According to a study by Cybersecurity Ventures magazine, a cyberattack took place every 39 seconds in 2023. That equates to over 2,200 attacks per day. Businesses and public authorities are aware of the growing threat posed by cybercrime. However, the path to building a resilient information and data fortress is not always clear or straightforward to implement. Monitoring entire IT and OT systems round the clock for irregularities can be time-consuming and expensive. Consequently, many organisations adopt a ‘tolerance for gaps’ approach. In the field of cyber security, however, this can have disastrous consequences. The damage resulting from security incidents detected too late is enormous. Every organisation must therefore find its own individual way to position itself securely and resiliently.
How much monitoring is required?
Intrusion detection systems (IDS) can be a first step in this process. According to the BSI, IDS are processes supported by technical tools and organisational integration. This definition alone shows that an IDS is not simply a technical purchase.
Before companies or public authorities consider implementing an ADR, there are a number of preliminary considerations to be made. Only in this way can they find the right solution and establish processes that work:
- Firstly, it must be precisely defined which areas are to be covered.
- Is it an IT or an OT environment, or a combination of both?
- How many and which end devices (e.g. manufacturers/models) are there?
- Which infrastructure components need to be taken into account?
- Which network zones exist, and what restrictions apply between them?
- What exactly is to be detected? Only known attack patterns, or also anomalies that the system can distinguish from normal behaviour using machine learning?
- Which service providers are involved in attack detection, and to what extent?
- Which specific tasks are to be handled? Just the reporting of alerts, or also the assessment, or even the response? Is a complete ‘Managed SOC’ package required?
- Who is responsible for which data?
- What other contracts need to be concluded, and with whom?
Raising the alarm is a skill that needs to be learnt
Once the preliminary considerations have been completed, the next step is to identify suitable technical systems or a combination of several systems. The BSI Act states the following in this regard: ‘The security systems deployed must continuously and automatically record and evaluate suitable parameters and characteristics from ongoing operations. They should be capable of continuously identifying and preventing threats, as well as providing for appropriate remedial measures in the event of incidents.” (Section 8a(1a), sentences 1 and 2 of the BSI Act)
A Security Information and Event Management (SIEM) system can assist with this through the relevant follow-up processes. A SIEM is a software solution that automatically collects, analyses and correlates security information and event data in real time from various sources in order to detect incidents, i.e. security incidents. To this end, it collects data organisation-wide, for example from network devices, server logs, end devices and applications. The collected data is then pre-processed, linked to additional information and optimised for efficient searchability. Ultimately, the system analyses and correlates the data to detect potential security incidents. This involves identifying patterns, anomalies and suspicious behaviour. Through artificial intelligence, trained for example via machine learning, a SIEM is able to learn patterns and thresholds and thus recognise known and normal behaviour. When a potential security incident is detected, the SIEM system generates alerts to inform security personnel. As the SIEM system is used over time, pattern recognition increasingly narrows down the number of false alarms.
SIEM systems play a key role in cyber security by providing a holistic view of security incidents, improving the detection of and response to threats, and helping to meet compliance requirements. When used in conjunction with other security components, such as intrusion detection systems (IDS) or managed detection and response (MDR) solutions, and in combination with defence mechanisms (e.g. a Computer Security Incident Response Team (CSIRT)), a SIEM is a central component of a robust security infrastructure. This infrastructure helps organisations to detect threats, respond to them and proactively prevent them. It is important to combine a SIEM strategically with other measures and to establish processes for handling the alerts that are triggered. Should an attack nevertheless succeed, the aim is to close the vulnerability as quickly as possible in order to limit the damage and restore business continuity – click here to read the article “Improving resilience: How to make your IT a rock-solid foundation”.