In defending a company against a hacker attack that paralyzes business processes, causes financial loss, and jeopardizes business reputation, the first step should be employee education, as their email accounts are the most common and easiest way to breach the system. However, this is only the first level of protection. Although employees are an important link, other key mechanisms of cybersecurity relate to a series of protective measures, programs, and patches that need to be integrated into the system, as well as knowing how to use them, i.e., recognizing intent and preempting a potential cyber attack.
– Investing in an information system without quality consideration of cybersecurity is generally an investment in one’s own cyber vulnerability. Subsequent interventions in the protection of such systems are more expensive solutions, less flexible, and harder to manage. The first assumption of protection is the identification of key information and systems for their processing that could be at risk of hacker attacks – says PwC’s senior cybersecurity manager Igor Hitrec.
Professional Training of People
Answers to the questions of what types of cyber or hacker attacks companies will face will be provided by quality and regular risk analysis, i.e., cybersecurity risk management, as well as valid answers to the questions of which protective mechanisms can reduce such risks. Most often, it concerns important business information and personal data that need to be protected and ensured for their availability, integrity, and confidentiality. Therefore, information systems and technology, business processes, and the people who use them must be prepared for the possibilities of responding to cyber attacks.
—
—– The most important mechanism is appropriate professional training of people. Continuous effort in raising awareness about cybersecurity, types of risks, and quick and simple ways of protection will very quickly demonstrate usefulness and value. Information systems must be able to track data changes, the timing of changes, and who made them. Data security storage, checks of data recovery procedures from backups, and the storage of backups must guarantee the requirement of availability – says Hitrec, explaining that security controls must be applied in all places where the risk of a cyber attack has been identified, from the infrastructure for connecting to the internet, all workplaces from which business information systems can be accessed, internal and external network infrastructure to computer servers, regardless of whether they are cloud resources or local data centers.
Selected controls must enable quality monitoring, detection, and stopping of cyber attacks, with special attention to their integration and quality orchestration of defense and response to hacker attacks.
– Information that is classified as confidential and high-value through classification control can be automatically protected by encryption along with secure exchange and storage. Newly discovered malicious code detected in controlled conditions, so-called sandbox-kontrol, and integrated with prevention and protection control immediately provides protection for all endpoints. Due to the sensitivity of the system, it is not possible to apply important security patches, and by controlling attack prevention, i.e., hiding vulnerability data, we deceive the attacker – says Hitrec.
Cyber Threat Intelligence
He also explains that monitoring reports on security threats (i.e., cyber threat intelligence) and exchanging information about observed tactics, techniques, and procedures of cyber attacks help in faster adaptation of defense. Regular penetration testing and simulations of cyber attacks will always provide valuable and measurable information on how secure the business is from such risks.
– I believe that the examples provided illustrate how necessary it is to think professionally and strategically about planning the protection of information infrastructure and managing it – concludes Hitrec.
The Vice President of the Croatian Association of Security Managers Alen Delić claims that, in order to protect business from malicious attacks, it is crucial to understand that every security, including information security, is a comprehensive and complex set of processes composed of various elements. Therefore, applying only one protective mechanism will not be sufficient to achieve an appropriate level of security. Instead, a combination of security measures should be applied to reduce the risk of attacks. In this set of measures, it should be understood that clearly and well-defined processes (which include policies and procedures), people (which implies their clear roles, responsibilities, and knowledge), and finally technologies, which must be properly applied, are equally important.
—
—– When it comes to the application of these mechanisms in practice, one must consider specificities of the business and available resources. However, some general guidelines based on frequent examples of attacks in the past year relate to areas that we can observe as key mechanisms. These include employee education, analysis of the entire set of information, using advanced or more advanced resource access mechanisms, proper management of privileges and access, establishing mechanisms for monitoring activities on networks and computers, data storage/backups, testing security mechanisms, and monitoring third parties that have access to resources – says Delić.
Every Individual and Group is Important
Employee education is linked to understanding the importance of each individual in the security chain, especially protection against attacks using social engineering mechanisms (phishing). By analyzing the entire set of information important for business and the attack surface, we want to find out what is crucial for business, not forgetting that equally important, along with confidentiality, can be availability and integrity of data.
Using advanced or more advanced resource access mechanisms along with proper use of complex passwords also means the possibility of using multi-factor authentication, and proper management of privileges and access means that employees have only as much access to data and resources as they need to perform their jobs. Important are the ways of protection and establishing mechanisms for monitoring activities on networks and computers to detect irregularities and potential attacks, as well as data storage or backups so that such storage is tested, then testing security mechanisms, both human and technological aspects, such as conducting penetration testing and vulnerability checks, and monitoring third parties that have access to resources or process personal data, which also implies their testing.
– It should certainly be emphasized, no matter how school-like it may sound, that the key to successful protection of business from attacks is a comprehensive and systematic approach to security that includes security measures that work in combination and educating and raising awareness about the importance of security for all employees in the organization. Plugging holes and implementing partial measures, as practice shows us, simply always results in more expensive, harder, and longer-lasting solutions – emphasizes Delić.
ISO 27001 Standard
That there is no hundred percent protection, but there is a possibility to influence the potential of whether an attack will occur, or, when an incident occurs, what the outcome or extent of harmful consequences will be, believes cybersecurity consultant DobarDan.neta and CNV-IBIS company Tino Šokić. He claims that it always comes down to risk calculations, i.e., how likely it is that something will happen and how much needs to be invested to reduce the risk.
According to him, the key mechanism in protecting against hacker attacks is a comprehensive approach, meaning that the entire system must be taken into account, from employees, technology to regulations, because hackers look for weak points in the system, and that weak point is often a person. For example, it is much harder to hack cryptographic protocols and protected applications than employee emails, so education is the best defense against hacker attacks.
—
—– Key mechanisms for protecting business can be realized in three steps; the first is the identification of people, assets, and processes of the company, the second is the selection of technical, organizational, and legal measures and tools for implementing protection, and the third is continuous testing and verification of what has been implemented. Since technology is like a living organism, we are forced to constantly maintain, monitor, and improve that system – says Šokić and emphasizes that often the biggest problem lies with the person, not the technology.
In addition, he claims that key mechanisms can only be applied with the help of comprehensive and timely support from the company’s management. One good approach to comprehensive application is, for example, the introduction of the ISO 27001 standard, an information security management system (ISMS), which encompasses everything from technical, organizational to legal aspects of security.
Frequent Compromises
Experts from the Span Cybersecurity Center provide daily assistance to clients in resolving various types of cyber attacks that bring not only financial consequences but also significant reputational risks. They often encounter compromises of email accounts and ransomware attacks. Compromise of email accounts can result in the theft of business data and the use of that account by the attacking group to reach business partners.
This type of attack can be prevented by using multi-factor authentication that uses tokens (TOTP) or hardware keys (FIDO2) and regularly applying patches across the entire information system, primarily on publicly accessible servers. On the other hand, ransomware attacks, along with data theft, create significant pressure on victims due to the direct impact on business processes. To significantly reduce the likelihood of becoming a victim of such an attack, all internal resources must be properly protected and access allowed only from the internal network or using VPN channels with multi-factor authentication. Span’s cybersecurity experts advise that the assessment of the organization’s security and the application of security solutions is best left to qualified professionals who will be able to continuously monitor the security of the entire information system of the organization while raising the organization’s security.
Ten Defensive Steps to Prevent Cyber Attacks
1. Accept a zero trust strategy.
2. Leave the protection methods to cybersecurity companies.
3. Encrypt data when sharing or uploading online.
4. Educate employees about online security.
5. Create complex passwords and/or use multiple different ones.
6. Set guidelines for online security.
7. Protect employee information and securely store data.
8. Establish joint cybersecurity policies with business partners.
9. Regularly review cybersecurity procedures.
10. Install top security antivirus software and endpoint protection.