ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    AV - should companies keep buying it?

    Scheduled Pinned Locked Moved IT Discussion
    71 Posts 9 Posters 5.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DustinB3403D
      DustinB3403 @Dashrender
      last edited by

      @Dashrender said in AV - should companies keep buying it?:

      if it's a zero day - the AV likely won't do squat.

      But neither would the user. As a lot of zero day's are all behind the scenes. Or things that are so ingrained in the day to day that a user doing nothing abnormal is exposed via the same process, but because of a malicious actor.

      DashrenderD 1 Reply Last reply Reply Quote 0
      • DashrenderD
        Dashrender @DustinB3403
        last edited by

        @DustinB3403 said in AV - should companies keep buying it?:

        @Dashrender said in AV - should companies keep buying it?:

        if it's a zero day - the AV likely won't do squat.

        But neither would the user. As a lot of zero day's are all behind the scenes. Or things that are so ingrained in the day to day that a user doing nothing abnormal is exposed via the same process, but because of a malicious actor.

        in most spearphishing attacks, the user has to initiate the contact - by clicking a link, etc. So, yes.. training can make the suspicious and possibly prevent them from clicking the link.

        DustinB3403D scottalanmillerS 2 Replies Last reply Reply Quote 0
        • DustinB3403D
          DustinB3403 @Dashrender
          last edited by

          @Dashrender said in AV - should companies keep buying it?:

          @DustinB3403 said in AV - should companies keep buying it?:

          @Dashrender said in AV - should companies keep buying it?:

          if it's a zero day - the AV likely won't do squat.

          But neither would the user. As a lot of zero day's are all behind the scenes. Or things that are so ingrained in the day to day that a user doing nothing abnormal is exposed via the same process, but because of a malicious actor.

          in most spearphishing attacks, the user has to initiate the contact - by clicking a link, etc. So, yes.. training can make the suspicious and possibly prevent them from clicking the link.

          Is most spearphising you're seeing of the zero-day variety? The kind I'm seeing are of the "yup, we know about it and AV killed it, and our user notified us of it before clicking on the link anyways" varietal.

          DashrenderD 1 Reply Last reply Reply Quote 0
          • DashrenderD
            Dashrender @DustinB3403
            last edited by Dashrender

            @DustinB3403 said in AV - should companies keep buying it?:

            @Dashrender said in AV - should companies keep buying it?:

            @DustinB3403 said in AV - should companies keep buying it?:

            @Dashrender said in AV - should companies keep buying it?:

            if it's a zero day - the AV likely won't do squat.

            But neither would the user. As a lot of zero day's are all behind the scenes. Or things that are so ingrained in the day to day that a user doing nothing abnormal is exposed via the same process, but because of a malicious actor.

            in most spearphishing attacks, the user has to initiate the contact - by clicking a link, etc. So, yes.. training can make the suspicious and possibly prevent them from clicking the link.

            Is most spearphising you're seeing of the zero-day variety? The kind I'm seeing are of the "yup, we know about it and AV killed it, and our user notified us of it before clicking on the link anyways" varietal.

            yeah, but in your case - the training was still the first to kick in - not the AV, that is assuming the training/user didn't fail. Of course if it did - which is the only reason the AV would be 'stopping' something.. then in that case, because not zero day - the av worked.

            But - as Scott already said - the idea here isn't to be rid of AV, because Windows comes with a decent AV already included...

            It more about it is better to buy the centralized console for AV or instead spend the money on training/update management solution?

            scottalanmillerS 1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller @RojoLoco
              last edited by

              @RojoLoco said in AV - should companies keep buying it?:

              I just found an extension for Windows Admin Center that looks like it might be some sort of central console for windows defender. Installing now, will report back findings.

              Whoa, that would be a huge win. I hope that this is real.

              1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller @JaredBusch
                last edited by

                @JaredBusch said in AV - should companies keep buying it?:

                The current price of Webroot is cheaper than us billing time to nuke and setup machines a couple times a year.

                Agreed that Webroot would be way cheaper than doing that. But not having Webroot, I've not seen anyone getting infected like that.

                If infections happened that often, and if Webroot would stop it, then absolutely that's a great deal. But without Webroot, but with proper setup otherwise (not running as admin, using Defender, etc.) we don't see but the rarest of infections.

                1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @Dashrender
                  last edited by

                  @Dashrender said in AV - should companies keep buying it?:

                  one being that the company actually values educating the company as a whole, not just a chastising of someone for something something wrong/bad/etc.

                  That could be worded that one expects their employees to be grown ups and the other feels the need to be condescending and treat them like idiots.

                  It's all perspective.

                  DashrenderD 1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller @DustinB3403
                    last edited by

                    @DustinB3403 said in AV - should companies keep buying it?:

                    All of the training in the world won't stop a sophisticated attack. Users are a great way to prevent a lot of the lowly attacks, but attacks from state actors or people who are targeting the business will, eventually be successful.

                    Same with security products. Even the best ones only stop so much.

                    1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @Dashrender
                      last edited by

                      @Dashrender said in AV - should companies keep buying it?:

                      @DustinB3403 said in AV - should companies keep buying it?:

                      @Dashrender said in AV - should companies keep buying it?:

                      if it's a zero day - the AV likely won't do squat.

                      But neither would the user. As a lot of zero day's are all behind the scenes. Or things that are so ingrained in the day to day that a user doing nothing abnormal is exposed via the same process, but because of a malicious actor.

                      in most spearphishing attacks, the user has to initiate the contact - by clicking a link, etc. So, yes.. training can make the suspicious and possibly prevent them from clicking the link.

                      True, spearphishing and zero day don't go together, though. A spearphishing attack by definition isn't a zero day.

                      1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller @Dashrender
                        last edited by

                        @Dashrender said in AV - should companies keep buying it?:

                        But - as Scott already said - the idea here isn't to be rid of AV, because Windows comes with a decent AV already included...
                        It more about it is better to buy the centralized console for AV or instead spend the money on training/update management solution?

                        Exactly, disabling all AV just to prove a point is silly. It really is about which kind of AV makes sense.

                        1 Reply Last reply Reply Quote 1
                        • DashrenderD
                          Dashrender @scottalanmiller
                          last edited by

                          @scottalanmiller said in AV - should companies keep buying it?:

                          @Dashrender said in AV - should companies keep buying it?:

                          one being that the company actually values educating the company as a whole, not just a chastising of someone for something something wrong/bad/etc.

                          That could be worded that one expects their employees to be grown ups and the other feels the need to be condescending and treat them like idiots.

                          It's all perspective.

                          Well then - I guess most of the world is idiots - because these are things that users just don't know - or at least never even consider until shown/educated on.

                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @Dashrender
                            last edited by

                            @Dashrender said in AV - should companies keep buying it?:

                            Well then - I guess most of the world is idiots

                            That should fall into the "well duh" category. Of course most of the world is idiots.

                            DashrenderD 1 Reply Last reply Reply Quote 1
                            • DashrenderD
                              Dashrender @scottalanmiller
                              last edited by

                              @scottalanmiller said in AV - should companies keep buying it?:

                              @Dashrender said in AV - should companies keep buying it?:

                              Well then - I guess most of the world is idiots

                              That should fall into the "well duh" category. Of course most of the world is idiots.

                              Along this line - the boss wants me to add to my duties - I now get to train our users on how to use a computer as well as how to be security minded. i.e. don't plug in random USB sticks into a computer, etc.

                              scottalanmillerS JaredBuschJ IRJI 3 Replies Last reply Reply Quote 1
                              • scottalanmillerS
                                scottalanmiller @Dashrender
                                last edited by

                                @Dashrender said in AV - should companies keep buying it?:

                                @scottalanmiller said in AV - should companies keep buying it?:

                                @Dashrender said in AV - should companies keep buying it?:

                                Well then - I guess most of the world is idiots

                                That should fall into the "well duh" category. Of course most of the world is idiots.

                                Along this line - the boss wants me to add to my duties - I now get to train our users on how to use a computer as well as how to be security minded. i.e. don't plug in random USB sticks into a computer, etc.

                                Not fun, but a good thing to be doing.

                                1 Reply Last reply Reply Quote 0
                                • JaredBuschJ
                                  JaredBusch @Dashrender
                                  last edited by JaredBusch

                                  @Dashrender said in AV - should companies keep buying it?:

                                  @scottalanmiller said in AV - should companies keep buying it?:

                                  @Dashrender said in AV - should companies keep buying it?:

                                  Well then - I guess most of the world is idiots

                                  That should fall into the "well duh" category. Of course most of the world is idiots.

                                  Along this line - the boss wants me to add to my duties - I now get to train our users on how to use a computer as well as how to be security minded. i.e. don't plug in random USB sticks into a computer, etc.

                                  Because you are cheaper than KnowB4?

                                  scottalanmillerS 1 Reply Last reply Reply Quote 1
                                  • scottalanmillerS
                                    scottalanmiller @JaredBusch
                                    last edited by

                                    @JaredBusch said in AV - should companies keep buying it?:

                                    @Dashrender said in AV - should companies keep buying it?:

                                    @scottalanmiller said in AV - should companies keep buying it?:

                                    @Dashrender said in AV - should companies keep buying it?:

                                    Well then - I guess most of the world is idiots

                                    That should fall into the "well duh" category. Of course most of the world is idiots.

                                    Along this line - the boss wants me to add to my duties - I now get to train our users on how to use a computer as well as how to be security minded. i.e. don't plug in random USB sticks into a computer, etc.

                                    Because you are cheaper than KnowB4?

                                    One would assume.

                                    1 Reply Last reply Reply Quote 0
                                    • IRJI
                                      IRJ @Dashrender
                                      last edited by

                                      @Dashrender said in AV - should companies keep buying it?:

                                      @scottalanmiller said in AV - should companies keep buying it?:

                                      @Dashrender said in AV - should companies keep buying it?:

                                      Well then - I guess most of the world is idiots

                                      That should fall into the "well duh" category. Of course most of the world is idiots.

                                      Along this line - the boss wants me to add to my duties - I now get to train our users on how to use a computer as well as how to be security minded. i.e. don't plug in random USB sticks into a computer, etc.

                                      You aren't blocking USB drives today?

                                      DashrenderD 1 Reply Last reply Reply Quote 0
                                      • DashrenderD
                                        Dashrender @IRJ
                                        last edited by

                                        @IRJ said in AV - should companies keep buying it?:

                                        @Dashrender said in AV - should companies keep buying it?:

                                        @scottalanmiller said in AV - should companies keep buying it?:

                                        @Dashrender said in AV - should companies keep buying it?:

                                        Well then - I guess most of the world is idiots

                                        That should fall into the "well duh" category. Of course most of the world is idiots.

                                        Along this line - the boss wants me to add to my duties - I now get to train our users on how to use a computer as well as how to be security minded. i.e. don't plug in random USB sticks into a computer, etc.

                                        You aren't blocking USB drives today?

                                        nope.
                                        That was just one example.

                                        Then there is the need to still use DVDs around here - that one I couldn't block.

                                        1 Reply Last reply Reply Quote 0
                                        • 1
                                        • 2
                                        • 3
                                        • 4
                                        • 4 / 4
                                        • First post
                                          Last post