Red Teams and Real Attacks: Misalignment due to Skewed Incentives

Red teamers are defenders' allies. Their goal is to help make defenders better by exposing security weaknesses. They enable defenders to know where the holes are so defenders can reinforce their defenses. But in practice, is that goal achieved?

When incentives are misaligned with outcome metrics, the value delivery fails. In practice, it’s hard to get this tuned to an efficient model for many reasons. The delivery of security outcomes red teams are meant to help suffer as a result. When red team reports are used to align resources to gaps, misaligned incentives result in prioritizing work of lower importance. This means organizations could mitigate more risk by paying attention to other, higher priority items.

To put these ideas to the test, we decided to take an objective look at incident data from our annual threat report to see if we could find mismatches between what the red team is reporting versus what real-world attackers are targeting.

This talk goes over what the data shows. We use measured results from our hundreds of protected companies to show where attackers show up and where red teams show up. We discuss some possible reasons and propose some things to consider, both for the red team and the leadership writing the rules of engagement.

 

About the Presenter: James Shank

James Shank is the Director of Threat Operations at Expel, where he runs the threat intelligence, vulnerability intelligence, and threat hunting programs. He is deeply involved in the Internet information security community, coordinating efforts to combat online threats. His notable contributions include a pivotal role in the takedown of Emotet, a collaborative effort with international network operators and law enforcement. James also contributes to the Ransomware Threat Focus Hub and is a member of NetDiligence’s Ransomware Advisory Group. He previously served on the Institute for Security and Technology’s Ransomware Task Force (RTF), chairing the Worst Case Scenario subcommittee. He facilitates several community Trust Groups that connect information security operators to ensure the continued operation of the Internet.

Next
Next

Bootkit-in-front-of-a-bootkit