Incident detection precursors and indicators are two very important things to pay attention to and
be able to identify. Normal precursors that I see within my job are Brute Force Attacks. If the attack
is unsuccessful, it normally means that it will occur again and most likely from the same location. If
our company does not have any business with that area then I am able to suggest that the subnet
range be blocked at the firewall. Being able to identify a precursor and acting on the information
appropriately can reduce risk overall. An indicator is something that provides proof that an incident
will likely occur or is currently happening. An example of an indicator could be seeing alarms for
data extraction, which would mean that something on the device identified could have been
compromised and needs to be addressed. Or, that popups are generating out of nowhere on an
Employees PC screen, which could indicate infection.
For this discussion I am choosing where I work for examples and challenges. I work for a tech
company that provides services to clients that operate within the healthcare field. A large amount
of information handled has to be HIPPA compliant and we operate with an ISO certification. With
that being said precursors are much safer to handle than actual indicators. Of course, every
company wants to mitigate risk but for our company this takes precedence. By dealing with
precursors when we find them, we are able to block and address them before it becomes an
indicator. When an indicator is found, specific procedures have been put in place to strictly stop the
bleeding and address the incident. I was told years ago that a precursor is a prelude to something
that can be dealt with to mitigate or eliminate damage. I believe that this holds true in our industry.