Most breaches I get called in to do not start with anything advanced. They start with a reused password and an alert nobody read.
The order below is the one I work in at a business with between five and fifty employees. It takes an afternoon.
Two-factor on everything, management included
Exceptions are the most common reason two-factor fails. I have seen three businesses where everyone had it except the managing director, because it was inconvenient. In two of them, that was the account that got used.
Use an app, not SMS. SMS beats nothing, but it can be taken over by someone who calls your mobile operator and claims to be you.
The order, if you only have an hour
- Turn on two-factor for everyone, including yourself.
- Remove exceptions that were made “temporarily”.
- Turn off legacy sign-in, which bypasses two-factor.
- Set an alert for sign-ins from a new country, to one named person.
None of this makes you invulnerable. It makes you a worse target than almost everyone else your size, and in practice that is what decides the outcome.
About this article
Noen har bruk for det du vet.
Det trenger ikke å være en stor sak. En forklaring, en erfaring, en advarsel du selv skulle hatt. Det er nok til å begynne.