Enterprise cybersecurity
An organisation’s security is measured by what it can restore, not by what it has bought.
- Parent division
- Physical and cyber security
The problem
Spending goes to tools, while incidents keep coming through the same three doors.
The incidents that bring an organisation to a standstill almost always enter through an account whose password has leaked, a service exposed to the internet that should not have been, or an attachment opened on a workstation that could reach the rest of the network.
None of these three doors closes by buying a product. They close through a maintained inventory, two-factor authentication, network segmentation, and backups whose restoration has actually been tested.
The difficulty is the order. An organisation starting from little gains more security by making its backups and its access reliable than by installing a detection tool no team will watch. A tool with no operator produces alerts nobody reads, and an annual invoice.
The order of measures, schematic
- 01Inventory
- Without it, no measure can be verified and no exposure can be assessed.
- 02Identities
- Two-factor authentication, separated administration accounts, removal of shared accounts.
- 03Segmentation
- Office, industrial and security separated, permitted flows enumerated one by one.
- 04Detection and logs
- Few rules, all of them handled, and retention long enough to reconstruct an incident.
- 05Offline backup
- Out of reach of the system it protects, failing which it is encrypted along with it.
- 06Tested restoration
- Restored from real data and timed. A backup never restored is an assumption.
Scope
What the service covers
- Inventory and exposure
- A full listing of equipment, services and accounts, a survey of what is reachable from the internet, and identification of unsupported systems and undocumented dependencies.
- Identities and access
- Two-factor authentication, separated administration accounts, removal of shared accounts, account lifecycle, review of privileged rights.
- Backup and restoration
- Offline or immutable backups, restoration tested against a real dataset and timed, maximum tolerable outage and data loss settled with the executive rather than with the technical team alone.
- Segmentation and hardening
- Office, industrial and security networks separated, filtering between segments, fewer exposed services, hardened workstation and server configuration.
- Detection and logging
- Centralised logs, retention long enough to reconstruct an incident, endpoint detection, and few alert rules, all of them actually handled.
- Incident handling
- A written procedure, a named escalation chain, the decisions to be taken within the first hour, at least one exercise run, and communications prepared before they are needed.
Situations
The most frequent situations
- Organisation with no dedicated security team
- IT is held by two or three people who do everything. The priority is closing the structural doors and making restoration certain, before any detection.
- After an incident
- The system is back up but nothing guarantees the cause has been addressed. Recovery means reconstructing the entry path, rotating every secret, and closing what was used.
- Contractual or supervisory requirement
- A lender, a supervising authority or a client imposes a level. The work is to document what exists, close the gaps, and produce evidence that stands up.
- Industrial environment
- Controllers and supervision systems that cannot be patched live alongside office IT. The answer is segmentation and control of remote access, not patching.
Requirements
What to require, of us as of anyone
These requirements hold whichever supplier is appointed. Written into a tender, they filter out the responses that will not hold.
- An inventory of systems and accounts, kept current, without which no measure can be verified.
- A restoration tested within the year, timed, on real data rather than a test file.
- Two-factor authentication on every remote access and every administration account, with no tolerated exception.
- The list of services reachable from the internet, and the justification for each one.
- Log retention long enough to reconstruct an incident discovered late.
- An incident procedure naming people rather than roles, and proven by an exercise.
- A reversibility clause: the ability to resume operations without the provider who set them up.
Pitfalls
Common mistakes, and what they cost
- Buying detection before backup
- Detection shortens the time to discovery; backup decides whether the organisation restarts. An organisation that detects without being able to restore observes the incident without being able to answer it.
- Backing up to storage reachable from the network
- A backup reachable with the same credentials as the system it protects is encrypted along with it. This is the most common tipping point between a costly incident and a permanent shutdown.
- Multiplying alert rules
- A console producing hundreds of alerts a day stops being read within a month. Few rules, all handled, beat theoretical coverage.
- Relying on awareness alone
- Training lowers the frequency of mistakes; it does not remove them. An architecture that assumes no user will ever open an attachment is an architecture that will give way.
Questions
Questions asked before consulting
Where should a limited budget start?
With inventory, offline backups and two-factor authentication. These three cost little, depend on no particular product, and address most of the scenarios that bring an organisation to a standstill. Detection, fine-grained segmentation and continuous monitoring come afterwards, once a team can operate them.
Is a backup enough against ransomware?
A backup whose restoration has been tested, kept out of reach of the system it protects, and whose time to service is known: largely yes. A backup never restored is not a backup, it is an assumption. Data disclosure remains a separate risk, which backup does not address.
Is a security operations centre worth it?
It is justified when the organisation has someone able to handle alerts around the clock, or delegates that handling to a third party under a response-time commitment. Without either, it produces logs that are useful after the incident — worth something, but not what it is usually credited with.
How should systems that cannot be patched be handled?
By isolating them. An industrial controller or an ageing supervision system is handled through segmentation, flow filtering, strict control of remote access and logging of connections. Replacement is planned over several budget years; isolation is put in place in a few weeks.
What should be required from a managed services provider?
The detail of their own access to your systems, traceability of their connections, named accounts rather than a shared one, their response-time commitments, and the conditions under which you take control back. A provider who refuses traceability of their access introduces a risk no tool compensates for.
Does certification equal security?
No. A certification attests that a management system exists and is followed. It says nothing about the real exposure of the information system on a given day. Both matter and are pursued in parallel; conflating them leads to documenting measures nobody applies.
Neighbouring subjects
Solutions concerned
Consultations · Pre-qualifications · Partnerships
Let us discuss the actual case.
Describe the site, the dominant constraint and the deadline. We will say what requires a preliminary study and what can be committed directly.