SolarWinds bolsters its security response capabilities following hack
The company is in the process of 'creating a new, highly-secure environment based upon the latest practices'


SolarWinds has revealed that it is in the process of bolstering its cyber security response and monitoring capabilities, seven weeks after a “highly sophisticated” cyber attack on its IT management systems.
The software provider is working on expanding teams, techniques, and processes responsible for monitoring, responding, and “hunting” for threat actors such as those who coordinated December’s attack.
In a webcast hosted by the company, SolarWinds' security advisor and former Facebook CSO Alex Stamos said that enterprises should not only invest in appropriate security tools, but also “embrace the inevitability” that they, too, could be hacked.
“The unfortunate truth is when you go against one of these adversaries of this level, you're dealing with people that have a huge amount of time and motivation to break into your company,” he said.
“People that have dedicated research teams that are looking for zero-day in the products you use, dedicated development teams who are building new tools and new command and control systems to break in, that are not going to be caught by existing antivirus, and that come in every day with their job to break into your company.
RELATED RESOURCE
How to improve cyber security for remote working
13 recommendations for security from any location
Stamos recommended that, instead of focusing solely on preventing the initial compromise, enterprises must take into consideration their detection, monitoring, alerting, and response strategies and tools on every step of the cyber kill chain.
He also advised companies to measure the effectiveness of their response by using red team and tabletop exercises, as well as employing “trusted third parties” to handle the top two percentile of activity, leaving the 98% for internal teams.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Stamos was taken on by SolarWinds last month in order to help manage the software provider’s recovery from December’s cyber attack, alongside former CISA head Chris Krebs. Krebs and Stamos have recently formed a security consulting business, of which expertise SolarWinds is expected to benefit from.
During the webcast, the company also announced that it has secured its existing build environment and is in the process of “creating a new, highly-secure environment based upon the latest practices”, which includes integrating a systems development life cycle in all the environments concerned with product development.
Having only graduated from City University in 2019, Sabina has already demonstrated her abilities as a keen writer and effective journalist. Currently a content writer for Drapers, Sabina spent a number of years writing for ITPro, specialising in networking and telecommunications, as well as charting the efforts of technology companies to improve their inclusion and diversity strategies, a topic close to her heart.
Sabina has also held a number of editorial roles at Harper's Bazaar, Cube Collective, and HighClouds.
-
JD Sports details cyber security revamp following January attack
News It hopes a multi-vendor approach will substantially improve its cyber resilience
By Connor Jones
-
96% of CISOs without necessary support to maintain cyber security
News Security professionals are leaving due to stress, and called out lack of understanding from co-workers
By Rory Bathgate
-
Employees behaving badly?
Whitepaper Why awareness training matters
By ITPro
-
Freshworks CISO Jason Loomis embraces the ‘shift left’ amid surging supply chain threats
Case Studies Fewer than 100 days in the role, Jason Loomis reveals his plans for the future of security at Freshworks, and discusses the rising threat of API vulnerablities
By Ross Kelly
-
CISOs reveal secrets to pandemic success in critical organisations
News The pandemic presented unique challenges for every business, but organisations tasked with delivering critical services may have worked the hardest
By Connor Jones
-
Almost 70% of CISOs expect a ransomware attack
News Many companies are willing to make ransomware payments in the face of the growing threat
By Danny Bradbury
-
CISOs aren’t leading by example when it comes to cyber security
News Cyber security leaders engage in risky online behavior, according to a survey
By Rene Millman
-
Panel Profile: Moonpig head of cyber security Tash Norris
IT Pro Panel We get face-to-face with one of the IT Pro Panellists
By IT Pro