Basic Cyber Hygiene for SMB
CIOREVIEW >> Cyber Security Africa >> NEWS

Alabbar Enterprises

Anwar Manha, Head of IT infrastructure & Information Security

Basic Cyber Hygiene for SMB

Anwar Manha, Head of IT infrastructure & Information Security
Anwar Manha, Head of IT infrastructure & Information Security, Alabbar Enterprises

No matter how big or small your organization is, having an information security program is vital in today's world, to ensure and protect the confidentiality, integrity, and availability of your organizational assets and data regardless of your industry. SMBs always have the challenge of starting an effective information security program due to the lack of specialized resources and budget constraints and see it as a responsibility of the IT department rather than an organizational responsibility.

What Needs to be Protected

Understanding what needs to be protected is the first step in an effective security program this could be anything from a critical server, database, confidential information, privacy, process, and your people. List these in an asset register in order of their importance to the business, which will become the scope of your information security program.

Once you have the visibility of assets that needs to be protected, choose an information security framework based on your scope and tailor it according to your business objective, requirements, and priority, following are some essential steps that SMBs can take to kick start their information security program.

Data Protection

Data is the most priceless asset; it has to be managed appropriately throughout its life cycle, and is very lucrative for attackers. Protecting the data should be the primary objective for any SMB information security program, to aid this you must have a proper backup strategy for enterprise data and this should be tested frequently to ensure the fail-proof backups.

 ​Data security involves understanding what needs to be protected, listing them in an asset register in order of their importance to the business, and then choosing an information security framework and tailor it according to the business objective 

Access Control

Organizations should maintain a strict access control list that specifies who has access to what, this will ensure the confidentiality and integrity of the organization's assets and data, and provide accountability for actions performed by your users. Use and promote Two-Factor Authentication wherever it is possible for authentication.

Vulnerability Management

Update all the software systems with the latest security patches and have a program to automate this process either through windows update service or any vulnerability management program.

Web Service and Remote Access

Access to published services over the internet and Remote access to organizational resources has to be controlled with the least privilege and need to know principles, users should have only the least access permissions required to perform their duties. Change the default port for commonly used services and use an alternative port.

Email Security

Email is the most common entry point for any type of cyber attack. using spam-filter and malware scanning tool at the email gateway can reduce the number of malicious email and attachments entering the organizational network, in addition, setup SPF,DKIM, and DMARC on your email gateway, this not only protect your organization but also your customers and vendors.

Security Awareness

Your end users are the critical part of your security program who can break it or make it, so it is important to have a security culture inside your organization, by providing security training and phishing campaign you can influence the end user's actions and behavior resulting more effective information security program.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.