4 min. read • Email this page
Listen to this blog post:
The right time for a cybersecurity rethink
The natural fall changes prepare us to start again.
Georgetown Math Professor and productivity expert Cal Newport advises that people not wait until the new year to recalibrate, but to make use of the fall. Maybe baked into us from the school-year start, the fall continues to feel like a natural time for new beginnings. And there’s evidence that the current seasonal daylight and temperature and leaf-color shifts send signals to our bodies that it is time for a new beginning1.
I began by writing a cyber-hygiene checklist, but caught myself – that isn’t quite what’s needed for an organization that has an internal IT department, a Managed Service Provider or a combination of both. Adding MFA and limiting permissions are something that pros should be handling for you.
Instead consider using this fall as a mindset reframing. I’d like you to consider two aspects to having and maintaining an Uptime Mindset, a phrase Bryley has coined to describe a cyber-aware organization well-prepared for the inevitable challenges of doing business in a computing environment. The goal, of course, is increased uptime.
Being cyber-aware
A cyber-aware organization knows what it has specifically. It knows which accounts are active, which services are in use, which devices are connected to the network. This sounds straightforward until you consider how quietly an environment drifts: someone leaves and their credentials remain active, a tool gets spun up for a project and never decommissioned, a department starts using a cloud service that nobody in IT knows about. While outside of some ideal protocol, these are the ordinary workings of an active organization.
Cyber-awareness means you periodically reaffirm that your current picture is accurate. Your MSP or internal IT team can do the detailed work, but they can only work with what they know exists. Your role is to make sure they have the complete picture.
Being fit to face cyber-challenges
No computing environment is fully secure. The truly useful question is what happens when something goes wrong. An organization that is fit to face cyber-challenges has thought this through in advance – not in a time of crisis. Backups are current and tested. Someone besides the primary IT contact knows the recovery steps. There’s a written procedure plain enough for a non-technical person to follow under pressure.
Ransomware, hardware failure and human error are among the hazards of operating in a computing environment. Resilience means the damage is limited and recovery is swift. That condition needs the same periodic attention as any other aspect of operational readiness.
The Uptime Mindset Reset
So to reset this fall, get IT in on a conversation. Work through these together with them: What in our computing environment has changed and what have we not looked at in more than a year? If we got hit with malware this Friday, what are the steps we need to follow?
Asking these questions that invite a close look at IT processes and practices will bring to the surface more that’s actually relevant to your organization than a general checklist.
Bryley has these kinds of conversations regularly and would welcome your call. To speak to Bryley’s Roy Pacitto please complete the form, below. Or you can email Roy at RPacitto@Bryley.com or reach him by phone at 978.562.6077 x217.
1 https://www.realsimple.com/why-september-makes-you-want-to-reset-your-life-12074718
Lawrence writes about networking and security. His consumer-scam writing has appeared on the Moneywise website. He’s written for Bryley since 2015.