sb-au logo
Story image

Five steps to ensure persistent data security across your network

02 May 2018

Network security has built in a basic foundation of strong protection across the perimeter, but that border is losing its strength as organisations move to the cloud.

According to Keysight Technologies, applications and infrastructure are increasingly cloud-based, which means businesses need to take a new approach.

Keysight Technologies’ vice president of portfolio marketing, Jeff Hassis, explains: “In its recent report, 2017 State of the Hybrid Cloud, Microsoft found that 63 per cent of organisations are already using hybrid cloud environments.”

“The result is that gaps are starting to appear in perimeter defences, which can be exploited by hackers or malware to steal information and personal data. Organisations need to focus less on perimeter defences and focus their efforts on identifying unusual user or network behaviour, which may be an early sign of a potential breach or attack.” 

According to Keysight Technologies, there are five ways that organisations can ensure network security:

1. Assign roles specific to new threats  Rather than spreading responsibility across the IT department or giving an existing manager additional responsibility, organisations should put a single person or team in charge of security to ensure the security strategy is given the attention it deserves. 

2. Audit data and infrastructure  It’s important to know what type of data an organisation is dealing with, including policies attached to each type of data, who has access, and where workloads accessing critical data are running. It’s also crucial to document data-capture methods for compliance. An initial audit and ongoing asset discovery can provide visibility into security and compliance postures in real time. It also lets organisations identify how and where it may be vulnerable, so it can act to close gaps. 

3. Create baselines  Once an organisation understands its data profiles, it needs to capture expected behaviours. This includes aspects like who is authorised to see data, and how that access is granted or denied, all of which should be recorded and turned into a baseline of expected behaviour. 

4. Monitor for abnormalities  Monitoring user and network behaviour against baselines can help organisations identify anomalies which could signal a potential breach. This could include a user downloading terabytes of data when their role doesn’t normally require them to do so, or a member of the marketing team accessing server logs. The security team can then investigate further to either stop a breach from happening or verify that the activity is legitimate. 

5. Secure data  Organisations need to secure their own processes and data. For example, personally-identifiable information needs to be secured through data masking to ensure security itself isn’t the weak link. 

“Security strategies focused on perimeter defences can no longer protect sensitive data against theft in today’s complex IT environments. Organisations need to be able to quickly identify threats and vulnerabilities inside their networks, to keep information safe,” Harris concludes.

Story image
Ripple20 threat could affect 35% of all IT environments – ExtraHop
The vulnerabilities have the potential to ‘ripple’ through complex software supply chains, enabling attackers to steal data or execute code.More
Story image
Just one click – that’s all it takes to let in cyber-crime
So how do organisations ensure that users are not compromised by simply doing their work?  The answer is surprisingly simple, writes Bufferzone Security business strategist for A/NZ Greg Wyman.More
Story image
Gartner: Security leaders must balance risk, trust and opportunity
Security and risk leaders must focus on balancing risk, trust and opportunity to help maintain the ability of their organisations to function.More
Story image
Kaspersky finds red tape biggest barrier against cybersecurity initiatives
The most common obstacles that inhibit or delay the implementation of industrial cybersecurity projects include the inability to stop production (34%), and bureaucratic steps, such as a lengthy approval process (31%) and having too many decision-makers (23%). More
Story image
Video: 10 Minute IT Jams - The benefits of converged cloud security
Today, Techday speaks to Forcepoint senior sales engineer and solutions architect Matthew Bant, who discusses the benefits of a converged cloud security model, and the pandemic's role in complicating the security stack in organisations around the world.More
Link image
Creating a lean business machine with automation and low-code
Forrester data indicates that process automation was a strategic initiative for many organizations before COVID and remains so after. Catch this webinar to learn more about automation.More