Skip to content
Silicon Shecky

Silicon Shecky

Infosec Practitioner

  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Solarwinds Sunbursts a Supernova: Early lessons learned

Posted on December 22, 2020 By Michael Kavka No Comments on Solarwinds Sunbursts a Supernova: Early lessons learned

There will be more fallout from Solarwinds to come. More companies will realize they are compromised due to either SUNBURST or SUPERNOVA (got to love the catchy, similar style names).

The question is what are you and your company going to do about it? What have you and your company learned?

Do not just throw money at this. Vendors will start trying to use this as a marketing ploy, especially to those that do in house development. If you do in house development, work on getting your Secure Development Lifecycle (SDLC) better. Do not over promise and over push your developers. If developers say they need some extra time for security testing, understand it will save you more issues in the long run. Understand that meeting compliance check boxes will not mean that security was met.

The rest of the corporate world should be doing a few things starting with your people and processes. Make sure that your company has in place a solid detection process, which includes enough staff, proper logging, solid SIEM/SOAR rules and notebooks, and a solid Incident Response plan. If your company is lacking in any of these, and that includes keeping people trained, it will be money well spent in the long term. Your company will get breached at some point and these processes plus properly trained people will always be needed. There is no perfect security, so detection is as important if not more important.

Understand there is no magic bullet. Security is a process not a destination, and burned out, overworked security people (especially in the SOC) do your company no good. Compensating by getting more and more tools without enough staff will cause burnout. People can only do so much in any given time. Make sure they get time off, and that means not disturbing them when they are off, if possible.

These are the lessons every company should learn from this situation.

 

 

Rants, Security Tags:Security, Solarwinds, Sunburst, Supernova

Post navigation

Previous Post: The One About Chained Exploits and Pentest Results
Next Post: Solarwinds Sunburst: Haven’t We Been Here Before?

Related Posts

  • Security is Reactionary, No Matter What Security
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

More Related Articles

Security is Reactionary, No Matter What Security
Defender, KQL and Lockbit Microsoft
Do well, not be “popular” Ramblings
Defense Layers: A Case Study Microsoft
Device vs. User Microsoft
Ransomware, Are You Ready? General

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP
  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

RSS feed: iFin Intel Feed iFin Intel Feed

  • Postal Service moves to finalize mail ballot regs before SCOTUS ruling August 22, 2026 djohnson
  • Frontier AI labs still won’t say how they’d contain a rogue model August 22, 2026 Rebecca Bellan
  • If you're not using AI to attack your own systems, your adversaries will August 22, 2026
  • Connecticut says data from 41,000 Medicaid members exposed in portal breach; the second portal incident this year August 22, 2026 Dissent
  • Hackers infect Android car head units with proxy botnet malware August 22, 2026 Bill Toulas
  • AWS Security makes an inscrutable choice August 21, 2026
  • Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain August 21, 2026 Yaron Avital
  • Friday Squid Blogging: Neon Flying Squid August 21, 2026 Bruce Schneier
  • CVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards August 21, 2026 aws@amazon.com
  • Lawmakers call for investigation into impact of CISA staffing cuts August 21, 2026
  • CVE-2026-77810 - Issue with Athena Federated Query Neptune Connector August 21, 2026 aws@amazon.com
  • Apollo discloses data breach from ongoing wave of attacks hitting financial sector August 21, 2026 Matt Kapko

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP

RSS feed: iFin Intel Feed iFin Intel Feed

  • Postal Service moves to finalize mail ballot regs before SCOTUS ruling August 22, 2026 djohnson
  • Frontier AI labs still won’t say how they’d contain a rogue model August 22, 2026 Rebecca Bellan
  • If you're not using AI to attack your own systems, your adversaries will August 22, 2026
  • Connecticut says data from 41,000 Medicaid members exposed in portal breach; the second portal incident this year August 22, 2026 Dissent
  • Hackers infect Android car head units with proxy botnet malware August 22, 2026 Bill Toulas
  • AWS Security makes an inscrutable choice August 21, 2026
  • Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain August 21, 2026 Yaron Avital
  • Friday Squid Blogging: Neon Flying Squid August 21, 2026 Bruce Schneier
  • CVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards August 21, 2026 aws@amazon.com
  • Lawmakers call for investigation into impact of CISA staffing cuts August 21, 2026
  • CVE-2026-77810 - Issue with Athena Federated Query Neptune Connector August 21, 2026 aws@amazon.com
  • Apollo discloses data breach from ongoing wave of attacks hitting financial sector August 21, 2026 Matt Kapko
  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Social Media

  • Bluesky
  • Mastodon
  • Twitter

Copyright © 2026 Silicon Shecky.