Right? Like you shall do log collection using, uh, cyber threat intelligence and system and audit events. Uh, okay, cool. That's a policy statement doing that.

How do I actually do that really hard? Right? And that's, that's the problem, right? It causes that confusion because people are concerned, I'm going to get assessed against this. It's, it's, it's funny you say they read like policy statements. 'cause I was just gonna say that it almost looks like derivatives that we build KPIs off of, right? Yes. Some kind of measurability tangent. Yes.

You know, and so, yeah, and I love that you said that, that it feels good on the front end and then you start digging in, you're like, huh, this is actually a lot more difficult than, Yeah, I was like stupid excited when I first dug in and I was reading the headlines of these things and then I got into the meat of it.

And the one thing I like that they do, and again, might be a reason for you just to peruse them for 15 or 20 minutes, is if you download the CPG worksheet, you have to do the worksheet. You can't use the web version. They actually add in columns for, um, cost impact and complexity. And cost is a weird metric. It's like $1 sign or $3 signs.

I have no idea what that maps do in terms of actual investment, but what it does is it gives you a quick gut check to say, oh, you know, well maybe if I do something that's, uh, you know, medium impact, medium complexity and low cost, that could be something that's easy to do, doesn't materially change my p and l, uh, and could help reduce a lot of risks.

So I did like that facet of it, because there's not really a good corollary of that in the other frameworks, but it's, again, it's still a little subjective or, or not well defined enough for me.

So, um, but you know, the good news is, is because you, you know, because they've mapped to NIST and they actually give you the, um, the, the subcategory identifiers for the nist uh, uh, um, items, you can easily use CIS workbench, uh, mappings to actually get your way as Phyllis, you know, linked, uh, an article actually that you can do this, you can actually very easily move your way between, uh, assisted CPG and see all the corresponding this CSF requirements and CIS requirements.

So like, you can do that work if you wanted to. I did it, but, uh, you know, take it from me. It wasn't a super valuable exercise. I didn't learn anything. I felt like I was just creating a, you know, a, you know, creating the Rosetta stone of how to map this, this new framework. And it, there wasn't any material value add there for me. So, Okay. Sorry, This has been, this has been a great rabbit trail.

I'm glad we chased this even though I went from, man, I got a lot of time to like, we're out. I gotta get over to Phyllis. Um, but yeah, I think that was well worth it. So maybe I'll just one last question for you, Ryan, and, and answer this kind of however you want to go. And then I'll flip over to, to Phyllis, right? Is, um, I wanna, I, one thing I that stood out to me in the report was, um, the execution phase that they have that's in there Mm-Hmm. Can you kind of walk us through that?

Walk us through mitigation steps, log collection, touch on that, you know, and can MSPs realistically do these things that are in here? Is that, is that even feasible and achievable? That is a question I asked myself the whole time I was reading this report. Um, uh, and I'll get into that, but for execution, what the report found is that PowerShell was, u was able to be successfully used in 14% of, um, the instances that they assessed and command line interfaces were used in 13.

So right there gives you a quarter of their success is based off of PowerShell and CLI. Okay. So then how do you defend against that? Um, well, their recommendation for the mitigations are zero trust, which is still like a mythical unicorn, you know, thing that's out there.

And a lot of people are still trying to figure out how to implement or talk about application control, which is more accessible these days using both built-in operating system capabilities and third party software applications. So I think that one's worth looking at, um, especially when it comes to PowerShell, like really wrapping your arms around PowerShell in your environment is an important thing to do.

And then, you know, their, their log monitoring objective, they say collect and store access and security focused logs for detection and incident response activities. So this is more like a log collection, um, which is literally what they, it's CPG two T log collection, um, uh, and it basically says store and access security focused logs. Well, what are the security focused logs for PowerShell, not in CPG, right? So like, what am I supposed to actually be logging?

What am I supposed to actually be detecting on and setting up incident response activities for? I think it's, I think what it does is it gives you the question and then you have to go figure out the answer, right? And I think that's where the next level down of like CS being like, here's the answer, is like, really nice, right? Um, so, um, you know, that's, that's kind of what they say. I think this is hard for an MSP to do independently.

And I think the more MSPs get into this, the more they're looking at like, this is why there's a value add in having some sort of partnership with some sort of MDR SIM or SOC as a service company that, um, you know, really how an MSP should use this support is just like say, Hey, I wanna talk with your, your guy that does detection engineering, and I wanna walk through this report and I wanna have him explain to me how they, you have detection set up for CLI tactics and PowerShell tactics and user execution tactics and, you know, um, all those sorts of things.

Like that's really where the value of this would come in, is in kinda quizzing your, your, your, your service providers on the breadth and depth of their, uh, their, their capabilities. 'cause often that's where you're getting this service from. So don't just read this report and assume, oh, my XY, Z vendor has got me covered here, actually go, go have a conversation with them, uh, and, and, and try and figure out where they have gaps. Um, a conversation's a good place to start. Solid, solid.

Love it. Uh, Phyllis, Yeah, thanks. No, I I, I really like that, um, question as well just because, um, it's often glib when we in the security community always say, turn on your audit logs. Like, what, what does that mean? Because then that's the next step. Not only turn them on and then you also have to like actually somehow comb through them to actually get some intel outta them. So that was a great response.

Um, so, you know, we talked already that 11, um, MITRE attack tactics, um, were um, mapped and you kind of went over why, you know, 11 out of the 15 or however many. Um, but was there anything that stood out to you or that seemed, um, you know, something we should pay more attention to as MSPs, especially those servicing s ltts? Yeah, I think this is where I'll get into the second level analysis.

So what I did is I, I went through, I actually had to do some normalization because some of the cisa CPG recommendations were written in the 2022 format, and some were written in 2023. So I went through and I normalized all that and I threw in a spreadsheet, and then I started playing around with pivot tables, which is what I always do to try and look for where there's interesting stuff. And what, what actually came out of this was, um, you are looking at it from a tactics perspective.

I was actually a little surprised by this, um, relative to the vz DBR. There's 33 total Mitre TTPs that they listed. 29 of them are distinct, which means, uh, I think six because math, um, are actually related to some sort of overlap. And it turns out there's only overlap two valid accounts and process injection. And that is really where the interesting thing came into me. And that's where I got down the rabbit hole of like, I don't think the guidance around valid account mitigation.

You know, they say do CPGs, you know, two A through two H, which, you know, as I was reading them, I was like, man, this basically reads just like, uh, controls four and five, like just totally ignore this and just go do controls four and five. Um, and it's interesting.

So that to me was kind of like the, what's the biggest takeaway is like if you really have a mitigation for valid accounts, because valid accounts shows up in four tactic areas and in each of those four accounts for more than half of the success.

So if you think about that, this is even before like lateral movement and discovery has happened, if you really have your valid account game on, you dramatically slow the ability of that attacker to move through your environment, which also increases your chances of detecting them, right? Especially when they're, you know, banning and all sorts of other good stuff like that.

Like the more, the more time it takes them to move through the environment or the more they have to move to another exotic tactic that maybe some other control in your environment is better equipped to detect the better success you have.

So I think for me that the, the TLDR of all of this is go look at the Mitre attack valid accounts, uh, sub, you know, uh, technique and sub techniques and really refocus in on looking at how effective are the controls I've implemented in controls four and five for CIS. 'cause that seems to be the way that, that they're really having a lot of success and frankly, that that mimics what we saw in the BZ DBIR. So credential security is crucial.

The other thing I'll say is, you know, the other thing that came up is having some repetition is process injection. Process injection showed up in two TTPs, which is basically they hijack a process to steal its, uh, privileges in order to be able to bypass things or do other things on the system that they wouldn't be able to do with the, the privileges that their process has or, you know, whatever they've hijacked.

And it got me thinking, you know, if you look at kind and I mapped out the mitigations that CIS would have for this, and CIS basically has deploy heads or deploy hips in addition to some other stuff like secure configuration, which is important and you should do, but it got me thinking about the over-reliance on ed. And if, if you really look at process injection, the control that most MSPs and SMBs have is gonna be their EDR.

The problem is, is in the impaired defenses or defense evasion tactic and the impaired defenses technique, they're bypassing your EDR. And so if you don't have those surrounding compensating layers of control around process injection, and you have all your, your eggs in your EDR basket, you're asking for it because, um, you know, there's, there's literally a book that was written on EDR version and it's coming out, I have it on pre-order.

Um, it's, it is a very common activity, um, that, that, you know, uh, that, that you will see in your environment. And so sometimes you have to ask yourself, you know, especially in your BIA, if your EDR is a really critical process or tool, you have to ask yourself, how am I equipped in to, to handle things in the face of a failure of that, of that process or that control?

And, um, you know, it kind of really got far away from process injection as I went down this pathway, but it really got me thinking about really gut checking, how reliant are you on the operation of your EDR? What are you gonna do when it gets evaded? And I think that's a good takeaway for MSPs two from all of this. Andrew, you're on mute. Uh, you're still on mute. How's that? There You go. There we go. Yeah. Better? Yep, we hear you Now you're on mute or can I not hear you?

Yeah, we can hear you. Yeah, we got you. Good. Yeah, we hear you. All right. I think I got it now, Phyllis. Yeah, can you hear me? Yeah, sorry about that. Um, settings. Um, Gary, quick question for you.

So when you go back and hear about, you know, 74% for Verizon, DB IRS credentials, 54% of you know, these, um, attacks being successful with, you know, you know, cred, valid credentials, should MSPs be changing how they're approaching, whether it be initial sales, qbr, you know, what they're doing, you know, in terms of what's most important in that account.

And you know, again, as you always say, it's on us, right, in terms of making sure those right controls and processors are in place and they're paying for it. But, um, I, I just love your thoughts. You're on mute. Oh yeah, I had my, my my cough button.

Um, you always hear me say, you know, when I hear a client or a prospect refuses MFA, like I as an I take responsibility for that if I'm an if as the m as the MSP, because if they understood the risk the way that we understand them, they would be pushing back a lot less on that and they would have a plan and they would be working with us.

And, but this whole thing is, look, if I zoom out from everything we've learned in on since I've been on this call, we have a challenge that it departments don't have. There are challenges. They have to have the knowledge and know what to do just like we do. They gotta give budget, that's what they have to do. You know, we have to develop these roles in process to lay across 50 or 60 or 70 accounts. We have to be able to show the value and change the price. I was on with an MSP this week.

You just closed the deal, over a hundred seats at $300 a seat. And I said, well, how are a lot of people telling me you can't do that? He's like, I don't know how you can't not do it. He said, I just sat down, we were $10,000 more a month than their other alternative. And that's the reason why they bought from us. I showed them our roles, our process, our tools, and I asked them, do you want that? Because if not, here's what $10,000 less looks like for me or anyone else. This is not about me.

This is what it looks like. And once you get there and you have that conviction and, and you take the responsibility, it's our responsibility to have our customers understand their risks. And when they tell us they won't do something that's dramatically increasing their risk, we've gotta stop blaming them, Andrew. And if you can't convince everybody, you better start having a sales and marketing engine because your biggest source of how MSPs get built is referrals. You just lost half of it.

Now what do you do? Does that make sense? Yeah. Well, yeah. Lemme let Phyllis continue. I'm curious when you said you lost half of it, but if we have time at the end, Well, I mean we're three have three minutes left. So I wanna give Ryan, um, any kind of closing thoughts that you have for the group, um, you know, as a result of, you know, reading this report. Yeah.

So the other second level analysis I did was to pull out all of the CPGs from each of the areas of the report and then again, throw them into a pivot table. And what I found was just five of the CPGs account for over half of all of the recommendations in the report. So your TLDR, if you wanna try and figure out the CISA CPGs and, and what to do with them is CPG three A, which is detecting relevant threats and TTPs, that's the only detect, uh, CPG that has repetition by the way.

And it has, I think it's repeated 10 times in the report two T, which is log collection, um, two C, which is use unique credentials, which is like a, you know, blink should had a V eight moment. Um, and then CPG two E separating user and privilege accounts, a novel idea.

Um, and then CPG two H phishing resistant MFA, so literally of the, you can summarize this entire report, don't overly on your EDR really double check your protections against the use of valid accounts and go have a look at CPGs three A, two T, two C, two E, and two H. And I think Gary just told us that this is totally doable by MSPs, right? A hundred percent, hundred percent EE everyone can do this. And it's conceptually simple. It's just really, really hard, fellas. It's really, really hard.

And you have to have a plan and you're not gonna get there if you're not there now. You won't be there in a quarter. So choose wisely your priorities every quarter. Yeah. Gary, when you hear this, oh, go ahead Phyllis. Sorry. No, I was gonna say, I really like, you know, when you say you really have to have that plan in place, um, because I mean, it is, it's all that planning and trying to figure out how, like you said, do that BIA and every Yeah.

What it also highlights, and Ryan, you and I have talked a lot about this, you know, it's, it's easy to be trivial about people process technology, but the process side, the more I sit with Ryan Gary and learn about putting in controls, you can put into control, but as he said, you can have MFA deployed, but that MFA could be horribly deployed. So it, it just kind of comes back to what you always talk about.

The, the roles, the criticality of understanding what role aligns to what job, what KPIs and, and how to actually measure that all the way through the business to the revenue. Like having metrics and accountability, somebody who's responsible for each of these and having metrics over time. Because every installation of everything should be a hundred percent the day, that day. What about a day later or three months later, or six months later?

And MSPs in the past, they're too used to doing a project and walking away and going onto the next thing. That's not how this works. The project is not the magic, right? The change is not the magic. It is keeping the discipline and having accountability and metrics to know that as you're going and closing more doors, that the doors five doors behind aren't reopened again, and you have no way of ever knowing. Right. Right. Ryan, thanks so much for coming on. We hope to have you back again soon.

Um, it would be awesome to have you back. I know you're gonna, uh, spend some more time with the family, but, uh, you're welcome to come back and co-host whenever you'd like. Um, Phyllis, Gary West, always great. And everybody, thanks so much for, uh, joining us. As always, we look forward to seeing y'all next week. Make it a great day. See You everyone. Bye.

Related Videos