Threat hunting: assuming the worst to strengthen resilience
Steve Mansfield-Devine · Network Security · 2017
There's a popular truism in the information security world that has become a cliché – that it's not a matter of if your organisation will be breached but when. As trite as this axiom sounds – and it is trotted out now with regularity – there's no getting away from the underlying reality, which is that it's true. And as Peter Cohen, strategic director for Countercept at MWR InfoSecurity, explains in this interview, there are good reasons for assuming that the ‘when’ is now and that the breach has already happened.1