| | MAY 2023ENTERPRISE SECURITY8IN MY OPINIONFACILITATING IT SECURITY FOR MEDIUM BUSINESSES AND ENTERPRISES IN AUSTRALIABy Vlad Vyshnivetskyy, Head of Cyber Security, PICA GroupInformation security (InfoSec, cyber, or IT security) is a critical component of any business. Confidentiality, integrity, and availability of IT assets are paramount in the modern digitised and technology-centric world.In Australia, medium businesses and enterprises (with 20 to 400 employees) face the same typical IT security threats as larger corporations big end of town. In this article, we'll look at the various aspects of IT security for such businesses.Understanding the ChallengesChallenge-wise, despite being medium-sized, these businesses still mostly lack dedicated or have limited IT and IT security staff. Coupled with a limited budget, this reflects that lean businesses have a primary focus on business aspects to survive in their competitive areas. Respectively, IT and IT Security functions usually have less recognition and support from senior management as compared to the main business, resulting in the depreciation of respective IT Security risks and threats.Slowly, business leaders start to realise how heavily their operations depend on IT, and how severe could be the outcomes of IT Security risks. Therefore let us look at the typical threats.Despite the challenges, the threat landscape for medium businesses and enterprises in Australia remains the same as for large corporations no discounts for size or smaller budgets and resources.Daily business threats consist of malicious emails and phishing attacks, signalling the need for staff security awareness knowledge and practice of cyber security hygiene. Ransomware attacks are also very common, sided with threats of data breaches. Accidental or intentional, insider threats are likewise present in everyday routines. IT infrastructure operations either on-premises or in a cloud, deal with threats of misconfigurations, unpatched or outdated software, third-party & IT supply chains, zeroday vulnerabilities, and legacy systems. Limited IT security staff often struggles to maintain up-to-date policies, procedures, and working documentation. Ease for regular business users to access Software-as-a-Service resources (shadow IT), the abundance of remote access, and staff working from anywhere these are not new but more and more present threats from modern business practices. So how to face them?Remediation controls to counter the threats relate to either technology, process, or people. They can be further classified by criticality essential, recommended, or advanced controls (in order of criticality).Delving into Essential ControlsEssential technology controls could start with the Australian (which would benefit any business worldwide) Cyber Security Centre's Essential 8 controls, even at Maturity Level Zero. These include application control, application patching, application hardening, MS Office macro settings, restricting admin privileges, Vlad Vyshnivetskyy
<
Page 7 |
Page 9 >