Don’t be lazy: Never trust, always verify.

Everything we can want is at our fingertips and ripe for the picking. But, should you really take all that you can?

After-all some of it may just me downright rotten. Yes I’m still speaking about technology.

Border walls don’t keep anyone out.

That next gen firewall your provider sold you at 50% margin is useless to a degree. Let’s remember a firewall is a detection device for the perimeter. As long as there are tunnels and your firewall is letting something through (like Facebook or Google) then anything can get in.

Data is the new border and it can be housed anywhere.

How many devices do you interact with on a day to day basis?

  1. Mobile phone
  2. Desktop/Laptop
  3. Tablet
  4. Smart something or the other tracking you
  5. VoIP handset
  6. Printer/Copier

Now chew on this. How many employees in your office, each with at least half of the above plus personal devices all connected to the work network?

The problem.

That pit in your stomach, is the realization your business is and has always been an ISP (Internet Service Provider) with a healthy mix of company owned and privately owned assets all interconnected on your network.

Someone will always get in, but what are you doing to prevent them from getting out with the data and being able to view and use that data?

Let’s be honest, it’s only a breach if they are able to get the data out of your systems. No matter what industry you’re in, we are all in the same boat. We have to protect the data, and our most valuable assets are our Achilles heal. People.

Your solution?

  1. You have the greatest next gen firewall with the best margin your provider sold you?
    1. Not good enough.
  2. You use the ever popular “next gen anti-malware”?
    1. Not good enough.
  3. Your network is segmented in to vLAN’s?
    1. Not good enough.
  4. Your provider is “monitoring & managing” your systems?
    1. I call BS, but we can get to that later, because a pre-configured notification for low disk space is what most of your providers are monitoring.
  5. You think you spend a lot of money on I.T. so you’re safe?
    1. No you’re not and yes, not good enough.

If you answered yes to any of the above, then we should set up a conversation to review your needs.

Our solution.

Identify what needs to be protected.

Set up policies to secure the Identity Management of your users.

We like single-sign-on (SSO), its a single centralized set of credentials (which in this day and age you don’t even control anymore) used to authenticate that you are who you say you are. This centralized identity allows you to access resources as defined by your company.

Now you’re thinking, well if the SSO credentials get breached then all is lost. Yes and no, if you have Kontinuum monitoring and detection in place (ie not that impotent monitoring and management your current provider is giving to you) we can help shut down the attack at a single point of failure saving you time to stem the breach.

It’s as simple as protecting the data at rest and in motion with Identity management.

By defending the user identity and the data, your systems will inherantly be more secure. Because you are literally controlling the data.

What else should be done?

  1. Is everything being logged?
    1. It is, great!
  2. Are your logs being audited for attacks and breaches?
    1. It’s not, scroll down and get in touch, its time to break up with your current provider.

If you’re a client of ours, your logs are stored in a Security Information & Event Management System (SIEM) and audited in a Security Operations Center (SOC) built from the ground up to help protect you 24/7.

Why does log aggregation and auditing matter? People are great, but we have a flaw. We are creatures of habit which is why continuous monitoring of data movements will help mitigate attacks and improve active response protocols.

The takeaway?

The old containerized method of security is useless by itself in today’s world. Protect your data and you will protect your business.

As always, if this is too much for you to handle or your existing I.T. provider is inept, get in touch with us.

Fan of the show?

If you have any questions you'd like to ask or would like to be a guest on the show, use one of the buttons below.

Copy of cover V.21
About

Plans are useless but planning is indispensable and crisis will reveal how you operate.

Join me as I discuss ongoing cybersecurity incidents, trends and best practices to help information security professionals catch threats before they become incidents.

Connect
  • info@amplifiedandintensified.com

  • Contact

  • Spotify

  • Apple Podcast

  • YouTube Channel