How to strengthen data security for 365

Issue 5 2023 Information Security, Infrastructure

Amid an alarming rise in ransomware attempts and cloud data security breaches globally, Obsidian Systems, a supplier of open-source software solutions, advises South African businesses to reassess their data protection strategies for Microsoft Office 365.

Despite Microsoft's robust and secure infrastructure, businesses must not overlook their critical role in the shared responsibility model. Many companies, large and small, mistakenly assume their data is fully protected by the cloud service provider. However, this misconception exposes them to considerable risks, particularly concerning the data residing in production and sandbox environments.

"Data protection is an intrinsic responsibility of every business," says Muggie van Staden, Managing Director of Obsidian Systems. "This includes data entering, living in, and leaving the system. It's vital to maintain proactive, long-term protection for all our IT environments."

Even beyond malicious users, there are many scenarios that can result in data loss. For example, accidental deletions, ransomware attacks, and delays in data restoration can all have severe implications on organisational operations. Regulatory fines, encrypted and unusable data, or potential business continuity disruptions are some scenarios that businesses may face.

To combat these risks, Obsidian advises enterprises to focus on four key Microsoft 365 data protection needs: data isolation, extended retention, flexible restoration, and service-level agreement (SLA) compliance:

• Data isolation: It is crucial to maintain separate backup copies outside of source environments. This best practice mitigates risks associated with data corruption and ransomware attacks.

• Extended retention: Long-term data retention without native limitations can safeguard against accidental deletions and ensure recoverability, even when data losses are only discovered months later.

• Flexible restoration: Quick and full-fidelity data recovery options can keep business disruptions to a minimum. Firms should not underestimate the potential time required to fully restore all data and site structures.

• SLA compliance: Businesses need dedicated controls to fulfil Recovery Point Objective (RPO) and Recovery Time Objective (RTO) requirements. Meeting these standards is not just about compliance; it's about ensuring business continuity.

“I can urge every company to leverage multi-layered security, which encompasses measures such as virtual airgaps of backup data, AES-256 bit encryption, early threat detection capabilities, and zero-trust access controls,” says van Staden.

In today's digital landscape, South African businesses cannot afford to be complacent. Data protection is a vital component of risk management and should be a top priority in every enterprise's strategic planning.

For more information, contact Obsidian Systems, +27 11 795 0200, www.obsidian.co.za




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

The TCO of cloud surveillance
DeepAlert Verifier Technews Publishing Surveillance Infrastructure
SMART Security Solutions asked two successful, home-grown cloud surveillance operators for their take on the benefits of cloud surveillance to the local market. Does cloud do everything, or are there areas where onsite solutions are preferable?

Read more...
A strong cybersecurity foundation
Milestone Systems Information Security
The data collected by cameras, connected sensors, and video management software can make a VMS an attractive target for malicious actors; therefore, being aware of the risks of an insecure video surveillance system and how to mitigate these are critical skills.

Read more...
Surveillance and cybersecurity
Cathexis Technologies Information Security
Whether your business runs a security system with a handful of cameras or it is an enterprise company with thousands of cameras monitoring sites across a multinational organisation, you must pay attention to cybersecurity.

Read more...
Cybersecurity and AI
AI & Data Analytics Information Security
Cybersecurity is one of the primary reasons that detecting the commonalities and threats of what is otherwise completely unknown is possible with tools such as SIEM and endpoint protection platforms.

Read more...
What are MFA fatigue attacks, and how can they be prevented?
Information Security
Multifactor authentication is a security measure that requires users to provide a second form of verification before they can log into a corporate network. It has long been considered essential for keeping fraudsters out. However, cybercriminals have been discovering clever ways to bypass it.

Read more...
SA's cybersecurity risks to watch
Information Security
The persistent myth is that cybercrime only targets the biggest companies and economies, but cybercriminals are not bound by geography, and rapidly digitising economies lure them in large numbers.

Read more...
Cyber insurance a key component in cyber defence strategies
Information Security
[Sponsored] Cyber insurance has become a key part of South African organisations’ risk reduction strategies, driven by the need for additional financial protection and contingency plans in the event of a cyber incident.

Read more...
Deception technology crucial to unmasking data theft
Information Security Security Services & Risk Management
The ‘silent theft’ of data is an increasingly prevalent cyber threat to businesses, driving the ongoing leakage of personal information in the public domain through undetected attacks that cannot even be policed by data privacy legislation.

Read more...
Data security and privacy in global mobility
Security Services & Risk Management Information Security
Data security and privacy in today’s interconnected world is of paramount importance. In the realm of global mobility, where individuals and organisations traverse borders for various reasons, safeguarding sensitive information becomes an even more critical imperative.

Read more...
Sophos celebrates partners and cybersecurity innovation at annual conference
News & Events Information Security
[Sponsored] Sun City hosted Sophos' annual partner event this year, which took place from 12 to 14 March. Sophos’ South African cybersecurity distributors and resellers gathered for an engaging two-day conference.

Read more...