Skip to main content
SolarWinds MSP
  • Login
  • Support
  • Partnerships
    • Partnerships Overview
    • Solution Provider Program
    • Technology Alliance Program
    • Distributor Program
SolarWinds MSP
  • Products
    • SolarWinds N-central Automate what you need. Tackle complex networks. Try this remote monitoring and management solution built to help maximize efficiency and scale.
    • SolarWinds RMM Start fast. Grow at your own pace. Try this powerful but simple remote monitoring and management solution.
    • SolarWinds EDR Defend against ransomware, zero-day attacks, and evolving online threats with Endpoint Detection and Response
    • SolarWinds Backup Manage data protection for servers, workstations applications, documents and Microsoft 365 from one SaaS dashboard.
    • Mail Protection & Archiving Protect users from email threats and downtime.
    • Password Management Easily adopt and demonstrate best practice password and documentation management workflows.
      • Passportal Demo
    • PSA & Ticketing Manage ticketing, reporting, and billing to increase helpdesk efficiency.
    • Remote Support Help support customers and their devices with remote support tools designed to be fast and powerful.
  • Solutions

    I'm looking for...

    • Security Solutions
    • Monitoring Solutions
    • Efficiency Solutions
  • Resources
    • Blog
    • Webcasts & Events
    • Ask the N-central Experts
    • Daily Live Demos
    • RMM Foundations Training
    • Upcoming Events
    • Upcoming Webcasts
    • Resource Center
    • COVID-19 Resources
    • Resource Library
      • Case Studies
      • Product Information
      • eBooks
      • White Papers
      • Infographics
    • SolarWinds MSP Free Tools
    • GDPR Resource Center
    • Security Resource Center
    • MSP Institute Webinar Series
    • MSP Advice Project
  • About
    • Contact
    • Customer Success
    • Worldwide sales and support
    • Careers
    • Awards and Recognition
    • Get A Quote
    • Newsroom
      • Press Releases
      • In The News
      • Media Contacts
      • COVID-19 Response
    • Leadership Team
    • Legal
      • Cookie Policy
      • Privacy Notice
      • Software Services Agreement
      • Terms of Use
      • Backup Fair Use Policy
    • Security
      • SolarWinds Security Statement
      • Vendor Data Protection Requirements
    • Support
  • IT Departments
  • Contact Sales
    • Get A Quote
    • General Inquiry
  • TRY NOW
    • SolarWinds RMM
    • SolarWinds Backup
    • MSP Manager
    • SolarWinds Passportal
    • SolarWinds N-central
    • SolarWinds Mail Assure
    • SolarWinds Risk Intelligence
    • SolarWinds Take Control
  • Request a Quote
  • Try Now
    • SolarWinds RMM
    • SolarWinds N-central
    • SolarWinds Backup
    • MSP Manager
    • SolarWinds Mail Assure
    • SolarWinds Passportal
    • SolarWinds Risk Intelligence
    • SolarWinds Take Control
Request quote
Filter Blogs
  • Filter by:
  • MSP Business
    • Automation
    • Backup & Disaster Recovery
    • Security-series
    • Best Practices
    • Business
    • Business Growth
    • Business Risk
    • Cloud Computing
    • Customer Service
    • Cybersecurity
    • Cybersecurity Awareness Month
    • Data
    • GDPR
    • Internet of Things
    • IT Support
    • ITSM
    • LOGICcards
    • Machine Learning
    • Mail
    • Managed Services
    • Marketing
    • Mobile
    • Networking
    • Operations
    • Podcast
    • Product
    • PSA
    • Remote Management
    • Research & Trends
    • Risk Intelligence
    • Security
    • Security Vlog
    • Service Desk
    • Services & Support
    • The Head Nerds
    • Tips & Advice
    • Training
Home Blog MSP Business Security NCSAM: Are You Prepared for Today’s Threats? 
Security

NCSAM: Are You Prepared for Today’s Threats? 

By SolarWinds MSP
6 October, 2020

Last week, we gave an overview of what we plan to cover as part of National Cybersecurity Awareness Month (NCSAM). Today, we’ll dive in on the first step of the process: prepare and prevent.

Staying secure requires you to continuously prepare environments for potential threats, deploying new preventive technologies and controls to keep threats out. Today, we’ll talk about this process. 

Preparing for the current threat environment

It’s not an overstatement to say the way we work has changed dramatically this year. While remote work has long been [ital]possible[/ital] for businesses, now, it has increasingly become the norm. If the industry has been sounding the drumbeat on the death of the perimeter for years, this should turn the volume of that drumbeat to 11. Many of the old fundamentals still apply, but some technologies and controls need updating. 

  • Vulnerability assessments: Part of the planning phase involves performing vulnerability assessments for your customers. Try running a vulnerability scan against the networks for which you’re responsible. Even a basic scanner can often help you root out things you wouldn’t normally find, like default passwords on devices or unpatched software. 
  • Identity and access management: When working with a new client, make sure users can only access the data and systems they need for their jobs. Once you have them up and running, try to audit access and permissions on a regular basis. Permissions can grow organically out of control if you don’t check in from time to time. Implementing this least-privilege principle limits the amount of data someone could steal, encrypt, or delete if they compromise an account (or if an insider attacks). 
  • Password security and multifactor authentication (MFA): Related to the previous point, set strong password rules and processes to prevent account takeovers. The easiest way to do this involves offering a password manager as a service to your customers, allowing users to automatically generate strong, unique passwords for the services they use. Even if you don’t, try to get users to change their passwords for mission critical services at least once a quarter. Finally, for higher risk accounts or data, introduce multifactor authentication (MFA) when accessing important resources, particularly when working offsite. 
  • Application gateways: With so many people working offsite, you’ll want to keep them from accessing sensitive corporate resources from a potentially insecure connection. Traditionally, VPNs have been the primary way of dealing with this. However, as organizations have had to support more workers outside the office, the industry has seen a number of vulnerabilities in VPNs crop up (and criminals have taken notice). Instead, you may want to try using an application gateway. Application gateways give you more control over who can access data and systems on the network. VPNs often grant access to a large portion of the network; an application gateway allows you to more finely tune access on a need-to-use basis, helping you better enforce a zero trust framework. 
  • Enlist the end users: Now that most employees work from home, you have less visibility into their security. They connect to home networks that may not be secure, and which often have dozens of devices connected to a single router, each representing a foot in the door. Security training is a must under any conditions, but it’s particularly important now. Make sure to get them to use caution when receiving emails (especially since we saw an uptick in email scams when the pandemic first started). Also, remind customers to set strong passwords on their home routers and on any devices connected to the network—including personal laptops and any IoT devices. It’s worth reminding them, too, to double check both their devices’ passwords [ital]and[/ital] any administrator pages for those devices. People rarely think to double check their home router’s administrator page, often leaving a default password and giving criminals an easy way onto their home networks. 
  • Pay attention to physical security: While many employees still work from home, some offices have opened and many workforces will have to contemplate a return-to-office plan. So don’t neglect physical security for your customers. You may not have a ton of control here, but it’s worth making sure you have an inventory of all company-issued devices, advise companies to be careful around keycard access, and make sure employees know to not let non employees into the building unsupervised. 
  • Patch regularly: Finally, make sure you’re patching on a regular basis. Set a schedule and try to patch critical systems often, especially for urgent security updates. While you likely already do this, you may need to expand the scope of the systems you regularly patch. Remote work has expanded what systems should be considered “mission critical”; make sure your patch policies cover the full breadth of important systems. 

Staying prepared

Today’s post focused on laying the groundwork for a secure environment. While this certainly helps when you take on a new customer at the moment, it’s worth double checking on many of these tips for your existing customers. If there’s an area you can improve, there’s no better time to do it than during National Cybersecurity Awareness Month. 

 

Next week, we’ll talk about the next phase—threat detection. But if you don’t want to wait, you can get a full overview of what you’ll need at each step today by downloading our free Cybersecurity Blueprint.

You might also like...
Automation

What the Head Nerds Were Up to in 2020

Security

January 2021 Patch Tuesday: One Actively Exploited Vulnerability and a Few Likely to Be

Security

December 2020 Patch Tuesday—A quiet(er) finish to a busy year in vulnerabilities

Security

Documentation Management API and Why It’s Important for the MSP Business

Security

What Is FIPS-140-2 Standard and When Is It Required?

Security

Malware-as-a-Service: A Crucial Reason Why Security Has Grown More Complex

Want to stay up to date?

Get the latest MSP tips, tricks, and ideas sent to your inbox each week.

Loading form....

If the form does not load in a few seconds, it is probably because your browser is using Tracking Protection. This is either an Ad Blocker plug-in or your browser is in private mode. Please allow tracking on this page to request a subscription.

Note: Firefox users may see a shield icon to the left of the URL in the address bar. Click on this to disable tracking protection for this session/site

Recent Posts
  • What the Head Nerds Were Up to in 2020
  • RMM and PSA Tools: How to Make the Most of Both
  • How to Empower an IT Help Desk Team for Success
  • Six Tips That Will Make Managing Your MSP Company Easier
  • January 2021 Patch Tuesday: One Actively Exploited Vulnerability and a Few Likely to Be
Categories:
  • Security (230)
  • Tips & Advice (122)
  • Best Practices (94)
  • Managed Services (86)
  • Backup & Disaster Recovery (83)
  • The Head Nerds (75)
  • Business Growth (75)
  • IT Support (42)
  • Business (39)
  • Automation (37)
  • Cybersecurity (37)
  • Operations (34)
  • Mail (33)
  • Remote Management (28)
  • ITSM (25)
  • Cloud Computing (21)
  • Networking (21)
  • Data (21)
  • Marketing (14)
  • Product (11)
  • PSA (11)
  • Service Desk (5)
  • Services & Support (5)
  • Mobile (4)
  • Risk Intelligence (4)
  • Internet of Things (3)
  • Customer Service (3)
  • Research & Trends (2)
  • Training (2)
  • GDPR (2)
  • Business Risk (1)
  • LOGICcards (1)
Show moreless
SolarWinds MSP

Products
  • SolarWinds RMM
  • SolarWinds N-central
  • SolarWinds Backup
  • SolarWinds EDR
  • SolarWinds MSP Manager
  • SolarWinds Mail Assure
  • SolarWinds Risk Intelligence
  • SolarWinds Take Control
  • SolarWinds Passportal
  • All Products Use Cases
Solutions
  • Security Solutions
  • Monitoring Solutions
  • Efficiency Solutions
  • Identify which RMM solution is right for me
  • Drive Efficiency with Automation
  • Manage my MSP Business More Efficiently
  • Manage my IT Department More Efficiently
  • Layered Security
  • Cross-Platform Support
  • Data-Driven Insights
About
  • About Us
  • Careers
  • Newsroom
  • Leadership Team
  • Upcoming Events
  • Subscription Preferences
  • SolarWinds
  • SolarWinds Trust Center
  • COVID-19 Response
Support
  • SolarWinds RMM
  • Solarwinds N-central
  • SolarWinds Backup
  • SolarWinds Mail Assure
  • SolarWinds Take Control
  • SolarWinds MSP Manager
  • Solarwinds Risk Intelligence
  • Solarwinds Threat Monitor
  • SolarWinds Passportal
  • SolarWinds Take Control Downloads
  • Backup & Recovery Downloads
  • Service Status

Footer 2

  • Legal Documents
  • Privacy
  • California Privacy Rights
  • Security Information
  • Sitemap

© SolarWinds MSP Canada ULC and SolarWinds MSP UK Ltd.
All Rights Reserved.