
In our time, more and more businesses are trying to secure their infrastructure against attacks, but they still make basic mistakes. Below you can see how such mistakes can be avoided.
- They are flexible with Admin accounts
Your business probably has multiple administrator accounts, giving employees unlimited control over vital hardware and services. And that's dangerous, according to Rob Clyde, CEO of Clyde Consulting.
Clyde calls admin accounts “the weak point of any organization.” He explains, “Administrators have full privileges and often have access to virtual environments and the cloud. This means that a hacker who gains access to an administrator account can literally take over an entire enterprise. And yet attacks targeting administrators are often overlooked.”
He recommends that organizations choose the number of administrator accounts and make sure that only those who need them have them. He also suggests that each account only have access to the resources it actually needs to do its job.
Finally, according to Clyde, the enterprise should consider secondary approval for certain procedures, such as deleting all virtual machines or containers. That way, even if hackers gain access to an administrator account, they won't be able to do as much damage because other administrators in the organization must also give approval for high-risk actions.
- They ignore the need for a comprehensive risk management framework
Companies often develop a set of security systems and procedures but fail to consider how cyber risks affect the entire organization. As a result, cybersecurity is seen as a purely technical issue that requires attention only from the IT department, not from the entire business. The result? Businesses are less secure because it is not possible for every team and individual to be aware of cyber risks and be vigilant against them. So says Chris Dimitriadis, former chairman of the ISACA Board of Directors.
Mr. Dimitriadis says that a comprehensive risk management framework should clearly outline how cyber risks translate into business risks and how they can impact the business. Organizations can risk millions of dollars and lose customer trust. This way, the entire company, from the board of directors to the employees, will be aware of the risks and be more likely to avoid them.
- They don't make the necessary updates
Mr. Clyde and Mr. Dimitriadis highlight the importance of what should be a routine part of a business’s proactive security routine. However, far too many organizations still forget to incorporate this practice. There are countless examples of unpatched vulnerabilities leading to successful cyberattacks, with losses literally running into the hundreds of millions of dollars.
- They ignore the security of IoT devices
It's easy for companies to forget that their IoT devices, like sensors and surveillance cameras, are a very large and very tempting target for hackers and can be easily exploited. Clyde says companies should treat them the same way they treat servers and other IT-related systems. That means not only making sure they're protected with things like firewalls, but also keeping them up to date and guarding against frequently changing passwords.
- They do not offer adequate training
The best protection against hackers and data breaches is a workforce educated on cybersecurity risks. But while that’s the first line of defense, the vast majority of companies haven’t instilled a solid cybersecurity culture. Clyde points to a 2018 ISACA study in which 95 percent of security professionals said there’s a gap between the security culture their company wants and the security culture they have.
The best way to instill a culture of cybersecurity awareness is through training. And proper training doesn't just mean seminars that employees reluctantly attend and then promptly forget. It means actively and continuously working on these issues.
