News, Releases, Events

Tsikada Holding Took Part in the “Security Territory: All About Information Security” Forum

This year, the holding acted as a forum partner, participated with its own exhibition stand, and presented an expert talk as part of the conference program. The presentation focused on "Managed Compromise: How to Build Infrastructure with Controlled Attack Consequences."

The attacker is already inside the infrastructure: an attack takes 12 to 24 hours to develop, legitimate accounts are used in 60−80% of cases, and recovery of critical systems can take from 3 to 14 days.

We are used to protecting the perimeter, but the attack is already inside. Budgets are spent on perimeter defense, while internal interactions within the infrastructure remain uncontrolled.

Pavel proposed a shift in paradigm: instead of fearing compromise, organizations should manage it as a standard scenario. The attacker chooses the entry point, but the scale of the consequences is determined by the architecture. Using the example of a major customer with a vulnerable video conferencing service, he showed how an attacker used architectural weaknesses to disrupt business operations.

The key takeaway: compromise is not just a risk, but a scenario that must be managed
Made on
Tilda