By Alexander Craddock and NateBraun
NetDirector
USFN Associate Member
With the latest generation of phishing and social
engineering assisted by the newest AI technologies, information security is
more important than ever for small businesses. According to the Acronis
Cyberthreats Report, H2 2023, AI-enhanced phishing attacks affected
over 90% of organizations surveyed and resulted in a 222% increase in email
attacks in 2023 when compared to the same time period in 2022.
This risk is especially great for any business dealing in
PII (Personally Identifiable Information), financial data, or legal – for the
default servicing industry, this is the triple threat that makes security a
high priority across the organization. One of the best strategies to ensure
data security is data segregation.
The goal is to ensure that only the individuals who are
authorized to view certain data sets have access to them – and that while that
access is secure, it remains easy and convenient for the team members who need
the data to do their job.
It’s easiest to envision a complete data segregation
strategy by visualizing the way a layered, segmented security protocol works on
physical documents. The familiar layers of security are present for most hard
copies of documents in the physical world. An example:
·
a property gateway (potentially with a security
guard) exists, verifying access to the property.
·
the building entrance uses a badge reader or
biometric scan, and a secondary badge entrance would provide further segregated
access to a particular wing.
·
within the wing, even fewer key cards would
grant access to certain hallways or individual rooms.
·
a certain key is required to unlock a particular
cabinet full of sensitive files.
In this example, there are up to six layers of security
present between the “outside world” and the sensitive information, each of
which limits access in steps. Could an outside unknown malicious actor get
access to a document in the file cabinet (without the use of “Hollywood
writers”)? The short answer is no. In this scenario, the only people who could
do harm are a very limited number of internal employees, restricted by the many
layers of access and significantly narrowing down potential threats.
What if one of those layers is compromised, like the lock on
the cabinet? Even with one or two less layers of security, the documents
themselves are still secure from outside access. Risk probability decreases
exponentially after each layer of security in place.
An equivalent layered segregation process is the best
approach to ensure a secure environment for digital data. For example:
·
A VPN gateway functions as the property access,
with as many as eight factors of verification in this “frontline” defense: a
username and password, with multifactor authentication (MFA) tokens matching
the PC/Device, IP Address/location, a one-time PIN from Authenticator, mobile
device registration for authenticating devices, and FaceID on the authenticated
device.
·
Firewall/security rules work as the building key
card: after VPN connection is established, the VPN client with an Endpoint
Security Profile can determine what access is allowed based on the user’s
account and group membership; denying or granting specific IP/port access.
·
Application authentication represents key card
access to specific rooms and hallways, and is separately managed in a similar
way to the VPN (factors include Internal WebUIs, File Shares, RDP, SSH, and a
different username/password requiring a new MFA)
·
Finally, the file cabinet lock is represented by
specific application access. After authentication in the previous steps, what
data is available to that authenticated user in the specific application? This
is the final step to ensuring the right data is readily available to users who
need it, and can also determine read/write permissions, modification
availability, etc.
Final questions to consider around data segregation include:
Q: How many layers does our company need?
A: One layer, even with MFA, is no longer enough. Companies
should have at minimum two layers each with their own multifactor
authentication before classified/protected information can be reached.
Q: Which technologies are most important to secure?
A: Endpoint security for physical devices (laptops, phones,
etc.) through which employees can access classified information is most
important. Authentication and file transfers for Unified Messaging technologies
(email, IM, phone, online conference, voicemail) is second most important. Web
based interfaces, applications, and connections would be third on the list.
These are the big three that absolutely need their own layers of
security, including MFA.
Copyright © 2024 USFN
USFNews - Feb. 21