Passwords

Download the white paper

How Identity and Access Management Can Protect Your Business

As more people access business applications remotely security threats could come from anywhere. As a result, strict identity verification is essential.

This approach, known as ‘Zero Trust’, means that each request is verified as though it comes from an untrusted network. This ensures that only authorised users and devices can access the business’s systems and data. Every access request should be fully authenticated, authorised and encrypted before granting access.

Password Management

Passwords are a staple of systems security. As businesses rely ever more on technology, the number of passwords each person uses has grown dramatically. The average person has over 200 accounts for different online services, which explains why people often reuse passwords. However, this increases the risk if any of those systems are hacked through a phishing attack.

The National Cyber Security Centre recommends using a password management tool to solve this problem. These store passwords in an encrypted database and only the user can access their passwords with a long and complex passphrase.

These tools also allow randomly generated passwords to be created for each system. So even if one of them is compromised, exposure is limited to only that service. As well as being highly secure, this also means that people no longer have to remember a variety of different passwords.

Whilst it is outside best security practice, shared passwords are a reality. As a result, password management tools provide a secure way to share a selected password to more than one person with a full audit trail.

Multi-Factor Authentication

A major step to improve system security, beyond usernames and passwords, is to ask for a third piece of information before someone can logon. Even if the username and password are stolen, for example through phishing, the account cannot be accessed without this third factor.

Example of this include:

  • A token with a number generator
  • A code sent by SMS
  • An app with a push notification
  • A card with codes

The most secure and convenient of these is the push notification. When someone tries to log in, their mobile shows a notification which they have to click to approve. This is secure because their phone is protected by a PIN or fingerprint.

Risk-Based Login

Systems can also check for anomalies in behaviour which suggest unauthorised attempts to access systems. Examples of login attempts which can be restricted include:

  • Devices with suspicious activity. E.g. A specific IP address which tries to access multiple businesses in sequence
  • Devices with hidden IP addresses as these prevent other checks on how that device is being used
  • Different locations which are impossible to travel between in that time. E.g. A login from the UK at 3pm then from Turkey at 4pm
  • Countries which staff would not travel to for business

Principle of Least Privilege

To limit exposure to malicious or accidental problems caused by users, employees should only have the minimum level of access they need to do their job. For example, the receptionist does not need access to the accounting systems and the accountant has no need to access the visitor logs.

In addition, people with administrator access should not use it on a day-to-day basis for regular work as many viruses follow the credentials of the logged in user.

Segmentation

Separating users from business-critical applications limits the damage, accidental or malicious, someone can do. It also restricts the spread of malware, like ransomware.

Malware is much more likely to be downloaded onto an individual’s computer rather than a server, so placing a firewall between those two devices helps to control the exposure. For example, an accounting server in a business’s office should be separated from users by a firewall.

Alongside this, other internet-enabled devices are being used in businesses. From voice-controlled assistants and smart light bulbs to smart thermostats and IP cameras. The best way to protect a business from the security risk of these devices is with network segmentation. This puts these untrusted devices in a dedicated network segment, separated from both users and servers.

Cyber Security to Protect Your Business

Learn more about how to keep your business safe in the white paper: Cyber Security: How to Protect Against Complex Threats.

This plain English guide from Always Secure covers:

  • The cyber security threats facing professional services firms
  • The risks and opportunities from new technology
  • How to protect and support a business with cyber security
  • An effective strategy to protect your data, devices and systems
  • What to look for in an IT security partner