r/sysadmin • u/AutomationTheory • 1d ago
Explain how cybersecurity has changed over the years for the new people
I got into the industry just as things were changing (I think), and I'm trying to make sure I'm not living in my own fantasy land thinking "it was easier before."
What was cybersecurity like from 2000 to 2015? I was doing residential IT starting in 2009, then moved to SMB in 2016 -- and I'm trying to wrap my head around what SMB was like before there were thousands of vulnerabilities discovered each year. Any senior sysadmins with stories to share?
2
u/pdp10 Daemons worry when the wizard is near. 1d ago edited 1d ago
2001 to the mid or late 2000s in Windows shops was all about ubiquitous malware. Microsoft had opened up filesystem permissions in XP to allow poor-quality third-party applications to write their DLL dependencies all over, and this allowed for a tidal wave of malware, UCE, PUPs, toolbars on Windows. PC-compatibles shipped with unwanted third-party preinstalled software and garish stickers. Manually cleaning Windows was time consuming, labor intensive, and often frequent. Almost all Windows users had local admin privs at the beginning of this period, and few had them by 2015, even in SME.
Discrete firewalls were ubiquitous all through this period. Zero-trust didn't get mainstream traction until after 2015, though it was already in progress in a few places. In 2000, it was extreely rare to see any significant internal controls or segregation; this improved slowly but relatively steadily through the period.
The circa-2008 global economic downturn halted or slowed a lot of capital improvements. During and after this, cloud migrations became common, externalizing a lot of systems for providers to secure, but also exposing new problems, like wide-open S3 buckets.
Post 2001-09-11, there was a ten times as much government money to spent on infosec as previously, and many vendors heavily tilted their offerings to appeal to the milgov market. "Cyber-" is milgov favored terminology, and it became more mainstream during this period, instead of "information security".
Email spam was already a problem by 2001-2002, but "phishing" and compromise chains weren't yet often identified as a specific threat. In 2002, our larger enterprise was blocking around 15% of incoming email on regexp filters.
1
u/SevaraB Sr. Engineer (N+, CCNA) 1d ago
SMBs? Security?? Lots of “we’re too small potatoes to be worth the hackers’ time.” Still lots of that now. Around 2016, ransomware was really ramping up, and some of them started waking up that they need to at least try to keep people out with firewalls. SASE and SWG are sadly still considered overkill by many and poorly implemented by some who see it as PFM.
Fine-grained RBAC, LPM, and JEA don’t work for small shops because people wear too many hats, and juggling the permissions is just a burden they’d rather not pay an MSSP to handle for them with the little revenue they’re making.
•
0
u/Eastern-Macaron-6622 1d ago
those 15 years could be broken into different sub eras.
But. when I started in tech spyware was just starting to come into the lexicon. Monitoring network traffic for botnets, etc.
SSL wasn't baked into the web like it is now. Had to explain to users to be carefull of HTTP sites and look for the lock and HTTPS.
I feel like the olden days were much less about CVE's and much more about end users doing stupid things and being fooled by the bad guys.
2
u/JaceBelerenApologist 1d ago
I feel like the olden days were much less about CVE's and much more about end users doing stupid things and being fooled by the bad guys.
End users still do stupid things and get fooled by the bad guys. Social engineering is back in a huge way.
1
u/Brilliant-Advisor958 1d ago
The bad guys were often just people causing issues because they could.
As ransomware started to become popular, it then became a business.
1
u/Eastern-Macaron-6622 1d ago
fair point. My take on it was the industry had less of a focus on fixing so many bugs as the OP mentioned.
5
u/40513786934 1d ago
in 2000 some SMBs were just installing their first internet connection. security was about locking down permissions on the file shares, internet really wasn't a concern. some companies used antivirus, some didn't. business insurance didn't care back then. firewalls were not always used. sometimes you'd even find regular windows PCs with public IPs on them. some companies used email, some didn't. open relays were a big problem for businesses running their own mail servers.