enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

PICA Group

IT Security for medium-sized businesses and enterprises in Australia

Vlad Vyshnivetskyy, Head of Cyber Security, PICA Group

Information Security (InfoSec, Cyber or IT Security) is a critical component of any business. Confidentiality, Integrity and Availability of IT assets are paramount in the modern digital and technology centric world.

In Australia, medium-sized businesses and enterprises (20-400 employees) face the same typical IT security threats as larger corporations – big end of town. In this article, we'll look at the various aspects of IT security for such businesses. Thus lets start with…

CHALLENGES

Despite being medium-sized, these businesses still mostly lack a dedicated IT staff or have limited IT and IT Security resources. Coupled with a limited budget, this reflects that lean businesses have a primary focus on business aspects to survive in their competitive areas. Respectively, IT and IT Security functions usually have less recognition and support from senior management as compared to the main business, resulting in depreciation of respective IT Security risks and threats.

Slowly, the business leaders start to realise how heavily their operations depend on IT, and how severe could be the outcomes of IT Security risks. Therefore – lets look at the common…

THREATS

Despite the challenges, the threat landscape for mediumsized businesses and enterprises in Australia remains the same as for large corporations – no discounts for size or smaller budgets and resources.

Daily business threats consist of malicious emails and phishing attacks, signalling the needs in staff security awareness knowledge and practice of cyber security hygiene. Ransomware attacks are also very common, sided with threats of data breaches. Accidental or intentional, insider threats are likewise present in everyday routines.

IT infrastructure operations either on-premises or in a cloud, deal with threats of misconfigurations, unpatched or outdated software, 3rd party & IT supply-chain, zero – day vulnerabilities, and legacy systems. Limited IT Security staff often struggle to maintain up to date policies, procedures and working documentation.

The easiness for regular business users to access Software-as-a-Service resources (shadow IT), wide adoption of remote access and staff working from anywhere – these are not new but more and more present threats from modern business practices.

"The Adversaries Need To Succeed Only Once Out Of Endless Attempts, While Security Measures Should Always Be On Top Of All Threats"

So how to face these threat? The answer is in.

REMEDIATIONS

Remediation controls to counter the threats relate to either technology, process, or people. They can be further classified by criticality – essential, recommended, or advanced controls (in order of criticality).

ESSENTIAL CONTROLS

Essential technology controls could start with the Australian Cyber Security Centre’s Essential 8 strategies (which could benefit any business world-wide), even at Maturity Level Zero. These include application control, application patching, application hardening, MS Office macro settings, restrict admin privileges, patch operating systems, configure Multi-Factor Authentication, and backup data.

Other technology essentials are – end point protection (EPP), network firewalls, secure email gateway (SEG), and virtual private networks (VPN) with remote access management. Disaster Recovery (DR) configuration, strategy and procedure as well as well-planned backup strategy are another strong points for businesses, especially with noticeable on-premises IT assets.

 In terms of processes, it is vital to formalise IT Security policies, work procedures and guidelines. This will require respective user education, which focuses on People’s IT Security awareness training, ideally with tests and simulations. Approval of IT Security policies by the CEO will also engage executive leadership support and get more compliance by all users.

It is hard to imagine any medium-sized business surviving in the modern threat landscape without having these essential controls implemented. Even if some of them are not in place, or don’t cover 100% of IT assets and users – it is pretty much a matter of time before a cyber security incident happens.

RECOMMENDED CONTROLS

Besides essentials, it is also recommended to invest in Data Leak Prevention (DLP), Secure Web-gateway (SWG), Cloud Access Security broker (CASB), and Vulnerability Management (VM) controls. Processes could benefit from formalised Incident Response (IR) plan, periodic IT Security penetration tests, and third-party security assessments. Access to a professional Virtual Chief Information Security Manager (vCISO) is also a prudent measure.

These controls help to address more sophisticated threats or decrease the severity of incidents if they happen.

ADVANCED CONTROLS

If the business has a high-value and low risk tolerance, more advanced IT Security controls would include Security Information and Event Management (SIEM), Managed Detection and Response (MDR) delivered by a Managed Security Services provider (MSSP) , Encryption of data at rest, and Cloud Access Posture Management (CAPM) especially for cloud-hosted IT Assets.

An independent IT Security assessment conducted by a professional assessor could help highlight weak spots or define an IT Security strategy. Businesses can assess their IT Security posture against the most adopted Cyber Security frameworks, like ISO 27001 standard (Information Security Management System) or National Institute of Standards and Technology (NIST - U.S. department of commerce).

If a business invests into the development of their own business applications or strongly depends on e-commerce operations, these assets should be respectively covered by their own Application and Web-sites security controls. Though these aspects are outside of scope of this article.

CONCLUSION

As the closing remarks, IT Security is not a point in time static state, but a journey, constantly reviewing all above mentioned treats, controls, and challenges.

Once implemented, many of these controls require daily, monthly, quarterly, or annual operations, maintenance, and review. Delivered either by in-house staff, or outsourced to contracted MSSP, IT Security is an aspect of survival for many modern businesses, and this trend is only increasing.

The adversaries need to succeed only once out of endless attempts, while security measures should be on top of all threats all the time. And as technologies are now used by every business user, IT Security is everyone’s responsibility. Stay safe!

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.