Skip to main content
Top Rated IT Provider · 5.0★ on Google · support answers in ~4 rings
ASG Information Technologies
Contact Us
Cybersecurity & Compliance
Cybersecurity Maintenance: Updating Security Measures
BM
Brigitte Mitchell
ASG Information Technologies
October 11, 2024

Cybersecurity Maintenance: Updating Security Measures

Cybersecurity maintenance is important for defending your business from threats. Security checks & weakness scans help build a strong defense

Cybersecurity Maintenance: Updating Your Security Measures

Cybersecurity maintenance is a key part of defending your business against online threats. Regular security checks, weakness scans, and system tests help build a strong defense strategy. These practices allow you to spot gaps in your IT setup, stop potential attacks, and keep your systems safe.

This article offers useful tips on effective cybersecurity upkeep methods. It covers the value of physical security, training staff about social tricks, and keeping all software up to date. You’ll learn how to adjust your safety measures as new threats appear and put in place best practices for a layered approach to guarding your company’s digital assets.

Regular Cybersecurity Maintenance Through Security Audits

You should be regularly auditing your IT environments, not just in your business, but also have a process for vendor management where you reach out to any cloud solution providers, data centers, and disaster recovery vendors you may be utilizing, asking some tough questions. When it comes to cybersecurity, you don’t know what you don’t know. If you’re not auditing and checking against IT security best practices, doing ongoing vulnerability scans and an annual penetration test, you have no idea how a hacker would be moving throughout your environment if they were to get into your business.

At ASG, this is something we include in most of our offerings, and it’s some of the most meaningful work we do. Many of our clients trust us to take care of their cybersecurity environment, and we get about 30 to 40 percent of our business because folks have been breached or lost data under other IT providers. A lot of what we do has to be very locked down and regimented. It’s about a proper process, not just the tools that help get you to a solid spot when it comes to your IT and cybersecurity maintenance.

Cybersecurity Maintenance Expert

The Importance of Vulnerability Scans

Vulnerability scans are great for letting you know what weaknesses you have, not just in your systems, but also the proprietary software you run, like your ERP, CRM, and sales process. It can pinpoint how a hacker would move around inside a company, leveraging exploits on outdated or vulnerable software.

Tracking all that down takes time, and while some will be false positives, many won’t be. At the very least, this should be done yearly for every business. We find that many IT providers simply don’t do it or charge their clients extra for it.

Don’t Overlook Physical Security

Physical security is also often overlooked. We deal extensively with Department of Defense supply chain, credit unions, and financial institutions. Anything we do has a breadth of compliance, and physical security is certainly a part of it. These businesses require some level of access control, with the majority having locked rooms or segments of the network with different business requirements.

Evaluating physical security measures is important, and cameras often play a role. However, cameras are one of the things most often caught on a vulnerability scan because most IT providers aren’t doing cameras for their clients or reaching out to the camera vendor to ensure the systems stay up to date. If your camera system was put in four years ago and hasn’t been updated once, it’s certainly vulnerable and shouldn’t be on your main network. If it is a problem, someone should look at it.

A developer writing code across multiple monitors while colleagues talk in the office behind him.

Determining the Optimal Schedule for Security Audits

Depending on your business, it’s generally good practice to do at least an annual security audit or risk assessment. For many clients, especially those with compliance requirements, the compliance dictates the schedule, along with the size and complexity of the environment and how much you need your IT to simply work.

These conversations need to be had at a higher level, with someone in your business who can sit down and discuss your software and processes. It should be part of your business process, not just your technology process.

The Threat of Social Engineering

Social engineering is probably the biggest factor out there. Most breaches occur because your staff simply let them in or respond in some way. Outside of breaches, there’s a lot of direct deposit fraud and other things that happen when attackers target your users, trying to pivot and get into an environment.

Here are some key points to remember:

  • At a bare minimum, there should be ongoing cybersecurity training and phishing testing for every staff member, especially those interfacing with customers, in sales, finance, or really across the board.
  • We often see critical vulnerabilities revealed during security audits, though the majority of the time, they’re mitigated by security controls we put in place, like hardening policies, tools, or processes.
  • Critical vulnerabilities happen all the time, especially with older, outdated software. Sometimes software vendors go away and you have to keep using older software.

It’s important to have an IT provider that can build additional controls to help protect your data and business.

Real-World Examples

Let me give you an example. Here in Connecticut, we’ve seen this a lot in manufacturing, where clients will have a legacy CNC program on a machine that’s wired. On a vulnerability scan, it’s the giant glaring red item. You have to end up splitting that off onto its own separate network or building additional compensating controls. That way, you’re at least protected in the event of something happening there, because those machines are expensive and it doesn’t always make business sense to spend $500,000 to replace them.

Another instance is when an engineer or staff member bypasses some sort of security policy. Regular security audits contribute to maintaining an effective cybersecurity posture simply by the fact that you don’t know what you don’t know. If you’re not regularly double-checking all of your settings, it’s as simple as that.

An illustration of cloud security: a padlock over a cloud ringed by shield, document, folder, email, and globe icons.

Keeping Systems Up-to-Date with Security Patches

Patch management is something that everybody should be doing across every client. Everyone should have a maintenance window where all systems go down, reboot, and refresh. However, we often see that most IT providers are only concerned with patching the things they deem themselves responsible for.

The Importance of Comprehensive Patching for Cybersecurity Maintenance

IT providers often don’t look at the client’s application stack or proprietary software, which can be just as vulnerable as the Windows updates that folks are doing or not doing. You should have a patch inventory and somebody should be looking at reports.

I don’t like talking about this because I feel like when we’re talking about patching with a client, we typically aren’t having the right conversation. As your IT provider, if we’re stuck at the level of patching, we’re probably having the wrong discussion. Everyone should have their computers on.

ASG’s Approach to Patching

At ASG, we handle things a little differently:

  • Security updates are pushed in real time. If there’s something important or high priority, everybody gets it and it applies the next time the system reboots.
  • The same goes for laptops. It’s hard for an IT provider to manage so many laptops and field staff for their clients. If they don’t leave their devices on during the maintenance window, they simply get the important updates the next time they turn on. It’s an easy way to make sure it’s working.

We also have a lot of monitoring built into our system. If somebody gets far behind in any way, we reach out to the client. We ask for those devices to be put on so that we can get them up to date. Alternatively, we know that the next time they check in, they’re going to get those updates.

IT security best practices

Rigorous Testing and Research

Our methodology is interesting because we’re patching so many thousands of devices now. You really have to test them quite rigorously. Typically, non-high or non-critical updates are pushed out a week or two later after testing them in the lab. Even for the more important updates, everything gets tested weekly in a live lab before being pushed into the system.

There’s also a lot of research that we have to do. We’re constantly checking forums, TechNet articles, and looking for issues or ways to avoid problems. Microsoft notably causes trouble all the time with their updates as they beta test on customers.

Patching is great though, and most MSPs tend to do this well. It’s built into all of our software and systems, making it relatively easy to configure patching for clients and ensure they stay up to date.

Obstacles and Challenges

Some of the biggest obstacles are legacy systems that don’t have patches. You can detect any vulnerabilities associated with these systems if you’re doing an ongoing security audit for clients. However, there’s not a great answer for most legacy software systems. You typically have to build a compensating control so that in the event of something happening, you’re still protected.

Besides that, it’s difficult when you’re managing patching at scale across hundreds of servers and thousands of endpoints. There’s always bound to be some sort of issue.

When we’re talking about testing, it’s important that you test not just your patching on workstations, but all the workstations of varying flavors, coming from old updates and new updates, servers, database servers, application servers, and all the different versions in between.

Along with it, you need a robust backup system because in the event of something happening, you’ve got to be able to roll it back. That’s really important. Microsoft has released patches multiple times this year that actually break things for clients. We’ve caught many of them, but if any of those make it through, it can be very impactful when a client comes in in the morning.

It’s super important that you’re really regimented in this approach and that you’ve got a solid policy.

The Security Implications of Not Patching

If you’re not doing updates, there’s a huge security implication. You end up extremely vulnerable to really anything out there. At the basic level, someone will be able to get in there and run a vulnerability scan.

Along with it, pretty much every type of compliance requires patching and some sort of methodology for at least addressing important and high security patches, notably from Windows, which is definitely vulnerable.

This is really all about cybersecurity maintenance, and patching has to be a part of your IT security best practices. If it isn’t and that stuff isn’t getting looked at, it’s very easy for a hacker, once they get into a network, to really pivot around.

Staying up to date is about preventing them once they get in or preventing them entirely from getting in to begin with. If things are up to date, then it’s much more difficult for somebody to pivot around a network and execute vulnerabilities outside of what is a zero-day vulnerability. Zero-day means nobody really knows about it or it’s just now making the news and there’s not an available update for it.

cybersecurity maintenance security

Adapting Security Measures to Evolving Threats

As an IT staff member, it’s always a challenge to stay ahead of emerging cybersecurity threats while also maintaining business operations. However, there are a couple of things you can do to really assist with this.

Staying Informed

First, stay up to date by subscribing to different RSS feeds and participating in sysadmin forums. Reddit is a remarkable resource for staying informed about what’s going on in the world of cybersecurity. By being part of these channels, you can see how people are responding to threats in real time.

Additionally, various compliance verticals like NIST and the DOD space have their own industry forums and boards where you can discuss how businesses are addressing these issues. It’s important to be involved across the breadth of your business and constantly check, update, and build additional controls and best practices.

Applying Solid Security Frameworks

Secondly, apply solid agile security frameworks. You have to build flexibility into your security strategies. Security is not a one-stop shop where you simply purchase a tool, roll it out, and consider yourself secure. It’s a business process like anything else, so you need a robust risk-based approach.

To that end, review quarterly for all clients against IT best practices and the NIST cybersecurity framework, and baseline everyone against that. A robust incident response plan and disaster recovery plan should be included as part of your cybersecurity maintenance. As an IT provider, it’s your responsibility to be able to respond effectively to any sort of issue.

Emerging Technology Concerns

Keep in mind that a lot of emerging technology typically has security holes and concerns, notably around AI. It’s important to consider where data is being sent and how it’s being stored.

Take Microsoft Copilot as an example. If it’s not set up correctly, people can use it to find and gain access to files they shouldn’t have access to.

Consequences of Poor Security Practices

I've seen firsthand the consequences of not having a solid baseline approach. We get a lot of clients who have been breached with other IT providers or internal staff. If there's no thought toward IT security best practices and no one is doing audits, the breaches are so much worse.

Here's a real-life scenario: a business's backup servers were compromised and they had to recover from the cloud, but they had never done a cloud test with their backup vendor. It took seven days for them to get their data back, during which time they couldn't work. These were businesses that required technology to function.

Benefits of Best Practices

On the other hand, when a business has ongoing audits against everything and follows IT security best practices, they can respond way more effectively to threats. Consider this:

  • Backup systems should be split off on separate networks with different security controls
  • They should not be connected to everything using the same password

However, we see a lot of providers out there engaging in these general bad habits. Probably about 60% of new clients we onboard have these issues, which is pretty concerning.

In summary, staying informed about emerging threats, applying solid security frameworks, and conducting regular audits are key to adapting your security measures in an evolving threat environment. By following IT security best practices and implementing a robust cybersecurity maintenance plan, you can respond effectively to any issues that arise and keep your business protected.

IT Security Best Practices for a Layered Approach

A multi-layered security approach enhances an organization's overall cybersecurity posture because cybersecurity is all about layers. It's about making sure at a user level that your staff are trained and not clicking and doing bad habits on the internet. It's about blocking them from certain risks entirely. It's about having robust firewalls that can detect intrusions, respond to them, and notify your IT staff so they can get in there and see what's going on.

Importance of Multiple Layers

If hackers get past your initial defenses, you need:

  • Solid endpoint protection
  • DNS filtering
  • The ability to know if a rogue server is being contacted in Russia or China trying to transmit ransomware keys

It's really about layers, just like an onion. You have to have multiple hoops for hackers to jump through, and the idea is to catch them as they're moving through or pivoting across the network.

Detecting Hackers Inside the Network

Most IT approaches focus on preventing somebody from getting in but don't have a lot of methodology for detecting them once they're inside. Hackers are smart enough now to patch vulnerabilities or remove any obvious holes when they get into an environment, and then they use legitimate tools to pivot across the network.

When talking about potential breaches, it's important to understand that it's not enough to just prevent people from getting in. You need to build a robust system for preventing them from doing damage or limiting damage in the event that they do get in.

Implementing Network Segmentation and Access Control

Everybody should have some level of network segmentation. You should have access control on everything, role-based permissions, and really be looking to implement zero trust principles layered onto your network scheme.

In cloud environments, we don't see enough IT providers guiding their clients towards segmenting their data. Imagine you have OneDrive with a tremendous amount of data that all your staff can access. That's a concern. Why not segment it so that if an HR representative gets breached, only the HR info is compromised, not your finance data as well? We see a lot of folks who don't have a great security posture, and we certainly do a lot of consulting against that when we first come on board with a client.

Cybersecurity Maintenance Awareness Training

Along with technical measures, you need to be doing cybersecurity awareness training. Your staff are often your weakest link unless you have a really bad IT approach. You need targeted training programs for different roles. As an example, your finance people should have finance technology training.

You should be doing phishing tests, and if individuals are failing them too often, you should be talking to business staff and training them in person. We see a lot of IT providers just send phishing tests and then do nothing about it, but that's not enough. You really have to have a culture of security consciousness.

Implementing a Solid Baseline of Cybersecurity Maintenance

These aren't high-end items or really that complicated, but it's important to have a robust, solid baseline layer of cybersecurity, which is a process, and then follow that process, add to it, and evolve as time goes on. We do a lot of that for clients.

Right out of the gate, we do an enormous risk assessment that's about 56 pages with hundreds of questions, all based on the cybersecurity framework but also on how an IT network should be set up from a functional perspective. We see it a lot out there, especially if you have a single individual doing your IT, where there's no thought process beyond just getting things working.

If cybersecurity maintenance and IT security best practices are implemented correctly, you can prevent breaches, respond effectively to them, and have a plan in the event of getting breached. You'll know that your backup data is good, and on top of it, you're very likely to detect hackers in between the layers of your security posture and stop you from getting breached entirely.

Enhance Your Cybersecurity Maintenance with Expert Support

Are you looking to improve your cybersecurity maintenance? Our team can guide you through the strategies outlined in this article. We provide custom solutions to meet your specific security requirements, from performing detailed audits to creating thorough patch management strategies.

Taking action before a security incident occurs is the best approach. Reach out to us to set up a meeting and find out how we can improve your cybersecurity defenses. Our goal is to help protect your company's assets and keep your operations running smoothly.

Let's collaborate to build a stronger, more secure future for your business. Contact us today to start your journey towards enhanced cybersecurity.

#Cybersecurity&Compliance
Share
Call · engineer in ~4 rings