Knowledge and visibility leads to security

1 August 2018 Information Security

Following on from the article on threat detection and solutions, John Mc Loughlin, CEO of J2 Software highlights the importance of knowledge in the fight against cybercrime, as well as the importance of visibility into all your systems, processes, digital assets and people. The following pointers are presented as a starting point to improved cyber awareness and security.

John Mc Loughlin.
John Mc Loughlin.

Knowledge is key

Knowing where the risks are is a great step in the fight against cyber-attacks, which must then be continually augmented with live, inline and ongoing user cyber-awareness training. Without helping your users know what they need to be aware of, they cannot be expected to be part of the fight. It is important to not simply shift the blame to the user when you have not taken adequate steps to make them aware of the threats.

Some of the areas that require visibility and actionable intelligence are:

• User activity – both on and off the corporate network.

• Access to in-house and cloud-based platforms.

• Behavioural monitoring of users and the applications they install.

• End-point protection, with correlation to global threat intelligence.

• Email access and usage. This must cater for external and internal email attacks.

• Asset detection and management with ongoing vulnerability assessment to discover where the gaps are before the compromise takes advantage of the vulnerability.

• User cybersecurity awareness that is relevant to the organisations. You cannot expect users to help prevent breaches when they do not know what to look out for.

Visibility is key

As we work in a hyper-connected world, it is no longer good enough to only monitor what happens on the corporate network. You also need to know where your assets are used out in the wild. Breaches from third-party contractors or online applications can lead to your organisation losing data because of poor cyber-hygiene or password reuse. The area of risk is vast and includes:

• The network – as in the physical network with switches, routers firewalls and similar equipment.

• The systems – as in the business applications that run your business. Some of which are in-house and some may be sitting out in the cloud.

• The equipment – as in the computers, laptops, VoIP, mobile devices that your users jump on every day to interact with the systems, customers and suppliers of your business. It is important to know where and what assets are being used across your landscape. It is more important to know whether these are vulnerable to attack and compromise.

• The people – this is the easiest part to hack. The attacker does not need to hack a system; it is far easier to hack a human. Using social engineering and deception it is easy to compromise individuals to part with their knowledge or access credentials.

• The dark web – the cyber underground is where compromised details are shared and traded. This is a critical part of the programme because if you do not know that your corporate records are being traded, you cannot take any steps to close the hole created by these breached records.

A layered solution

Layered, overlapping solutions are required to win the fight against evolving threats. It is not enough to have only a firewall and antivirus solution in place when you do not have any idea regarding access and standard behaviour. Using the layered approach, when one layer is defeated you immediately detect the breach within another. Once detected you then have the capability to update all other layers to make sure the attack is nullified in future. Some of the layers will include, but not be limited to:

• End-point protection with automated updates and behavioural monitoring.

• Inline Domain Name System (DNS) or Internet monitoring and security – on or off the network from any connection.

• Email gateway and internal security measures to identify malicious attacks via email. This must include advanced capabilities to prevent phishing, whaling, impersonation attempts and armoured attachments.

• Backup – managed and monitored backup is crucial. It is also a key aspect to make sure that you have built-in and automated ransomware protection. If it is not the corporate standard, then it cannot be encrypted. Why allow something to take hold. It is cheaper, faster and more convenient to prevent than recover.

• User activity monitoring which must include known and unknown deviations from standard behaviour.

• Network, wireless and machine intrusion detection along with the complementary vulnerability assessments and remediation.

Mc Loughlin concludes: “All of these should be tied together in order to get a single 360-degree view of the overall threat and risk landscape for your organisation. Once you have the knowledge and total visibility, you have the capability to respond. Many of the basic tasks can be automated, which also ensures consistency and immediate reaction.”

For more information contact J2 Software, +27 87 238 1870, [email protected], www.j2.co.za.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Want effective Attack Surface Management? Think like an attacker.
Information Security
Effective ASM requires companies to think like attackers, anticipate risks, and act decisively to reduce exposure by knowing their environment, deploying a structured approach, leveraging capable tools, and addressing both internal and external risks.

Read more...
The growing role of hybrid backup
Infrastructure Information Security
As Africa’s digital economy rapidly grows, businesses across the continent are facing the challenge of securing data in an environment characterised by evolving cyberthreats, unreliable connectivity and diverse regulatory frameworks.

Read more...
POPIA non-compliance puts municipalities at risk
Information Security Government and Parastatal (Industry)
Digital responsibility must go beyond POPIA compliance to recognising that privacy and service delivery are fundamentally linked. Despite this, only 51 out of 257 municipalities submitted their mandatory data protection and access to information reports in 2024.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...
Most wanted malware
News & Events Information Security
Check Point Software Technologies unveiled its Global Threat Index for June 2025, highlighting a surge in new and evolving threats. Eight African countries are among the most targeted as malware leaders AsyncRAT and FakeUpdates expand.

Read more...
Welcome to the new cyber battleground
Information Security
The Iran-Israel conflict is rapidly redefining modern warfare, pushing the boundaries of cyber capabilities and creating a new, borderless digital battlefield. Fortinet’s CISO, Dr Carl Windsor, offers a critical, in-depth analysis of the escalating tactics and global implications in his latest report.

Read more...
African industries may overestimate cyber defences
Information Security
A significant perception gap exists in security awareness training: 68% of leaders believe training is tailored to roles, yet only a third of employees feel adequately trained. Many organisations only conduct annual or biannual generic training that may not effectively change behaviour.

Read more...
SMARTpod talks to Sophos and Phishield
SMART Security Solutions Technews Publishing Sophos Videos Information Security News & Events
SMARTpod recently spoke with Pieter Nel, Sales Director for SADC at Sophos, and Sarel Lamprecht, MD at Phishield, about ransomware and their new cyber insurance partnership.

Read more...
Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
Corporate and academic teams can register for Kaspersky contest
Kaspersky News & Events Information Security
Kaspersky has announced the registration opening for its new Kaspersky{CTF} (Capture the Flag) competition, inviting academic and corporate teams from around the globe to compete in a battle of skill, strategy and innovation.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.