Secure your company from cyber attack

Akiram

Free Member
Aug 24, 2016
3
0
Hello all,

apart from firewall, anti-malware and anti-virus software, how do you secure your company from the threat of cyber attacks? Has any of you considered achieving Cyber Essentials certification?

Marika
 

soundengineeruk

Free Member
Jul 25, 2012
380
66
Walsall
My advice is:
  • Encrypt data
    • Encrypt Hard drives on machine (desktop, laptop), desktops especially if home based business
      • Bitlocker (free with various editions of Windows)
      • VeraCrypt (Open Source)
      • Symantic (Paid)
    • USB or External storage devices
    • Sensitive data; especially if storing to the cloud (Dropbox, one drive)
  • External hardware Firewall that sits between the internet and network..
    • Do not rely on software based on like Windows or the one that comes with your favourite Anti virus/malware software
    • A cost effective one is an old desktop or one off ebay (£40 to £60) with 2 network cards running PFSense.
      • A number of my small/home based clients have this, especially if a shared internet with home..
  • Work on least privilege access
    • If you issue any machines make sure that full admin rights are not provided
  • Security Awareness
    • Change passwords every 30/60 days
    • Do not use the same password for everything
    • Do not use easy to guess password (abc123) or something personal like your partners or children(s) names. Use complex passwords like rYx59gnP@jhw$NNp
 
  • Like
Reactions: Akiram
Upvote 0

Akiram

Free Member
Aug 24, 2016
3
0
It's a scheme developed by the UK Government to help companies improve their cyber security and avoid being victim of basic cyber attacks. It's based on 5 security controls (some of them mentioned by @soundengineeruk ).

The company I work for is one of the certification bodies for the scheme and has cost-effective solutions to help small and medium companies become cyber secure.
 
Upvote 0

John Blakeman

Free Member
Aug 5, 2016
48
4
I'm astounded on a regular basis by business owner's wilful ignorance in this field.
Business critical IT systems brought down because of a lack of backup / disaster recovery plan usually cost much time, money and reputation.

Learning this lesson first hand seems to be what motivates most into listening to us annoying IT engineers.
 
Upvote 0

soundengineeruk

Free Member
Jul 25, 2012
380
66
Walsall
Learning this lesson first hand seems to be what motivates most into listening to us annoying IT engineers.

It is a constant battle, some listen and some don't. The ones who don't listen, listen when they have lost or been breached.. Cyber Crime is on the increase from single Joe Blogs to the top dog corporations.
 
  • Like
Reactions: John Blakeman
Upvote 0

Ian Sutherland

Free Member
Aug 25, 2016
59
11
Darlington
I'm an advocate for cloud solutions, so where possible I would suggest hosting your data and applications with a cloud provider and let them look after cyber security i.e. having nothing on site or on PCs, then if you get attacked or hacked the risk is lessened (although you still need to be vigilant in protecting access to your cloud services). Look for providers with ISO27001 certification. Ideally go for one's in the UK that will let you visit their data centres so you can see where your data is kept and the security around it.
 
Upvote 0

CyberHour.com

Free Member
Aug 27, 2016
22
3
If you are talking for an website / application or online game what you should do is to host your project with provider who will can provide you speed,security and stability.

What you should be looking for is DDOS protection with high capacity .
Also avoid shared hosting and go for linux based VPS or Dedicated server.

I'm not aware of any serious and secure hosting provider with privacy protection who would let you to walk free inside their data centers. On our datacenter the only one who can access it is our staff members. If the datacenter let you to walk in then the whole idea behind security and privacy is gone.
 
Upvote 0

Stuartb3502

Free Member
Aug 19, 2016
18
2
South East
As a little contrast to a list of security technologies...

You can spend all day and all night forever looking at different technical lock-downs and measures to take, but it's often looking at the problem with the wrong end of the telescope once you're past the basics.

My advice is:

1) Work out what risks you're concerned about.

2) To do 1) you need to have a think about what information and services you need to protect.

3) To to 2) you'll need to think about why you want or need to protect these things - e.g. because you need them to run your business, the law requires it, the risk of reputational damage etc.

4) Prioritise the risks (often it can be helpful to use a scoring system which might look something like Risk Level x Impact = Score. Risk Level is how likely (e.g. 1-5) the risk is to happen and Impact is how big a deal it is if it happens (again, say 1-5).

You can look up risk assessment if you want and make it more complex, but in a nutshell this will do and you're just trying to get some perspective on what to worry about most and crucially, where you should spend money.

This may sound like a massive faff compared to asking for some recommendations and doing the ones like the sound of, but it changes it from being a technical problem to a business one.

If you don't do something like the above, you can spend fortunes and still miss the most important things.

Simplifying a little...

Things like Cyberessentials bundle up basic security measures that the majority of businesses should consider and essential security knowledge. It's an attempt to simplify doing something about security. Worthwhile if you don't know where to start, but don't get a false sense of....well, you know.

When you go through the steps set out above, consider a broad set of risks because when the stuff hits the fan, it doesn't matter whether it was some super clever DDoS attack from the other side of the world or the cleaner unplugging your server, the impact's the same.

Other advantages of the approach I recommend:

a) If you go through the above, you should be in a much better position to determine how much time and money to throw at the problem. On the one hand it will always be tempting to think that it's money spent on nothing (like insurance right :)?) On the other hand there will be plenty of security specialists who will give all sorts of dire warnings about how you need to do everything under the Sun. Neither's right unless tailored to your business (and the stage of your business).

b) You may work out that you have enough valuable information and services at risk that you want to get some paid help form a specialist to help with some of the assessment above and selection of security measures.

c) You'll need to consider the non-technical risks before getting to technical "solutions" e.g. employees/contractors accessing customer data not just external cyber attack.

d) You may be able to find a non-technical workarounds before you get to technical "solutions". - e.g. a (now trivial) example would be with credit card data - many ecommerce businesses now avoid the risk of holding credit card data altogether by using a payment processor. Another would be staff background checking and limiting access to data.

None of the above is meant to suggest that technical solutions for security are no good or not needed. There is a whole industry for security products and services whose marketing puts these uppermost in our minds. The reality is that addressing security in a business-like and effective fashion is about more than checklists.
 
Upvote 0

dexterash

Free Member
Feb 15, 2016
20
3
Coventry
Backup. Backup. Oh, did I say backup? And a recovery plan.
And updates.

Any measures someone takes will slow down an attack and maybe avoid simple attacks, but IT security (generally speaking - either network, data, website, app server, internal app etc) can't be bulletproofed (due to several reasons, including "social" ones).

In any event, it is important to know how fast can you react into isolating the "trouble", identifying the source/fixing the entry point(if it can be done) and then recover. After recovery, there might be some other steps needed (for example, in case of a databreach). But al; depends on the business type, as there isn't a for-all-cases recipe.
 
Upvote 0

Latest Articles