1. Know the organization
Modern companies change at the speed of light. Either to increase responsiveness to customer needs, mitigate business risks, or just improve competitiveness. Keeping track of this changes is a herculean task.
The first step is about knowing the organization and its assets: technologies, devices, networks, services, applications running on the devices, etc.
The sum of these assets defines the attack surface. Vulnerabilities on this attack surface expose the company to risk.
Comprehensive awareness and control over these assets are key to mitigate the resulting security risk.
note: the definition of the organization could grow to include what others have to say about the organization and its products, including items like brand social media, deep web bragging, devices used to access company resources and services, etc.
2. Educate others
Employee negligence is the leading cause of data breaches and ransomware. Every day employees make “almost insignificant” decisions that could jeopardize the business. The higher the hierarchy level the higher the potential impact. Make sure everyone’s behavior is security conscious.
Let us take a look at some hypothetical questions that could have been posed by an employee:
- John: “I got an email from a friend with a password protected file named “pay_confidential.xls”. Can I open it? I have the password in the message.” — No. A lot of ransomware has been caught via macro execution. People go to the trouble of clicking twice OK to proceed on warning pop-ups, just to satisfy their curiosity.
- Susan: I am traveling, my cell phone is dead and today is the deadline to send this quotation. Can I use the hotel free access PC to do it? — No. Free access computers are known to be a malware nursery.
- Peter: My marriage is in troubles. To avoid having my wife find out, can I use the corporate email to register myself on a dating site? — No. This risky behavior provides leverage to extort corporate IP.
Many other everyday activities could put your organization at risk. Training and role playing are key in bringing awareness to what constitutes careless security behavior.
Partners and vendors should also be managed and audited. Their vulnerabilities and security awareness level are also your organization vulnerabilities and security concerns. Education here comes from contract obligations and auditing. There are plenty of third-party security risk assessment providers to work with.
Ultimately the organization is only as strong as its weakest link.
3. Know the threats
Threats are evolving at a fast pace and a vast ecosystem of criminals and adversaries are willing to prey on your business value and intellectual property. Even organizations that know themselves and educate their employees get attacked successfully and end up tracking indicators of compromise (IoCs).
The end goal is detecting and stopping attacks before they happen (indicators of attack, IoAs). In order to do this one needs threat intelligence, knowledge about the threat actors and the threat activities that constitute the threat flow that will ultimately lead to the attack.
Threat intelligence needs to be:
- actionable, not just data or information but actual detailed intelligence with identification, classification, mitigation strategy, severity level, etc;
- real-time or near real-time to address zero-day exploits and short term evasive attacks.
Threat intelligence is a mandatory element of any comprehensive security program.

This is just the beginning of a long and demanding journey. Continuously monitoring and execution is key. The organization will keep changing, training will not last for ever and for sure the level of sophistication of the attacks will increase as well as intensify.
