7.5 Things That Will Protect You Before, During and After a Cyber Event

padlock for cybersecurity and cyber event protection
The call came early one morning. The report was that none of the files on the network server were accessible. The SOC also reported detecting anomalous behavior in the middle of the night and isolating resources on the network to stop what appeared to be a hacker trying to gain more access.

After investigation, it became apparent that at least one server on the network had been ransomware-locked. The good news is that the Advanced EDR tool and SOC detected the activity early and isolated the damage. The bad news was that the threat actor did get in.

After further investigation and remediation, the damage was limited. The hacker had only infiltrated one server and none of the workstations. After careful evaluation, making sure the threat actor’s access was terminated, resetting security, and performing some system restores, service was restored. This was a good outcome, but it still forced the company down for more than a day.

How did it happen? In this case, and in others we have seen, the point of entry was a breach of the company’s remote access. In this instance, one of the user’s VPN credentials was compromised, and the threat actor got in that way. They may have obtained the credentials through phishing or brute-force attempts, along with an overly permissive password policy.

This and other breaches we have helped remediate underline the need to adhere to IT best practices with more diligence than ever. Preventing these attacks is the best place to focus time and energy. If you have ever been through the pain of a breach, your awareness and concern over following them will be significantly heightened!

What are the core things that will keep us safe in a cyber event? Honestly, they are the somewhat boring things our Strategic Technology Advisors talk about all the time with customers.

Here are 7.5 Things That Will Protect You Before, During, and After a Cyber Event

1) MFA for Remote Access

However your team members access your network remotely, whether through a VPN, Screen Connect, Tailscale, some form of RDP, or some other remote access tool, make sure that you are using multi-factor authentication. This requires entering an additional code periodically to authenticate to the system. Also, make sure MFA is turned on for ALL users, without exception. Yes, this is an extra step, but I can’t stress enough that it is ABSOLUTELY necessary.

2) Up-To-Date Firewall

Your firewall is the traffic cop between you and the Internet. It needs to be updated or patched when new security releases come out. Many times, this is a manual update, depending on the brand, so it gets overlooked. There needs to be a process in place to make sure updates happen. Also, this device should not be allowed to go beyond the support period, because after that, the maker no longer produces security updates. Keep that firewall refreshed and working for you!

3) Advanced EDR with SOC

Here we are with the IT acronyms. We used to call this antivirus, but now it’s much more involved. EDR stands for Endpoint Detection and Response. SOC stands for Security Operations Center. This is clearly a case where this is not your father’s antivirus, and that old stuff is not good enough anymore. You need a product that detects viruses, detects anomalous behavior that might indicate someone is infiltrating your network, and has a 24×7 team of security experts addressing any issues. This is no longer optional. It is a MUST.

4) Cyber Awareness Training

How do threat actors gain access? Often through phishing, but generally through trickery. They use all sorts of schemes to trick your team into giving up information or access and can perpetrate these nefarious tactics at scale, without regard to company size or value. Cyber Awareness Training helps your team stay savvy so threat actors can’t fool them.

5) Up-to-Date Networking Products

If you are a client of CTaccess, you are aware of the cycle planning that we help you do. Often, we think of this cycle planning as smart asset management so our team isn’t slowed down by older hardware. Another reason this is so important is that if a threat actor breaches your network and you have old, out-of-support operating systems or hypervisors, they can move around undetected and more quickly. Being diligent about removing unsupported software is key to staying safe.

6) Backup and Disaster Recover

If you ever have a cyber incident, the value of your backup will be tested. Is it solid and tested? Do you have an offsite or cloud copy that is immutable (locked so the threat actor can’t destroy it)? Is your recovery time fast enough? There are many backup options to speed recovery and add extra protection. Depending on your business, exploring options for faster uptime or more resilience may be important.

7) Hybrid Cloud and Diversification

If you are still running most of your resources on your local network, diversifying data and applications to cloud hosting helps spread things out so a breach is less likely to take your whole operation down. Moving user files to SharePoint and OneDrive is a simple example. And even moving certain key applications to SaaS puts them in a separate basket, making it harder for a single threat activity to take down all operations.

7.5) Passwords

This one only counts as a half point, because I feel like it is just too obvious, but still so many people don’t follow good policy. Make sure everyone follows a password policy that aligns with best practices, with ABSOLUTELY no exceptions.

The security of our networks is just too important. None of us can afford to be down or want to go through the pain of recovery. Though we can never eliminate all risk, a simple adherence to these points will reduce your likelihood of a breach to a low level.