auditcarriere.nl

Why should IT Auditors use Memory Forensics to enhance the cybersecurity posture of their clients?

Nieuws
14-06-2024
Robert Jan Mora
The fight against cybercrime requires more than traditional security measures. IT auditors, who assess the robustness of an organization's cybersecurity, must step up their game.

Auteur: Robert Jan Mora

1. Introduction

In the last decade, organizations have adopted Endpoint Detection and Response (EDR) capabilities to combat nation-state threats and cybercrime, often based on auditors' recommendations. However, EDR alone has not significantly reduced ransomware attacks. This is partly due to a lack of staff to interpret alerts and the growing ability of threat actors to evade EDR. A recent study showed that 26 EDR vendors failed to prevent all tested evasion techniques, with tools like EDRBlast rendering several EDR solutions ineffective1 en 2.

The fight against cybercrime requires more than traditional security measures. IT auditors, who assess the robustness of an organization's cybersecurity, must step up their game. Despite passing audits, many organizations still suffer from ransomware, highlighting the inadequacy of current controls. Auditors typically rely on interviews, documentation, and limited technical checks, which is no longer sufficient.

But how can auditors determine if a client's system or network is in a trusted state, compromised, or without specific "stated" controls without ever sampling and analyzing the volatile memory of critical systems?

[....]

Gerelateerde vacatures

Geïnteresseerd in een carrière bij organisaties in ditzelfde vakgebied? Bekijk hieronder de gerelateerde vacatures en vind de perfecte match voor jou!
Promovendum
4.600 - 6.150
Medior
Dordrecht
Als Cyber Risk Specialist bij Promovendum beoordeel je ICT-omgevingen, wijzigingen en applicaties op technische cyberrisico’s, adviseer je over beheersmaatregelen en compliance (DORA/AVG), rapporteer je aan management en ondersteun je incidentrespons.
Rijksoverheid
4.132 - 6.275
Medior
Den Haag
Als Financieel beleidsmedewerker bij directie HO&S organiseer en voer je financiële processen uit, coördineer je subsidies en opdrachten, bewaak je voortgang en betalingen, ondersteun je Kamervragen/begrotingsdebatten en ontwikkel je richting...
Ministerie van Financiën
4.818 - 7.956
Medior, Senior
Den Haag
Als Operationeel Risicomanager bij het Agentschap adviseer je over operationele en IT-risico’s, coördineer je de Corporate Risk Assessment, voer je interne controles uit, versterk je business continuity en begeleid je...
ING
10.754 - 16.947
Senior
Amsterdam
As a Technology Chief Information Security Officer (Tech CISO) at ING, you lead cybersecurity across the CTO domain, translating global security strategy into secure-by-design engineering, risk governance, compliance, metrics, and...