All articles

How to protect your organisation against cyber threats when all hell breaks loose in the world: 12 steps

War or no war, every conflict in the world now has an enormous digital dimension: alongside physical attacks, digital attacks are an integral part of the battlefield. The same applies now.

Cyber advice and warnings are coming at you from every direction. If you let interventions or half-truths guide you, the risk is overprotection in the most expensive case and underprotection in the riskiest case.

Let us be honest: as an owner, IT manager or CISO, you want to protect your interests.

What is right? What must happen immediately? Where do you start? Where does the most urgent and dangerous threat come from? How do I increase our resilience? This article helps you, as an IT manager or CISO, make the right decisions. We show how a hacker works and what you can do to protect your organisation against bad outcomes and worse.

Who wants to attack me?

Although there are currently no indications of widespread attacks against Dutch companies, opportunistic and ideologically motivated attacks cannot be ruled out. A group of opportunistic hackers could, for example, develop malware to attack businesses. State-backed groups may also try to gain access to critical and vital infrastructure.

How could I be hacked?

A hacker always takes either a general or a targeted approach:

  • General attacks use a known or unknown vulnerability in a product used by many companies, such as Citrix or email software like Microsoft Exchange. Many IP addresses are then scanned and attacked. Phishing emails may also be sent to large numbers of email addresses.
  • Another approach is targeted hacking, where one or a few companies are selected as targets. The hacker first reconnoitres the target, analysing the infrastructure, external applications and users. After reconnaissance, vulnerable systems may be found and exploited, or specific users may be hacked through phishing.

After gaining access to a system through either a general or targeted approach, the hacker will try to increase their initial privileges once a persistent connection has been established to the attacker's command and control (C2)[1] server. Through this C2 server, the hacker can continue the attack remotely. Within the internal network, the attacker goes for the pot of gold: servers and applications containing important information. Or, if the aim is to gain control over the network, they look for servers and applications that allow that. Such an attacker will not simply pursue Domain Admin or the highest privileges if unnecessary, because those roles may be monitored much more closely. After escalating privileges through various routes, the attacker can take over computers and servers, install ransomware or steal sensitive information.

[TECH] How can I improve my security?

Following these twelve tips makes your business more resilient to cybersecurity attacks.

  1. A firewall is the first line of defence in network security. It monitors incoming and outgoing network traffic and decides which traffic is allowed or blocked based on a defined set of security rules. It forms a barrier between secure, managed, trusted internal networks and untrusted external networks such as the internet. Monitor carefully which servers connect to which ports and addresses. For example, a demilitarised zone (DMZ), a network segment between the internal and external networks, does not itself need to make external connections but responds to traffic from outside. If a DMZ initiates connections to the outside world, this may indicate connections to the attacker's C2 server! Connections initiated from the DMZ are not always malicious, however. In some situations and specific network designs, a connection may also be initiated from the DMZ. Examine carefully whether traffic is legitimate and monitor whether new traffic appears alongside trusted traffic.
  2. Although you may be concerned about Russian attacks, do not develop tunnel vision around Russian IP addresses! Anyone can rent a server in the Netherlands, Norway or anywhere else in the world. Hackers follow the news too, so they know an IP address from Russia may currently look suspicious. They therefore use tricks, proxies and rented servers to attack from other IP ranges.
  3. Using multifactor authentication (MFA) is crucial. Make sure all accounts have MFA. A security key is very useful, but authenticator apps are also a reliable option.

PLEASE NOTE: Push notification-based MFA is not always advisable. This method involves a user approving access by accepting a notification from a mobile MFA application. The danger is that hackers keep attempting to log in until someone accidentally approves the push notification.

  1. Do not forget basic hygiene measures:
    • Keep updating systems and check user permissions. All accounts should have the lowest possible privileges they need. Users with excessive permissions could, for example, disable critical security measures in Windows systems, making it easier for an attacker to gain entry.
    • Ensure the network is correctly segmented. This prevents a virus or attacker from spreading throughout the network.
    • Establish a complete vulnerability management programme that gives you 24/7 insight into vulnerabilities.
  2. Phishing has been among businesses' top 3 cyber risks for years and is one of the most effective forms of cybercrime. Make sure employees are alert to these attacks and know how to recognise a phishing email. Phishing is not limited to email: it can also happen through social media such as LinkedIn or by telephone. Also ensure employees can report a possible phishing attack internally. After validation, inform employees so nobody falls for the phishing email, or so anyone who accidentally has can come forward for mitigating steps to limit the damage.
  3. Check that backups actually exist. Keep backups in a secure location without direct access from your internal network. If backups are directly connected to and accessible from the network, a hacker can encrypt them with ransomware too.
  4. A DDoS attack, in which cybercriminals deliberately send enormous amounts of data to a server, can seriously affect the availability of your services. Determine the critical elements of your service and then investigate where they are vulnerable. Work with your internet or hosting provider to put sound measures and arrangements in place. Consider a paid anti-DDoS solution such as Akamai, Cloudflare or AWS Shield when using AWS.
  5. Make sure you know which processes are normal. Carefully examine which Windows processes your business uses and which applications are permitted. One best practice is to put permitted applications on an allowlist. Other applications then cannot simply be used within a Windows environment. This may seem difficult, but various tools are already available. Windows SRUM and different Endpoint Detection and Response (EDR) products can help by recording the processes and applications used over recent days or weeks. That list can help secure systems without disrupting business processes. Options such as AuditD and Sysmon are also available for Linux.
  6. An advanced EDR solution is crucial for detecting viruses and malware. Ensure EDR is optimally configured and that you know how systems can be quarantined, automatically or otherwise, when suspicious behaviour occurs. Also investigate deploying an Incident Detection & Response (IDR) solution: a security measure that recognises intruders early in the attack chain, allowing immediate intervention to prevent worse outcomes. IDR also provides direct insight into the cause and impact of a cyber incident.
  7. Create a clear Incident Response (IR) plan. You will then know which steps to take if one or more systems are hacked. Experimenting and panicking at that point is very costly, so it is worth having a comprehensive, validated and tested plan ready in advance. When creating such a plan, make sure it is also tested within the organisation. Fire drills take place every year too!

See also our ultimate step-by-step plan for recovering from a ransomware attack.

  1. Check whether and how well your systems are logged. Logs must be retained long enough in a secure place so attacks can be investigated when unusual behaviour is detected. Without logs, you cannot trace anything and your organisation is effectively blind within its digital infrastructure.
  2. Make sound arrangements with cybersecurity companies and Digital Forensics and Incident Response (DFIR) teams. It is important to have a reliable partner who can act promptly during an incident.

Unfortunately, there is no 100% tailored checklist for digital security. Organisations and networks are dynamic and all unique. Start by mapping your business-critical processes: what can you not do without for a day or an hour? Which supply chain are you in? Test your risk picture: what is our attack surface? How do hackers see us? With this information, take immediate measures to make things as difficult as possible for hackers. Even if an initial hack occurs, you can prevent the hacker from moving further into the network and making it unavailable through ransomware.

Need independent advice?

The most important thing is to have insight and a plan. Does your organisation need help with that? We are happy to think critically with you about what needs doing now and at which level of your organisation. We give you our view of your current situation and, if you wish, make you an offer. If we cannot help, we will refer you elsewhere.

Schedule a free clarity call.

[1] https://en.wikipedia.org/wiki/Command_and_control


Back to all articles