There’s a bad habit that I think pervades infosec right now: Focusing on the technology without understanding and nailing the basics.
For instance – having IDS and IPS systems on all segments of your network is good… but doesn’t help you if you’re not monitoring and doing correlation on the resulting output (and following up on events!).
A SIM solution won’t really do much by itself to help your relative risk if you don’t have someone looking at it’s output and acting on it.
The point is – having all the new technology is good, but if you don’t have the policies and procedures in place to maximize the advantage it gives you… you’re not doing yourself – or your company – any favors.
Sometimes it’s good to go back to basics. Make sure you have policies and procedures and that the appropriate people are made aware of them and fully understand them. Test yourself (and your team!). Audit your logs and compliance with policies. Follow through with your policies!
Don’t get caught in the trap of putting the technology at a higher priority than the fundamentals.
Keep this in mind: Logs are worthless if you’re not looking at them.














