Skip to main content
Guidance

How to prepare for and plan your organisation's response to severe cyber threat: a guide for CNI

Act now to be ready to withstand and recover from severe cyber attacks.

Page 9 of 26

2.1 Increase monitoring of threats and network activity

Organisations need to accept that increased monitoring means there will be an increased volume of alerts and greater sensitivity within security appliances. It is useful to consider where you can uplift your resources to assist triage activities.

To limit security risks, you should ensure protocols used within and between your network environments feature data formats that enable simple validation of both the protocol and its data. Use schemas to inspect and verify protocols and data payloads at key trust boundaries. In addition, since introducing change within operational networks can raise concerns about possible effects on safety or availability, developing and testing this validation in advance helps minimise those risks and reassures stakeholders that the system will remain stable.

There are several ways you can increase your threat monitoring, and further guidance to consult:

Activity to increase monitoringHow it helps
 
Use External Attack Surface Management (EASM) tools to help identify, monitor and reduce vulnerabilities within your assets.

To identify, monitor and reduce vulnerabilities.

Undertake proactive (rather than reactive) threat hunting.

To identify cyber threats which have evaded your existing security controls:

  • Refer to CAF Principle 2 on threat hunting. 
  • Use log file analysis to support this.
  • Regularly test whether your logs provide the information needed to respond effectively. 
  • Validate your detection capabilities using, for example, simulated compromise exercises. 
Monitor network traffic patterns in both on-premises infrastructure and cloud-hosted systems.

Logging and monitoring helps you identify patterns of activity, which in turn provide indicators of compromise (IOCs).

For OT networks, implement additional monitoring.This is important because OT traffic volumes are typically much lower and use specific protocols. Therefore anything outside of the expected traffic baselines could be an indicator of a possible OT network compromise.

Published

Reviewed

Version

1.0