In the 1930s, France built a trench network called the Maginot Line to rebuff any invasion. The philosophy was simple: if you map out all the places an enemy can attack, and lay down a lot of men and fortifications at those places, you can rebuff any attack. The problem is, you can't map every possible avenue for attack.
What does this have to do with IT security? Today many business owners install an antivirus program as their Maginot Line and call it a day. However there are many ways to get into a network that circumvent antivirus software.
Hackers are creating viruses faster than antivirus programs can recognize them (about 100,000 new virus types are released daily), and professional cybercriminals will often test their creations against all commercially available platforms before releasing them onto the net.
Even if you had a perfect antivirus program that could detect and stop every single threat, there are many attacks that work around antivirus programs entirely. For example, if a hacker can get an employee to click on a compromised email or website, or "brute force guess" a weak password, all the antivirus software in the world won't help you.
There are several vulnerabilities a hacker can target: the physical layer, the human layer, the network layer, and the mobile layer. You need a defense plan that will allow you to quickly notice and respond to breaches at each level.
THE PHYSICAL LAYER
The physical layer refers to the computers and devices that you have in your office. This is the easiest layer to defend, but is exploited surprisingly often.
Here are a few examples:
-Device loss accounts for 41% of data breaches, compared with just 25% derived from hacking and malware (Trend Micro)
-The breaches perpetrated by Chelsea Manning and Edward Snowden occurred because they were able to access devices with sensitive information. CompTIA left 200 USB devices in front of various public spaces across the country to see if people would pick up a strange device and insert it into their work or personal computers. 17% fell for it.
To protect at the physical layer, you need to:
-Keep all computers and devices under the supervision of an employee or locked away at all times
-Only let authorized employees use your devices
-Do not plug in any unknown USB devices
-Destroy obsolete hard drives before throwing them out
THE HUMAN LAYER
The human layer refers to the activities that your employees perform. 95% of security incidents involve human error (IBM). Ashley Schwartau of The Security Awareness Company says the two biggest mistakes a company can make are "assuming their employees know internal security policies" and "assuming their employees care enough to follow policy".
Here are some ways hackers exploit human foibles:
-Guessing or brute-force solving passwords
-Tricking employees to open compromised emails or visit compromised websites
-Tricking employees to divulge sensitive information
For the human layer, you need to:
-Enforce mandatory password changes every 30 to 60 days, or after you lose an employee
-Train your employees on best practices every 6 months
-Provide incentives for security conscious behavior
-Distribute sensitive information on a need to know basis
-Require two or more individuals to sign off on any transfers of funds
-Watch for suspicious behavior
THE NETWORK LAYER
The network layer refers to software attacks delivered online. This is by far the most common vector for attacks. There are many types of malware: some will spy on you, some will siphon off funds, some will lock away your files.
However, they are all transmitted in the same way:
-Spam emails or compromised sites
-"Drive by" downloads, etc.
To protect against malware:
-Don't use business devices on an unsecured network
-Don't allow foreign devices to access your WiFi network
-Use firewalls to protect your network
-Make your sure your WiFi network is encrypted
-Use antivirus software and keep it updated. Although it is not the be all, end all of security, it will protect you from the most common viruses and help you to notice irregularities
-Use programs that detect suspicious software behavior
THE MOBILE LAYER
The mobile layer refers to the mobile devices used by you and your employees. Security consciousness for mobile devices often lags behind consciousness about security on other platforms, which is why there are 11.6 million infected devices at any given moment.
There are several common vectors for compromising mobile devices:
To protect your mobile devices you can:
-Use secure passwords
-Use reputable security apps
-Enable remote wipe options
Just as each line of defense would have been useless without an HQ to move forces to where they were needed most, IT defense-in-depth policy needs to have a single person, able to monitor each layer for suspicious activity and respond accordingly.