1
00:00:06,540 --> 00:00:08,130
- So welcome to lesson six,

2
00:00:08,130 --> 00:00:11,640
explain common threat
vectors and attack surfaces.

3
00:00:11,640 --> 00:00:13,020
In lesson six, one,

4
00:00:13,020 --> 00:00:15,630
we're gonna focus in on
operational threat vectors,

5
00:00:15,630 --> 00:00:17,250
but we're gonna start with describing

6
00:00:17,250 --> 00:00:20,160
what do we even mean by a threat vector?

7
00:00:20,160 --> 00:00:22,650
A threat vector, which
is also sometimes called

8
00:00:22,650 --> 00:00:26,220
an attack vector, is any potential pathway

9
00:00:26,220 --> 00:00:28,683
or scenario that can be exploited.

10
00:00:29,610 --> 00:00:31,620
The common threat vectors include

11
00:00:31,620 --> 00:00:33,480
malicious emails and phishing attacks,

12
00:00:33,480 --> 00:00:36,840
or weaker stolen passwords,
or drive-by download attacks,

13
00:00:36,840 --> 00:00:40,560
or web applications, or out-of-day
applications or devices,

14
00:00:40,560 --> 00:00:43,680
or even exploiting trusted relationships.

15
00:00:43,680 --> 00:00:47,880
An attack surface is the sum
of all of our threat vectors.

16
00:00:47,880 --> 00:00:50,220
So again, the threat vector
is any potential pathway

17
00:00:50,220 --> 00:00:51,810
or scenario that can be exploited,

18
00:00:51,810 --> 00:00:55,713
and the attack surface is the
sum of all threat vectors.

19
00:00:57,120 --> 00:00:59,190
So in this lesson, we're gonna focus in

20
00:00:59,190 --> 00:01:00,780
on operational threat vectors.

21
00:01:00,780 --> 00:01:03,330
Now, operational threat vectors manifest

22
00:01:03,330 --> 00:01:06,570
in our day-to-day activities
or day-to-day operations,

23
00:01:06,570 --> 00:01:10,293
and they generally related to
a lack of internal controls.

24
00:01:11,320 --> 00:01:14,520
Now, examples of operational
internal controls

25
00:01:14,520 --> 00:01:16,530
are things like policies and standards,

26
00:01:16,530 --> 00:01:18,810
risk management, training and education,

27
00:01:18,810 --> 00:01:20,400
third-party due diligence,

28
00:01:20,400 --> 00:01:22,710
segregation of duties, and monitoring.

29
00:01:22,710 --> 00:01:23,850
The number of these controls

30
00:01:23,850 --> 00:01:25,830
we have not yet talked
about in this course,

31
00:01:25,830 --> 00:01:28,830
but don't fear, we will be
talking about them at some point.

32
00:01:30,870 --> 00:01:33,090
Okay, so a reminder, a threat vector

33
00:01:33,090 --> 00:01:36,480
is a potential pathway or
scenario that can be exploited.

34
00:01:36,480 --> 00:01:38,460
So let's do a quick survey

35
00:01:38,460 --> 00:01:41,280
of what these different potential
pathways or scenarios are,

36
00:01:41,280 --> 00:01:43,680
and then we're gonna dive
into each one of them.

37
00:01:43,680 --> 00:01:45,960
So default credentials, weak permissions,

38
00:01:45,960 --> 00:01:48,870
data exfiltrations, open service ports,

39
00:01:48,870 --> 00:01:51,150
unsupported systems and software,

40
00:01:51,150 --> 00:01:55,530
shadow IT, unsecure networks,
and vulnerable software.

41
00:01:55,530 --> 00:01:58,960
These are all potential
pathways or scenarios

42
00:01:58,960 --> 00:02:02,880
that can be exploited from
an operational perspective.

43
00:02:02,880 --> 00:02:04,980
So let's take a look at each one of these,

44
00:02:04,980 --> 00:02:06,600
starting with default credentials.

45
00:02:06,600 --> 00:02:08,010
So what's the issue?

46
00:02:08,010 --> 00:02:09,780
Well, default credentials are the ones

47
00:02:09,780 --> 00:02:11,730
that are initially set up by the vendor,

48
00:02:11,730 --> 00:02:14,520
and many hardware devices
and software applications

49
00:02:14,520 --> 00:02:18,690
come and ship with the default
or built-in credentials,

50
00:02:18,690 --> 00:02:20,010
and generally, that's gonna be

51
00:02:20,010 --> 00:02:23,223
an administrative username and password.

52
00:02:24,750 --> 00:02:28,020
So if that name, username
and password is known,

53
00:02:28,020 --> 00:02:28,853
what can happen?

54
00:02:28,853 --> 00:02:31,590
Well, unauthorized access and compromise,

55
00:02:31,590 --> 00:02:34,440
and it becomes a pathway
to pivot to other devices.

56
00:02:34,440 --> 00:02:36,600
Sometimes we're like,
well, it's not a system

57
00:02:36,600 --> 00:02:38,790
we really care about securing that much,

58
00:02:38,790 --> 00:02:41,160
but remember that our
attackers do a lot of pivoting.

59
00:02:41,160 --> 00:02:42,960
They might come to a less secure system

60
00:02:42,960 --> 00:02:44,700
to get to a more secure system.

61
00:02:44,700 --> 00:02:47,340
And for sure, a quick
search on the internet

62
00:02:47,340 --> 00:02:49,860
will usually reveal default credentials

63
00:02:49,860 --> 00:02:51,270
for a specific product,

64
00:02:51,270 --> 00:02:55,080
so we never wanna be using
the default credential.

65
00:02:55,080 --> 00:02:56,400
Why might we use it?

66
00:02:56,400 --> 00:02:58,410
Convenience, forgetfulness,

67
00:02:58,410 --> 00:03:00,150
that it's really available and out there,

68
00:03:00,150 --> 00:03:02,610
and sometimes just plain old laziness.

69
00:03:02,610 --> 00:03:04,770
So response, we wanna be changing

70
00:03:04,770 --> 00:03:06,900
or disabling default credentials.

71
00:03:06,900 --> 00:03:09,303
We never wanna be using
default credentials.

72
00:03:10,260 --> 00:03:12,510
Next up is weak permissions.

73
00:03:12,510 --> 00:03:13,830
Now, weak permissions are those

74
00:03:13,830 --> 00:03:15,810
that allow for unnecessary access.

75
00:03:15,810 --> 00:03:17,910
That could be to a device,
an operating system,

76
00:03:17,910 --> 00:03:20,970
an application, or the cloud.

77
00:03:20,970 --> 00:03:23,550
The impact, well, if we
have weak permissions,

78
00:03:23,550 --> 00:03:25,410
we could have unauthorized access,

79
00:03:25,410 --> 00:03:28,800
access violations, privacy violations.

80
00:03:28,800 --> 00:03:30,720
Why do we end up with weak permissions?

81
00:03:30,720 --> 00:03:33,360
Often it's a lack of understanding.

82
00:03:33,360 --> 00:03:34,980
Sometimes it's poor classification.

83
00:03:34,980 --> 00:03:38,580
We haven't classified our data correctly,

84
00:03:38,580 --> 00:03:40,110
or maybe not even at all.

85
00:03:40,110 --> 00:03:42,030
And sometimes it's just overconfidence.

86
00:03:42,030 --> 00:03:43,170
It's like, no, everybody will be fine.

87
00:03:43,170 --> 00:03:44,490
They can go ahead and do that.

88
00:03:44,490 --> 00:03:46,050
I hear that a lot in the fields

89
00:03:46,050 --> 00:03:47,280
where someone says, oh, I wasn't sure

90
00:03:47,280 --> 00:03:48,240
what rights to give them,

91
00:03:48,240 --> 00:03:49,980
and they're always coming back for more,

92
00:03:49,980 --> 00:03:52,700
so I just gave them administrative
rights and permissions.

93
00:03:52,700 --> 00:03:55,520
It's like, no, no, no, that's a bad idea.

94
00:03:55,520 --> 00:03:58,170
So our response, we wanna
have documented policies

95
00:03:58,170 --> 00:04:00,990
and procedures, we wanna
educate management,

96
00:04:00,990 --> 00:04:02,730
we wanna have configuration management,

97
00:04:02,730 --> 00:04:04,803
and we wanna have good standardization.

98
00:04:07,080 --> 00:04:08,973
Next up is data exfiltration.

99
00:04:08,973 --> 00:04:12,210
Now, data exfiltration is the inadvertent,

100
00:04:12,210 --> 00:04:15,540
accidental, or intentional
transmission, transfer,

101
00:04:15,540 --> 00:04:18,030
or retrieval of data that's in violation

102
00:04:18,030 --> 00:04:19,560
of a security policy.

103
00:04:19,560 --> 00:04:21,990
So it's something that you're
not supposed to send out.

104
00:04:21,990 --> 00:04:25,290
Let's say it's a customer record,

105
00:04:25,290 --> 00:04:27,870
and that customer record has
a social security number.

106
00:04:27,870 --> 00:04:31,080
You're never supposed to
email that, but you do.

107
00:04:31,080 --> 00:04:34,323
So that would be a form
of data exfiltration.

108
00:04:35,490 --> 00:04:38,400
Now, the impact, we can end up
with unauthorized disclosure,

109
00:04:38,400 --> 00:04:41,640
a data breach, regulatory
compliance violations.

110
00:04:41,640 --> 00:04:43,050
Why does this happen?

111
00:04:43,050 --> 00:04:46,110
Well, it could be incorrect
labeling or classification.

112
00:04:46,110 --> 00:04:48,570
Very often, it's user error.

113
00:04:48,570 --> 00:04:50,100
It could be accidental data

114
00:04:50,100 --> 00:04:51,840
that's been included in a document.

115
00:04:51,840 --> 00:04:53,640
I just worked on a case not that long ago

116
00:04:53,640 --> 00:04:57,480
where a spreadsheet, an Excel
spreadsheet, got sent out.

117
00:04:57,480 --> 00:05:00,930
It had a lot of very
personal information in it,

118
00:05:00,930 --> 00:05:03,330
but all of those columns had been hidden.

119
00:05:03,330 --> 00:05:05,640
So the person who actually emailed it out

120
00:05:05,640 --> 00:05:07,800
looked at it and said, oh, this is fine.

121
00:05:07,800 --> 00:05:11,130
There's nothing in there
that would prevent me

122
00:05:11,130 --> 00:05:13,140
from emailing it out through our system.

123
00:05:13,140 --> 00:05:15,360
But in fact, in those hidden columns

124
00:05:15,360 --> 00:05:18,273
was some very, very personal information.

125
00:05:19,700 --> 00:05:21,420
And of course, malicious activity,

126
00:05:21,420 --> 00:05:24,690
like an APT, an Advanced
Persistent Threat,

127
00:05:24,690 --> 00:05:28,740
is sometimes will result
in data exfiltration.

128
00:05:28,740 --> 00:05:31,680
So our response, good data
classification controls.

129
00:05:31,680 --> 00:05:34,560
We'll be talking a lot about
classification later on.

130
00:05:34,560 --> 00:05:36,750
DLP, data loss prevention monitoring,

131
00:05:36,750 --> 00:05:39,510
having good firewall
rules, user education,

132
00:05:39,510 --> 00:05:42,723
having non-disclosure
agreements, and log reviews.

133
00:05:44,780 --> 00:05:47,100
Next is open service ports.

134
00:05:47,100 --> 00:05:49,410
Our issue, our open service ports

135
00:05:49,410 --> 00:05:51,930
are ports that are
those in listening mode.

136
00:05:51,930 --> 00:05:53,880
Now, if a port's gonna
be in listening mode,

137
00:05:53,880 --> 00:05:56,850
that means it has to have
something tied into it

138
00:05:56,850 --> 00:06:00,453
in the system, like an
application or a utility.

139
00:06:01,820 --> 00:06:05,880
So the impact could be
exposure, potential exploit,

140
00:06:05,880 --> 00:06:08,880
unauthorized access, denial of service,

141
00:06:08,880 --> 00:06:12,780
or even problems with the
integrity of device management.

142
00:06:12,780 --> 00:06:14,490
Because one of the really big problems

143
00:06:14,490 --> 00:06:17,310
about having these open service
ports that aren't necessary

144
00:06:17,310 --> 00:06:19,890
is that nobody's paying attention to them.

145
00:06:19,890 --> 00:06:21,300
So why might we have these?

146
00:06:21,300 --> 00:06:24,450
Well, poor non-existent
configuration management,

147
00:06:24,450 --> 00:06:27,330
not implementing the principle
of least functionality,

148
00:06:27,330 --> 00:06:31,140
unrestricted permission to
install a device or software.

149
00:06:31,140 --> 00:06:33,360
Our response, configuration management,

150
00:06:33,360 --> 00:06:35,040
and we've talked about that earlier,

151
00:06:35,040 --> 00:06:37,800
ongoing system hardening,
which we will be talking about,

152
00:06:37,800 --> 00:06:40,200
account restrictions, which
we will be talking about,

153
00:06:40,200 --> 00:06:43,760
and vulnerability scanning
to identify these open ports

154
00:06:43,760 --> 00:06:46,053
and associated services.

155
00:06:48,200 --> 00:06:50,520
We have unsupported systems and software.

156
00:06:50,520 --> 00:06:53,220
This is a really significant
operational issue.

157
00:06:53,220 --> 00:06:55,440
And there's two components to it.

158
00:06:55,440 --> 00:06:58,240
It could be that we have
unsupported systems and software

159
00:06:58,240 --> 00:07:00,880
because we have the
unauthorized installation

160
00:07:00,880 --> 00:07:02,820
of devices or software.

161
00:07:02,820 --> 00:07:03,900
So it wasn't authorized,

162
00:07:03,900 --> 00:07:05,250
so no one's paying attention to it,

163
00:07:05,250 --> 00:07:06,780
so we don't have vulnerability management,

164
00:07:06,780 --> 00:07:07,860
we don't have patch management,

165
00:07:07,860 --> 00:07:09,690
we don't have configuration management,

166
00:07:09,690 --> 00:07:13,170
we're not including it in our
assessments or in our audits.

167
00:07:13,170 --> 00:07:15,060
Or, and this is a really common one,

168
00:07:15,060 --> 00:07:16,260
more common than it should be,

169
00:07:16,260 --> 00:07:19,280
we could be running systems or software

170
00:07:19,280 --> 00:07:21,240
that have reached their end of life

171
00:07:21,240 --> 00:07:23,250
or their end of support.

172
00:07:23,250 --> 00:07:25,890
End of life means the
product is now obsolete

173
00:07:25,890 --> 00:07:27,060
and there's no more features

174
00:07:27,060 --> 00:07:28,800
or functionalities being developed.

175
00:07:28,800 --> 00:07:31,470
End of support means that
there's no longer any support,

176
00:07:31,470 --> 00:07:33,330
including vulnerability management,

177
00:07:33,330 --> 00:07:35,223
meaning no more patches.

178
00:07:36,080 --> 00:07:38,970
So the impact, unauthorized access,

179
00:07:38,970 --> 00:07:42,060
exploits, compatibility issues,

180
00:07:42,060 --> 00:07:44,280
downtime, and we can
have license violations.

181
00:07:44,280 --> 00:07:46,560
Why does this happen?

182
00:07:46,560 --> 00:07:49,230
Often it's because of a
lack of centralized control,

183
00:07:49,230 --> 00:07:51,660
it may be because there's
local administrative privileges

184
00:07:51,660 --> 00:07:53,500
on the local workstation,

185
00:07:53,500 --> 00:07:56,850
could be for end of life and
absence of refresh policies,

186
00:07:56,850 --> 00:07:58,470
could be budgetary constraints

187
00:07:58,470 --> 00:08:00,150
or just a lack of understanding

188
00:08:00,150 --> 00:08:03,960
of why we should not be using
products past end of life

189
00:08:03,960 --> 00:08:07,083
or at very least past end of support.

190
00:08:08,100 --> 00:08:10,260
Response, configuration management,

191
00:08:10,260 --> 00:08:11,760
permissions management,

192
00:08:11,760 --> 00:08:13,830
having refreshed policies and standards,

193
00:08:13,830 --> 00:08:15,180
resource management,

194
00:08:15,180 --> 00:08:16,863
and certainly budget allocation.

195
00:08:18,860 --> 00:08:20,460
Next we come to Shadow IT,

196
00:08:20,460 --> 00:08:24,630
which I mentioned very
briefly in an earlier lesson.

197
00:08:24,630 --> 00:08:28,980
Shadow IT is the use of on-premise
or cloud-based resources

198
00:08:28,980 --> 00:08:32,160
that bypass the IT department.

199
00:08:32,160 --> 00:08:33,540
So how does that work?

200
00:08:33,540 --> 00:08:35,440
Well, let's say I'm in the HR department

201
00:08:35,440 --> 00:08:38,100
and I really wanna have a new application

202
00:08:38,100 --> 00:08:40,080
for doing performance reviews.

203
00:08:40,080 --> 00:08:42,480
Now, pre-cloud, right,

204
00:08:42,480 --> 00:08:44,540
I would have probably
had to go look for one

205
00:08:44,540 --> 00:08:48,520
and then I would have brought
the IT in during the demos

206
00:08:48,520 --> 00:08:50,820
and then when I actually bought it,

207
00:08:50,820 --> 00:08:52,950
the IT team would
probably set up the server

208
00:08:52,950 --> 00:08:57,090
and manage or co-manage the application.

209
00:08:57,090 --> 00:08:58,620
But now what can I do?

210
00:08:58,620 --> 00:09:01,650
Well, I go out and find
a software as a service

211
00:09:01,650 --> 00:09:03,870
or a SaaS application, right,

212
00:09:03,870 --> 00:09:05,580
go out probably port 443

213
00:09:05,580 --> 00:09:07,620
that I have the rights to go out to,

214
00:09:07,620 --> 00:09:10,020
all I have to do is
maybe pay my monthly fee

215
00:09:10,020 --> 00:09:13,593
and I never have to involve IT whatsoever.

216
00:09:14,490 --> 00:09:16,170
Well, that's convenient,

217
00:09:16,170 --> 00:09:18,660
but the bad news is all
of those various controls

218
00:09:18,660 --> 00:09:21,240
that IT would probably put in place,

219
00:09:21,240 --> 00:09:25,320
I've bypassed and that's
a danger of Shadow IT.

220
00:09:25,320 --> 00:09:28,320
So the impact could be the
violation of security policies

221
00:09:28,320 --> 00:09:33,000
like authentication or
encryption or doing backups.

222
00:09:33,000 --> 00:09:34,830
The causes, well, availability now

223
00:09:34,830 --> 00:09:37,560
of cloud-based software as a service,

224
00:09:37,560 --> 00:09:40,500
the sense that controls are onerous

225
00:09:40,500 --> 00:09:42,870
and or that IT is hard to work with.

226
00:09:42,870 --> 00:09:47,490
So there's a determination
to really kind of bypass IT.

227
00:09:47,490 --> 00:09:48,840
Now that could be using cloud

228
00:09:48,840 --> 00:09:51,540
or that could be just
setting up their own devices

229
00:09:51,540 --> 00:09:53,130
inside a department and saying,

230
00:09:53,130 --> 00:09:54,640
I'm just not gonna get IT involved

231
00:09:54,640 --> 00:09:57,660
because the controls
are gonna be putting on

232
00:09:57,660 --> 00:10:01,503
are just so difficult or IT
is so difficult to work with.

233
00:10:02,380 --> 00:10:05,850
The response, user education for the cloud

234
00:10:05,850 --> 00:10:07,260
using what's known as CASBs,

235
00:10:07,260 --> 00:10:08,820
cloud access security brokers,

236
00:10:08,820 --> 00:10:12,300
having firewall rules, having a log review

237
00:10:12,300 --> 00:10:14,100
and having accounting audits.

238
00:10:14,100 --> 00:10:17,043
But user education is probably
number one on this list.

239
00:10:18,420 --> 00:10:21,200
And that my friends brings us
to a three second challenge

240
00:10:21,200 --> 00:10:23,643
about operational issues.

241
00:10:24,690 --> 00:10:27,690
The unauthorized removal of digital data.

242
00:10:27,690 --> 00:10:29,820
What's the term we use to describe that?

243
00:10:29,820 --> 00:10:31,443
One, two, three.

244
00:10:32,700 --> 00:10:35,193
It's gonna be data exfiltration.

245
00:10:36,080 --> 00:10:39,330
Question two, credentials
that are initially set up

246
00:10:39,330 --> 00:10:40,203
by a vendor.

247
00:10:41,100 --> 00:10:42,873
One, two, three.

248
00:10:44,130 --> 00:10:45,720
Those are the default credentials

249
00:10:45,720 --> 00:10:47,760
and we know we always wanna change them

250
00:10:47,760 --> 00:10:49,563
or not use them, disable them.

251
00:10:51,800 --> 00:10:55,293
Question three, a potential
pathway that can be exploited.

252
00:10:56,700 --> 00:10:59,550
One, two, three.

253
00:10:59,550 --> 00:11:00,873
That's a threat vector.

254
00:11:03,300 --> 00:11:06,210
Number four, the use of
cloud-based applications

255
00:11:06,210 --> 00:11:09,453
and services that bypass
the IT department.

256
00:11:10,500 --> 00:11:12,030
One, two, three.

257
00:11:12,030 --> 00:11:14,340
It's what we just talked about.

258
00:11:14,340 --> 00:11:15,363
That's Shadow IT.

259
00:11:16,860 --> 00:11:21,390
And lastly, number five, the
sum of all threat vectors.

260
00:11:21,390 --> 00:11:23,310
What do we call the sum
of all threat vectors?

261
00:11:23,310 --> 00:11:24,663
One, two, three.

262
00:11:25,950 --> 00:11:27,423
That's our attack surface.

263
00:11:28,940 --> 00:11:31,080
All right, ready to do
a security in action.

264
00:11:31,080 --> 00:11:33,660
This one's about
operational threat vectors.

265
00:11:33,660 --> 00:11:35,160
You've been asked to make a presentation

266
00:11:35,160 --> 00:11:37,280
about the root cause or causes

267
00:11:37,280 --> 00:11:40,940
of successful operational exploits.

268
00:11:40,940 --> 00:11:43,060
What would you stress?

269
00:11:43,060 --> 00:11:45,060
So we've looked at a whole pantheon

270
00:11:45,060 --> 00:11:47,160
of different operational threat vectors

271
00:11:47,160 --> 00:11:51,300
and you need to make a
presentation about the root cause.

272
00:11:51,300 --> 00:11:54,360
So not about the threat
vectors themselves necessarily,

273
00:11:54,360 --> 00:11:55,710
but about the root cause

274
00:11:55,710 --> 00:11:58,300
of successful operational exploits.

275
00:11:58,300 --> 00:12:00,300
So what would you stress?

276
00:12:00,300 --> 00:12:02,280
Go ahead and put me on
pause, write down some notes

277
00:12:02,280 --> 00:12:04,170
about those root causes

278
00:12:04,170 --> 00:12:06,030
and what you're gonna
stress in that presentation

279
00:12:06,030 --> 00:12:07,130
and then come on back.

280
00:12:09,750 --> 00:12:12,060
Well, our operational
threat vectors manifest

281
00:12:12,060 --> 00:12:13,620
in our day-to-day activities

282
00:12:13,620 --> 00:12:15,390
and they're generally related

283
00:12:15,390 --> 00:12:18,060
to a lack of internal controls.

284
00:12:18,060 --> 00:12:20,310
So root causes include things like

285
00:12:20,310 --> 00:12:23,220
an insufficient
understanding and awareness

286
00:12:23,220 --> 00:12:25,980
at all levels of our organization.

287
00:12:25,980 --> 00:12:29,170
Maybe having a weak
security strategy and policy

288
00:12:30,080 --> 00:12:32,100
and having poor auditing practices,

289
00:12:32,100 --> 00:12:34,830
meaning that we're not looking
to see what do we have,

290
00:12:34,830 --> 00:12:37,470
right, we don't have
those assurance activities

291
00:12:37,470 --> 00:12:40,770
that will tell us that we have
the right controls in place.

292
00:12:40,770 --> 00:12:43,860
You know, very often operational
threat vectors happen

293
00:12:43,860 --> 00:12:47,220
because folks are so busy
doing whatever their job is,

294
00:12:47,220 --> 00:12:48,840
right, they're being a clinician,

295
00:12:48,840 --> 00:12:50,010
they're being an attorney,

296
00:12:50,010 --> 00:12:52,380
they're, you know, being a designer

297
00:12:52,380 --> 00:12:54,720
that they don't think about

298
00:12:54,720 --> 00:12:56,460
some of these operational threat vectors

299
00:12:56,460 --> 00:12:59,800
but it's your job and my job
as cybersecurity practitioners

300
00:12:59,800 --> 00:13:02,190
to really keep an eye out on these

301
00:13:02,190 --> 00:13:05,220
and make sure that we have, you know,

302
00:13:05,220 --> 00:13:08,070
a good security posture
in our organization

303
00:13:08,070 --> 00:13:10,650
and we don't let these
operational threat vectors

304
00:13:10,650 --> 00:13:13,830
kind of open us up to any kind of harm.

305
00:13:13,830 --> 00:13:15,390
And being able to do that, my friends,

306
00:13:15,390 --> 00:13:17,560
is security in action.

307
00:13:17,560 --> 00:13:19,940
That brings you to a
pretty big word cloud.

308
00:13:19,940 --> 00:13:22,110
Make sure that you can speak to

309
00:13:22,110 --> 00:13:24,090
all of these different issues,

310
00:13:24,090 --> 00:13:27,060
that you understand why
they could potentially

311
00:13:27,060 --> 00:13:28,800
cause problems for an organization

312
00:13:28,800 --> 00:13:31,980
and a good understanding of
what we're gonna do about it.

313
00:13:31,980 --> 00:13:36,540
I recognize that a lot of the
things I said we could do,

314
00:13:36,540 --> 00:13:38,480
right, in response, we
haven't talked about yet

315
00:13:38,480 --> 00:13:40,320
but never fear, we will be talking about

316
00:13:40,320 --> 00:13:42,420
all of them in this course.

317
00:13:42,420 --> 00:13:43,350
All right, when you're ready,

318
00:13:43,350 --> 00:13:44,950
I'll see you at the next lesson.
