{"id":1858,"date":"2020-10-20T19:27:41","date_gmt":"2020-10-20T18:27:41","guid":{"rendered":"http:\/\/www.intelligentcio.com\/north-america\/?p=1858"},"modified":"2020-10-20T19:27:42","modified_gmt":"2020-10-20T18:27:42","slug":"10-top-tips-for-ensuring-a-companys-cybersecurity-is-not-put-at-risk","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/north-america\/2020\/10\/20\/10-top-tips-for-ensuring-a-companys-cybersecurity-is-not-put-at-risk\/","title":{"rendered":"10 top tips for ensuring a company\u2019s cybersecurity is not put at risk"},"content":{"rendered":"\n<p><em>We asked industry experts how technology leaders can ensure the work practices of their colleagues do not put their company\u2019s cybersecurity at risk.<\/em><\/p>\n\n\n\n<p>Here\u2019s the response from Rob Chapman, Director of Security Architecture at Cybera.<\/p>\n\n\n\n<p>\u201cThis is a great question worth a regular revisit. The answer is a combination of appropriate technology controls and enforced policy. The hard part is enforcing policy consistently. We\u2019re talking about limiting the blast radius of user actions whether unintended or subversive. People tend to choose the path of least resistance. You should build your policies and controls so that people make better choices.<\/p>\n\n\n\n<p>Start with a risk assessment. When you examine your environment ask the question: \u201cWhat\u2019s the worst that could happen if my employee does x?\u201d There\u2019s no magic solution but rather a net gain of efforts across lots of domains.<\/p>\n\n\n\n<p>Here are some ways to get started but consider bringing in a professional. Having a new set of eyes on your environment can often help uncover areas you might be blind to.<\/p>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\"><li>Standardize on a set of controls to help guide your security program. If you have a compliance obligation like PCI it may help fill in some of these gaps. Getting started I recommend the CIS top 20 controls <a href=\"https:\/\/www.cisecurity.org\/controls\/cis-controls-list\/\">https:\/\/www.cisecurity.org\/controls\/cis-controls-list\/<\/a>. Several of the items I list below are captured here and a few more I don\u2019t have the space to list.<\/li><li>Turn on multi-factor authentication everywhere especially email. MFA is the best bang for your buck.<\/li><li>Segment your network. Printers, servers, workstations and infrastructure systems should be on their own network segments with appropriate firewall rules between them. You should not have a flat network where anything can talk to anything else it wants.<\/li><li>Invest in an email security\/firewall solution. These won\u2019t catch everything, but they cut down on a lot of noise. Phishing is probably your biggest area of weakness for employee vulnerability.<\/li><li>Remove unnecessary administrative access and practice least privilege. Your average employee should never be admin on their computer. They shouldn\u2019t be root, domain admin, SAP_ALL, or have full file server access. Build appropriate roles for users and remove all admin access.<\/li><li>Install a good endpoint, detection and response (EDR) solution. Modern EDR platforms are generally really good at preventing malware, fileless threats and ransomware.<\/li><li>Require MFA and encrypted VPN for any remote access to the environment. You\u2019re probably not Google so don\u2019t worry about anything fancier if you aren\u2019t doing this. If you can remote desktop from home without VPN then you\u2019re probably doing this wrong.<\/li><li>No special snowflakes. I don\u2019t care if it\u2019s an executive or some remote salesperson. No one is exempt from security controls. Snowflakes kill security controls. If you\u2019re a technology leader and you have admin rights to anything you\u2019re probably over provisioned.<\/li><li>Enforce long passwords. Don\u2019t change them too often. Once a year is probably plenty. Whatever length you have set now is probably not long enough.<\/li><li>Plan for failure. You should have regular backups and a Business Continuity plan for when things break. You should also be testing your backups regularly. Lastly, your backups shouldn\u2019t be accessible from the systems that are being backed up.\u201d<\/li><\/ol>\n","protected":false},"excerpt":{"rendered":"<p>We asked industry experts how technology leaders can ensure the work practices of their colleagues do not put their company\u2019s cybersecurity at risk. Here\u2019s the response from Rob Chapman, Director of Security Architecture at Cybera. \u201cThis is a great question worth a regular revisit. The answer is a combination of appropriate technology controls and enforced [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":1859,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[3,17,42,43],"tags":[1040],"class_list":["post-1858","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-analysis","category-enterprise-security","category-thought-leadership","category-top-stories","tag-editors-question"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/1858","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/comments?post=1858"}],"version-history":[{"count":2,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/1858\/revisions"}],"predecessor-version":[{"id":1861,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/1858\/revisions\/1861"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media\/1859"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media?parent=1858"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/categories?post=1858"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/tags?post=1858"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}