Start with identity
Most incidents begin with a compromised account. Enforce multi-factor authentication everywhere it is available, starting with email, remote access and administrative accounts.
Remove access promptly when people change roles or leave, and review privileged accounts regularly.
Keep systems patched
Unpatched software remains one of the easiest routes in for attackers. Automate updates for operating systems and applications, and track anything that cannot be patched quickly.
Back up and test recovery
A backup you have never restored is an assumption, not a control. Keep at least one copy offline or immutable and test restoration on a schedule.
Prepare to respond
Decide in advance who does what during an incident, who needs to be informed and how you will communicate. A one-page plan beats improvisation under pressure.
Key takeaways
- Secure accounts first
- Automate patching
- Test your restores
- Write down your response plan