

You’ll need to rewind the clock as you search for evidence of compromise as a result of the SolarWinds Orion breach.Now let’s dig into some observations and recommendations: In turn, that helps our customers and any impacted businesses, in general, better understand their own risk as they navigate their way through this mess. That transparency helped the entire cybersecurity industry understand the technical nature of the attack and begin to wrap our arms around the broader business impact to our customers. These orgs continue to be transparent on the technical and mission aspects of this attack. With a few days hindsight, we wanted to take a breath and offer some observations on how things are going, what we can expect going forward and how organizations everywhere should be thinking about detecting post-compromise malicious activity.īefore we dive into the “here’s what we’re seeing and how you should plan for the long haul,” let’s take a minute to applaud the leadership shown by FireEye, Microsoft and CISA. The revelation of SolarWinds’ Orion monitoring product being compromised by nation state intelligence is keeping a bunch of people very busy heading into the holidays. Well, 2020 is really going out with some fanfare, isn’t it?
