44
CYBER CRIME & CYBER SECURITY
TRENDS IN AFRICA
BEST PRACTICE GUIDELINES FOR BUSINESSES
Ensure All Devices Allowed on Company
Networks Have Adequate Security Protections
If a bring-your-own-device (BYOD) policy is in place, ensure a
minimal security profile is established for any devices that are
allowed access to the network.
Implement a Removable Media Policy
Where practical, restrict unauthorized devices, such as external
portable hard-drives and other removable media. Such devices
can both introduce malware and facilitate intellectual property
breaches, whether intentional or unintentional. If external
media devices are permitted, automatically scan them for
viruses upon connection to the network and use a DLP solution
to monitor and restrict copying confidential data to unencrypted external storage devices.
Be Aggressive in Updating and Patching
Update, patch, and migrate from outdated and insecure
browsers, applications, and browser plugins. This also applies
to operating systems, not just across computers, but mobile,
ICS, and IoT devices as well. Keep virus and intrusion prevention definitions at the latest available versions using vendors’
automatic updates.
Most software vendors work diligently to patch exploited
software vulnerabilities; however, such patches can only be
effective if adopted in the field. Wherever possible, automate
patch deployments to maintain protection against vulnerabilities across the organization.
Enforce an Effective Password Policy
Ensure passwords are strong. Passwords should be at least 8-10
characters long and include a mixture of letters and numbers.
Encourage users to avoid re-using the same passwords on
multiple websites and sharing passwords with others should be
forbidden. Passwords should be changed regularly, at least every
90 days.
Restrict Email Attachments
Configure mail servers to block or remove email that contains
file attachments that are commonly used to spread viruses, such
as .VBS, .BAT, .EXE, .PIF, and .SCR files. Enterprises should investigate policies for .PDFs that are allowed to be included as email
attachments. Ensure that mail servers are adequately protected
by security software and that email is thoroughly scanned.
Ensure Infection and Incident Response
Procedures Are in Place
TT Keep
your security vendor contact information handy; know
who you will call, and what steps you will take if you have
one or more infected systems.
TT Ensure
that a backup-and-restore solution is in place in
order to restore lost or compromised data in the event of
successful attack or catastrophic data loss.
TT Make
use of post-infection detection capabilities from
web gateway, endpoint security solutions and firewalls to
identify infected systems.
TT Isolate
infected computers to prevent the risk of further
infection within the organization, and restore using trusted
backup media.
TT If
network services are exploited by malicious code or some
other threat, disable or block access to those services until a
patch is applied.
Educate Employees
As ever, basic common sense and the introduction of good
security habits can go a long way to keeping sites and servers
safe this year.
TT Do
not open attachments unless they are expected and
come from a known and trusted source, and do not execute
software that is downloaded from the Internet (if such
actions are permitted) unless from a trusted source or the
download has been scanned for malware.
Ensure Regular Backups Are Available
TT Be
cautious when clicking on URLs in emails or social media
programs, even when coming from trusted sources and
friends.
Create and maintain regular backups of critical systems, as
well as endpoints. In the event of a security or data emergency,
backups should be easily accessible to minimize downtime of
services and employee productivity.
TT Deploy
web browser URL reputation plugin solutions that
display the reputation of websites from searches.
TT Restrict
software to corporate-approved applications, if
possible, and avoid downloading software from file sharing
sites. Only download packages directly from trusted
vendors’ websites.