10 Major Security Holes in Almost Every Law Firm
The security holes in most law firms, make their organization a hackers dream. If cyber criminals can take this security holes and use them as a way to get in- they have a party on their hands. We know that is something you want to avoid.
We've listed 10 major security holes we see in almost every law firm. Read them and identify how many of them apply to your firm. If you have even one of these security holes, it is time to take action.
- No defined security permissions on file shares.
- Users have local admin rights without separation of privileged accounts.
- No two-factor authentication (2FA) for M365 and VPN.
- No conditional access on M365.
- No email logging and security event management.
- No security event management on the VPN and firewall.
- No end-point detection system.
- No ongoing security awareness testing and training.
- Lack of Internet Content Control and DNS Level Filtering.
- Lack of policies and procedure, and the requisite testing of those P&P is an issue.
Just as much as you don't want cyber criminals throwing a party at your expense, we don't want them throwing a party at your expense either.
The goal is to think/assume incident/breach. Don't be naive in assuming you can stop it – instead assume it will happen, and put all of the pieces in place to: mitigate, respond and recover.
Read the Full Blog!
|