Ian Wright’s Post

View profile for Ian Wright

Founder & CEO @ Secmatics | Cybersecurity

The cybersecurity industry puts far too much focus on breach detection rather than prevention. Here we have a state-sponsored cyber group targeting military and nuclear programs, and they are exploiting a set of well known CVEs that really should have been patched a long time ago. This tactic works because a significant number of organisations (including those running our critical national infrastructure) still haven't patched these CVEs. Imagine buying the best burglar alarm money can buy and then never taking the time to close your front door. If you are putting all of your security budget into internal tools without securing your external attack surface then this is exactly what you are doing (and it will never work). NCSC article: https://lnkd.in/eE-fqiyz The joint NCSC, NSA, CISA, CNMF, DC3, NIS and NPA advisory: https://lnkd.in/eJvszdPE

To view or add a comment, sign in

Explore topics