Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Government highlights technical options to defend networks

by The Gurus
January 23, 2015
in Editor's News
Share on FacebookShare on Twitter

Putting in place security controls and processes and adopting a defence-in-depth approach are the keys ways to reduce your exposure to a cyber attack.
 
According to a Government document, on “Common Cyber Attacks: Reducing The Impact”, preventing, detecting or disrupting the attack at the earliest opportunity limits the business impact and the potential for reputational damage.
 
The report claimed that there are “effective and affordable ways” to reduce your organisation’s exposure to the more common types of cyber attack on systems that are exposed to the internet, and named these as:
 
Boundary firewalls and internet gateways to establish network perimeter defences, block access to known malicious domains and prevent users’ computers from communicating directly with the internet;
 

  • Malware protection to establish and maintain malware defences to detect and respond to known attack code;

 

  • Patch management to patch known vulnerabilities with the latest version of the software, to prevent attacks which exploit software bugs;

 

  • Whitelisting and execution control to prevent unknown software from being able to run or install itself;

 

  • Secure configurationto- restrict the functionality of every device, operating system and application to the minimum needed for business to function;

 

  • Password policy to ensure that an appropriate password policy is in place and followed;

 

  • User access control, including limiting normal users’ execution permissions and enforcing the principle of least privilege.

 
It also recommended security monitoring, user training and awareness and security incident management if your organisation is likely to be targeted by a more technically capable attacker.
 
The report devolved the stages of attack into four categories of mitigation – survey, delivery, breach and affect. The survey stage recommended user training, education and awareness as well as secure configuration to minimise the information that Internet-facing devices disclose about their configuration and software versions, and ensures they cannot be probed for any vulnerabilities.
 
The delivery options available to an attacker can be significantly diminished by applying and maintaining a small number of security controls, which are even more effective when applied in combination, it said.
 
In terms of mitigating the breach, it said that the ability to successfully exploit known vulnerabilities can be effectively mitigated with just a few controls, which are best deployed together. “All commodity malware depends on known and predominately patchable software flaws,” it said. “Effective patch management of vulnerabilities ensures that patches are applied at the earliest opportunity, limiting the time your organisation is exposed to known software vulnerabilities.”
 
Malware protection, particularly within the internet gateway and secure configuration were the recommendations here, as they can remove unnecessary software and default user accounts, and can also ensure that default passwords are changed, and any automatic features that could immediately activate malware are turned off.
 
Finall
y, mitigating the affect stage means that if all the measures for the survey, delivery and breach stages are consistently in place, the majority of attacks using commodity capability are likely to be unsuccessful.
 
“However, if your adversary is able to use bespoke capabilities then you have to assume that they will evade them and get into your systems,” it said. “Ideally, you should have a good understanding of what constitutes ‘normal’ activity on your network, and effective security monitoring should be capable of identifying any unusual activity.”
 
The report said that the threat of attack is ever present as new vulnerabilities are released and commodity tools are produced to exploit them, and doing nothing is no longer an option. “Protect your organisation and your reputation by establishing some basic cyber defences to ensure that your name is not added to the growing list of victims,” it said.

Tags: attackGovernmentMitigation
ShareTweet
Previous Post

Adobe Flash zero day detected, the first of many – Industry views

Next Post

Minecraft claims its users were phished, rather than hacked

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol