{"id":80004,"date":"2022-12-12T09:33:39","date_gmt":"2022-12-12T09:33:39","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/2022\/12\/12\/four-strategies-for-making-the-network-safer\/"},"modified":"2023-05-25T10:23:09","modified_gmt":"2023-05-25T09:23:09","slug":"four-strategies-for-making-the-network-safer","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2022\/12\/12\/four-strategies-for-making-the-network-safer\/","title":{"rendered":"Four strategies for making the network safer"},"content":{"rendered":"\n<p>Adrian Taylor, Regional VP of Sales at A10 Networks, discusses the key considerations cybersecurity leaders should include in their business strategy to ensure they protect the network and guarantee digital safety.<\/p>\n\n\n\n<p>CSOs, CIOs and CISOs have never had it so tough. Alongside their traditional responsibilities, they must now face a cybersecurity\u202fthreat environment that is growing exponentially, as well as a growing cyberskills gap. As a result, many of them are reporting burnout.<\/p>\n\n\n\n<p>Today,\u202fransomware\u202fhas become one of the greatest network security threats organisations have had to deal with. Increasingly sophisticated and distributed at a high speed via the Internet and private networks using military-grade encryption, today\u2019s ransomware attacks demand multi-million-dollar ransoms.&nbsp;As per the findings of the <em>2022 IBM Security X-Force Threat Intelligence Index<\/em>, the Middle East and Africa (MEA) region was ranked fourth worldwide for the most ransomware attacks. According to a report by Group-IB, between Q1 2021 and Q1 2022, the data belonging to 147 companies from the MEA region was uploaded on ransomware dedicated leak sites (DLS). And this is only one of the many threats targeting organisations.<\/p>\n\n\n\n<p>There are also\u202fDistributed Denial of Service (DDoS) attacks, Man in the Middle (MitM) attacks, social engineering, insider threats, malware and advanced persistent threats (APTs) to contend with \u2013 and those are just the most common\u202fnetwork security threats.<\/p>\n\n\n\n<p>Here are four strategies to make cybersecurity professionals\u2019 organisations safer from the countless network security threats they\u2019ll be facing in the near future:<\/p>\n\n\n\n<p><strong>1 Create a \u2018security-first\u2019 culture<\/strong><\/p>\n\n\n\n<p>The\u202fproblem for CSOs\u202fis that, while most employees have some basic knowledge of cybersecurity best practices, that is pretty much all they have. Without ongoing training, knowledge testing and awareness, staff behaviour is one of the biggest cybersecurity risks that organisations face.<\/p>\n\n\n\n<p>A study by Accenture\u202frevealed that less than half of new employees receive cybersecurity training and regular updates throughout their career. Just four in 10 respondents said insider threat programs were a high priority.<\/p>\n\n\n\n<p>Organisations must look to create a robust and distributed digital immune system with a radical re-engineering of staff behaviour. Business leaders need to have\u202faccountability for cybersecurity; security teams need to collaborate with business leaders to create and implement policies that will actually work and those policies need to be routinely re-evaluated and tested.<\/p>\n\n\n\n<p><strong>2<\/strong> <strong>Create a continuous security education programme<\/strong><\/p>\n\n\n\n<p>A \u2018security-first\u2019 culture requires that all members of the culture appreciate the concept of network security threats. For this to actually have an impact on culture, however, staff must be trained routinely to ensure their knowledge is current.<\/p>\n\n\n\n<p><strong>3<\/strong> <strong>Implement a Zero Trust model throughout the business<\/strong><\/p>\n\n\n\n<p>Well-trained staff and a monitored environment are crucial to the successful protection of any organisation but without a foundational\u202fZero Trust environment, defences will be intrinsically weak.<\/p>\n\n\n\n<p>The\u202fZero Trust model\u202fis a strategy for preventing network security threats that all enterprises and governments should be using to defend their networks. It consists of four components:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Network traffic control:<\/strong>\u202fEngineering networks to have micro-segments and micro-perimeters ensures that network traffic flow is restricted and limits the impact of overly broad user privileges and access. The goal is to allow only as much network access to services as is needed to get the job done. Anything beyond the minimum is a potential threat.<\/li>\n\n\n\n<li><strong>Instrumentation:<\/strong>\u202fThe ability to monitor network traffic in-depth along with comprehensive analytics and response automation provides fast and effective incident detection.<\/li>\n\n\n\n<li><strong>Multi-vendor network integration:<\/strong>\u202fReal networks aren\u2019t limited to a single vendor. Even if they could be, additional tools are still needed to provide the features that a single vendor won\u2019t provide. The goal is to get all of the multi-vendor network components working together as seamlessly as possible to enable compliance and unified cybersecurity. This is a very difficult and complex project but keeping this strategic goal in mind as the network evolves will create a far more effective cybersecurity posture.<\/li>\n\n\n\n<li><strong>Monitoring:<\/strong>\u202fEnsure comprehensive and centralised visibility into users, devices, data, the network and workflows. This also includes visibility into all encrypted channels.<\/li>\n<\/ul>\n\n\n\n<p>At its core, the\u202fZero Trust model\u202fis based on not trusting anyone or anything on the company. This means that network access is never granted without the network knowing exactly who or what is gaining access.<\/p>\n\n\n\n<p><strong>4 Establish and test Disaster Recovery plans&nbsp;<\/strong><\/p>\n\n\n\n<p>A key part of a Disaster Recovery plan involves backups. However, it is surprising how often restoring from backup systems in real-world situations doesn\u2019t perform as expected. It\u2019s important to know which digital assets are and are not included in backups and how long it will take to restore content.<\/p>\n\n\n\n<p>CSOs should plan the order in which backed-up resources will be recovered, know what the startup window will be and test backups as a routine task with specific validation checks to ensure that a recovery is possible.<\/p>\n\n\n\n<p><strong>Staying secure<\/strong><strong><\/strong><\/p>\n\n\n\n<p>The CSO\u2019s job isn\u2019t getting any easier, but solid planning using the four strategies will help ensure an organisation\u2019s digital safety. In addition, partnering with top-level enterprise cybersecurity vendors will ensure that critical security technology and best practices are central to the organisation\u2019s cybersecurity strategy.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Adrian Taylor, Regional VP of Sales at A10 Networks, discusses the key considerations cybersecurity leaders should include in their business strategy to ensure they protect the network and guarantee digital safety. CSOs, CIOs and CISOs have never had it so tough. Alongside their traditional responsibilities, they must now face a cybersecurity\u202fthreat environment that is growing [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":80347,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[14804,6,13],"tags":[],"class_list":["post-80004","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-insights","category-top-stories"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/80004","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=80004"}],"version-history":[{"count":3,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/80004\/revisions"}],"predecessor-version":[{"id":80264,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/80004\/revisions\/80264"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/80347"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=80004"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=80004"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=80004"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}