- Reassessment of cybersecurity means examining assumptions.
- ‘Safe choices’ may not be all that safe.
- Be prepared to change what’s on the table at procurement time.
The vast majority of operations in today’s organisations are contingent on technology. Technology is under attack by bad actors, and even those well-reputed in the cybersecurity sector are far from immune from being compromised.
Protecting any organisation from data loss is a numbers game: odds of cyber incursion can only be made longer. The oft-repeated (and oft-ignored) advice to patch devices and protect systems in various ways (zero-trust, perimeter defence, authentication, privilege management, and so on) lifts an organisation out of the ‘easy victim’ status relatively simply.
But there are huge assumptions made about IT, its users, software, and common services in the workplace. For example, laptop fleets have to be refreshed every few years. So why keep using the same laptops from the same supplier? Surely, there are safer alternatives? Multi-factor authentication (MFA) is known to be effective in preventing data breaches, so if platform XYZ doesn’t support it, why use platform XYZ? Could platform ABC work as well, and offer MFA out of the box?
Objective reassessment of cybersecurity practices means challenging assumptions and having the courage to see change through. The following list details some issues organisations could consider to improve cybersecurity and resilience. Some of them need monetary buy-in from decision-makers, while others are more operational. Almost without exception, change requires staff education, and that too costs. The benefits of some of what follows, apart from better cybersecurity, include improved data privacy, and a more engaged workforce (thanks to all that ongoing education and training), one with a deeper knowledge of the tools they use to get a day’s work done.
2FA
Ensure that every platform used throughout the organisation uses 2FA (two-factor authentication). If there’s a solution that doesn’t allow MFA, plan and instigate a migration to a platform that fulfils the same need in the business, but that has a secure 2FA facility.
Note that secondary authentication by SMS or email is not acceptable. Organisations should use hardware authentication devices or an authentication/OTP (one-time-password) application that’s given to every member of staff, contractor or third-party, preferably one with a biometric lock – fingerprint, facial recognition, etc.
Password managers
Equip every member of staff with a software password manager, and insist on its use on mobile, desktop, and in-browser. Many providers of such software allow staff accounts they can use in their home lives, and this should be encouraged. Ensure adequate training is given to every member of staff in how to use the software.
While rotating passwords and forcing password changes is held not to increase security effectiveness, an initial forced password reset on every platform in use in the organisation might be considered once staff are confident with the password manager app’s use. Perhaps a password reset or two could be part of staff training?
Single sign on
The balance that SSO (single sign-on) keeps between convenience (for users, line-of-business managers, helpdesk administration) and the presence of a single point of failure might be reassessed in light of some data breaches. The decreased attack surface that SSO presents also makes it an obvious target, given SSO providers tend to be well-known.
Organisations might consider running their own SSO service, or go back to separate account access credentials on every service. Sure, having discrete credentials for every platform can be an administrative headache and inconvenient for users, but as long as login policies and privileges are maintained, login separation limits the potential fallout from a single breach.
Snapshots
Assuming that attacks happen, and one will, one day, be succesful is core to any reassessment of cybersecurity. With that eventuality in mind, it might be wise to consider migrating all the organisation’s data to repositories where data can be duplicated at filesystem level (snapshots), with scheduling set according to the importance of the data stored. Meta relies on Btrfs, while ZFS is often touted as superior. Amend disaster recovery procedures and the practice routines for all technical staff (see below).
With filesystem-level backup, it’s also possible to allow end-users access to snapshots of their own data so they can restore old versions of documents and files deleted or lost without needed helpdesk intervention. Staff training will be appropriate in this context, although the cost could be seen as offset by savings made on the time expended by IT support staff in the long term.
The organisation’s data storage methods may need reassessment to achieve snapshot capability. Cloud storage may need to be replaced or rebuilt, and it may be worth considering taking some, if not all, storage back on-premise for the sake of backups and recovery.
Disaster recovery practice
Ensure that all IT staff can retrieve and restore lost data, and that they practise the procedures regularly. Having one or two personnel only who are conversant with how data recovery works creates a point of failure that’s likely to be tested at the least convenient moment.
Given the safe assumption a cyber attack or disastrous data loss is coming, being ready to recover data at any scale, in an acceptable timeframe, should be cybersecurity 101.
Staff equipment, part one
If the organisation needs its employees to use a mobile phone in the context of work, then such devices should be supplied by the employer to facilitate this. By issuing work mobiles, the organisation is justified in locking down any device and services it’s to access. The device shouldn’t allow any other applications or modifications other than those mandated, and the services accessed can be locked to company-issued devices.
This step prevents the mixing of work and personal accounts and services, and prevents unauthorised access by unrecognised devices in ways that ‘BYOD-and-hope’ policies can’t.
Staff equipment, part two
The Windows operating system could have been designed with insecurity at its core. Thanks to the wide variety of applications Windows has had to run over the years, and the resulting legacy support that has had to be part of the operating system, the Windows desktop represents a security breach waiting to happen, despite the many applications that purport to lock it down.
To remove all staff devices from the category of low-hanging fruit for bad actors, transition the organisation’s desktop to an alternative such as FreeBSD, Linux, or for the deep-pocketed, the expensive yet relatively more secure macOS.
Such a transition will require extensive testing of the applications and services in current use by the workforce, and a significant investment in training for users and IT support staff. But no other measure is more effective for cybersecurity than moving the organisation to a computer operating system that’s secure by design.
People are the weakest link in any security chain, so issuing what’s a cocked and loaded gun to staff is asking for trouble that the majority of organisations seem happy turn a blind eye to.
Service alternatives
In most organisations, software and services get embedded into workflows by design or, nearly as often, by accident or happenstance. If IT staff are to be responsible for maintaining cybersecurity, they need the wherewithal to change established platforms as long as more secure alternatives exist, or – in extreme cases – rule against the use of some commonly-used applications.
Using Teams or Slack as messaging platforms, for example, may be widespread, but can be switched out for alternatives that are simpler, less expensive to run or license, and have much better security provenance. Similarly, platforms like Office 365 or Google Workspace are considered ubiquitous, yet offer few advantages other than not needing staff to be trained in their use. Alternatives may offer only security by obscurity, but there are options for 99.9% of even the most complex of application suites that, unlike the household name standards, have been engineered to operate more securely.
Conclusions
Rethinking cybersecurity means rethinking computing, and the ways that employees use technology. The standard choices in platforms and software can be dictated not so much by their efficacy as products, but by the efficacy of the vendor’s marketing activities.
The old saying went that no one ever got fired for choosing IBM. Today, people do get fired for using Cloudflare, Okta, LastPass, Windows or Android, usually a month or two after a data breach. But, of course, no one gets fired when those products are the subject of procurement negotiations. They’re ‘safe’ choices, after all, aren’t they?
Author
- View all posts
Joe Green is a writer based in Bristol, UK. He acquired his first Mac and dial-up modem in 1992 and has worked in the tech industry since 2000. He writes and podcasts, specialising in open-source, networking, cybersecurity, software development and online privacy.