Hello everyone,
During the analysis of our log data archives scheduled by the marketing team at short notice, it was unfortunately noticed that none of our AI models have yet broken out and stolen data from you. However, we are continuing to work at full speed to change this. 😉
To make the waiting time until then entertaining, here are a few posts and resources that have reached my inbox (and thus yours) in the conventional way:
A Tale of 2 SOCs: Nice title for one of the rare CISA reports on their Red Team Assessments, again with very helpful lessons learned and this time with evaluation of the SOC teams. Example A:
- Initial Access is very old-fashioned (Default credentials in a web app => Phishing emails are then sent from an internal email address => Bingo)
- Misconfigurations found on one endpoint (MAQ = 10) and in ADCS (certificate templates) => access to virtually all clients => passwords found for databases and applications on workstations
- Applications with high application permissions used to compromise Entra ID (presented in great detail, via a cascade of refresh tokens)
- There is also some advertising for Microsoft Conditional Access for Workload Identities at this point in the report
- SOC Team ignored the EDR messages (all medium / low severity) because there were thousands of other higher priority messages during the same period, most of them false positives
- In addition, unclear responsibilities, interfaces and probably at least 2 different EDR tools (presumably for clients / servers or different business units). In one case, something was noticed, but the investigation was stopped because no person responsible for a server could be assigned.
Â
It is certainly worthwhile to discuss the scenarios with your own team. In any case, in my opinion, grist to the mill of the advocates of impact-based remuneration components.
At this point question to the community:
- When introducing a SIEM/SOC, a major driver of the time required is the baselining + tuning to the customer-specific environment to improve the signal-to-noise ratio (which was obviously insufficiently done in the above example).
- Examples of typical false positives: backup jobs, PS scripts, remote access tools, service accounts, tool downloads from SW developers…
- What approaches are there now (through Gen AI?) to further automate and shorten this phase?
Interesting figures from BaFin on ICT incidents in 2025 that became reportable under DORA last year:
- Approximately 500 independent incidents reported with ~1200 organizations affected. 60 of these were cross-incidents involving multiple organizations (supply chain)
- Of these, 11% were successful cyberattacks (the other 89% were operational disruptions, e.g. at payment service providers or due to SW updates)
- Simple rule of three:
- BAFIN regulates approx. 3,500 institutions in Germany (excluding individual funds, i.e. mainly banks / credit institutions, insurance companies, leasing companies, capital investment companies).
- Approximately 3% of financial institutions were therefore affected by at least 1 reportable successful cyberattack within 1 year – many of them via affiliated service providers, of course
- If anyone has discovered more precise data sources or a mistake in thinking, please let me know
Â
The BSI has provided training materials for the training of critical infrastructure auditors . Didactically valuable are in particular. the exercises with solutions for scope, asset management, risk analyses, attack detection (simple log analysis) and lists of deficiencies – thank you, someone really made an effort!
Again, my appeal is to please collect good practices and audit results anonymously and make them publicly available in order to make the entire audit/certification business more calibratable and automatable.
It’s unbelievable that every auditor still builds his personal repository and the ratings are so individual, isn’t it? The timeline, podcasts and news are full of opinions about powerful AI agents, their hidden messages and the impending end of humanity. But probably the last refuge for human work is not the plumber, but the basic security audit.
Â
A Pipelab employee (Pipelab: OSS Agent Guardrail), whose job is to prevent exactly such misconduct, has published a few easy-to-read tips for avoiding false positives during monitoring.
- Examples:
- Agent reads the documentation of a vulnerability scanner with all possible descriptions of CVEs and attack patterns
- Input of error messages such as “Token Expired, 401 unauthorized”
- Inconsistent account names for different systems => Perceived as a concerted action
- Why interesting? Without appropriate tuning, important alarms were quickly ignored by the SOC teams, see above.
Â
However, AI can not only break out uncontrollably, but sometimes even simply do its job. Says Prophet (provider of AI SecOps, reference customers including BorgWarner + Rubrik) and advertises ~50% savings potential compared to conventional MDR contracts with at least the same monitoring quality.
Â
The highlight of pricing: Billing according to the number of alerts examined, not according to log volume or number of endpoints. Of course, a breach warranty or similar would be even more convincing. Nevertheless, it is interesting as an extended workbench for smaller MSSPs and in-house SOCs.
Â
And if you need to rewallpaper or are looking for a large-format poster, you will find original patterns at Wiz: For example, a comparison of the logging capabilities of common VCS systems (Github, Gitlab, Bitbucket and AzureDevops) and recommendations for secure settings (e.g. WebHooks for event push). Mapping on MITRE ATT&CK. However, when printed on DIN A1, I now need reading glasses.
Â
M&A Headlines:
- No idea what Cyera (Data-/AI-Sec) is doing with all the money, maybe the next purchase is already planned after Oasis . In any case, there is another 400 million USD, so this year already more than 1.4 billion in new funding, with a rumored valuation of 12 billion USD
- Exein (firmware security for IoT devices using eBPF sensor from Italy) receives 270 million USD at a 1.7 billion valuation. Very cool European success story – never thought it would be so huge, you never stop learning. Asian chip and ECU manufacturers are probably big customers by now
- Ontinue (MSSP specializing in MS Stack) is bought by competitor Quorum . Total approx. 500 employees
- Cylake (Next Gen On Prem Security “for the largest and most regulated organizations”, a few weeks ago under this heading) collects another 250 million USD in funding
- Quantinuum (Quantum Key Distribution as a Possible Mechanism for Future Key Distribution) Receives $100 Million Research Grant from the U.S. Dept. of Commerce
- Proofpoint (owner Thoma Bravo) is apparently talking to Varonis about a takeover, and the share price has already reacted. All the more interesting because Proofpoint had to grant significantly better conditions for the new bonds in the recent refinancing round (> 9% interest). Apparently, business is booming.
- Kiteworks (secure data exchange) buys Bonfy (DSPM+DLP)
- Cymphony.IO (Identity + Access Mgmt., s.u.) erhält 25. MIo. USD u.a. von Sequoia
- Hackuity (RBVM of France) raises ~$19 million in a Series B
- Harvey (Legal Tech) kauft Guardrails.AI (…)
- Jamf (Apple MDM) kauft KeepAware (Browser Sec)
- SonicWall (founded in 1991) has once again narrowly escaped corporate death by means of debt restructuring: Excessive over-indebtedness through PE meets declining sales due to the cyber attack and accumulation of vulnerabilities in the firewalls. Without the interest burden, however, the company would still be highly profitable – after all, around 17,000 channel partners also have an interest in maintaining it.
Â
Notes from vendor conversations:
Â
Auticon:
- IT consulting (SW development, data science, compliance, infosec) with approx. 450 employees worldwide (headquarters in Germany), all consultants neurodivergent. Of course a brilliant idea, once again annoyed with myself that I didn’t have it
- Ideal: Remote activities and tasks that require a high level of concentration, have high demands on care (e.g. pen tests, detailed audits, forensic analyses, detection engineering, threat hunting), own time management
- Unfavorable: Firefighting in acute incidents, short-term postponements, sudden demands, vague work instructions, travel + face-to-face appointments (exceptions prove the rule, of course)
- ~500 customers advised in the last 15 years, many corporations + authorities, including Siemens, Zurich, Infineon, Ergo, Henkel. Daimler. Hypovereinsbank, Sanofi. Also looks good in the sustainability report (was openly mentioned as a sales argument)
- Consulting teams are supported by “job coaches” who have IT project management experience, but especially help with communication and team management with customers. Interestingly, the job coaches are largely financed by inclusion offices, so they do not have to be paid by customers
- Sympathetic team, feel free to take a look / inquire, certainly also interesting for MSSP (Auticon does not offer managed services itself)
Â
Xorlab:
- Swiss provider for email security (inline gateway with sandbox for MS Office + pdf file attachments)
- Already ~150 corporate customers, including Swisscom, Vontobel, Haufe, Schweizer Post, Zürcher Kantonalbank. Many KRITIS operators use the solution as a supplement to Microsoft or alternatives as a 2nd filter
- Context analysis (ML of email traffic based on metadata such as typical connections, urgency, content). Of course, demanding in terms of data protection
- Analysis of mails delivered but subsequently reported as suspicious by users => Depending on the implementation, it can then also be automagically deleted in other mailboxes
- On prem / SaaS or hybrid (on prem + M365) in the same functionality
- Licensing based on number of personal mailboxes
- As an interested party, you can also be bombarded as a stress test to check the tightness of the current mail filter, no prior allowlisting necessary
Â
Cymphony:
- Startup around Data & Identity Sec (“AI Readiness”), Israeli founders, HQ USA, customers e.g. Syngenta and KKR (currently no customers in the EU yet)
- Connects to all relevant data sources, security, IdP/IAM and ITSM tools. Focus currently still on SaaS, on prem requires additional effort
- Automatic data classification based on content checking, data traffic, user behavior
- Access Graph, of course also for AI applications => detection of exposure
- Countermeasures (deletion of data, access restrictions) based on risk calculation can be triggered and tracked in the tool itself => Depends on the integrations, of course
- Forensics / Access Tracking
Â
As always, nothing here is AI-generated. Questions, suggestions, comments, experience reports, topic requests and also opposing opinions or corrections are welcome by email. Ditto for unsubscribing from the mailing list.
Â
For the people who have received the market commentary for the first time: Here you can register if you are interested or socialize the archive.
Best regards,
Jannis Stemmann
