‘Broken window, broken business’ and cybersecurity

Issue 1 2021 Cyber Security

Here at Networks Unlimited Africa, as we anticipate the trends and threats that we foresee for the coming year, we are applying the ‘broken window, broken business’ principle when looking at our internal cybersecurity posture.

The term broken window comes from George Kelling, a criminologist who wrote in 1982 that, “Social psychologists and police officers tend to agree that if a window in a building is broken and is left unrepaired, all the rest of the windows will soon be broken… vandalism can occur anywhere once communal barriers… are lowered by actions that seem to signal that ‘no one cares’.”[1]

Applying the broken window, broken business principle when looking at your internal cybersecurity posture means, in essence, making sure that you have no broken windows, or gaps in your security through which uninvited elements could enter. In order to do this, you first need to create a firm baseline to develop your posture.

Your foundations are strong networks and segmentation, which can be achieved either in-house or outsourced to a third-party expert. We see a lot of companies overlooking the basics and then, at a later stage, getting caught in the trap of needing to acquire solutions to plug security gaps. This can become very expensive.

We advise that, when looking to build any network and adding security on top of this, it is important to ensure that you are using human resources who are certified within their respective fields. Smaller organisations often make the mistake of using a ‘just enough’ mentality to get the network operating.

Stefan van de Giessen.

Fix the cracks

As a first step to cover all of your bases, ensure that you don’t have any cracks in your posture – in essence, a broken window. A lack of proper network segmentation, as well as inadequate password management and a vulnerable email security, are all factors that can act as broken policy.

Additionally, the endpoint is one of the most crucial vectors for attack, especially considering the current, significantly increased number of employees working from home. This is a true broken window potential.

Organisations must ensure that endpoints are protected by a next-generation antivirus and thereby closely monitored for any malicious activity. Traditional antivirus has become irrelevant due to the evolution of attacks, including file-less attacks. Additionally, the endpoints need to be secure as they initiate access to your virtual private network.

In conclusion, companies need to adopt a broken window attitude when reviewing their cybersecurity posture. Establishing and maintaining the fundamentals is crucial in ensuring your environment does not fall into disrepair, making it an appealing target to cybercriminals. If a strong foundational plan addressing the points we have discussed is maintained, your posture will remain strong, ensuring your organisation is as well protected as it can be.

For more information contact Networks Unlimited Africa, +27 11 202 8400, david.wilson@nu.co.za, www.networksunlimited.africa

[1] https://www.theatlantic.com/magazine/archive/1982/03/broken-windows/304465/

Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

Securing access to the data centre
Issue 1 2021, Suprema , Cyber Security
When looking for a solution to securing your data centre, FaceStation F2 stands out in terms of its versatility, security and rich feature offering.

Secure alternative to passwords
Issue 1 2021, Suprema , Cyber Security
Fingerprint biometrics offer a secure alternative to regular passwords; they cannot be lost/forgotten and cannot be shared.

Information visibility is key for brand protection
Issue 1 2021 , Cyber Security
High-value employees now give away more information in the social media age than ever before and businesses need a solution that will immediately block, hide or remove racial slurs, sensitive data like credit card numbers, competitor posts, scams, malicious links and more.

Further exit of skills possible
Issue 1 2021, Galix Group , Cyber Security
Lifting international travel restrictions could have a severe impact on South Africa’s already depleted cybersecurity skills pool.

A new security approach for the modern network
Issue 1 2021 , Cyber Security
In a digitally transforming world, the traditional firewall is no longer as effective as it used to be.

Cybersecurity in 2020: lessons for tomorrow
Issue 1 2021 , Cyber Security
There is a visible jump in awareness around online security, precisely because of the remote working trend that became a reality in 2020.

Small business security trends for 2021
Issue 1 2021 , Cyber Security
Recent surveys suggest that many small business owners are still operating under a false sense of cybersecurity.

Jian: The double-edged cyber sword
Issue 1 2021 , Editor's Choice, Cyber Security
A Chinese-affiliated attack group (APT31) cloned and actively used an American-affiliated attack group’s (Equation Group) cyber-offensive tool codenamed EpMe. Both attack tools exploit a then unknown Windows vulnerability for elevating the privileges of the attacker on the infected machine.

Losing face
Access & Identity Management Handbook 2021 , Cyber Security
Can hackers steal your identity with just your face? Face biometrics have boomed amidst the pandemic, stressing the necessity of 2FA.

Five ransomware predictions for 2021
Issue 9 2020 , Cyber Security
How to stay ahead of cyber criminals and protect your data