"We don't need anything, everything's secure, and we have nothing secret anyway"
Words I often hear from SMBs ( small and medium-sized businesses ). Don't expect criticism from me; it's similar to health. We deal with problems only when they happen.
Words I often hear from SMBs (small and medium-sized businesses). Don't expect criticism from me; it's similar to health. We deal with problems only when they happen. We're not experts in this area and it's easy for us to put on the "rose-tinted glasses".
You can find guides on the internet for everything, including security (cybersecurity), so why not knock something together at home on the cheap?
💡 The problem is two things — plus a third on top:
1) Context — you always need it. Without it you'll just blindly follow guides (which can be damn good, but might not be).
2) Complexity — when your company grows a bit, you've got more than 50 people, and things are still being run punk-rock style.
3) The tempting offer of "magic pills" that solve everything cheaply and forever. No IT staff needed — just MAGIC, install it and it's done. They might come labelled MFA, EDR, XDR, etc. By themselves these are great technologies — but vendors often massively overpromise…
🤔 What to do?
1) I have a colleague who's a cybersecurity pro
Then you've practically won. All they need to do is keep learning regularly and be "reasonably sensible". A periodic independent review from someone outside your company is a good idea. You get reassurance that you're heading the right way and maybe pick up a few tips. The opinion of a competent person is always handy.
2) IT — and security with it — is handled by our IT person (or IT firm), and they say everything's covered.
This one is trickier. People in smaller companies (and not only there) think every IT person is an expert in everything. From swapping printer toner, through physical and virtual servers, to firewalls and cybersecurity. And on every vendor's hardware, of course… No, that's really not how it works.
You can't get your Škoda fixed at a Volvo dealership; a paint specialist doesn't understand car electronics, even if they work at an auto shop, and so on.
👉 New-Year giveaways 🎁
Category 1) — one independent review is queued up for Q1/2024, just send me a message — first come, first served 🔥
Category 2) — I've prepared a few questions. Definitely not exhaustive, but you'll get a basic overview. You should get clear answers from your IT, whether they're in-house or an external firm. For anyone who'd like a review / status check / recommendations, I have 3 × 🎁 for the fastest movers.
🎯 The goal is to minimize cyber risk and financial losses. Money first, always. 🎯
🤚 Backups
1) Are we backing up our systems and data?
2) Are we using the 3-2-1 backup approach?
3) Do we have an immutable backup — one that ideally not even our own "IT person" can delete?
4) Are we backing up our cloud environments too?
5) Are we testing recovery — and when did we last test it?
👮♂️ User-account security
1) Do users not have administrator rights — whether on their laptops or in cloud apps?
2) Where possible, are we using multi-factor authentication (MFA)?
3) Am I applying the principle of least privilege — meaning I only have the permissions I need for daily work? Even an admin shouldn't be sending email under an account with admin privileges.
4) I'm not saving passwords in the web browser?
5) Do my employees / colleagues have a sense of what phishing is, why attackers do it, and how it works?
💻 Endpoint and software security
1) Am I using an advanced antivirus solution — ideally EDR or XDR?
2) Are devices that access company data managed? In other words, can I configure them centrally — and even wipe them if needed?
3) Are all devices encrypted? In case of loss or theft.
4) Am I making no exceptions and regularly auto-updating my devices and all software, with visibility on it?
5) If a device has a known critical vulnerability, will I find out about it automatically?