Cybersecurity: ‘Whodunnit’ Is Much Less Important Than ‘What Do We Do Now?’


A strange shift has occurred in the world of cybersecurity media coverage. It used to be that journalists covering data breaches focused on what types of data were taken and what kind of damage the event would cause the company. These days, when a major data breach occurs, who committed the breach often takes the spotlight away from the more important fact of how it was achieved. There are more important questions than “whodunnit” when it comes to network breaches and data theft.

Asking The Right Questions

When your system is hacked, there are five questions that are more important to ask than who was responsible:

1. What Was The Means Of Entry?

Network visibility is essential. If security managers have a real-time view of every connected device, every authorised user and how secure each device is, they have a better chance of pin-pointing where are the weakest links in their armour.

2. What Can Be Done To Fix It?

Repairing the damage is more important than placing blame, and speedy remediation is dependent on good visibility. The faster you can see and determine the size of the rip in your safety net, the faster it can be repaired. Companies have a clear fiscal incentive to minimise downtime, so this element is critical to running a business seamlessly.

3. How Much Was Stolen?

It can take an agonisingly long time to determine the scope of a data loss. This is especially damaging when a data breach affects consumers. Quantifying the breach with speed and confidence causes an affected company less harm in the long run.

4. Are We Still Compromised?

After a breach has been detected, a lot of energy is put into stopping and assessing the extent of the impact. However, without proper visibility, most companies are left wondering if they are still being breached – that is, whether the attackers left undiscovered backdoors that will allow them back into the company’s systems later, when the incident response goes down.

5. What Can We Learn From This?

To ensure that the same infiltration tactic never works twice, cyberdefences must evolve: intelligently, automatically and rapidly. Pragmatic, real-world defence depends not on making a network impenetrable, but on making it so challenging to crack that most attackers will eventually move on to easier targets.

Asking these five questions is more complex and time-consuming than merely asking “whodunnit?” but they zero in on the key information needed to mitigate and prevent cyberattacks.

Keep Your Focus, Defend Your Network

It’s human nature to want to solve the crime and capture the attacker. But in cyberspace, being able to pinpoint the identity, location and sponsor of the attack is often a waste of energy. Instead, focus on creating dynamic defences that make hackers’ lives so difficult that they turn away in favour of an easier mark. Yes, there’s something satisfying about being able to say “whodunnit,” but when it comes to defending your network, attribution is merely a diversion.

Pedro Abreu

With more than 15 years of business experience in the high-tech industry across Europe and North America, Pedro Abreu brings a deep understanding of all go-to-market aspects to his role of Chief Strategy Officer at ForeScout, along with knowledge of building highly effective teams and developing strong relationships with clients and stakeholders.