麻豆入口

How to Prepare Your Business for Cyberattacks

Bulletproofing your business against a cyberattack can help protect you from today鈥檚 threats.

Nick Espinosa

Bulletproofing your business against a cyberattack can help protect you from today鈥檚 threats.

Here are the most urgent items to put on your list to quickly prepare your business.

Update ALL Critical Infrastructure, Operating Systems and Software.
We primarily update or patch our computers, phones, wireless access points and everything else to fix a known vulnerability. Ignoring or skipping updates makes hacking into your life much easier. A couple of years ago, we were called into a 麻豆入口 member company due to a data breach where the attacker exploited a known vulnerability in their firewall and got in. If that member had simply kept their firewall up to date, we would have never gotten that call.

Enable Multifactor Authentication (MFA) On Everything You Can.
Gone are the days of only having a username and password to protect assets like email. Now, we鈥檙e using Multifactor Authentication (and more) to protect our logins. MFA is free for most platforms, like Microsoft Office 365. Studies have shown that using MFA with an authenticator app has thwarted over 99 percent of account compromises targeting Office 365 accounts.

Ensure ALL Devices Have Threat Detection.
If I break into your network, I will start inventorying everything connected. If I鈥檓 able to find a computer without an Endpoint Detection Response (formerly antivirus) agent, I will then use that to leverage my attacks. Make sure everything has threat detection 鈥 no exceptions!

Double Check Your Backups.
Periodically test your backups鈥 recovery capabilities to ensure they鈥檙e backing up everything they need to. Also, have onsite backups (if you have onsite servers that need backing up) and send backups to the cloud, as they are much harder to attack. Encrypt your backups so they can鈥檛 be stolen and ransomed against you.

Alert Employees To Maintain Vigilance And Look For Threats.
Education is beyond important for a sound defensive strategy. Ensure all employees are properly trained to spot phishing emails, bad sites and more. Also make sure the training is role-based. Individuals with access to things like money need training at least once a month via phishing testing and subsequent training if they fail to spot and block the phishing attempts.

Geo Block Firewalls and Identity Management Systems.
Many firewalls and identity management systems give an organization the ability to block all traffic coming to their systems. Don鈥檛 have clients or business interests in Russia? Then why can Russia see your firewall when you can tell your firewall to turn into a black hole for all internet traffic except for traffic from countries where you do business? Why do your company logins work in Russia as well? Make sure those are locked to where you are geographically.

Industrial Control Systems Should Be Tested To Ensure They Work Offline.
If the internet goes down, does the HVAC controller stop working? That was a problem with Google Nest devices in many homes. Google had a major outage, and people couldn鈥檛 use their thermostats to heat or cool their homes while they were down. Can your customer鈥檚 buildings still heat and cool without internet? If there are other critical industrial control systems at play, can they also work offline?

These are only the most critical steps to securing your business from an impending cyberattack. We don鈥檛 know how far the current war in Ukraine will escalate, but if Russia must retaliate against the West, their best bet is to launch infrastructure attacks against us all. Following these basic steps will make your business that much harder to hit.

Nick Espinosa is a cybersecurity expert, working with companies to design custom cyberdefense strategies. Learn more at www.securityfanatics.com.

 


Published: May 16, 2023

IN THIS ISSUE


Big Clients Require Big Partners

JPMorgan Chase & Co.鈥檚 global headquarters becomes AABCO鈥檚 next commercial HVAC client in NYC.


Bringing Shade to Schools

Intech helps install sheet metal shade structures at California schools.


Evaluating the Environmental Impact of Architectural Metals

Zahner talks about how the Life Cycle Assessment accounts for the environmental impact of metal material from its initial extraction through manufacture and use and on to the end of its designed useful life. 


Exploring metal鈥檚 role in sustainable architecture

Metals are different from nearly all other materials used in our built environment. Once the useful life has ended, the metal is collected and recycled.


Going to Market

With advertising, 128-year-old Welsch Heating & Cooling Co. isn鈥檛 afraid to try new ways to reach their customers 鈥 as long as they work. 


How to Prepare Your Business for Cyberattacks

Bulletproofing your business against a cyberattack can help protect you from today鈥檚 threats.


Metal is a Low Waste, Sustainable Building Material

Sustainability is more than just an industry buzzword at Zahner. It's a daily commitment to preserving and protecting the natural resources we鈥檝e been entrusted with and using them responsibly in the built environment.


Sheet Metal Werks Shifts Field Hours to Shop Hours

The Illinois company saved significant man-hours by planning ahead. 


麻豆入口 at the White House & 麻豆入口 Endorses Bipartisan Bill on Substance Abuse

麻豆入口 was asked to be part of a policy roundtable on supply chain for highly efficient heat pumps and related decarbonization technologies that are key parts of whole house retrofits.


麻豆入口 Government & Technical Updates & Engagement Opportunities

The first quarter is always busy at 麻豆入口. We have lots of association events, our technical department is out in force, labor is starting its bargaining season and the government relations team is focused on many regulatory issues. 


The Challenges With Manning Megaprojects

With the pandemic entering a new phase, construction has boomed with what are now widely known as 鈥渕egaprojects.鈥 Every day, it feels like there鈥檚 a new stadium, microprocessor factory or some other massive project getting underway. The demand for


Top Contractor Strategies for 2023, Part 2

In the last issue of SMACNews, I presented the first five of Grassi鈥檚 Top 10 Contractor Strategies for 2023. Those approaches to purchasing, procurement, prequalification, increased costs and project management are designed to cut through the noise


Understanding The Notice Requirements In Your CBA

For contractors with collective bargaining agreements (CBAs) expiring in 2023, it is important to remember that most CBAs, including the Standard Form, include an 鈥渆vergreen鈥 or 鈥渁utomatic renewal鈥 clause.