
October 24, 2019 • Garrett Garitano
IT security events are the stuff of nightmares for security professionals. All your finely tuned procedures and systems fail. Then you have to scramble to define the problem, hire outside consultants and answer difficult questions from customers and managers. The reputational damage from IT security events includes fines from governments, lawsuits and lost customer trust. […]
IT security events are the stuff of nightmares for security professionals. All your finely tuned procedures and systems fail. Then you have to scramble to define the problem, hire outside consultants and answer difficult questions from customers and managers. The reputational damage from IT security events includes fines from governments, lawsuits and lost customer trust. You need to take a proactive approach to avoid IT security events. Use this multi-phase strategy to shore up your defenses with better passwords and IT security habits.
Phase 1: Conduct an IT Security Assessment
Merely ordering the IT security department to deliver better security is not helpful. There are a thousand ways to improve security. Where should they focus? Which improvements will deliver the best return? Fortunately, you do not have to guess. You can get the answer by starting with an assessment project.
To find the security problems in your organization, we recommend internal analysis and external analysis. First, start with your organization’s internal situation, since that is the easiest to assess.
Assessing your current IT security
Now that you have a good understanding of your IT security situation, let’s change focus on the external world. We are going to look for threats, technologies and industry trends that may impact our organization.
At the end of this analysis project, review your observations. You will probably find a large number of areas to work on. That is a natural outcome since IT security challenges are continually evolving. However, you need to make choices about where to focus your energies to get the highest return on your efforts.
For each potential security improvement, ask yourself three questions:
You will probably find password management is a critical area on which to focus. Let’s carry that example forward to the next step.
Phase 2: Implement a High-Value IT Security Improvement Project
Based on your analysis in Phase 1, you decide to focus your IT security event prevention efforts on one improvement: better passwords. To implement that change, you need to engage employees and make passwords easy for them. Let’s address both points in turn.
Engage Employees To Improve Password Behavior
IT security starts with improving awareness. When employees understand the critical role robust passwords play in the organization, they will be more likely to follow your requirements.
Empower Employees By Offering Better Password Tools
Simply asking employees to “do better” with passwords will only carry you so far. You also need to recognize that most people do not think about their passwords that much. Therefore, you need to make password management easy. What if you could offer 24/7 reliable password administration? You can make that happen this month by implementing Apollo, a specialized IT security chatbot.
Take Your First Step To Better Passwords Today
Delivering better passwords is a crucial technique to prevent IT security events. By using identity and access management tools, you can enforce stronger passwords throughout the organization. By going through the analysis steps we’ve laid out, you can also find other security gaps to address. Just remember to prioritize your findings and solve one gap at a time. By continuously improving IT security, you will make security events much less likely.