CYBER SECURITY: Low-cost and no-cost things organisations can do to improve their cyber security
Cyber
security
IT
department of any organization is a good place to start to get a basic
understanding of its overall cyber security posture.
·
The IT department should be able to provide details on controls,
ports, services, firewall rules and device configurations: How these things are
secured, how that is monitored, and how that could be changed to meet the most
likely cyber threats to your organization.
·
IT departments should also be able to provide details about how
the network is sub-netted or segmented,
said Venables, which can useful in ensuring staff can access only areas
appropriate for their roles.
·
If attackers are in your network, segmenting it can slow them
down and make it more difficult for them to move around.
·
Should consideris whether to allow employees access to webmail
and unrestricted web browsing from work IT environments: Not only is webmail a
good way of getting bad stuff in, it is also a good way for attackers or
malicious insiders to get stolen data out.
·
Organizations should also consider blocking the major threat
vectors used in websites, such as JavaScript, Java, Flash Player, and macros.
