8 | | MAY 2022IN MY OPINIONFor anyone who reads the newspaper or accesses news on the internet, it's become quite common to see data breaches, ransomware, and other security attacks on way too frequent occasions. My non-technical friends are asking if this is due to the "work from anywhere" situation that we're now experiencing thanks to the COVID working situation. Personally, I don't think so. Why not? Because we were experiencing these things prior to COVID. I do agree that COVID escalated the `work from anywhere' initiative for many companies, yet it hasn't changed the threat, but rather expanded the threat landscape. So, what does it take to protect an organization from falling victim to the cyber criminals? Just how hard can it be? Well, quite difficult. As an attacker, I only need to find one way into an organization. As a defender, I must plug every hole to prevent a would-be attacker from gaining access. And I must do it without negatively impacting my user community. And I will never have enough people or budget to do all I'd like to do. In that type of environment, how does one give assurance that there are adequate controls to protect the organization? The key is to identify and manage risk. What are the threats? What controls or protections do you need to put in place to minimize the impact of that threat or reduce the risk to an acceptable degree? For instance, if an organization is concerned with stolen credentials being used for unauthorized access, employing MFA/2FA or multifactor authentication/2 factor authentication. This requires a user to know the username and password to access an account plus have additional control to authenticate, such as an SMS code, a code from an authentication app, or a biometric authentication method. This doesn't fully mitigate the risk, but it greatly reduces it. By doing a proper risk assessment, an organization can identify key risks, likely threat actors, and typical threats and put proper controls in place. A lot of attacks are opportunistic attacks. The attacker didn't specifically target you or your organization. They were simply scanning and looking for easy targets. If they find an entry point, they will try it. For these types of attackers, you want to make sure your organization is just a little more protected than the others, so the criminals will focus their effort on the other easier targets. To be clear, this doesn't mean a determined and focused attacker isn't going to persist against you, this is more the opportunistic attackers. For the opportunistic attackers, the key is proper cyber hygiene, or focusing on the basics. If you do the basics and do them consistently, you are much less likely to end up in the news as the next victim to a cyber-breach. There are many things that can be added to the term hygiene, yet I'll simplify and go with five:1. Vulnerability management - Patch your system. Fix your known bads. These are things that an attacker can leverage to FUTURE-PROOFING CYBER SECURITY SYSTEMS IN A POST-PANDEMIC WORLDBy Benjamin Corll, Vice President, Cyber Security, Coats
< Page 7 | Page 9 >