There is incredible value in taking a ‘back to basics’ approach to endpoint security. Focusing efforts on the fundamental aspects of security helps create a rock-solid, network foundation without the costs associated with procuring new hardware or software.
In the previous two articles, we discussed the importance of network visibility and data protection, that is, knowing exactly what’s on the network from servers to endpoints to data, and how to protect critical data with backup and recovery. The third tenet of a back to basics approach involves user roles.
Today, users are often on the front lines of the cybersecurity battle because they are some of the easiest targets. Instead of attacking a complex software vulnerability, using social engineering techniques, hackers can create extremely convincing email messages to users, which contain files designed to infect machines with malware or links to compromised websites used to extract information.
IT can help protect vulnerable users and secure data from social engineering and malware by placing a strong emphasis on assigning proper roles to each user – and removing administrator privileges – so that malware cannot be executed.
How account management helps
Typically, when a device becomes infected with malware it’s because the malicious code was able to be executed on a machine with
administrator privileges or exploited a vulnerability. It’s much simpler to target user machines and hope they have right level of privileges rather than try to exploit an advanced (and unpatched) vulnerability. In fact, when leveraged by cyber criminals, user privileges can act as a key vulnerability, granting intruders access to execute malicious software and gaining a foothold for a larger attack. Limiting user privileges on company hardware helps keep networks safe because it can help limit the scale of potential breaches, isolating them to a single device, or hopefully prevent them before they even start.
It goes without saying that in highly regulated environments such as the public sector, controlling user privileges should be a top priority. However, this basic IT function should not be overlooked by other organizations.
Make the most of your IT team’s time
In a recent McAfee Labs Threat Report, 67 percent of organizations indicated they had seen an increase in attacks and 93 percent reported they were unable to triage all relevant threats, a clear sign they are overwhelmed by the sheer number of security incidents. The recent Intel Security Cloud Report also suggests there is a shortage of security professionals, with 49 percent of organizations saying they had slow adoption of cloud services because of a lack of security skills.
A back to basics approach to security can help ease the burden of a rise in security incidents on IT teams by preventing many issues from happening. From network visibility to data protection and user management, the three tenets of this approach focus on the fundamentals of a secure enterprise network.
A fourth pillar: education
In many ways, education is just as important as network visibility, data protection and user management, but it is often a longer-term project. Teaching users about security best practices is an excellent preventative measure and worth the investment, because users can help identify sensitive data, and help prevent breaches.
Educating users in security best-practices is also an ongoing, long-term strategy and requires executive-level support to be truly effective, but is a worthwhile pursuit.
Get back to basics with DG Technology
In this three-part blog series, we’ve identified the three fundamentals that every security strategy should get right: network visibility, data protection and backup and user management. Now, get the right security strategy in place for your organization with a complimentary consultation with DG Technology’s team of security specialists.
It cannot be overstated: a “back to basics” approach to system security can reduce the number of administrative tasks and improve the overall security of an organization’s network. Those in charge of managing the day-to-day IT operations or C-level strategy for IT can often be in reactive mode – especially in the wake of a security incident – which can lead to a constant feeling of being overwhelmed and unnecessary purchases.
Going back to basics is about making sure priorities are focused. For example, instead of trying to protect every device on a network, organizations should focus on data protection best practices. Data protection through backup and recovery is an essential best practice and if the worst does occur it can make all the difference.
Identify prime backup targets
Data protection is not a ‘set-it-and-forget-it’ type of function. Often, it’s a complex undertaking that requires many steps. However, it’s a critical, basic IT function that comprises one of the three fundamental pillars of a back to basics IT security approach (the others being network visibility and account management).
When it comes to data protection, because many IT teams work in reactive modes they believe purchasing firewalls or attempting to protect an entire organization’s network using hardware or endpoint software is the best strategy. While there is value in threat prevention appliances such as firewalls, the first priority should actually be to understand where the most sensitive data on the network resides and how it should be protected (View http://www.dgtechllc.com/blog/why-you-need-a-back-to-basics-approach-for-network-security).
The first step in a data protection strategy should be identifying which data is most sensitive to an organization (beyond the requirements laid out by industry-specific rules and regulations). Tapping into the knowledge of users, typically employees, can be hugely beneficial. Users often know more about the data being used than IT simply because they are the ones consistently using it. This type of data identification can be especially beneficial when looking at unstructured data.
Create a backup and recovery strategy
Once sensitive data has been identified, the second step is to create a comprehensive backup and recovery strategy with scheduled
backups of critical data. Most large organizations with an IT team will already have backup in place and a schedule for periodic backups. While it’s important to include any new sensitive information in a revised backup strategy, the emphasis for those with established plans should be on the recovery side (the next step).
The third step is to ensure backups are always tested. Many well-intentioned IT teams have very good backup strategies but fail to test their backups. If you can’t recover a backup, the entire exercise is unproductive. Backups must be reliable and easy to recover. It’s critical to perform routine tests of backups and if backups are encrypted it’s doubly important simply because in case of emergency – such as a ransomware attack – recovery of a previous backup could be the only solution.
It goes without saying that backups also need to be stored off-site in case of a physical security breach, fire or other natural disaster where hardware is lost. Having backups in multiple locations also increases their security.
Create a comprehensive security strategy
Data protection through backup and recovery is a basic IT function, one that most IT teams should already be performing, yet many backups go untested which can lead to disaster should they ever be called into service. With the abundance of unstructured data on most corporate networks, it’s possible that critical data also goes unprotected.
Creating an extensive backup and recovery strategy can protect you in case of an attack, and it does not have to be complicated. DG Technology helps you secure your critical data, appliances and infrastructure, from the mainframe to the endpoint. Schedule a complimentary consultation with DG’s team of security specialists and get started on a back to basics approach to backup and recovery.
With the abundance of cybersecurity threats and vulnerabilities today, it can be tempting to see purchasing the latest security appliances and software as the light at the end of the tunnel. But even the most advanced network security system cannot completely secure an organization that has not built its security strategy on the fundamental best practices.
In fact, instead of rushing to vet the latest firewalls or buy licences for endpoint protection, IT teams should go back to basics. Specifically focusing on three basic tenets of a strong baseline security strategy: visibility, data protection and user management. Beginning with visibility, we’ll discuss each of these in a separate blog.
Why back to basics?
In a recent McAfee Threat Report (December 2016), 26 percent of security practitioners acknowledge operating in a reactive mode despite having a plan for a proactive security operation (https://www.mcafee.com/us/resources/reports/rp-quarterly-threats-dec-2016.pdf). In other words, it’s hard to keep up with the sheer volume of security concerns. From data breaches to ransomware, for those in charge of locking down networks it seems as if there is no escape from the cyberthreats of our modern, connected workplaces. With many security vendors offering network appliances and security software that promise to protect data, it’s easy to feel like the only way out is to “spend to secure.” The trouble is IT budgets (let alone security budgets) are already limited. Getting back to the basics – addressing the fundamental pain points of most networks – can help stretch budgets, create efficiencies and build a more secure IT environment overall.
Know your network
The most basic aspect of securing your network is knowing exactly what is running on it. Being able to identify every system and
application is essential to providing comprehensive security. In other words, if you don’t know what’s supposed to be on the network, there’s no way to completely secure it. Good visibility means being able to see the logs coming from the systems and knowing everything is configured correctly.
Increase simplicity
The more devices and applications running on a network, the more difficult it is to track down potential vulnerabilities and the harder it becomes to identify threats. Today’s networks are complex, especially given how likely organizations are to be deploying public, private or hybrid cloud environments, so without exceptional network visibility, security is a challenge. Having visibility into the entire network increases the ability of IT to respond to any potential threats.
Reduce downtime
IT’s ability to see the network it needs to manage can be a difference-maker, not only for security management but in maintaining network availability. High visibility is critical to troubleshooting and resolving any potential issues that could arise and lead to network downtime. Maintaining network visibility therefore becomes not only a good IT security decision, but a strong business decision as downtime can mean lost revenue.
Support your existing security investments
Network security appliances and tools are only able to protect what they know is out there. Without network visibility, it’s impossible for existing security tools to be as effective as possible.
The first tenet of a best-in-class security strategy is network visibility. Knowing exactly how a network is set up helps IT respond to the ever-changing threat landscape, allowing administrators to protect networks with much of the same agility potential attackers use. In this way, visibility is not only about security, it’s about IT performance.
Look for upcoming blogs that address the next steps in the back-to-basics approach: data protection and user account management. Also, view our infographic on how to get back to basics with your cyber security program.
Ready to have DG help you get back to basics? Contact us today and schedule a complimentary consultation with our team of security specialists.
Today’s cybersecurity threat landscape is constantly changing. With IT budgets stretched to the limit and new threats emerging every day, it’s essential for organizations to ground their technology use with security best practices.
DG Technology recommends implementing a “back-to-basics” cybersecurity program to mitigate common threats. Described in the infographic below, IT should focus on the three pillars of visibility, data protection and user management. This three-phase approach addresses many of the most common security concerns without the need to increase IT budgets or procure new, expensive security appliances.
Underpinning these three pillars should be a commitment to education. Users are on the front lines of the cybersecurity and teaching them the basics of security – from identifying potential threats to safe browsing techniques – can be an effective means of protecting critical data.
Get started implementing a back-to-basics cybersecurity program by contacting DG Technology.

On May 12, 2017, the powerful WannaCry ransomware infected more than 300,000 computers in over 150 countries in less than 24 hours. Six weeks after the WannaCry attack, a variant of the ransomware called Petya arrived on the scene and began to spread rapidly.
WannaCry uses command-line instructions to quietly delete any shadow volumes, delete backup catalogs, and disable automatic
repair at boot time. With the backups gone, it writes itself into tasksche.exe or mssecsv.exe in a randomly generated folder and gives itself full access to all files. Petya overcomes some of the safeguards put in to battle WannaCry such as stealing administrator credentials with a password dump tool to run wmic.exe to execute the malware directly on a remote machine.
The McAfee Labs Threats Report: September 2017 outlines several best practices to defend your organization against these two insidious malware threats.
Be vigilant in your software and file management
WannaCry and Petya exposed the continued use of old and unsupported operating systems and lax patch-update processes followed by some organizations. Set up a rigorous program to maintain and update your software applications, particularly those involved with your operating systems. It’s also a good idea to regularly backup data files and verify network restore procedures.
Impose key restrictions
Since ransomware is usually designed to run under well-known operating system folders, restrict code execution to prevent it from reaching them and blocking it from encrypting data. You should also restrict administrative and system access which can create an extra layer of protection by preventing malware from using default accounts to perform their operations. Consider removing local administrative rights to prevent ransomware from running on a local system. This will also block access to any critical system resources and files that ransomware targets for encryption.
Implement strict email policies
Securing email communication is key to preventing malware from infecting your system. Filter email content to limit spam emails and reduce the potential for attacks. Block attachments to reduce the attack surface. Implement a policy that restricts certain file extensions from being sent by email. Analyze those attachments with a sandboxing solution and remove them with an email security appliance.
Always be monitoring
Continually monitor and inspect network traffic to help identify abnormal traffic associated with malware behaviors. Use threat intelligence data feeds to help detect threats faster.
Conduct ongoing training
Ransomware often infects a system through phishing attacks using email attachments, downloads, and cross-scripting web browsing. Educate your network users on the dangers of malware threats and things to look for to guard against allowing an attack.
DG Technology is a certified McAfee partner and can help you leverage the full line of McAfee security solutions. Contact DG Technology to learn how we can help you implement an integrated approach to defense against malware and ransomware.