O mais recente relatório da Agência de Segurança Cibernética e Infraestrutura dos EUA (CISA), intitulado “A Tale of Two SOCs“, revela que sistemas de segurança podem falhar mesmo com amplo financiamento, caso não haja analistas treinados para responder aos alertas de forma eficaz.
O mais recente relatório da Agência de Segurança Cibernética e Infraestrutura dos EUA (CISA), intitulado “A Tale of Two SOCs“, revela que sistemas de segurança podem falhar mesmo com amplo financiamento, caso não haja analistas treinados para responder aos alertas de forma eficaz.
Em contexto
- Tema: Ciberseguridad — Riesgo, identidad, respuesta a incidentes y cumplimiento.
- Fonte: CISO Advisor
- Publicado: 25/08/2026
Continuar lendo na fonte original →
Trecho publicado automaticamente pelo radar do site. O texto completo pertence ao veículo e está vinculado acima.
Why it matters
Most incidents that end up being expensive did not start with a sophisticated technique. They started with an account that should have been closed when somebody resigned, a server nobody knew was still on, or a broad permission granted to unblock someone that then stayed forever.
I separate technical risk from business risk, because they do not always match. A critical vulnerability in an isolated system matters less than a medium one in the system that issues invoices. Prioritising by severity without looking at where the money is is an expensive way to work hard and protect little.
What usually goes wrong
Where it usually breaks is response, not prevention. There are tools, there are alerts, and when something real happens nobody knows who decides to disconnect, who gets called first, or what the customer is told. Valuable hours get lost arguing about that while the problem grows.
What to watch
- What could be restored and how fast — a backup that was never tested does not count.
- How it was communicated to customers and regulators, which is where reputational cost is decided.
- Whether third parties or suppliers were in the chain, because the perimeter now includes partners.
How I read this entry
What I would review this very week is access: accounts belonging to people who left, permissions that grew without anyone trimming them, and shared credentials everybody swears do not exist. It is the least glamorous work and the one that cuts off the most attacks.
The original story is published in another language; the excerpt is quoted as the publisher delivers it and the commentary is written in English.
Living through this in your own team?
Open the chat and tell me how you're handling it. I'm interested in comparing notes.