Are You Ready for the Next Wave of Cyber Attacks? Top 3 Security Strategies You Should Adopt Today


This past October, Kroll Inc. reported in their Annual Global Fraud Report that for the first time electronic theft surpassed physical theft and that firms providing financial services were amongst those who were most impacted by the surge in cyber attacks. Later that same month, the United States Federal Bureau of Investigation (FBI) reported that cyber criminals were focusing their attention on small to medium-sized businesses.

As someone who has been professionally and legally hacking into computer systems and networks on behalf of organizations (often called penetration testing or ethical hacking) for more than 10 years I have seen many Fortune 100 organizations struggle with protecting their own networks and systems from cyber criminals. This should come as pretty grim news especially for smaller businesses that generally do not have the resources, time or expertise to sufficiently secure their systems. There are however easy to adopt security best strategies that will help make your systems and data more resilient to cyber attacks. These are:

  • Defense in Depth
  • Least Privileges
  • Attack Surface Reduction

Defense in Depth

The first security strategy that organizations should be adopting today is called Defense in Depth. The Defense in Depth strategy starts with the notion that every system at some point will fail. For example, car brakes, airplane landing gear and even the hinges that hold your front door upright will all eventually fail. The same applies for electronic and digital systems that are designed to keep cyber criminals out, such as, but not limited to, firewalls, anti-malware scanning software, and intrusion detection devices. These will all fail at some point.

The Defense in Depth strategy accepts this notion and layers two or more controls to mitigate risks. If one control fails, then there is one other control right behind it to mitigate the overall risk. A great example of the Defense in Depth strategy is how your local bank protects the cash inside from criminals. On the outermost defensive layer, the bank uses locked doors to keep criminals out at night. If the locked doors fail, then there is an alarm system inside. If the alarm system fails, then the vault inside can still provide protection for the cash. If the criminals are able to get past the vault, well then it's game over for the bank, but the point of that exercise was to see how using multiple layers of defense can be used to make the job of the criminals that much more difficult and reduce their chances of success. The same multi-layer defensive strategy can be used for effectively addressing the risk created by cyber criminals.

How you can use this strategy today: Think about the customer امنیت سایبریdata that you have been entrusted to protect. If a cyber criminal tried to gain unauthorized access to that data, what defensive measures are in place to stop them? A firewall? If that firewall failed, what's the next implemented defensive measure to stop them and so on? Document each of these layers and add or remove defensive layers as necessary. It is entirely up to you and your organization to decide how many and the types layers of defense to use. What I suggest is that you make that evaluation based on the criticality or sensitivity of the systems and data your organization is protecting and to use the general rule that the more critical or sensitive the system or data, the more protective layers you should be using.




0 Comments

Curated for You

Popular

Top Contributors more

Latest blog