If your inbox looks anything like ours it is full of news about the recent cyber attack which ransacked the Colonial Pipeline. In case you did not hear about it (in which case you live under a rock) here's a little recap of what occurred:
A U.S. drinking water treatment facility's cybersecurity was challenged when an unidentified cyber actor that gained access to the facility's supervisory control and data acquisition system. The actors were most likely accessed by finding soft spots in the treatment plants security system, such as weak password security and an outdated operating system. Several government organizations, including the FBI, Cybersecurity and Infrastructure Security Agency (CISA), Environmental Protection Agency (EPA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC), have seen first-hand the cybersecurity criminals targeting and exploiting computer software on operating systems with end-of-life status to gain access to systems that they're not authorized to use. Click here to learn more about how you can protect your business from these criminals.
Here are our top ten security recommendations so you can ensure that your business doesn’t become the next victim:
- - Use multiple-factor authentication.
- - Update to the latest version of the operating system (e.g., Windows 10).
- - Use strong passwords to protect Remote Desktop Protocol (RDP) credentials.
- - Ensure anti-virus, spam filters, and firewalls are up to date, properly configured, and secure.
- - Audit network configurations and isolate computer systems that cannot be updated.
- - Audit your network for systems using RDP, closing unused RDP ports, applying multiple-factor authentication wherever possible, and logging RDP login attempts.
- - Audit logs for all remote connection protocols.
- - Train users to identify and report attempts at social engineering.
- - Identify and suspend access of users exhibiting unusual activity.
- - Utilize the ‘Block and Allow’ list which enables a user to control which other organizational users of TeamViewer may request access to the system.
Check out our Cybersecurity Awareness Training Webinar for more info.