Golden Time

In the Army, we defined “Golden Time” not only as the period around sunrise or sunset, but also as the time when the watch changes shift, or when one unit replaces another.

“Golden Time” was always a time when increased vigilance and readiness were imperative because most attacks occur during this time.  

Typically, sunrise and sunset are the times of day when people – whether in the military or in civilian life – tend to be less alert. Such a lapse in alertness can easily happen when one army force replaces another.  

The departing force’s duties and responsibilities are transitioning a new force. They’re tired and ready to leave. The replacements are still getting used to the base; learning more about their new duties and schedules; and can be less attuned to potential danger. Fortunately, experienced command and planning units prepare and execute meticulously to make sure each force turnover happens efficiently, vigilantly, and with the least amount risk.

Risks During Transitions to the Cloud

Similar scenarios play out for many of today’s businesses during digital transformation and in particular, during the transition to the cloud.  

In cloud transitions, the goal is move business processes from an on-premises environment to a cloud-based environment. Inevitably, as the transition progresses, some business processes are fully transferred while others are still in flux. It’s during this period of the turnover that incident response playbooks are no longer relevant.  Reality has changed.  The new environment doesn’t reflect the one the playbook was written for, and the threats to the new digital footprint are not addressed.  

Also, while it is the case that most of the company’s IT/security resources are proficient with the on-prem environment, they most likely will not yet fully understand the new technology within IaaS, PaaS and SaaS, making it very hard to respond efficiently to incidents.  

Additionally, while in transition teams might not have the right event logs connected to the SIEM and/or understand how to correlate between the events to monitor suspicious activity. And given that there will be a lot of duplicated business process on-prem and on-cloud for a period of time, it will be complicated to understand if a breach happened and impossible to track lateral movement as any breach could start on-prem and move to the cloud and vice versa.  

This is the ‘best’ time for attackers to make a move against an organization. Most organizations transitioning to the cloud do it over a year or more, leaving a lot of opportunities for adversaries to act.

What should you do?

Times like cloud transition require extra caution and precise tracking of business processes that are migrating to the cloud. It is necessary to validate if a process still exists on-prem or not. Care must be taken to ensure security settings don’t open new holes and breaches. Information (logs) being saved and monitored must be validated for completeness, so that when something happens, there is enough to run an investigation. Training and evaluation is essential to ensure that cloud security and hybrid incident response skills are present in the organization and among suppliers. This is vital now more than ever before since it is very hard to hire new resources with cloud security knowledge.  

What are the top five new security challenges in cloud environments?

LAST UPDATED:

May 3, 2024

Don't miss these stories:

5 Common Threat Actor Tactics Used in Cloud, Identity, and SaaS Attacks

Explore five common tactics used in cloud attacks and recommendations on how to defend against them.

Tactical Guide to Threat Hunting in Snowflake Environments

It was brought to our attention that a threat actor has been observed using stolen customer credentials to target organizations utilizing Snowflake databases.

Unlocking Cloud Security with Managed Detection and Response

See how Mitiga’s Cloud Managed Detection and Response tackles complex cyber threats with proactive threat management and advanced automation at scale.

Rethinking Crown Jewels Analysis: Mitigating Cybersecurity Bias

Uncover the risks of bias in Crown Jewels Analysis (CJA) and learn strategies to protect your organization's most valuable assets with a comprehensive approach.

Microsoft Breach by Midnight Blizzard (APT29): What Happened?

Understand the Midnight Blizzard Microsoft breach by APT29, what happened, and key steps organizations should take to strengthen their defenses.

Understanding Lateral Movement Attacks in Hybrid Environments

Learn how lateral movement attacks pose serious risks in on-prem, cloud, or hybrid environments, and discover effective strategies to mitigate these threats.