| | 9 MAY 2022A lot of attacks are opportunistic attacks. For the opportunistic attackers, the key is proper cyber hygiene, or focusing on the basicsgain entry to your environment. These are not zero-days that are unknown, these are well-known and usually fixable. Apply patches or configuration changes in a timely manner. 2. Enable MFA or 2FA - Multifactor or 2-factor authentication. This can prevent unauthorized logins if the credentials are lost or stolen due to a data breach. Yes, this has end-user impact. Do it anyway.3. Remove local admin rights from systems - A normal user cannot install software. If you click on a link that wants to install malware, as a normal user it shouldn't install. If you're running as a local admin, this will mess up the system. This too may impact users, yet they'll adapt quickly. 4. Backup your systems - If it's important, back it up. And make sure that the account to create the backup cannot delete backups. Make sure the backups are not on the same network as your system, so that an attacker cannot delete backups. This is vital in a ransomware situation. 5. Train your users - Technology will fail. Something will get past your defenses. People will then need to decide. At the very least, train users how to report suspicious activity. There are a lot of other things that I want to add to the list above, but I'll keep it simple. What I would add to #1 would be asset management as I need to know what to patch, so those two go hand in hand.To defend your organization, you need to take a risk-based approach. This means conducting a risk assessment and then using it to determine proper controls. Then you need to implement those controls and put them on all systems or roll them out consistently in your environment. By focusing on the basics, you can better defend your organization and reduce the chances of your organization being the next victim mentioned in the nightly news cycle. Little improvements have a lot of impact on the overall security of your organization. This existed prior to COVID and it is likely to persist long after the COVID is forgotten. Security is a journey and we need to continue to focus on the basics if we expect to continue to stay safe and secure.
<
Page 8 |
Page 10 >