Cyber attackers are becoming increasingly adept at evading enterprise defenses in order to secure lucrative rewards from businesses desperate to recover.

It is therefore key that security teams work proactively to identify vulnerabilities and be able to effectively leverage techniques such as pen testing, red/purple teaming and breach attack simulation.

Security testing, or offensive security, is as important as an organization’s security tools, especially as malicious actors turn to AI to refine their attacks.

According to Foundry’s CSO Security Priorities Study, a quarter of organizations are weighing up additional spending on third-party security evaluation services.1

This reflects an increasing emphasis on offensive security. “It is the only way to stay ahead of the attack,” warns Sharon Nimirovski, a cyber strategy consultant at EPAM.

Penetration testing exposes technical shortcomings, including misconfiguration, unpatched vulnerabilities and gaps in defenses, and is increasingly mandated by regulators.

But although it is a well-understood approach to security, pentesting can lack the flexibility needed to tackle more acute threats. “It’s not outside the box thinking,” he says.

Next level

Red team exercises go further, simulating how an adversary will attack the organization’s system, adapting their tactics and taking the initiative to bypass defenses.

A professional offensive security consultant will, of course, agree rules of engagement with the client ahead of the exercise, but the process is far more dynamic than a pen test.

“It’s a proactive approach to security. It’s performed to reveal security issues before the bad guys do it,” explains Andrei Dzesiatsik, Head of EPAM Offensive Security. “We explain to the stakeholders what we have found, why it is important, and what risks it brings.”

By pitting offensive teams against an organization’s blue, defensive teams in real time, CSOs will learn how their people will react to a fast-moving cyber attack. These exercises, also known as “purple teaming”, produce real insights into an organization’s resilience, as teams adapt to changing threats.

A third offensive tool, breach and attack simulation, or BAS, uses information on new and emerging threats found on the dark web, together with details of the business’ own systems and defenses. Bringing these elements together uncovers the threats likely to pose the greatest risk.2

BAS can be automated, but a trusted consultant will go further than just list vulnerabilities. They will recommend for remediation, based on the organization’s current security tools.

Layers of testing

Taken together, these offensive security measures will do more than find weaknesses. They expose where security teams lack visibility across their systems, but also where security tools are producing too much information.

“Alert fatigue means that attackers know defenders have too many incidents they need to analyze, and can blind them even more before a real attack,” warns Nimirovski.

CSOs and CISOs are increasingly concerned about security teams becoming overloaded by excessive volumes of alerts, something attackers are looking to exploit, not least through AI.

And AI itself is causing IT security teams to look more closely at offensive security measures. AI systems can harbor security weaknesses that are not always obvious during deployment. A red team has the flexibility to try different methods to find those flaws.

And, as Nimirovski points out, AI is also being used to improve defenses, for example by summarizing security reviews for code and automating fixes.

“I haven’t seen an AI hacker yet, because it’s not about the data, it’s about the way of thinking,” he says. “On the defensive side, I see automation moving to AI. It’s happening already.”

As AI embeds itself in modern enterprise, it’s vital security leaders master the breadth of offensive security approaches to ward off attackers.


1 Foundry, Security Priorities Study, 2024

2 EPAM, Breaking Down Two Techniques to Stay Ahead of Cybersecurity Threats


Share
Share