We’re increasingly hearing from organizations that need to establish security policies, either to meet the requirements of a client or to qualify for cyber insurance that insures against breaches and similar losses. Details vary, and we’re happy to work with you on the specifics, but here are some of the questions you may be asked. Of course, you don’t have to prove that you’re doing the right thing to some other company. Answering these questions for yourself can only improve your security readiness.
- Do you enroll all organizational devices in a device management solution?
With device management, an IT department or managed services provider (MSP) maintains oversight and control over all organizational devices. That helps automate configuration and deployment, provide secure access to organizational resources, ensure consistent security policies, manage apps and operating system updates, track device inventory and status, and more.
- Do you have an organization-wide backup strategy with offsite backups?
Regular backups — some stored offsite — are essential if you need to recover from lost or stolen hardware, a natural disaster, or a ransomware attack. Even though ransomware isn’t a significant problem in the Apple world, it wouldn’t hurt to start creating immutable backups using “write once, read many” tape or something like Ntiva’s Cloud Backup. This technology ensures that cloud-based backups can’t be corrupted. Finally, have you tested restoring files and recovering critical systems from your backup data? Backup is important, but only if you can restore.
- Do you have a policy for updates?
Installing security-related updates to operating systems and major apps is essential, but how quickly that happens has to be weighed against problems that version changes can cause for essential workflows. There’s no correct answer, but you want to ensure you aren’t leaving your organization’s apps and devices vulnerable to known security exploits for longer than necessary.
- Do you have a strong password management policy?
Short, easily guessed, or cracked passwords are the primary ways attackers breach corporate networks and systems. At a minimum, your password management policy should:
- Require that all passwords be stored in a password manager.
- New passwords are generated by the password manager and meet the minimum requirements for strength.
- And two-factor authentication is used when available.
- Do you use an endpoint protection platform?
Endpoint protection is software that prevents and detects malware on employee workstations, often with an organizational dashboard and management capabilities. Although the Mac doesn’t have nearly the exposure to malware that Windows does, it’s still important to keep computers free of malware that could hurt performance, exfiltrate data, or provide an entry point for future attacks. Endpoint protection is usually part of a more comprehensive managed systems approach that can also ensure that devices adhere to security policies like full disk encryption, run only approved software, stay up to date with security updates, and more.
- Do you have a list of sensitive data on your network?
Precisely what counts as sensitive data will vary by organization, but anything related to network and corporate security qualifies, as does any personally identifiable information you may hold. It’s not uncommon to store information about people that includes names, email addresses, phone numbers, and postal addresses. But you should be even more careful if you store Social Security numbers, credit card numbers, driver’s licenses, passports, financial records, or medical records. Knowing what you have is the first step; after that, consider what additional precautions you should take to protect such information.
- Do you provide periodic anti-fraud and security training to employees?
Social engineering is another common way attackers gain access to corporate networks and systems. Does your organization require that all employees take regular training to learn how to identify phishing attacks, require appropriate approvals for unusual transactions or access requests, and report suspected incidents to the necessary people? If an administrative aide in the accounting department gets an email request from the CEO to pay an urgent invoice to a new vendor, will that person know how to respond?
- Do you allow access to organizational email and systems from personal devices?
It’s tempting to allow users to access their email from personal devices or to have contractors use their personal email addresses for work communications. We recommend keeping as clear a line as possible between work and personal devices and accounts to reduce the security implications of such mixing. Particularly when there’s sensitive information in play, personal email addresses should never be used for work communications, and if personal devices are being used, they should be set up with two-factor authentication for organizational logins. Or even better, use Conditional Access to help ensure the equipment accessing your networks and corporate information is secure, and that the person using that machine is the authorized user.
- Do you have incident and disaster response plans?
Bad things happen, and it’s important to consider how you would respond to different types of security incidents and natural disasters. How will your organization maintain crucial business operations, communicate with employees, coordinate with partners (insurance, legal, PR, and clients), and more? Is your plan written down and updated regularly? Have you tested key aspects of your plan?
- Who will you turn to when trouble strikes?
The level of scrutiny from all parties involved — clients, vendors, partners, team members, insurance providers — escalates quickly when a security incident is discovered. It’s best to prepare for this scenario during a time when everyone is calm and thinking clearly. A lot of organizations think that their IT team has security under control. However, information security is not information technology.
We know there’s a lot to think about regarding security in today’s world, and we’re always available to help if you’d like assistance answering any of the above questions.
(Featured image by iStock.com/Bulat Silvia)