Cyber SecurityHuman ErrorInsider ThreatTraining

Strengthening Cybersecurity Teams’ Capabilities

Strengthening Cybersecurity Teams’ Capabilities

Strengthening Cybersecurity Teams' Capabilities

Immersive Labs provide the world's first Cyber Workforce Optimisation (CWO) platform that allows any organisation to gauge their cybersecurity readiness. It goes beyond simple training and certification tick boxing to provide a platform that empowers organisations to measure, map to risk, and optimise the cyber abilities of their entire workforce. The Cyber Workforce Optimisation website has detailed information on the platform.

The use patterns of thousands of organisations using the platform to improve their cybersecurity posture provides data that can be analysed and used to deliver insights into trends across all business sectors. Immersive Labs has analysed the usage data from 18 months of engagement with the platform and published the findings in their Cyber Workforce Benchmark 2022 report.

Cyber Workforce Benchmark 2022

The free report outlining and discussing the findings is available to download here. It has a deep dive into 18 months of cyber workforce capability data and insights, collected from 2100 organisations and based on over 500,000 cyber exercises and simulations. It is the first industry report on global cyber knowledge, skills, and judgement.

The report outlines key lessons for anyone looking to improve the cybersecurity capabilities of their organisation. It also maps the findings against the MITRE ATT&CK framework tactics and technique descriptions. These are easily understandable and simplify decision-making on what needs improving.

There Is a Bias Towards Defending Against Early Attack Stages

The MITRE ATT&CK framework gets presented as a matrix that covers the typical steps in a cyberattack, from initial access attempts on the left to breaches and data loss on the right. This is relevant to the findings in the Cyber Workforce Benchmark 2022 report, as there is a focus on items near the left-hand side of the matrix in the data analysed. Across all sectors using the CWO platform, security professionals are much more interested in improving their skills in attack tactics and techniques used during the early stages of a cyberattack. For example, taking labs about how to improve skills on how malicious code runs, were five times more popular than labs relating to data collection or exfiltration.

On one level this makes sense, as preventing attackers from getting access will reduce the need for actions and skills towards the right of the MITRE ATT&CK framework matrix. However, this is a mistaken thought process. It violates a golden rule of cybersecurity - assume a breach will occur and plan to recover afterwards, which requires developing skills across the complete MITRE ATT&CK framework matrix.

Long Lead Times on Reported Vulnerabilities

The Cyber Workforce Benchmark report also showed long lead times between new vulnerabilities and organisations developing the skills to defend against them. The report demonstrates this via data showing the time taken by 35,000 people at 400 large organisations to develop the skills, knowledge, and judgement to counter 185 cyber threats.

The average time between a vulnerability report and users of the CWO platform consuming labs or other resources on that topic was 96 days. However, the critical national infrastructure sector was much worse than the overall average, as organisations in that vital sector average 137 days before accessing materials on new vulnerabilities. A worrying trend given that critical infrastructure is a tempting target for state-backed cybercriminals. For balance, we should highlight the entertainment and leisure sector with an average of 65 days. Nothing to be too proud about, but it was the best.

Some Vulnerabilities Cut Through

There have been a few cyber threats and newly discovered vulnerabilities in the last two years that have received so much coverage in specialist and general news outlets that they are impossible to miss. The Cyber Workforce Benchmark report reflects this as the data shows that four of the top five fastest skills developed during 2021 on the CWO platform relate to the Log4j vulnerability. The Log4j issue was everywhere in the news and justly accompanied by apocalyptic warnings on how dangerous it is. This spurred many security professionals using CWO to use labs detailing how to look for and address the vulnerability.

Organisations should apply the Log4j urgency to all vulnerabilities based on the risk score that CISA and other national cybersecurity agencies assign.

If you would like to chat to someone about the Immersive Labs Cyber Workforce Optimisation platform, then reach out to your Renaissance contact or use this form.