10/21/2020
In the wake of the COVID-19 pandemic, working remote is the new norm for many and working from outside the office adds a new level of complexity to network security.
The PCs and Laptops used to connect remotely are typically less protected and home usage often means going to different types of websites, opening up additional paths for cyber threats. The uptick in phishing attacks is an early warning that cyber criminals have been adjusting their tactics from targeting relatively well secured business networks to less defended/secured home offices and other connections used by remote workers.
The goal is to protect the business network from any and all outside threats while still allowing remote users to work productively. As we continue to adjust how and where we work, we wanted to send out what our new recommended minimums are to secure businesses from cyber threats. Below is what we recommend as a starting point or baseline security to protect business networks.
Endpoint Protection
In the past, antivirus protection was all that was needed. Now, that need has morphed into Endpoint Protection which is a sophisticated suite of tools that provides antivirus, antimalware, AI that analyzes malicious patterns, and OS hardening that blocks exploits. This is a crucial line of defense for the local machine. Sophos Intercept X Endpoint is our starting point recommendation for all home and business machines. Those using traditional antivirus alone need to upgrade.
Patching and Preventive Maintenance with ESNSS
Keeping up with patches and maintenance is another crucial part of securing machines and networks from cyber threats. Our Expert Support Now Security Suite or ESNSS provides real time monitoring with managed OS patching, and regular maintenance that ensures operating systems are up to date and secured from evolving threats.
Managed Firewall
Firewalls secure access to and from the internet for business networks and are required for network protection. Firewalls provide VPN access that is needed to secure remote access and no business should allow remote access without a VPN. We recommend our managed Firewall solution that includes a managed and monitored Sophos Firewall which can be enabled with Synchronized Security adding an additional layer of protection with local machines that have Sophos Intercept X Endpoint.
Virtual Private Network – VPN
VPNs create a secure tunnel to connect to a business network and are a function of a business’s firewall. Software VPNs or VPNs that are not provided by the firewall connected to the business are not the same and do not protect the network. Our solution is a VPN administered through our managed firewall.
Offsite Backup
No matter how secure a business network is, data backups will always be needed to safeguard data from loss due to a cyberattack or hardware failure. We offer offsite storage and backup of critical data for servers, workstations and O365 email accounts as well as high availability replication and failover solutions for mission critical systems. Backups are often the first recovery method in ransomware cases due to cost of downtime and repair costs and storing backup data offsite ensures that data is secured and remains available.
Two-Factor Authentication – 2FA
Two-factor authentication (2FA) is a specific type of multi-factor authentication (MFA) that strengthens access security by requiring two methods to verify your identity. The factors include something you know - like a username and password - plus something you have - like a smartphone app - to approve authentication requests. 2FA protects against phishing, social engineering, and secures your logins from attackers exploiting weak or stolen credentials. We are a Duo Technology Partner and recommend Duo be used for O365 and all other internet facing applications.
Encryption
If company data is stored on laptops, home computers, or other devices that are not securely located in the office, those devices should be encrypted. Encryption ensures that the data stored on those devices is not accessible if that device is lost or stolen. We utilize Sophos Central Device Encryption to protect against this.
Dark Web Monitoring
Stolen usernames and passwords are constantly being uploaded to the dark web where cybercriminals use these credentials to gain access to business networks along with thousands of other sites including banking, filesharing, and social media. Our monitoring service alerts businesses as new employee credentials are found and often provides the source of the breach as well as the password itself.
Is Your Business is Prepared?
We are helping many businesses remain productive by setting up secure ways for people to access their systems remotely and we continue to enhance and add new solutions as needs change.
For more information on how we can help your business cope with this new normal, contact us at [email protected], call 586-816-0015, or visit www.cnetsys.com.