{"id":33051,"date":"2019-01-28T12:40:34","date_gmt":"2019-01-28T12:40:34","guid":{"rendered":"http:\/\/www.intelligentcio.com\/me\/?p=33051"},"modified":"2019-01-31T11:17:17","modified_gmt":"2019-01-31T11:17:17","slug":"a-layered-approach-to-cybersecurity-people-processes-and-technology-2","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2019\/01\/28\/a-layered-approach-to-cybersecurity-people-processes-and-technology-2\/","title":{"rendered":"A layered approach to cybersecurity: People, processes and technology"},"content":{"rendered":"<p><em><strong>Alain Penel, Regional Vice President \u2013 Middle East, Fortinet, outlines the various approaches to cybersecurity, which includes the three crucial aspects \u2013 people, processes and technology.<\/strong><\/em><\/p>\n<p>Cybercrime is an ever-present threat facing organisations of all sizes. In order to safeguard themselves against a successful data breach, IT teams must stay a step ahead of cybercriminals by defending against a barrage of increasingly-sophisticated attacks at high volumes.<\/p>\n<p>In\u00a0Q3 of 2018 alone, FortiGuard Labs detected 1,114 exploits per firm, each representing an opportunity for a cybercriminal to infiltrate a network and exfiltrate or compromise valuable data.<\/p>\n<p>What complicates this challenge further is that the strategies and attack vectors that cybercriminals rely on are always evolving. It\u2019s the classic problem of security teams having to cover every contingency, while cybercriminals only need to slip past defences once.<\/p>\n<p>Because of this, IT teams must continuously update their defences based on current threat trends. Today, IoT, mobile malware, cryptojacking and botnets are top focuses for cybercriminals, but they may have moved on to new threats by Q4.<\/p>\n<p>With this in mind, IT security teams have a lot of ground to cover. Unfortunately, there is no silver bullet to guarantee effective security posture, nor a single defensive mechanism that can ensure security across modern distributed networks. In order to defend against today\u2019s threats, IT teams must take a layered approach to their cybersecurity.<\/p>\n<p><strong>A layered approach to cybersecurity<\/strong><\/p>\n<p>Many think of a layered approach to cybersecurity in terms of technology and tools. This means having various security controls in place to protect separate entryways. For example, deploying a\u00a0web application firewall, endpoint protections and secure email gateways, rather than relying only on traditional perimeter defences.<\/p>\n<p>While these solutions are all part of a layered security approach, it actually goes well beyond deploying layers of different security tools. For cybersecurity to be effective, organisations must also consider how they leverage people and processes.<\/p>\n<p>When combined into a single, integrated framework, an overlapping strategy based on security tools, people and processes will yield the most effective defences.<\/p>\n<p><strong>Security tactics for people, processes and technology<\/strong><\/p>\n<p>As IT teams seek to create a layered security environment, there are several tactics they should consider:<\/p>\n<p><strong>People<\/strong><\/p>\n<p>Employees can create some of the greatest risks to cybersecurity. However, when they are well informed they can also be an asset and a first line of defence. Often, cybercriminals will specifically target employees as an attack vector based on their lack of knowledge for security best practices.<\/p>\n<p>For example, cybercriminals might target employees with phishing emails designed to get them to click on a malicious link or divulge credentials. With this in mind, it\u2019s imperative that organisations conduct regular training sessions throughout the year to keep employees aware of potential scams and the ways they can make their organisation vulnerable.<\/p>\n<p>Training programmes like these will create a strong culture of cybersecurity that can go a long way toward minimising threats.<\/p>\n<p>A few of the cyberhygiene points IT teams will want to inform employees of include:<\/p>\n<ul>\n<li>Creating strong passwords that are unique to each account and not reused, ensuring personal and work passwords are separate<\/li>\n<li>Not opening or clicking links in suspicious emails or those from unfamiliar senders<\/li>\n<li>Ensuring applications and operating systems are updated regularly as soon as patches are released and not installing any unknown outside software, as they can open security vulnerabilities in the network<\/li>\n<li>Immediately reporting any unusual behaviour or something strange happening on their computers<\/li>\n<\/ul>\n<p>Another way IT teams can improve cybersecurity at the employee level is with access management policies such as the principle of least privilege, which provides a person with access to data only if it is necessary to do their job \u2013 thereby reducing the exposure and consequences of a breach.<\/p>\n<p><strong>Processes<\/strong><\/p>\n<p>This layer of cybersecurity ensures that IT teams have strategies in place to proactively prevent and to respond quickly and effectively in the event of a cybersecurity incident.<\/p>\n<p>First, IT security teams should have a cyberincident response plan in place. A good incident response plan will provide an organisation with repeatable procedures and an operational approach to addressing cybersecurity incidents to recover business processes as quickly and efficiently as possible.<\/p>\n<p>In addition, ensuring proper backups are in place and regularly testing these backups is imperative to minimising downtime and increasing the chances of data recovery from a cyberevent.<\/p>\n<p>Next is the collection and analysis of threat research. Every security strategy and tool must be informed by current threat intelligence in order to effectively detect and respond to threats. For example, threat research might reveal that cybercriminals have been carrying out attacks through a specific vulnerability or targeting endpoints with a specific malware.<\/p>\n<p>Armed with this information, IT teams can then take proactive measures by making any necessary system updates and increasing monitoring to detect behaviour indicative of one of these attacks. It is also important that IT teams consult both local and global threat data for the most comprehensive understanding of the threat landscape.<\/p>\n<p>Another important process on the road to effective cybersecurity is the prioritisation of assets. While IT teams remain strained due to the cybersecurity skills gap, networks have become increasingly sophisticated, making it impossible to manually monitor each area of the network at all times.<\/p>\n<p>Therefore, IT teams must know where all their assets are and prioritise these assets based on which are most business critical and would have the greatest impact on the business if breached.<\/p>\n<p>From there, security teams can develop policies and deploy strategies to keep this data more secure and minimise consequences. This might mean using network segmentation to add an extra level of security or creating access control policies based on who needs access to these specific sets of data.<\/p>\n<p><strong>Technology<\/strong><\/p>\n<p>As discussed previously, there are a host of technologies that security teams can implement in order to layer their defences. That being said, it\u2019s important that IT teams do not implement isolated point solutions as they layer their defences, but rather, select those tools based on their ability to be integrated and automated to create a Security Fabric that can facilitate the rapid detection and mitigation of threats.<\/p>\n<p>Another tactic IT teams should leverage is deception technology. Network complexity is an achilles heel for adversaries. Deception technologies level the playing field by automating the creation of dynamic decoys that are dispersed throughout the IT environment, making it harder for the adversary to determine which assets are fake and which are real.<\/p>\n<p>When an adversary can\u2019t make this distinction, cybercriminals are forced to waste time on fake assets and exercise caution as they look for tripwires embedded in these fake environments. This may require them to alter their tactics, thereby increasing their chances of being detected by security teams.<\/p>\n<p>Finally, IT teams should leverage segmentation. Adversaries target networks to gain access to and exploit organisations\u2019 business-critical data, whether that is their customer and personnel information, intellectual property, financial records, etc.<\/p>\n<p>Segmenting corporate networks enables IT teams to separate their applications and sensitive data into different segments of sub-networks with varying degrees of security. This allows for greater access control on critical systems, thereby limiting exposure if there is a breach.<\/p>\n<p><strong>Final thoughts<\/strong><\/p>\n<p>Modern network security requires a layered defence\u00a0approach\u00a0that factors in people, processes and technology. Together, such tactics \u2013 including creating a strong culture of security, conducting threat research, prioritising assets and deploying modern network controls \u2013 will enhance visibility and shorten threat response times, resulting in minimising the impact of cyberattacks.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Alain Penel, Regional Vice President \u2013 Middle East, Fortinet, outlines the various approaches to cybersecurity, which includes the three crucial aspects \u2013 people, processes and technology. Cybercrime is an ever-present threat facing organisations of all sizes. In order to safeguard themselves against a successful data breach, IT teams must stay a step ahead of cybercriminals [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":33052,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,36,4115,809,3629,79],"tags":[2669,1529,3106,1530,255,35,562],"class_list":["post-33051","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-intelligent-technology","category-intelligent-technology-newsletter","category-more-news","category-newsletter","category-used","tag-alain-penel","tag-cybercrime","tag-cybercriminals","tag-cybersecurity","tag-data-breach","tag-fortinet","tag-middle-east"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/33051","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=33051"}],"version-history":[{"count":5,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/33051\/revisions"}],"predecessor-version":[{"id":33070,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/33051\/revisions\/33070"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/33052"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=33051"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=33051"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=33051"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}