Are We Secure? - Alchemy Systems

At Alchemy Systems, this is without doubt the question we get asked most by our clients – which is good, as it does demonstrate that security is upper most on their minds. Luckily for our clients, if they have followed our advice then our answer is always yes…although there is no such thing as 100% security (be weary of companies that promise you 100% security). Security breaches should be looked upon in terms of when rather than if, and then ensuring you have the best practices in place to mitigate any problems. The dark types as we like to call them are a clever bunch and constantly develop sophisticated ways to bypass even the most robust security.

What we always advocate is a layered approach to security and this simply meanshttps://www.alchemysys.co.uk/ employing a number of precautionary measures to tackle the problem. The central idea behind layered security is the belief that the most effective way to protect IT systems from a broad range of attacks is by employing an array of counteracting strategies. Layered security efforts attempt to address problems with different kinds of hacking or phishing, denial of service attacks and other cyber attacks, as well as worms, viruses, malware and other kinds of more passive or indirect system invasions.

Our security mantra at Alchemy Systems is Reduce, Remove, Secure. Some of the strategies we employ include:

 

1. Physical Security –  seems like an obvious one but it is amazing how many businesses still take this for granted! Physical security is an important layer in any layered approach. Guards, gates, locks and key cards all help keep people away from systems that they shouldn’t touch or alter.

 

2. Network Security – A key layer, good network security measures should include firewalls, intrusion detection and prevention systems (IDS/IPS), and general networking equipment such as switches and routers configured with their security features enabled. Establish trust domains for security access and smaller local area networks (LANs) to shape and manage network traffic.

 

3. Computer Hardening – Well known (and published) software vulnerabilities are the number one way that intruders gain access to automation systems. Examples of Computer Hardening include the use of:

  • ¨ Antivirus software – Best of breed only. The top AV vendors have invested greatly to ensure that they can respond to the latest attacks.
  • ¨ Application white-listing
  • ¨ Host intrusion-detection systems (HIDS) and other endpoint security solutions
  • ¨ Removal of unused applications, protocols and services
  • ¨ Closing unnecessary ports
  • ¨ Software and operating system patching – Ensure that systems are kept up to date

 

4. Access Controls – An important layer, access controls give organisation the ability to control, restrict, monitor, and protect resource availability, integrity and confidentiality. Some measures may include force username/password logins, password frequency change / combinations, disabling local admin permissions etc. The rule of least privilege, meaning people only have access to things at the level they need, ensures data loss is minimised.

 

5. The Human Layer – By far the most important precautionary layer because as we mentioned above there is no such thing as 100% security so constant user vigilance is key. The best antivirus software in the world will not prevent a user from clicking on a link within a malicious email

Absolute security may not be within reach however businesses effectively tackle the risks posed by these threats by following good practices.

Alchemy Systems can now provide the following to help you achieve the multi-layered approach that we advocate.

  • ¨ Cyber Essentials and Cyber Essentials + certification – We can assess your network and processes and put right anything that needs to be done, and then put you through the certification. This is a huge step towards being covered for the new GDPR legislation coming in May.
  • ¨ Phishing awareness and training – We can provide you with training combined with simulated email phishing attacks using a system that has over 14,000 customers and rising.
  • ¨ Penetration testing - Penetration is the practice of testing computer systems, networks, and web-applications to find vulnerabilities that attackers could exploit.
  • ¨ Vulnerability scanning - networks require regular scanning and remediation to detect and defend against threats from hackers who use holes in these systems to access and attack systems.
  • ¨ GDPR – We can provide you with a GDPR readiness audit that will leave you with a Data Protection Lawyer certified Gap Analysis that will show you areas that need to be improved.
  • ¨ Antivirus – We provide an extremely good antivirus product that also blocks un-certified programs from running. None of our clients using this product have ever had any data loss as a result of a virus or ransomware attack.

To coincide with the Government’s £1.9bn cyber-security initiative, Alchemy Systems are also offering Free IT Security Audits for any company in Devon, Cornwall or Somerset.

Contact Alchemy Systems today, and take the first step towards a better, more stable and cost efficient IT infrastructure.

 

 

Call us – 0330 043 0801

Email – Hello@alchemysys.co.uk

www.alchemysys.co.uk

 


Like   Back to Top   Seen 502 times   Liked 0 times
Subscribe to Updates And Join Over 1.2K Subscribers Today!

Subscribe to:
x

Subscribe to Updates

If you enjoyed this, why not subscribe to free email updates and join over 1275 subscribers today!

Subscribe to updates



Subscribe to:

Alternatively, you can subscribe via RSS RSS

‹ Return to

All email subscriptions must be confirmed to comply with GDPR.

I've already subscribed / don't show me this again