Site icon bbrief

Rethinking cybersecurity – when the firewall is no longer enough


John McLoughlin | CEO | J2 Software | mail me |


Your firewall cannot save you because the workplace it was designed to protect barely exists anymore. Employees work from anywhere. Applications sit in the cloud, while data moves between platforms and devices. Businesses also increasingly rely on third parties and connected services. The office may still have a firewall, but the business itself has long since moved beyond its walls.

The other major change is the scale and speed of the threat. Cyber criminals increasingly use automation and AI to find weaknesses and target businesses at scale. They do not necessarily need to know who you are before they attack you. Instead, they can find exposed systems, compromised credentials, vulnerable devices or poor security controls. They can then exploit the easiest route in.

Security beyond the perimeter

That means businesses need to rethink security for modern businesses. Instead of viewing security as a perimeter, they need to focus on visibility and resilience across the entire organisation’s digital footprint.

Our approach to protecting the modern business is to provide complete visibility across five key areas of digital risk: Users, Email, Data, Machines and Internet. These are the areas businesses depend on. They are also the areas attackers will target.

It does not help to have multi-layered email defences if machines are not adequately protected. Similarly, deploying endpoint protection is not enough if there is no visibility of access and activity across cloud platforms. Threats have evolved, yet many businesses still think they can defend themselves in the same way they did five years ago and remain secure.

Physical and digital security should also form part of the same risk conversation. A physical security incident can become a cyber incident very quickly. An attacker gaining access to an office can create digital consequences. So can a stolen laptop, an unauthorised person accessing equipment, session theft or someone being forced to provide credentials.

Connecting physical and digital risk

The reverse is also true. A compromised account or device can potentially provide access to physical systems, buildings or connected infrastructure.

The objective is not to connect every security system together for the sake of it. Instead, it is to create a unified understanding of risk. Security teams need to know what matters to the business, who has access to it and what that access looks like. They also need to understand what happens if that access is compromised.

Physical and digital security may remain separate operational functions. However, they should not remain separate risk conversations.

Smart building technology illustrates why this matters. Connected access control, cameras, sensors, environmental systems and building management platforms can provide far greater visibility and control. However, every connected device can also become another potential entry point.

The mistake would be to assume that something is not a cybersecurity concern because it is a building system. If it connects to a network, stores information, has an account or allows remote access, businesses need to consider it part of the organisation’s cyber risk environment. Smart buildings therefore need smart security.

Defining the minimum security posture

So, how does a business determine its minimum viable security posture? Start by asking a slightly different question: what would happen if we lost access to our critical systems tomorrow?

Every business should identify the systems, data, people and processes it absolutely needs to continue operating. Then, work backwards and ask what could prevent access to those things.

At a minimum, businesses should have strong identity controls, including MFA. They also need appropriate access and administrator separation. Properly protected and monitored email is essential. So are modern endpoint protection with EDR and monitoring, secure and tested backups, patching and vulnerability management, and visibility across critical systems.

Technology alone is not enough, however. Someone needs responsibility for knowing when something is wrong and taking action. A security alert that nobody sees or responds to is not security.

This matters even for smaller businesses. Having an effective security capability does not necessarily mean employing an internal security team. Instead, it means having access to the right expertise, whether that expertise is internal, outsourced, or co-managed.

From prevention to resilience

The same principle applies to business continuity and resilience. Prevention alone is not enough because every business should assume that something will eventually get through.

The question is whether the organisation can detect it, respond to it and recover without the incident becoming an existential business problem. That requires secure and tested backups, protected endpoints and email, strong identity and access controls, patched systems and continuous visibility of significant security events. However, it also requires a plan.

Who makes the decision to isolate a system? Who contacts the bank? Who communicates with customers? Who has access to backups? Who leads the response? How does the business continue operating while the incident is being resolved?

Resilience is not simply having a disaster recovery document sitting in a drawer. It means having the people, processes, technology and visibility to detect an incident, contain it, recover from it and keep the business moving.

This is where rethinking security for modern businesses becomes particularly important. Security cannot focus only on stopping an attack. It must also consider how the organisation will operate when prevention fails.

Building a business that can keep moving

The objective is not to create a business that can never be attacked. That is not realistic. Instead, the objective is to create a business that is difficult to compromise, quick to detect an attack, capable of responding effectively and resilient enough to continue operating when something does happen.

That means rethinking security for modern businesses as an ongoing organisational capability rather than a single defensive layer. The focus must extend across users, email, data, machines and the internet, while also recognising the connection between physical and digital risk.

In a hyper-connected and increasingly dangerous digital world, security is not about building a higher wall around the office. It is about knowing where the walls no longer exist.


 

Exit mobile version