While new tools are needed to combat ever changing security threats, it is helpful to examine the history of the APT, because it is possible to derive many important lessons for defending against them in the future.
McAfee investigators reported that the primary goal of the attack was to gain access to and modify source code repositories at these high-tech, security and defense contractor companies. At the time, these repositories were not generally protected to a high security standard.
By publicizing its experiences, Google helped to promote awareness of the risk and encourage investment in better security countermeasures. Many companies still remain reluctant to admit being victims of similar attacks, although regulatory compliance requirements have been progressively forcing enterprises to be more open about their security incidents.