On this post I will tell you how simple hygiene actions (with no additional tools required) can be implemented within your network, preventing digital illness and unnecessary disruption exposure.
On our previous post, Cyber Hygiene basics, we saw the similarity between body hygiene and network cyber hygiene. We also realized that the first step towards cleaning our network would be mapping. The depth of your mapping will determine your future ability to implement the coming suggested actions. We recommend to detail as possible, however, we do understand that it consumes time and manpower effort.
Highly important to emphasize is that hygiene does not require spending money on technology and tools. On the contrary, we believe you should start simple with your existing tools and only once processes are controlled and stable, consider automation and enforcement.
Prioritizing is the place where the organization draws lines between his crucial assets that eventually makes the money and additional services that support the money-making process. Since we cannot eliminate all risks, prioritization will segment our assets. Here is how to:
Categorizing network devices and software won’t just help you to get the most important tasks done quickly, it also allows you to better manage the IT and security workloads.
The ultimate step in the Cyber hygiene methodology is responding. Here are the actions that you can do to secure and reduce the likelihood of a cyber-attack. I divided the list into two categories: permanent actions (more like habits) and actions you should do periodically.
You can determine the interval periods and you should set up a task list routine that should be done every period determined.
Although it might not be consider as hygiene, another important step is employees training.
Eventually, many attacks start with employees that have legitimate access and do mistakes or being manipulated to mistake. Teach them to avoid mistakes. Make them understand why certain action is a risky one. guide them how to act in the digital world. Here are some massages to pass:
Risks are a business problem and each organization will deal with it differently. The logic is simple, keep the network clean as possible, organized and updated. Once achieved and you will have less problems. If you do have a problem, it will probably be easier to find, analyze and respond to.
I invite you to start implementing cyber hygiene in your organization. If you need assistance or even deeper guidance, we at CST-360 would love to assist. Just contact us.
These posts are the firsts out of some new series I will write about cyber world fundamentals.
My name is Yoav Berger, and I am an analyst at CST-360. I started a research process on cyber-related topics, and I wish to share what I have learned. Eventually, the goal of these posts is to help anyone who wants to improve his cybersecurity knowledge and give fundamental cybersecurity tools that can be applied right away.
