This eBook includes the following formats, accessible from your Account page after purchase:
EPUB
The open industry format known for its reflowable content and usability on supported mobile devices.
PDF
The popular standard, used most often with the free Acrobat® Reader® software.
This eBook requires no passwords or activation to read. We customize your eBook by discreetly watermarking it with your name, making it uniquely yours.
This eBook includes the following formats, accessible from your Account page after purchase:
EPUB
The open industry format known for its reflowable content and usability on supported mobile devices.
PDF
The popular standard, used most often with the free Acrobat® Reader® software.
This eBook requires no passwords or activation to read. We customize your eBook by discreetly watermarking it with your name, making it uniquely yours.
Cyber Defense for the Hybrid Enterprise in the Age of AI explores how digital fraud, ransomware, malicious devices, and AI-driven cyber threats evolved into a modern cyber battlefield where attackers increasingly abuse automation, stealth, identity manipulation, and legitimate enterprise protocols to bypass traditional security defenses. Built from real-world enterprise incidents, Cisco security research, and operational experience across hybrid infrastructures, this book delivers a practical guide for understanding, detecting, and defending against modern cyberattacks using vendor-agnostic methodologies such as Zero Trust, NIST SP 800-207, NIST SP 800-30, CISA Zero Trust principles, Cyber Kill Chain, MITRE ATT&CK, and Cisco SAFE aligned with world-class security architectures.
Developed from a collaboration between Cisco and a global enterprise impacted by repeated digital fraud incidents, this book introduces the concept of the digital battlefield through different generations of real-world attacks observed in production environments. It also presents three attack models developed in Cisco labs: L.U.M.A. (Layer 2 Undetected Mobile Access), LTR-SMB (Little Red SMB Attack), and LTR-Inject (Little Red Wireless Inject Attack). These attack models demonstrate how adversaries can exploit Layer 2 communication, trusted enterprise protocols, wireless infrastructures, mobile networks, and identity spoofing techniques to evade traditional security controls and expand laterally across enterprise environments.
One of the most unique aspects of this book is that readers experience the battlefield from both perspectives: the attackers side and the defenders side. Through adversary emulation exercises, penetration testing simulations, and real-world attack scenarios, readers gain a practical understanding of how modern attacks evolve across the complete attack lifecycle, including reconnaissance, lateral movement, persistence, ransomware propagation, malicious device infiltration, credential abuse, and data exfiltration. At the same time, this book demonstrates how defenders can detect and contain these threats using behavioral analytics, Zero Trust principles, and technologies such as Cisco ISE, TrustSec, MACsec, Secure Firewall, Secure Network Analytics, and Splunk integrated into adaptive security architectures.
Through practical deployment guidance, real-world case studies, lab simulations, and adversary emulation scenarios, security professionals will gain actionable strategies to implement continuous verification, behavioral analytics, automated threat containment, microsegmentation, macrosegmentation, and identity-aware security controls across enterprise and hybrid environments.
More than a theoretical cybersecurity book, Cyber Defense for the Hybrid Enterprise in the Age of AI serves as a field-tested operational playbook for architects, engineers, SOC analysts, penetration testers, and security leaders responsible for protecting modern infrastructures against the next generation cyber threats.
Key Features
Introduction xxvi
Chapter 1 The Evolution of Cyber Threats: Digital Fraud, Ransomware, and AI-Driven Attacks 1
A Call to Secure the Future 1
The Rise of Digital Fraud and Ransomware Attacks: A Shifting Battlefield 4
The Psychology Behind Social Engineering: How Cybercriminals Exploit Human Nature 9
Ransomware from Simple Lockers to Organized Crime: The Rise of
The Future of Ransomware: AI-Powered and Nation-StateBacked Attacks 27
Defense Strategies: Preparing for the Future of Ransomware 31
Key Tactics Used by Cybercriminals 42
Insider Threats: The Enemy Within 44
The Economic Impact of Cybercrime on Businesses, Financial Institutions, and Individuals 46
Understanding Cybercriminal Motivations and Attack Vectors 48
Summary 49
References in This Chapter 52
Chapter 2 The Hackers Modus Operandi: The Attack Anatomy 55
Step-by-Step Breakdown: A Call to an Old Friend 55
Cybercrime Group Organization, Structure, Roles, and Law Enforcement
Countermeasures 57
Law Enforcement Tactics: How Authorities Track and Dismantle Cybercrime Networks 67
The Future of Cybercrime and Law Enforcement Strategies 70
The Hackers Toolbox: Cybercriminals Find Their Tools and Use Them 84
Hacktivism, Cyber Terrorism, and Nation-State Operations 89
The Underground Economy 92
Foundations of Security Frameworks 97
Summary 107
References in This Chapter 110
Chapter 3 The Security Journey: Business Strategy Alignment 111
A Change in Perspective 111
The Security Strategy Roadmap 113
Translating Security Requirements into Solutions 126
Translating Security Requirements into Risk 130
From Reactive Defense to a Living Security Strategy 132
Cybersecurity Return on Investment (ROI) 137
Case Study: ACME Petroleum OT Infrastructure 142
Summary 146
References in This Chapter 148
Chapter 4 Mapping the Threat Landscape: A Strategic Approach to Network Security Assessments 151
Revealing the Unknown 151
The Strategic Zero Trust Readiness Assessment: A Framework to Start a Zero Trust Journey 155
Zero Trust Network Assessment Blueprint: Details of the Process 169
Summary 188
References in This Chapter 190
Chapter 5 Field Validation: A Step-by-Step Case Study in Threat and Risk Assessment 193
Turning Strategy into Execution: Stepping Out of the Shadows 193
ACME Bank Case Study: Strategic Zero Trust Network Architecture Assessment 194
The Five-Phase Security Lifecycle Approach 198
Summary 259
References in This Chapter 261
Chapter 6 Inside the Insider Threat: How Fraudulent Devices Undermined a Banks Defenses 263
The Insider Actor Recruitment: Planting the Seed of Betrayal 263
Exposing the Weaknesses of Wired Corporate LANs 270
Summary 296
References in This Chapter 299
Chapter 7 Behind the Scenes: The Setup of Fraudulent Devices 301
Fraudulent Devices Exposed 301
Fraudulent Devices in Action 304
Summary 335
References in This Chapter 337
Chapter 8 The Live Attack: Showtime 339
The Deal Was Sealed 339
The Attack Execution: Assuming the Victims Identity 340
The Attack Execution: When Security Fails to See the Deception 348
The Human Breach: The Insiders Dilemma 352
The Money Mules: The Human Conveyor Belt 357
Noise in the Network: When Skill Fails, Silence Breaks 361
Summary 366
References in This Chapter 370
Chapter 9 Strategic Foundations of Defense: Zero Trust, SAFE, and AI 371
The Counterattack: Building Digital Resilience 371
Zero Trust Principles Applied to Mitigate the Attack 373
Cisco SAFE: From Complexity to a Defensible Architecture 377
AI-Assisted Vulnerability Discovery: Exploration at Machine Speed 398
Case Study: Using an AI-Assisted Vulnerability Discovery Tool 426
AI-Driven Cyber Defense: Leveraging Machine Learning and Security LLMs
Case Study: Leveraging Foundation-Sec-8B to Investigate ACME Banks Fraud Incident 459
Summary 463
References in This Chapter 465
Chapter 10 Identity and Access Control: Building Security with Cisco ISE 467
The Nemesis Revelation: Restoring Trust at the Access Layer 467
Designing a Zero TrustAligned Cisco ISE Architecture 469
Summary 569
References in This Chapter 572
Chapter 11 EastWest Defense: MACsec Encryption and TrustSec Microsegmentation 573
When the Enemy Moves in Silence: Thinking Like the Attacker Inside the Network 573
Microsegmentation in Context: Granularity, Scope, and Control 575
Introducing TrustSec: Identity as the Basis for Segmentation 580
Case Study: ACME Bank Microsegmentation Project 582
MACsec: Establishing Trust and Confidentiality 629
OT Segmentation Strategy: From Purdue Architecture to Zero Trust Enforcement 647
Summary 671
References in This Chapter 674
Chapter 12 NorthSouth Defense: Secure Firewall and the Macrosegmentation Strategy 677
When the Perimeter Is Not Enough: Rethinking NorthSouth Defense 677
Hybrid Mesh Firewall Architecture: The Foundational Theory 727
Summary 745
References in This Chapter 748
Chapter 13 Proactive Threat Defense: Leveraging NDR, XDR, and SIEM 749
A Different Way of Seeing 749
When the Invisible Becomes Visible 750
From Visibility to Understanding: The Role of NDR, XDR, and SIEM 753
Advanced Lateral Movement and Remote Access Techniques 771
Summary 890
References in This Chapter 895
TOC, 9780135472774, 9/2/2026
