Sun Tzu's Art of Cyberwar

An ancient Chinese military treatise from the 5th century BC, The Art of War by Sun Tzu, is considered a definitive work on military strategy and tactics. Through the ages, military leaders have been inspired by it, even to this day.

Beyond the military, its advice on how to outsmart opponents has been applied to various competitive fields from business to sports. Increasingly, as warfare moves from the battlefield to the realm of cyber-space, its principles are being seen as especially applicable to cybersecurity.

Despite being written thousands of years ago, these classic defense strategies are undoubtedly still relevant, for the modern defender of IT infrastructure. The principles of Sun Tzu are not only relevant to defense, but also for understanding the approach of attackers.

Know the Enemy and Know Yourself

One of the most often quoted Sun Tzu quotes has enduring resonance for many situations in life, including cyber-security. To understand how a hacker is likely to operate, we must first understand their motivations and what they are trying to achieve. When we know what assets they are likely to target, we can better focus on effectively protecting them.

To be properly prepared for cyber-incidents, we must also have a clear understanding of our own business and infrastructure, where is our data held? What software are we running? Is everything patched and maintained? What’s more, is the proper training in place for staff? Attackers will always ‘strike at what is weak,’ and employees are often the weakest link in the security chain.

All Warfare is Based on Deception

Many of the methods used by attackers are based on deception, whether that’s phishing, spear phishing, whaling or social engineering. Often used to trick unsuspecting employees into engaging with malicious attachments or links, phishing attacks are becoming increasingly sophisticated, with hackers now tricking employees by posing as more senior members of staff and even CEOs, requesting funds to be transferred.

Recent ISACA research has found that 1 in 5 UK office workers have fallen prey to phishing scams, while over half said their employer has not provided any cyber-security awareness training. Employee training and awareness is key to limiting the risk of deception by malicious attackers, and as the above example demonstrates, this training needs to be rolled out to the most senior staff, too.

Attack him where he is Unprepared… 

Appear where you are Unexpected

While employees can be a weak link in the chain, they are not the only route inside an organisation. It’s important to remember that attackers will also have been trained to know their enemy and, in preparation for an attack, will have done their homework on all possible routes and weaknesses. Organisations should therefore consider all avenues of access and what vulnerabilities they might have.

Fortunately, with exercises such as penetration testing, organisations are now able to assess their own security before a hacker does. Through this exercise, organizations can not only scan their systems for vulnerabilities, they can also test employee knowledge and awareness by simulating a real-world attack scenario.

Just as Water retains no Constant Shape…  

In Warfare there are no Constant Conditions

Attackers are agile, so organisations need to be as well. As organizations become wise to traditional attack methods, hackers will only develop new ones in a constant arms race for supremacy.

At the same time, businesses are continually evolving and adapting, whether that’s upgrading systems, introducing new technologies or changing business models. Businesses should be mindful that all of this change can introduce new cyber security risks, or remove old ones. One of the best ways to be prepared is to keep up to date with the latest best practice frameworks for enterprise IT, such as COBIT 5.

In the Midst of Chaos there is also Opportunity 

When it comes to cyber-security breaches, the rule is always ‘when,’ not ‘if.’ When breaches occur, organisations should focus on the lessons they can learn and improvements they can make as a result. The root cause should be identified and changes should be swiftly implemented to address this, with the lessons learned shared with all relevant staff.

Suffering a breach can provide the opportunity to reflect and revisit the strategies organisations have in place. Why not apply strategies that have been tried and tested over millennia? As Sun Tzu says, “The opportunity to secure ourselves against defeat lies in our own hands”.

Info-Security

You Might Also Read:

Russian General Brags About Cyberwar Successes:

Fighting The Invisible War In CyberSpace:

 

 

« Hackers Hit Russian Bank Customers
WannaCry Was Not A Phishing Attack »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Interpol

Interpol

Interpol is the world’s largest international police organization. It is committed to the global fight against cybercrime, as well as tackling cyber-enabled crimes.

Talend

Talend

Talend is a leader in cloud and big data integration software. Applications include Risk and Compliance management.

National Agency for the Security of Information Systems (ANSSI) - France

National Agency for the Security of Information Systems (ANSSI) - France

The role of Agence Nationale de la Sécurité des Systèmes d'Information (ANSSI) is to foster a coordinated, ambitious, pro-active response to cybersecurity issues in France.

National Centre of Incident Readiness & Strategy for Cybersecurity (NISC) - Japan

National Centre of Incident Readiness & Strategy for Cybersecurity (NISC) - Japan

NISC was established as a secretariat of the Cybersecurity Strategy Headquarters in collaboration with the public and private sectors to create a "free, fair and secure cyberspace" in Japan.

Openminded (OPMD)

Openminded (OPMD)

Openminded is a French security and network services company.

SBS CyberSecurity

SBS CyberSecurity

SBS CyberSecurity is a premier cybersecurity consulting and audit firm.

Applied Security (APSEC)

Applied Security (APSEC)

APSEC provides products and services in the areas of encryption, digital signature, authentication and data loss prevention.

TorGuard

TorGuard

TorGuard is a Virtual Private Network services provider offering secure encrypted access to the internet.

CipherTrace

CipherTrace

CipherTrace develops cryptocurrency Anti-Money Laundering, cryptocurrency forensics, and blockchain threat intelligence solutions.

Padlock

Padlock

Padlock is a trusted platform with an intimate knowledge of the cybersecurity industry that connects businesses with freelance professionals

Symantec

Symantec

Symantec delivers data-centric hybrid security for the largest, most complex organizations in the world – on devices, in private data centers, and in the cloud.

CoursesOnline

CoursesOnline

CoursesOnline.co.uk is a database listing IT security courses from providers across the UK.

Flexxon

Flexxon

Flexxon is the industry leader to develop NAND flash storage devices. Our key focus is to innovate memory devices ensuring data security and reliability.

Secjur

Secjur

Secjur is a provider of AI-based compliance tools that aim to put compliance, data protection, information security and whistleblowing on autopilot.

Ultima

Ultima

Ultima are on a mission to help businesses unlock their true potential by using the right IT to protect your company’s revenue and reputation – 24/7.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.