The most common way into a business is not a clever piece of malware. It is an account: one that belonged to somebody who left eight months ago, or one protected by a password that was also used on a website that has since been breached.
What we manage
- Accounts created properly when somebody joins, with the access their role needs and no more
- Accounts closed the day somebody leaves — the half that gets forgotten, and the half that matters
- Multi-factor authentication, so a stolen password on its own is not enough
- A password policy people can actually follow, rather than one that guarantees sticky notes
- Administrator accounts kept separate from everyday accounts, and kept few
- Periodic review of who has access to what, because it drifts
On password rules
Forcing a change every thirty days is now understood to make things worse, not better. People respond by choosing a predictable pattern and incrementing a number, which is easier to guess than the password they had before.
Length beats complexity, reuse is the real enemy, and multi-factor authentication does more for your security than any rule about capital letters. We will set the policy that way, and explain why to anybody who expects the old advice.
Leavers
An account nobody closed has no owner watching it, no reason to look odd, and often no expiry. It is the quietest way into a business there is, and the fix costs nothing but a process.
If you are not certain every former member of staff has been disabled everywhere, that is worth checking this week. We can go through it with you.
Related
Sits alongside corporate data protection and the wider controls in our IT security service.
Part of our IT security service. Most clients take this as part of a wider agreement rather than on its own. See the full service.
Nicosia +357 22 356 840 · Limassol +357 25 030 261 · Larnaca +357 24 030 269 · info@itlogicpro.net
