{"id":403,"date":"2020-02-04T17:35:00","date_gmt":"2020-02-04T17:35:00","guid":{"rendered":"https:\/\/www.cycognito.com\/blog\/?p=403"},"modified":"2024-08-02T15:28:39","modified_gmt":"2024-08-02T22:28:39","slug":"the-castle-has-fallen-protect-your-it-ecosystem","status":"publish","type":"post","link":"https:\/\/www.cycognito.com\/blog\/the-castle-has-fallen-protect-your-it-ecosystem\/","title":{"rendered":"Take a Post-Medieval Approach to Attack Surface Defense"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">When security teams had control<\/h2>\n\n\n\n<p>The 1990s was a good time for security teams, when our networks only had a couple points of ingress and egress.&nbsp;<\/p>\n\n\n\n<p>Just like defending a castle, defending an IT environment with only one or two points of entry and exit enables one to spend limited resources on building thick layers of hardened defenses. One could defend a castle with a moat, a drawbridge, murder holes, reinforced doors, stone walls, entrenched archers, and armor-fitted knights to name only a few.<\/p>\n\n\n\n<p> In the early days of computing with singular monolithic data centers and only one or two points of presence on the internet, we could layer firewalls, web application firewalls, obfuscate behind network address translation (NAT), intrusion detection\/prevention systems, and if all that failed, we could still fall back on a myriad of host-based defenses like endpoint detection and response, host-based intrusion detection and antivirus.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The days of the castle builders<\/h2>\n\n\n\n<p>The 1990s and early 2000s were the days of the castle builders and security spending reflected the layering strategy to a tee. Enter Amazon Web Services Elastic Compute Cloud in 2006, Azure in 2010, and Google Cloud Platform in 2011 with dreams of IaaS. Salesforce, Atlassian and Git debuted to consume our data as SaaS. Partners, subsidiaries and economies of scale demanded direct access to our networks to exchange data. <\/p>\n\n\n\n<p>The castle that hosted our data, infrastructure and operations has crumbled by convenience and necessity; our monolith melted from hardened, tightly controlled, handfuls of internet-exposed assets and ingress\/egress points to a broad field with new, complex interrelationships between our offices, legacy data centers, IaaS, SaaS, partners and subsidiaries, without the impenetrable walls of the past.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">And then the Internet changed everything<\/h2>\n\n\n\n<p>Want to compromise a company\u2019s data in the post-castle world? Why be traditional and attack their data center directly when you can attack a partner and lateral your way in (Target)? Why launch nuanced SQL injection attacks against a hardened perimeter when you can find an unmanaged, abandoned or misconfigured asset to be your beachhead (Novaestrat)? With the ease in which we can spin up workloads and mangle access control lists, can we reasonably expect our&nbsp;<a href=\"\/learn\/attack-surface-management.php\">attack surface<\/a>&nbsp;to be in any way relatable to our prior experience, and should we expect our IT staff to be flawless in maintaining and monitoring that surface?<\/p>\n\n\n\n<p>As a former federal Security Operations Center dweller who loved building robust castle-style defenses, I have to give way to the new paradigm and admit the old ways of thinking aren\u2019t compatible with today\u2019s varied IT ecosystem. The ways into our networks and to our data are now legion, differentiated in both scope and means of entry. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The only effective way of managing risk<\/h2>\n\n\n\n<p>Even when we don\u2019t control the infrastructure, we\u2019re responsible for the data (SaaS); even when we control the infrastructure, a single keystroke in an access control list in cloud environments\/IaaS can expose our data to the world. The only effective way of managing risk posed by all of these environments and interconnects is to map what\u2019s exposed to adversaries (assets),\u00a0<a href=\"\/blog\/vulnerability-scanners-are-no-match-for-modern-threats\/\" target=\"_blank\" rel=\"noreferrer noopener\">identify weaknesses<\/a>\u00a0(issues), and remediate on a continuous basis. The\u00a0<a href=\"\/platform\/\">CyCognito platform<\/a>\u00a0was designed for this new paradigm.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Your attack surface has changed. It&#8217;s time for a new paradigm and admit the old ways of thinking aren\u2019t compatible with today\u2019s varied IT ecosystem.<\/p>\n","protected":false},"author":26,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[6,9],"class_list":["post-403","post","type-post","status-publish","format-standard","hentry","category-perspectives","tag-attack-surface-management","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Take a Post-Medieval Approach to Attack Surface Defense | CyCognito Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cycognito.com\/blog\/the-castle-has-fallen-protect-your-it-ecosystem\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Take a Post-Medieval Approach to Attack Surface Defense | CyCognito Blog\" \/>\n<meta property=\"og:description\" content=\"Your attack surface has changed. It&#039;s time for a new paradigm and admit the old ways of thinking aren\u2019t compatible with today\u2019s varied IT ecosystem.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cycognito.com\/blog\/the-castle-has-fallen-protect-your-it-ecosystem\/\" \/>\n<meta property=\"og:site_name\" content=\"CyCognito Blog\" \/>\n<meta property=\"article:published_time\" content=\"2020-02-04T17:35:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-08-02T22:28:39+00:00\" \/>\n<meta name=\"author\" content=\"CyCognito Staff\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"CyCognito Staff\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/the-castle-has-fallen-protect-your-it-ecosystem\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/the-castle-has-fallen-protect-your-it-ecosystem\/\"},\"author\":{\"name\":\"CyCognito Staff\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/e1e418d7d4a6d3abf5de7ef65d04da91\"},\"headline\":\"Take a Post-Medieval Approach to Attack Surface Defense\",\"datePublished\":\"2020-02-04T17:35:00+00:00\",\"dateModified\":\"2024-08-02T22:28:39+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/the-castle-has-fallen-protect-your-it-ecosystem\/\"},\"wordCount\":548,\"publisher\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\"},\"keywords\":[\"Attack Surface Management\",\"Cybersecurity\"],\"articleSection\":[\"Perspectives\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/the-castle-has-fallen-protect-your-it-ecosystem\/\",\"url\":\"https:\/\/www.cycognito.com\/blog\/the-castle-has-fallen-protect-your-it-ecosystem\/\",\"name\":\"Take a Post-Medieval Approach to Attack Surface Defense | CyCognito Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#website\"},\"datePublished\":\"2020-02-04T17:35:00+00:00\",\"dateModified\":\"2024-08-02T22:28:39+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/the-castle-has-fallen-protect-your-it-ecosystem\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.cycognito.com\/blog\/the-castle-has-fallen-protect-your-it-ecosystem\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/the-castle-has-fallen-protect-your-it-ecosystem\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.cycognito.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Take a Post-Medieval Approach to Attack Surface Defense\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#website\",\"url\":\"https:\/\/www.cycognito.com\/blog\/\",\"name\":\"Cycognito Blog\",\"description\":\"Research, Product News and Latest Updates\",\"publisher\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.cycognito.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\",\"name\":\"Cycognito\",\"url\":\"https:\/\/www.cycognito.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png\",\"contentUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png\",\"width\":1720,\"height\":550,\"caption\":\"Cycognito\"},\"image\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/e1e418d7d4a6d3abf5de7ef65d04da91\",\"name\":\"CyCognito Staff\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/dc81941cde3349893dfc090c431e4dc0?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/dc81941cde3349893dfc090c431e4dc0?s=96&d=mm&r=g\",\"caption\":\"CyCognito Staff\"},\"description\":\"Rule Your Risk\",\"url\":\"https:\/\/www.cycognito.com\/blog\/author\/cycognito\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Take a Post-Medieval Approach to Attack Surface Defense | CyCognito Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.cycognito.com\/blog\/the-castle-has-fallen-protect-your-it-ecosystem\/","og_locale":"en_US","og_type":"article","og_title":"Take a Post-Medieval Approach to Attack Surface Defense | CyCognito Blog","og_description":"Your attack surface has changed. It's time for a new paradigm and admit the old ways of thinking aren\u2019t compatible with today\u2019s varied IT ecosystem.","og_url":"https:\/\/www.cycognito.com\/blog\/the-castle-has-fallen-protect-your-it-ecosystem\/","og_site_name":"CyCognito Blog","article_published_time":"2020-02-04T17:35:00+00:00","article_modified_time":"2024-08-02T22:28:39+00:00","author":"CyCognito Staff","twitter_card":"summary_large_image","twitter_misc":{"Written by":"CyCognito Staff","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.cycognito.com\/blog\/the-castle-has-fallen-protect-your-it-ecosystem\/#article","isPartOf":{"@id":"https:\/\/www.cycognito.com\/blog\/the-castle-has-fallen-protect-your-it-ecosystem\/"},"author":{"name":"CyCognito Staff","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/e1e418d7d4a6d3abf5de7ef65d04da91"},"headline":"Take a Post-Medieval Approach to Attack Surface Defense","datePublished":"2020-02-04T17:35:00+00:00","dateModified":"2024-08-02T22:28:39+00:00","mainEntityOfPage":{"@id":"https:\/\/www.cycognito.com\/blog\/the-castle-has-fallen-protect-your-it-ecosystem\/"},"wordCount":548,"publisher":{"@id":"https:\/\/www.cycognito.com\/blog\/#organization"},"keywords":["Attack Surface Management","Cybersecurity"],"articleSection":["Perspectives"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.cycognito.com\/blog\/the-castle-has-fallen-protect-your-it-ecosystem\/","url":"https:\/\/www.cycognito.com\/blog\/the-castle-has-fallen-protect-your-it-ecosystem\/","name":"Take a Post-Medieval Approach to Attack Surface Defense | CyCognito Blog","isPartOf":{"@id":"https:\/\/www.cycognito.com\/blog\/#website"},"datePublished":"2020-02-04T17:35:00+00:00","dateModified":"2024-08-02T22:28:39+00:00","breadcrumb":{"@id":"https:\/\/www.cycognito.com\/blog\/the-castle-has-fallen-protect-your-it-ecosystem\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.cycognito.com\/blog\/the-castle-has-fallen-protect-your-it-ecosystem\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.cycognito.com\/blog\/the-castle-has-fallen-protect-your-it-ecosystem\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.cycognito.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Take a Post-Medieval Approach to Attack Surface Defense"}]},{"@type":"WebSite","@id":"https:\/\/www.cycognito.com\/blog\/#website","url":"https:\/\/www.cycognito.com\/blog\/","name":"Cycognito Blog","description":"Research, Product News and Latest Updates","publisher":{"@id":"https:\/\/www.cycognito.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.cycognito.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.cycognito.com\/blog\/#organization","name":"Cycognito","url":"https:\/\/www.cycognito.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png","contentUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png","width":1720,"height":550,"caption":"Cycognito"},"image":{"@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/e1e418d7d4a6d3abf5de7ef65d04da91","name":"CyCognito Staff","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/dc81941cde3349893dfc090c431e4dc0?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/dc81941cde3349893dfc090c431e4dc0?s=96&d=mm&r=g","caption":"CyCognito Staff"},"description":"Rule Your Risk","url":"https:\/\/www.cycognito.com\/blog\/author\/cycognito\/"}]}},"_links":{"self":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/403","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/users\/26"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/comments?post=403"}],"version-history":[{"count":10,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/403\/revisions"}],"predecessor-version":[{"id":1068,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/403\/revisions\/1068"}],"wp:attachment":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/media?parent=403"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/categories?post=403"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/tags?post=403"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}