Search
By Prasun Howli, Kathryn Rock
On May 17, 2022, the cybersecurity authorities1 of the United States, Canada, the Netherlands, New Zealand, and the UK published a joint cybersecurity advisory titled, “Weak Security Controls and Practices Routinely Exploited for Initial Access.”2 The advisory highlights the common techniques exploited by the malicious actors to gain initial access to the victim’s network and the common weaknesses in the control environment. Additionally, the advisory outlines some of the best practices that can be adopted to strengthen the control environment. This cybersecurity alert provides an overview of the advisory and the key areas above.
The advisory stated that the common techniques used by the adversaries to gain unauthorized access to a victim’s internal environment include:
Exploit public-facing application — An adversary can gain access by exploiting weaknesses on internet-facing applications, e.g., a design flaw in the external-facing website.
External remote services — A bad actor can use compromised credentials to gain access using remote services such as a Virtual Private Network, Citrix3, etc.
Phishing — Phishing is a technique to obtain legitimate access credentials using various methods such as social engineering or including a malicious attachment in electronic communication.
Trusted relationship — A trusted third party or service provider can have legitimate access to the victim’s system, which can be exploited by malicious actors to gain access to the internal network.
The advisory noted that some of the most common weaknesses are:
Guidehouse has assisted numerous clients in assessing their cybersecurity and operationalizing compliance requirements using regulations, standards, and guidance issued by authorities and global data privacy regulations. We have supported our clients by:
Guidehouse is a global consultancy providing advisory, digital, and managed services to the commercial and public sectors. Purpose-built to serve the national security, financial services, healthcare, energy, and infrastructure industries, the firm collaborates with leaders to outwit complexity and achieve transformational changes that meaningfully shape the future.