{"id":5226,"date":"2024-09-10T15:43:34","date_gmt":"2024-09-10T20:43:34","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-operations\/how-a-centuries-old-company-reached-security-maturity"},"modified":"2024-09-10T15:43:34","modified_gmt":"2024-09-10T20:43:34","slug":"how-a-centuries-old-company-reached-security-maturity","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/09\/10\/how-a-centuries-old-company-reached-security-maturity\/","title":{"rendered":"How a Centuries-Old Company Reached Security Maturity"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt3dd839d6c6de645a\/66db97dd51d8b21e43d32af1\/changelock-M-Production-alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-a-centuries-old-company-reached-security-maturity.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-a-centuries-old-company-reached-security-maturity.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">LV=, the leading pension, savings, insurance, and retirement company in the UK, has a long and storied history. Over the years, the 180-year-old company has expanded its portfolio to provide every type of insurance, investment, pension, and retirement offering imaginable. It has continued to push the boundaries of what&#8217;s possible, investing in new technology.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">By 2021, much of the new infrastructure and other digital modernization was complete. At the same time, company leaders suspected that its approach to security wasn&#8217;t as effective as it could be. To find out, the company hired one of the Big 4 accounting firms to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/some-65-of-organizations-now-weigh-their-cyber-maturity-\" rel=\"noopener\">assess the situation<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> by comparing it to the NIST cybersecurity framework.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">What came back was sobering.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;It became apparent how low the maturity was,&#8221; says Dan Baylis, the chief information security and data officer LV= hired to fix the situation. &#8220;That&#8217;s when they realized that they needed to invest and address the sins of the past.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Assessing the Existing Security Stack\">Assessing the Existing Security Stack<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As soon as Baylis was hired, he assessed the entire security stack, along with processes and procedures.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">He found plenty of issues. Most importantly, the infrastructure lacked modern security controls. For example, the system still had signature-based antivirus controls, and the email gateway wasn&#8217;t aware of modern threats.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Baylis also determined that there was no way to measure the effectiveness of security controls. In addition, each individual security control, such as anti-malware, wasn&#8217;t fully connected to the entire infrastructure. Instead, it could monitor only what it was directly connected to. And because there was no central view, the security team could only be reactive to things like vulnerability disclosures.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The relatively rudimentary security infrastructure also prevented company executives from making data-driven security decisions.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Being data-driven takes the emotion out of things. For example, if we&#8217;re telling someone that they don&#8217;t have the right patching levels or are missing security controls in a certain area, the data should back it up,&#8221; Baylis says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Baylis also believed that LV= needed the protection of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/distrust-and-verify-why-comprehensive-network-visibility-is-required-for-mature-zero-trust-architectures\" rel=\"noopener\">continuous security validation<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> but that it couldn&#8217;t get there with its legacy security controls.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Continuous security validation would enable us to have the evidence to underpin the investments and improvements we needed,&#8221; he says. &#8220;So I could explain, &#8216;This is how attacks happen, and this is how resilient we are to them.&#8217; So instead of asking them to trust me, I could show them.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Overhauling the Security Infrastructure\">Overhauling the Security Infrastructure<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">With his assessment complete, Baylis started rebuilding the company&#8217;s security infrastructure from the ground up.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The first order of business was implementing a breach attack and detection system (BAS) to help monitor for security blind spots and provide continuous security testing.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">More organizations than ever are using security tools that provide attack path management and security control validation like BAS, pen testing as a service (PTaaS), and continuous automated red teaming (CART). In a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/omdia.tech.informa.com\/om121453\/market-landscape-incident-simulation-amp-testing-ist\" rel=\"noopener\">recent survey<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> (subscription required), Omdia found that 71% of 400 security decision-makers consider these tools important or extremely important.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">BAS is a methodology for determining how well security tools are working so they can be optimized, explains Andrew Braunberg, principal analyst at Omdia. BAS tools do this by simulating attacks, often using established threat models such as the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-analytics\/enterprise-siem-blind-mitre-attack-coverage\" rel=\"noopener\">MITRE ATT&amp;CK framework<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. BAS tools can also typically perform automated simulations, threat model mapping, and continuous testing.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Baylis started by implementing Cymulate&#8217;s BAS solution. The most important features to him were the ability to test emergent threats, continuous security validation, and a consolidated view of the company&#8217;s security posture.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I wanted a tool that could not only help me demonstrate our risk exposure but tell the story of how resilient we are to cyber threats,&#8221; he explains.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Using the tool, Baylis says he has been able to show decision-makers active attacks and demonstrate the company&#8217;s new resiliency to them, along with the health of endpoint controls and gateways.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Next up was choosing a tool for continuous control monitoring. Baylis chose Axonius, which monitors data from different sources \u2014 like Active Directory, anti-malware controls, and patching \u2014 and provides a holistic view. With that information, the team was able to build dashboards that show the company&#8217;s security-control coverage gaps.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Baylis also chose SecurityScorecard, a tool that calculates the health and effectiveness of an organization&#8217;s cybersecurity infrastructure. This addition enabled the organization to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/ics-ot-security\/ransomware-data-breaches-inundate-ot-industrial-sector\" rel=\"noopener\">benchmark its security posture<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> against its peers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This led to another watershed moment, when LV= received a &#8220;C&#8221; on its security rating from SecurityScorecard. As a result, the team made hundreds of changes related to issues like expired certificates and weak ciphers. The company now has an &#8220;A&#8221; rating.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Rounding out the new security infrastructure were next-generation anti-malware controls, a new email gateway, a new Web gateway, and a password manager.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Supporting the Human Side of Security\">Supporting the Human Side of Security<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Now that LV=&#8217;s security tooling has been modernized, Baylis is turning his attention to the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/human-centric-security-model-meets-people-where-they-are\" rel=\"noopener\">human risk<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> side of the security equation. He implemented a dedicated <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/remote-workforce\/one-third-of-users-click-on-phishing\" rel=\"noopener\">phishing test and training<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> for employees. He&#8217;s also thinking about hardening the company&#8217;s email infrastructure.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;While we will have a continued focus on cyber resilience, we also want to encourage good security awareness,&#8221; he said. &#8220;Both are critical for effective security.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/how-a-centuries-old-company-reached-security-maturity\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>LV=, the leading pension, savings, insurance, and retirement company in<\/p>\n","protected":false},"author":12,"featured_media":5227,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5226","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-a-centuries-old-company-reached-security-maturity-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-a-centuries-old-company-reached-security-maturity-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-a-centuries-old-company-reached-security-maturity-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-a-centuries-old-company-reached-security-maturity-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-a-centuries-old-company-reached-security-maturity-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-a-centuries-old-company-reached-security-maturity-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-a-centuries-old-company-reached-security-maturity-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-a-centuries-old-company-reached-security-maturity-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-a-centuries-old-company-reached-security-maturity-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-a-centuries-old-company-reached-security-maturity-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-a-centuries-old-company-reached-security-maturity-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5226","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5226"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5226\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5227"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5226"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5226"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5226"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}