Closing_the_Operational_Security_Gap

Published on
Embed video
Share video
Ask about this video

Scene 1 (0s)

TRUEPATH IT + TECMA Closing the Operational Security Gap A Business Case for the TruePath Expanded Co-Managed Security Program Executive Leadership Briefing I September 2026.

Scene 2 (4m 59s)

[Audio] The company experienced significant disruptions due to cyber attacks on its systems. These disruptions lasted for three days and affected various aspects of the business including operations, productivity, and financial performance. The attackers exploited vulnerabilities in the company's endpoint and identity management systems, gaining persistent remote access and taking control of a key Microsoft 365 account. This incident highlights the limitations of traditional perimeter-based security measures. The breach demonstrated that even the most secure systems can be compromised if they are not properly configured or maintained. The attack also showed that advanced threat actors can exploit weaknesses in multiple vectors simultaneously. The impact of the breach was substantial, resulting in a loss of $426000 annually in top-line revenue exposure and $35,500 per month in lost productive labor. The total cost of the breach was estimated at $426000 per year, which is equivalent to the annual operating costs of the company. A strategic upgrade to the company's security program is recommended to address the exposed gaps in its defenses. This would involve implementing new technologies and processes to improve the overall security posture of the organization. The proposed solution would provide a more robust defense against future threats and help to mitigate the risk of similar breaches occurring in the future..

Scene 3 (5m 5s)

[Audio] The company experienced a series of breaches that compromised their operations due to persistent remote access and a hijacked Microsoft 365 account. These breaches occurred across two vectors: endpoint and identity. The breaches highlighted the need for enhanced security measures to protect against sophisticated threats. Tecma's expanded co-managed security program offers a strategic solution to close exposed gaps and mitigate risks. This program resulted in significant cost savings and productivity gains. By implementing this program, Tecma can effectively address its operational security gap and ensure business continuity..

Scene 4 (5m 48s)

[Audio] The company has experienced significant disruptions due to a security breach. The breach occurred on a Tuesday morning when an employee accidentally left a laptop unattended at a coffee shop. The laptop contained sensitive information about clients and was stolen by a thief who had been watching the employee's activities. The thief then used the stolen data to commit identity theft against several clients. The incident highlights the importance of having a robust security program in place to protect sensitive information. The breach caused significant disruptions to the company's operations. Staff were pulled away from their normal duties to recover systems, leading to interrupted client work and operating backlogs. The company's top-line revenue exposure model provided a clear picture of the financial impact, with estimated losses of $945000 over three days of disruption. This figure represents the quantifiable revenue exposure, but also includes the unquantified friction of lost labor and delayed client deliverables. The incident demonstrates the need for a comprehensive security solution to prevent similar disruptions in the future. A robust security program would help to mitigate the risks associated with data breaches and protect sensitive information. The company should consider investing in a TruePath Expanded Co-Managed Security Program to address its security needs..

Scene 5 (7m 18s)

[Audio] The threat landscape is escalating, with attackers increasingly using stolen credentials and legitimate software to bypass traditional perimeter defenses. This shift has resulted in faster-than-ever average times between initial access and lateral movement. In fact, the fastest observed case of lateral movement was achieved by A1, who used stolen credentials and legitimate software to breach our systems. Furthermore, the percentage of detections that are malware-free continues to decline, indicating a growing sophistication among attackers. With attackers now able to bypass traditional defenses so easily, it's clear that we need to rethink our security approach. That's why we're exploring a co-managed security program, like the one offered by TruePath, to help us stay ahead of these threats. By partnering with TruePath, we can leverage their expertise and technology to close the operational security gap and protect our business from these evolving threats..

Scene 6 (8m 22s)

[Audio] The attackers exploited two primary vectors to gain access to Tecma's systems. Firstly, they used the endpoint vector, ScreenConnect, to install legitimate remote control software that created a persistent backdoor. This allowed them to maintain unauthorized remote access to the systems even after the initial breach. Secondly, they utilized the identity vector, M365, to gain access to the systems. They used valid credentials to log in from a foreign country, Nigeria, and then bypassed the network firewalls entirely to weaponize internal communication routing. This allowed them to hijack the company's Microsoft 365 account and use it to spread malware and carry out further attacks. The attackers exploited these vulnerabilities to gain access to the systems, create a persistent backdoor, and maintain unauthorized remote access..

Scene 7 (9m 21s)

[Audio] The TruePath Expanded Security Program has been designed to provide comprehensive security measures to protect our organization from various threats. This program includes several key components, such as 24/7 SOC monitoring, M365 protection, MFA enforcement, email security, and user secure human risk training. These measures will help us to identify and mitigate potential security risks, ensuring the integrity of our systems and data. Additionally, the program includes dedicated engineering hours to address any issues that may arise and ensure the separation of our networks. By implementing this program, we can significantly enhance our overall security posture and reduce the risk of security breaches..

Scene 8 (10m 14s)

[Audio] The TruePath Expanded Co-Managed Security Program has identified several key security gaps that need to be addressed. Our Vector Mitigation Matrix highlights the exploited vectors that have been used to gain unauthorized access to our systems. These include endpoint persistence, cloud identity/M365, social engineering, and September incident evidence. Specifically, we have seen malicious ScreenConnect installations on September 3rd and 15th, as well as unauthorized login and inbox rule manipulation on September 24th. Additionally, we have received 653 phishing emails sent from a trusted account, using a deceptive request such as "Documento para revisión". Our mitigation efforts focus on providing 24/7 SOC monitoring and 160 dedicated engineering hours to enable network separation and rapid containment. We also enforce Multifactor Authentication, advanced email security, and provide secure human risk management and anti-phishing training. By addressing these security gaps, we can close the operational security gap and ensure the continued integrity of our business operations..

Scene 9 (11m 30s)

[Audio] The organization has implemented a comprehensive cybersecurity strategy to mitigate risks associated with cyber-attacks. The strategy focuses on employee education and awareness, as well as implementing robust security measures to prevent unauthorized access. The organization also conducts regular security audits to identify vulnerabilities and address them before they become major issues. Furthermore, the organization invests in advanced technologies such as artificial intelligence and machine learning to enhance its threat detection capabilities. These efforts have resulted in significant improvements in the organization's overall security posture..

Scene 10 (12m 15s)

[Audio] The Co-Managed Responsibility Blueprint outlines the technical execution of the TruePath Expanded Co-Managed Security Program. This blueprint defines the roles and responsibilities of both TruePath and Tecma in maintaining security coverage and SOC coordination. Key aspects include tracking isolation, cleanup, and evidence of completed work, implementing approved changes, and reporting unresolved risks. Additionally, TruePath leads technical execution, while Tecma owns business authority, overseeing key areas such as assigning return-to-service decision-makers, providing access to affected devices, enforcing staff compliance with MFA and usecure training, and approving change windows, priorities, and funding. These components ensure a comprehensive approach to managing security and resilience..

Scene 11 (13m 11s)

[Audio] The company has invested heavily in its security measures to protect its data and systems from cyber threats. The annual investment to secure Tecma operations is equivalent to less than 1.5 days of revenue exposure. Inaction is not a neutral financial position; it is the acceptance of extreme, documented risk. The cost of securing Tecma operations is $426000 annually, while the potential loss due to non-security measures is $945000, representing 3 days of downtime. This represents a significant return on investment, with a payback period of approximately 2.2 years. Furthermore, the severe outage scenario, where Tecma's operations are compromised by persistent remote access and a hijacked Microsoft 365 account, highlights the importance of proactive security measures. By investing in our co-managed security program, we can mitigate these risks and ensure the continuity of our operations..

Scene 12 (14m 18s)

[Audio] The organization's current system is vulnerable to cyber attacks due to inadequate security measures. The lack of multi-factor authentication has left our systems exposed to unauthorized access. Our current incident response plan is incomplete and does not account for potential future threats. Furthermore, the existing remote access tools have not been properly vetted, leaving them open to exploitation. The organization needs to address these issues immediately to prevent further damage. To implement the necessary changes, we must approve the baseline investment of $35,500 per month. This amount will cover the costs associated with upgrading our security infrastructure and conducting regular security audits. We must also confirm the final incident cleanup and assign a designated decision-maker to oversee the implementation of new security protocols. In addition to these measures, we must enforce universal multi-factor authentication across all systems. This will provide an additional layer of security and protect against unauthorized access. We will also conduct mandatory user education training for all staff members over the next 30 days. Furthermore, we will deploy advanced email protection and conduct an audit to identify and remove any unapproved remote access tools. These steps are essential in ensuring the security and integrity of our systems. Over the next 90 days, we will conduct a thorough review of critical logs and network surveys to identify vulnerabilities and weaknesses. We will also initiate the first projects from the 160-hour engineering sprint for systemic network separation. This effort will help us achieve success by verifying resilience and maintaining uninterrupted productivity. We must prioritize the security and integrity of our systems above all else. By taking these proactive steps, we can mitigate risks and prevent potential breaches. We must remain vigilant and continue to monitor our systems for any signs of compromise. Only through concerted effort and dedication can we ensure the long-term security of our organization..