homepage
Menu
Open menu
  • Training
    Go one level top Back

    Training

    • Courses

      Build cyber prowess with training from renowned experts

    • Hands-On Simulations

      Hands-on learning exercises keep you at the top of your cyber game

    • Certifications

      Demonstrate cybersecurity expertise with GIAC certifications

    • Ways to Train

      Multiple training options to best fit your schedule and preferred learning style

    • Training Events & Summits

      Expert-led training at locations around the world

    • Free Training Events

      Upcoming workshops, webinars and local events

    • Security Awareness

      Harden enterprise security with end-user and role-based training

    Featured: Solutions for Emerging Risks

    Discover tailored resources that translate emerging threats into actionable strategies

    Risk-Based Solutions

    Can't find what you are looking for?

    Let us help.
    Contact us
  • Learning Paths
    Go one level top Back

    Learning Paths

    • By Focus Area

      Chart your path to job-specific training courses

    • By NICE Framework

      Navigate cybersecurity training through NICE framework roles

    • DoDD 8140 Work Roles

      US DoD 8140 Directive Frameworks

    • By European Skills Framework

      Align your enterprise cyber skills with ECSF profiles

    • By Skills Roadmap

      Find the right training path based on critical skills

    • New to Cyber

      Give your cybersecurity career the right foundation for success

    • Leadership

      Training designed to help security leaders reduce organizational risk

    • Degree and Certificate Programs

      Gain the skills, certifications, and confidence to launch or advance your cybersecurity career.

    Featured

    New to Cyber resources

    Start your career
  • Community Resources
    Go one level top Back

    Community Resources

    Watch & Listen

    • Webinars
    • Live Streams
    • Podcasts

    Read

    • Blog
    • Newsletters
    • White Papers
    • Internet Storm Center

    Download

    • Open Source Tools
    • Posters & Cheat Sheets
    • Policy Templates
    • Summit Presentations
    • SANS Community Benefits

      Connect, learn, and share with other cybersecurity professionals

    • CISO Network

      Engage, challenge, and network with fellow CISOs in this exclusive community of security leaders

  • For Organizations
    Go one level top Back

    For Organizations

    Team Development

    • Why Partner with SANS
    • Group Purchasing
    • Skills & Talent Assessments
    • Private & Custom Training

    Leadership Development

    • Leadership Courses & Accreditation
    • Executive Cybersecurity Exercises
    • CISO Network

    Security Awareness

    • End-User Training
    • Phishing Simulation
    • Specialized Role-Based Training
    • Risk Assessments
    • Public Sector Partnerships

      Explore industry-specific programming and customized training solutions

    • Sponsorship Opportunities

      Sponsor a SANS event or research paper

    Interested in developing a training plan to fit your organization’s needs?

    We're here to help.
    Contact us
  • Talk with an expert
  • Log In
  • Join - it's free
  • Account
    • Account Dashboard
    • Log Out
  1. Home >
  2. Blog >
  3. Rekt Casino Revisited: Operational Series Part 4
Mark-Orlando-370x370.jpg
Mark Orlando

Rekt Casino Revisited: Operational Series Part 4

Pulling It All Together

April 2, 2021

This is Part 4 of 4 of our Rekt Casino Operational Leadership series, which itself is a sequel to our Transformation Series dealing with the same case study. You can read the other parts of the Operational Leadership series here:

  • Part 1
  • Part 2
  • Part 3

If you haven’t been following the Rekt Casino webcast series, let’s get you up to speed: Rekt Casino suffered a breach due to a ransomware attack. The Casino did not have an operational security capability in place to help it resist intrusions, maintain awareness of its weaknesses, or identify and respond to attacks.

In our fourth and final webcast of our series, we talked about how the three disciplines in the Operational Leadership Series – the Critical Security Controls, Vulnerability Management, and Security Operations- can come together to get Rekt on the path to a stronger, more proactive defense. These disciplines are part of the SANS Operational Leadership Triad:

  • SEC566: Implementing and Auditing the Critical Security Controls with James Tarala
  • MGT516: Managing Security Vulnerabilities: Enterprise and Cloud with David Hazar
  • MGT551: Building and Leading Security Operations Centers with Mark Orlando and John Hubbard

As we’ll see in this post, each of these disciplines provides a key element of the kind of defense that Rekt must now build in the aftermath of a major breach. We will also see that while each discipline represents a potentially massive undertaking in terms of time and investment, there are things we can do to build out basic capabilities we can expand and improve as Rekt’s new security program matures.

OperationalTriad.jpg

Building a Strong Foundation

Having discussed how each of these disciplines could have positioned Rekt Casino to defend itself more effectively, we can now look at how implementing all three in concert forms a more robust foundation upon which we can build a proactive defense.

From a SEC566 perspective, implementing the Critical Security Controls would have:

  • Provided Rekt with a library of prioritized defenses
  • Given Rekt a roadmap to implement a baseline set of controls and a mechanism to measure defensive progress over time
  • Enabled Rekt to perform control-oriented risk assessment, using vulnerability management to help them continuously measure gaps and opportunities for improvement
  • Put Rekt on a path to event-oriented risk assessment, where security operations informs defensive planning based on attacks and other observed events

A strong defense starts with the right technical controls. The goal is to gain as much situational awareness as possible, prevent as many attacks as possible, and detect the things we cannot and did not prevent. The Critical Security Controls are an effective security framework because they are based on actual attacks launched regularly against networks. Priority is given to Controls that (1) mitigate known attacks (2) address a wide variety of attacks, and (3) identify and stop attackers early in the compromise cycle.

From a MGT516 perspective, enterprise vulnerability management would have:

  • Provided an accurate picture of Rekt’s weaknesses and exposures to help drive control and monitoring priorities
  • Established a common goal for many of the Critical Security Controls ultimately designed to support better vulnerability management
  • Provided a cross-functional goal of identifying and reducing vulnerabilities, to which the security operations team and security engineering would contribute

By understanding common issues and how to solve them, Rekt Casino will be better prepared to meet the challenges ahead and guide its IT teams and the broader organization to successfully treat vulnerabilities. The approach taken in MGT516 aligns to other modernization efforts Rekt is likely to take in the near future as it evaluates expansion into the cloud or implementing new processes like DevOps.

From a MGT551 perspective, a security operations center would have:

  • Helped Rekt shift from an outdated, prevention-oriented mindset to a more modern detection oriented mindset
  • Provided an over-arching monitoring capability to track the status and efficacy of the critical security controls
  • Applied the context and awareness generated by the critical security controls and vulnerability management programs to identify and respond to attacks
  • Provided situational awareness for the vulnerability management program by identifying new vulnerabilities, systems outside of program coverage, and changes in asset status based on incidents and other events

Information technology is so tightly woven into the fabric of modern business that cyber risk has become business risk, and this has certainly proven true for Rekt Casino. A security operations team analyzing telemetry from across the environment that includes control data and vulnerability information can be the difference between a temporary disruption and a massive business loss.

Starting the Journey

Each of these disciplines represent significant investments Rekt Casino, or any other organization, must make to be more resistant to attack. But without some capability in each of these disciplines, our operational defense doesn’t have the whole picture. Strong operational leadership in each of these three key disciplines will provide a robust and flexible starting point for a more proactive defense. More importantly, that defense will be focused on Rekt’s unique business and risk profile with controls and monitoring that prioritizes the biggest gains first.

For critical security controls, there are many sources of inventory data and some of the basic capabilities within the control library. Use a spreadsheet or data warehouse, engage with your IT management teams, and maximize the data to which you already have access to make as much progress as possible before turning to more significant new investments.

In vulnerability management, getting as much coverage as possible is one of the earliest and most important goals, and the biggest challenge – using a combination of tools at the network and host layers, the right access, and the right technical analysis of the data, organizations like Rekt Casino can build complete inventories of both hardware and software. This effort isn’t wholly reliant on major commercial scanning tools and may be supplemented by configuration management and patch management efforts.

In security operations, use existing frameworks like MITRE’s ATT&CK matrix to define threats facing your organization in common terms and prioritize your preventative controls and monitoring accordingly. Revisit the profile you have built often to update it based on new controls, vulnerabilities, and attacks you have observed, and share those insights with the other security functions so that they too can adjust and improve. Look to the risk appetite of your organization to strike the right balance between preventative controls and more passive, detection-oriented controls. Strive for prevention but do not compromise on detection!

Once we deploy basic capabilities in each of these areas, we have a baseline on which to grow and improve. Security is a process, not a state of being, and as we have followed Rekt Casino on their journey from breach to recovery to improvement we can now look to our own organizations to undertake the same initiatives. The SANS Operational Leadership Triad provides three entry points for this journey, so pick the one that is right for you.

About the Author

Mark Orlando is a SANS Associate Instructor, co-author MGT551: Building and Leading Security Operations Centers, instructor for SEC450: Blue Team Fundamentals: Security Operations and Analysis, and the Co-Founder and CEO of Bionic Cyber. Prior to Bionic, Mark built, assessed, and managed security teams at the Pentagon, the White House, the Department of Energy, and numerous Fortune 500 clients. Mark has presented on security operations and assessment at DefCon's Blue Team Village, the Institute for Applied Network Security (IANS) Forum, BSidesDC, and the RSA Conference and has been quoted in the New York Times, the Washington Post, Forbes, and many other publications. He holds a Bachelor's Degree in Advanced Information Technology from George Mason University and served in the US Marine Corps as an Artillery Non-Commissioned Officer.

More About Mark
Share:
TwitterLinkedInFacebook
Copy url Url was copied to clipboard
Subscribe to SANS Newsletters
Receive curated news, vulnerabilities, & security awareness tips
United States
Canada
United Kingdom
Spain
Belgium
Denmark
Norway
Netherlands
Australia
India
Japan
Singapore
Afghanistan
Aland Islands
Albania
Algeria
American Samoa
Andorra
Angola
Anguilla
Antarctica
Antigua and Barbuda
Argentina
Armenia
Aruba
Austria
Azerbaijan
Bahamas
Bahrain
Bangladesh
Barbados
Belarus
Belize
Benin
Bermuda
Bhutan
Bolivia
Bonaire, Sint Eustatius, and Saba
Bosnia And Herzegovina
Botswana
Bouvet Island
Brazil
British Indian Ocean Territory
Brunei Darussalam
Bulgaria
Burkina Faso
Burundi
Cambodia
Cameroon
Cape Verde
Cayman Islands
Central African Republic
Chad
Chile
China
Christmas Island
Cocos (Keeling) Islands
Colombia
Comoros
Cook Islands
Costa Rica
Cote D'ivoire
Croatia (Local Name: Hrvatska)
Curacao
Cyprus
Czech Republic
Democratic Republic of the Congo
Djibouti
Dominica
Dominican Republic
East Timor
Ecuador
Egypt
El Salvador
Equatorial Guinea
Eritrea
Estonia
Eswatini
Ethiopia
Falkland Islands (Malvinas)
Faroe Islands
Fiji
Finland
France
French Guiana
French Polynesia
French Southern Territories
Gabon
Gambia
Georgia
Germany
Ghana
Gibraltar
Greece
Greenland
Grenada
Guadeloupe
Guam
Guatemala
Guernsey
Guinea
Guinea-Bissau
Guyana
Haiti
Heard And McDonald Islands
Honduras
Hong Kong
Hungary
Iceland
Indonesia
Iraq
Ireland
Isle of Man
Israel
Italy
Jamaica
Jersey
Jordan
Kazakhstan
Kenya
Kiribati
Korea, Republic Of
Kosovo
Kuwait
Kyrgyzstan
Lao People's Democratic Republic
Latvia
Lebanon
Lesotho
Liberia
Liechtenstein
Lithuania
Luxembourg
Macau
Madagascar
Malawi
Malaysia
Maldives
Mali
Malta
Marshall Islands
Martinique
Mauritania
Mauritius
Mayotte
Mexico
Micronesia, Federated States Of
Moldova, Republic Of
Monaco
Mongolia
Montenegro
Montserrat
Morocco
Mozambique
Myanmar
Namibia
Nauru
Nepal
Netherlands Antilles
New Caledonia
New Zealand
Nicaragua
Niger
Nigeria
Niue
Norfolk Island
North Macedonia
Northern Mariana Islands
Oman
Pakistan
Palau
Palestine
Panama
Papua New Guinea
Paraguay
Peru
Philippines
Pitcairn
Poland
Portugal
Puerto Rico
Qatar
Reunion
Romania
Russian Federation
Rwanda
Saint Bartholemy
Saint Kitts And Nevis
Saint Lucia
Saint Martin
Saint Vincent And The Grenadines
Samoa
San Marino
Sao Tome And Principe
Saudi Arabia
Senegal
Serbia
Seychelles
Sierra Leone
Sint Maarten
Slovakia
Slovenia
Solomon Islands
South Africa
South Georgia and the South Sandwich Islands
South Sudan
Sri Lanka
St. Helena
St. Pierre And Miquelon
Suriname
Svalbard And Jan Mayen Islands
Sweden
Switzerland
Taiwan
Tajikistan
Tanzania, United Republic Of
Thailand
Togo
Tokelau
Tonga
Trinidad And Tobago
Tunisia
Turkey
Turkmenistan
Turks And Caicos Islands
Tuvalu
Uganda
Ukraine
United Arab Emirates
United States Minor Outlying Islands
Uruguay
Uzbekistan
Vanuatu
Vatican City State
Venezuela
Vietnam
Virgin Islands (British)
Virgin Islands (U.S.)
Wallis And Futuna Islands
Western Sahara
Yemen
Zambia
Zimbabwe

By providing this information, you agree to the processing of your personal data by SANS as described in our Privacy Policy.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Recommended Training

  • SEC580: Metasploit for Enterprise Penetration Testing™
  • SEC301: Introduction to Cyber Security™
  • SEC549: Cloud Security Architecture

Tags:
  • Cybersecurity Leadership

Related Content

Blog
MGT - Blog - VMMM-SAT 2.0 – New & Improved!_340 x 340.jpg
Cybersecurity Leadership
March 10, 2025
Vulnerability Management Maturity Model – Self-Assessment Tool (VMMM-SAT 2.0 – New & Improved!)
The VMMM-SAT 2.0 help assess where your program stands and identify areas of improvement.
Jonathan_Risto_370x370.png
Jonathan Risto
read more
Blog
CIS-Controls-v8-Released-340x340.png
Cybersecurity Leadership
January 6, 2025
CIS Controls v8
CIS Released version 8.1 in June, 2024
SANS_social_88x82.jpg
SANS Institute
read more
Blog
MGT - Blog - Practical Applications of GenAI in a SOC_340 x 340.jpg
Cybersecurity Leadership
September 26, 2024
Practical Applications of GenAI in a SOC
There are a few standout candidates for the application of GenAI with Data Loss Prevention (DLP) alerts.
Shawn_Chakravarty_340x340.png
Shawn Chakravarty
read more
  • Company
  • Mission
  • Instructors
  • About
  • FAQ
  • Press
  • Contact Us
  • Careers
  • Policies
  • Training Programs
  • Work Study
  • Academies & Scholarships
  • Public Sector Partnerships
  • Law Enforcement
  • SkillsFuture Singapore
  • Degree Programs
  • Get Involved
  • Join the Community
  • Become an Instructor
  • Become a Sponsor
  • Speak at a Summit
  • Join the CISO Network
  • Award Programs
  • Partner Portal
Subscribe to SANS Newsletters
Receive curated news, vulnerabilities, & security awareness tips
United States
Canada
United Kingdom
Spain
Belgium
Denmark
Norway
Netherlands
Australia
India
Japan
Singapore
Afghanistan
Aland Islands
Albania
Algeria
American Samoa
Andorra
Angola
Anguilla
Antarctica
Antigua and Barbuda
Argentina
Armenia
Aruba
Austria
Azerbaijan
Bahamas
Bahrain
Bangladesh
Barbados
Belarus
Belize
Benin
Bermuda
Bhutan
Bolivia
Bonaire, Sint Eustatius, and Saba
Bosnia And Herzegovina
Botswana
Bouvet Island
Brazil
British Indian Ocean Territory
Brunei Darussalam
Bulgaria
Burkina Faso
Burundi
Cambodia
Cameroon
Cape Verde
Cayman Islands
Central African Republic
Chad
Chile
China
Christmas Island
Cocos (Keeling) Islands
Colombia
Comoros
Cook Islands
Costa Rica
Cote D'ivoire
Croatia (Local Name: Hrvatska)
Curacao
Cyprus
Czech Republic
Democratic Republic of the Congo
Djibouti
Dominica
Dominican Republic
East Timor
Ecuador
Egypt
El Salvador
Equatorial Guinea
Eritrea
Estonia
Eswatini
Ethiopia
Falkland Islands (Malvinas)
Faroe Islands
Fiji
Finland
France
French Guiana
French Polynesia
French Southern Territories
Gabon
Gambia
Georgia
Germany
Ghana
Gibraltar
Greece
Greenland
Grenada
Guadeloupe
Guam
Guatemala
Guernsey
Guinea
Guinea-Bissau
Guyana
Haiti
Heard And McDonald Islands
Honduras
Hong Kong
Hungary
Iceland
Indonesia
Iraq
Ireland
Isle of Man
Israel
Italy
Jamaica
Jersey
Jordan
Kazakhstan
Kenya
Kiribati
Korea, Republic Of
Kosovo
Kuwait
Kyrgyzstan
Lao People's Democratic Republic
Latvia
Lebanon
Lesotho
Liberia
Liechtenstein
Lithuania
Luxembourg
Macau
Madagascar
Malawi
Malaysia
Maldives
Mali
Malta
Marshall Islands
Martinique
Mauritania
Mauritius
Mayotte
Mexico
Micronesia, Federated States Of
Moldova, Republic Of
Monaco
Mongolia
Montenegro
Montserrat
Morocco
Mozambique
Myanmar
Namibia
Nauru
Nepal
Netherlands Antilles
New Caledonia
New Zealand
Nicaragua
Niger
Nigeria
Niue
Norfolk Island
North Macedonia
Northern Mariana Islands
Oman
Pakistan
Palau
Palestine
Panama
Papua New Guinea
Paraguay
Peru
Philippines
Pitcairn
Poland
Portugal
Puerto Rico
Qatar
Reunion
Romania
Russian Federation
Rwanda
Saint Bartholemy
Saint Kitts And Nevis
Saint Lucia
Saint Martin
Saint Vincent And The Grenadines
Samoa
San Marino
Sao Tome And Principe
Saudi Arabia
Senegal
Serbia
Seychelles
Sierra Leone
Sint Maarten
Slovakia
Slovenia
Solomon Islands
South Africa
South Georgia and the South Sandwich Islands
South Sudan
Sri Lanka
St. Helena
St. Pierre And Miquelon
Suriname
Svalbard And Jan Mayen Islands
Sweden
Switzerland
Taiwan
Tajikistan
Tanzania, United Republic Of
Thailand
Togo
Tokelau
Tonga
Trinidad And Tobago
Tunisia
Turkey
Turkmenistan
Turks And Caicos Islands
Tuvalu
Uganda
Ukraine
United Arab Emirates
United States Minor Outlying Islands
Uruguay
Uzbekistan
Vanuatu
Vatican City State
Venezuela
Vietnam
Virgin Islands (British)
Virgin Islands (U.S.)
Wallis And Futuna Islands
Western Sahara
Yemen
Zambia
Zimbabwe

By providing this information, you agree to the processing of your personal data by SANS as described in our Privacy Policy.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
  • Privacy Policy
  • Terms and Conditions
  • Do Not Sell/Share My Personal Information
  • Contact
  • Careers
© 2025 The Escal Institute of Advanced Technologies, Inc. d/b/a SANS Institute. Our Terms and Conditions detail our trademark and copyright rights. Any unauthorized use is expressly prohibited.
  • Twitter
  • Facebook
  • Youtube
  • LinkedIn