Cybercriminals are relentless. They ceaselessly explore new ways to penetrate cybersecurity defenses. Not even the pandemic can slow them down. A recent study found that web application attacks surged by 51 percent since the COVID-19 vaccines hit the news. This is another significant bump in the volume of attacks observed since the pandemic started.
In response, security professionals try to promptly plug the newly discovered vulnerabilities and update threat detection systems to prevent novel attacks from successfully breaching security controls.
Individually, it is extremely difficult for security firms to keep up with the exponentially growing volume of cyber attacks and their evolving sophistication. However, with collaboration, security professionals and organizations can boost the effects of their efforts dramatically. Cooperation among security experts worldwide is arguably the best counterattack to cyber attacks.
The concept of cybersecurity collaboration
Better cyber threat intelligence–this is the main thrust of collaboration. Conventionally, security teams gather threat intelligence to be used in updating indicators for threat detection or they rely on the database updates of their security providers. By collaborating with other organizations and threat information sources, security teams get to address their security weaknesses more effectively and improve their existing systems in the process.
An excellent example of cybersecurity collaboration is the establishment of MITRE ATT&CK. First developed in 2013 and officially launched in 2015, MITRE ATT&CK serves as a comprehensive resource to combat the increasing and evolving cyber-attacks that affect organizations worldwide. It includes inputs from various security firms, government organizations, academia, and cybersecurity experts.
The MITRE ATT&CK framework improves the ability of organizations to detect cyber threats and attacks by detailing the ways an attack may have been undertaken and what its likely signs and symptoms are. It provides answers to the questions on how the attacker may penetrate defenses and what it is doing in the compromised network or devices.
This framework is already being employed by many security firms as it bolsters their cyber risk assessment protocols, particularly when it comes to continuous testing and automated evaluations. Cymulate, for example, operationalizes the ATT&CK framework to simulate cyber attack flows across the cyber kill chain while also contributing to the threat intelligence accumulated by the framework.
Strategic cooperation
The focus of cybersecurity collaboration is enhanced threat intelligence. It is mainly about making sure that everyone is aware of the attacks that can possibly hit them, so they can have the means to detect, block, or mitigate and remediate in case a security breach has already occurred.
An insightful Think CSC piece asserts that collaboration is the future of cybersecurity. “Shared information benefits all,” it argues. While it may sound reasonable for some to keep their cybersecurity strategies as “secret weapons” against potential attackers, in the greater scheme of things, it is more advantageous to contribute to a community of cybersecurity knowledge and action plans.
It is not uncommon for ransomware, for example, to be decrypted by teams that come from different companies. Security experts understand how serious the threats of modern cyberattacks are. If one company falls to a novel attack, it won’t be long before others suffer from similar vulnerabilities and fold down. Without a doubt, it is better to work together to understand threats before they turn into far-reaching problems.
This is why security firms prefer to share their latest threat discoveries and methods of addressing attacks. Instead of hoarding the most recent security intelligence they collect and the strategies they formulate, they choose to form alliances.
“These alliances are ultimately focused on the wider world, rather than on individual companies and industries. The companies involved reason that working together gives them the ability to create the kind of safe, peaceful digital environment they need to innovate and protect their customers,” a cybersecurity and privacy expert Daniel Dobrygowski explains in a Harvard Business Review article.
Additionally, collaboration fosters diverse expertise. It is virtually impossible for a single security firm, let alone the security team of a small company, to have expertise in all kinds of attacks or variations of threats that target specific industries, networks, or organization setups. By working with each other, organizations get to benefit from the expertise of others while sharing the information and strategies they have developed.
Cybercriminals do not discriminate when picking their targets. They attack whoever is vulnerable and even those that appear to be properly secured. It is a “one v many” scenario for those that decide to go solo with their security posture. Surviving in such a setup is highly improbable. However, through collaboration, it becomes a “many v many” situation, which radically reduces the possibility of falling prey to hackers and other bad actors.
Solorigate lessons from Microsoft
In a blog post, Microsoft called for collaboration in responding to critical cyber problems like Solorigate, which is regarded as a nation-state cyberattack. “As we shared earlier this is a moment of reckoning for our industry and needs a unified response of defenders across public and private sectors,” the post wrote.
Also known as SUNBURST, Solorigate is yet another aggressive and sophisticated attack that poses serious threats not only to businesses but to entire governments. Microsoft has been doing everything it can to plug security leaks on its end, but the world’s biggest software company is not confident that it cannot adequately deal with problems similar to Solorigate on its own.
Microsoft says that it has been regularly informing its software users about emerging threats. The company has put up a Solorigate resource center to provide actionable updates to security teams. Still, the company believes that industry collaboration is the right solution to complex novel cyber-attacks particularly those that are suspected to be state-sponsored. Various players in the field of cybersecurity need to work together to share information, help strengthen defenses, and enable rapid attack response.
Microsoft President Brad Smith echoes the same thoughts as he emphasizes how important it is for everyone involved in cybersecurity to work together to detect new threats before they become critical problems. “If there is a common lesson from the past few years, it’s the importance of combining ongoing learning with new innovations, greater collaboration, and constant courage,” Smith surmises as he explains how the evolution of threats should be met with more effective security strategies.
Compensating for an inherent weakness
Collaboration is a natural solution to the inherent weakness of cybersecurity: being easier to break than to build. Hackers only need to exploit an obscure vulnerability to gain access to a network or introduce malware to wreak havoc on digital assets. They only need one point of entry to have a successful attack, whereas security teams need to make sure that all entry points do not become accessible to myriad assailants.
Cybersecurity is too critical a concern to be made into a ground for competition. It is only logical to promote collaboration to ensure prompt access to threat information, which helps enable stronger defenses and more effective mitigation and remediation.

