Stopping Attacks, Smarter Identity, and Edge-First Security – Tech Field Day Takeaways
At Security Field Day, Tom Hollingsworth and the Tech Field Day delegates explored how DNS defense can disrupt modern attacks, why centralized identity management reduces risk and friction, and how security must move beyond the traditional perimeter as users and data shift to the cloud. We also welcomed new companies like Square X and 1Password, fresh voices like Sarah Nolan and Kate Scarcella, and industry veteran Alan Shimel, all bringing unique insights to the discussion. Watch the highlights and dive deeper into the future of enterprise security.
Transcript
I'm Tom Hollingsworth event lead here at Tech Field Day, and here are my takeaways from Security Field day 14. Hi everyone. We just finished up a wonderful event security field day 14, and it was full of great conversations about all kinds of facets of security, whether we're talking about securing our users and their identities, or ensuring that your enterprise is running on the best possible security options available.
We had a little bit of everything for everyone. We even got to throw in a great delegate round table discussing all of the aspects of policy enforcement, but I figured if you don't have time to watch all of the things that happened at Security Field Day, you just need the big takeaways, and that's what we're here for today. So here are my three big takeaways from Security Field Day Attacks are more sophisticated than ever and they're relying on more and more services as outlined in the presentation from info blocks.
Finding ways to disrupt the infrastructure that attackers are using can reduce the impacts of those attacks. This includes things like identifying domain registrations and blocking DNS lookups to help alleviate the issues. You've probably seen this yourself with some very complex attacks that reuse assets from a number of services to make those login boxes look legitimate.
And as we saw in one of the presentations that dealt with threat hunting, in some cases, they are pseudo legitimate because you type your username and password into the box and it passes that through to a login prompt. It just so happens to borrow that information and drop it somewhere else as your, uh, you're moving along. And I think that this cannot be underestimated enough.
The scale and complexity of the attacks that are going on today require reliance on those other services, things like those crazy jumbled up DNS entries that you see in the system that are allowing you to go places that look legitimate. If you're not looking at the URL, it really underscores how important it is to have control over all of the services operating in your network. DNS is probably the, the one that most people are the least familiar with that has the most impact on the way that your security posture can operate.
And I highly recommend checking out the presentation from Infoblox because they go into the kinds of depth that you really should be looking at your infrastructure and understanding how you can alleviate these potential attacks. Identity management is all about reducing friction. One password showed how integrated solutions can help reduce friction that users feel when they're trying to authenticate to systems.
More importantly, centralized identity management means smaller attack services and things like shared passwords and logins or even SSH key sharing can have an impact on that. Having a robust infrastructure leads to happier users and better overall hygiene. Anyone who's ever used SSH keys to log into a remote server knows that if you are able to get ahold of those, there's no prompt or login, you are immediately authenticated.
And if someone is looking for those kinds of keys or other keys in the system, they know that if they can find them and purloin them, then what you get out of it is someone who can trigger an attack and you might not even know what's going on. And there is this constant push and pull in the industry. Do we want to use centralized identity management?
Do we want have something more distributed? Do we wanna make this something that the enterprise security admins have more purview over? Or do we wanna leave it up to the users to implement new functionality and features such as pass keys, which are probably inherently more secure than your average run of the mill password system, but do require different kinds of setups in order to be able to manage them effectively like you would from any other kind of enterprise solution?
It's important to understand that you have to challenge your users and understand the way that they're using the systems before you can implement one of these kinds of systems to deal with the, uh, never ending sprawl of passwords. And you have to make sure that you're using good hygiene. And I'm not just talking about setting your passwords to expire every 90 days.
I'm talking about keeping track of what's out there, how often your users are changing their passwords and what they're changing them to or encouraging other kinds of multifactor authentication like biometrics and or, you know, um, authenticator apps. Because if you don't use them in concert with your known secrets like passwords, you're gonna find yourself quickly getting violated when the attackers who have more advanced technical means are on top of you and trying to get the things that matter to you. The most.
Traditional security architecture is undergoing a transformation. The idea of a traditional perimeter is quickly disappearing. Security needs to be close to the edges of what we consider to be our traditional model thanks to all of the services that are moving into the cloud and the users that are effectively moving away from our traditional enterprise networks.
Solutions need to address where the users and the data live, not where we hope that they end up. Enforcement points continue to be a challenge that need to be planned out in advance and not just spread everywhere. And if you looked at the presentations that we got from HPE and from Nile, they understand this too.
HPE is what I would consider to be more of a traditional networking security architecture. They are using things like SRX firewalls and they're using SD WAN to help connect users that live on the fringes of your network, possibly even working from home and giving them the same kind of experience that they get in the enterprise while also keeping them safe. And if there's anything we've learned over the last few years when it comes to remote work, not all traffic is the same.
My traffic for work related items needs to take a priority over my child's Xbox doing an update for the big game that they bought last week. Not only do we need to make sure that that traffic is being scanned correctly and all of the policies that my corporate security use are put in place, but it needs to ensure that the rest of the traffic on my network is able to flow unimpeded without impacting my productivity. When you get to something like Nile, they're using network as a service, as a model where they come in and they make sure that everything is configured properly for what they're doing.
That can even cause your network security and operations teams to have to take a different look at the way they're doing their security, more policies being put in place and more strictly defined so that when they're implemented, it makes a huge difference to people as they're trying to figure out how best to keep our users safe. And we actually had a great conversation with one of Nile's customers, jet Zero, about how it's enabling them to have good connectivity, but also keep their research and their product information secure from people that might want to take it. We were very excited to have some new people joining us at the event.
Uh, some of our new companies included Square X and one password. We were very happy to have them featured for the first time. We're also very excited to see new delegates like Sarah Nolan and Kate Scarcella who were able to jump in with both feet and really had a lot to add to the conversation.
And we loved the ability that they could bring their security expertise to our lineup of new and old presenters. And we were also thrilled that Alan Shimmel could join us for the event. com and clicking on the link for Security Field Day.
You can also subscribe to our YouTube channel and you'll get notified whenever those videos are posted. Thank you very much for watching this episode of Tech Field Day takeaways on the Tech Field Day plus YouTube channel. If you enjoyed it, please be sure to like, subscribe and share your thoughts on Security Field Day.
In the comments and on the comments of our videos, be sure that you follow Tech Field Day on X and Twitter, blue Sky and Mastodon for more updates. And check out all of our presentation videos from every one of our events on the Tech Field Day website and Tech Field, a YouTube channel. Our next event is Tech Field Day exclusive with Microsoft Security on October 9th.
Make sure you check out our website for more details on the schedule and topics. Tune in live also on our LinkedIn page and on Techstrong TV for all the details. Thank you very much for your patronage of Security Field Day and I can't wait to see you at our next event.