Managed Detection & Response
Always On – we ensure our customers’ resilience, 24x7x365
Read moreCyber Threat Intelligence
Word-class data, analysis and insights on threat actors and the evolving threat landscape.
Threat Insights Threat Intelligence Feeds Threat Monitors Cyber Defence FeedEmergency Response Retainers
Get a fast response from world-class experts and rapidly reinstate business continuity.
Read moreConsulting
Highly specialized services to identify and remediate complex risks and threats.
AD Health Check Compromise Assessment Emergency Response Penetration TestingWhat’s New?
Emergency Response
Read moreManaged Detection and Response (MDR)
Read moreBrand Protection
Anti-PhishingCyber Threat Intelligence
Threat Insights Threat Intelligence Feeds Threat Monitors Cyber Defence FeedCyber Threat Intelligence
Threat MonitorsManaged Detection and Response (MDR)
Read moreEmergency Response Retainers
Read moreConsulting
Emergency ResponseManaged Detection and Response (MDR)
Read moreCyber Threat Intelligence (CTI)
Threat MonitorsEmergency Response
Read moreManaged Detection and Response (MDR)
Read moreBrand Protection
Anti-PhishingCyber Threat Intelligence
Threat Insights Threat Intelligence Feeds Threat Monitors Cyber Defence FeedCyber Threat Intelligence
Threat MonitorsManaged Detection and Response (MDR)
Read moreEmergency Response Retainers
Read moreConsulting
Emergency ResponseManaged Detection and Response (MDR)
Read moreCyber Threat Intelligence (CTI)
Threat Monitors
Threat Intelligence Portal
- “Articles” and “Platinum Alert Service” will be merged into Threat Insights
- “CIRK” will be renamed Remote Forensics
- “Crimeware” will be renamed Investigation and will be upgraded with an IOC search interface, and an interactive Threat Cloud
- “Drop Data” will be renamed Compromised Data
- “PhishDB” will be renamed Anti-Phishing
Please see our press release for more information:
https://csis.com/csis-s-latest-news-and-announcements/csis-launches-new-threat-intelligence-portal/
Cyber Threat Intelligence
Cyber Defense Feed:
Managed Detection & Response
Explained:
The "Near Miss" is a classification specifically targeted towards providing more clear reporting to the customers. The "Near Miss" allows us to define incidents as successful or not without the severity classification change as a result.
A "Near Miss" is a potential incident in which there was no damage, privilege escalation, lateral movement, data leak, or significant security consequence, but where, given a slight shift in time, environment, or mitigations in place, damage or security consequences could have occurred. In short, a near-miss is a failed attack.
Further, the "Near Miss" classification will allow us to explain the potential impact of an incident, no matter the technical skill level. Likewise, the amount of failed attacks or near-misses against an organization can be utilized to determine both the threat-level that organization faces, as well as help, expose and identify if there are obvious weaknesses with security posture that are leading to a high number of near misses.
Concrete examples where “Near Miss” would apply (also see exemplary incidents at the bottom of the mail):
More generally:
CIRK
Other
Stay informed.
Get our Cyber Bytes!