DID YOU RESTART IT?
SECURITY MONITORING ACTIVE
OPEN A TICKET
SECURITY EVENT / SEC-310

Please stop clicking things.

THREAT LEVEL HUMAN
Suspicious email delivered.
Employee opened attachment.
Employee entered password.
Employee approved unexpected MFA request.
Security controls blocked suspicious activity.
Account secured. Sessions revoked. Investigation started.
Employee asked whether they should click the email again.
INCIDENT SUMMARY
  • Suspicious sign-in detected
  • Account access restricted
  • Active sessions revoked
  • Credentials reset
  • Endpoint reviewed
  • User gently reminded about phishing
REVIEW SECURITY STACK →
PROTECTION STACK

Security should have layers.

007 CONTROLS / ACTIVE
ID CONTROL FUNCTION STATUS
SEC-101 Endpoint Protection DETECT + BLOCK ACTIVE
SEC-118 Multi-Factor Authentication VERIFY USERS ACTIVE
SEC-204 Email Security FILTER THREATS ACTIVE
SEC-226 Patch Management REDUCE EXPOSURE ACTIVE
SEC-310 Threat Monitoring WATCH EVENTS ACTIVE
SEC-404 Security Awareness TRAIN HUMANS ACTIVE
SEC-500 Incident Response Planning PREPARE ACTIVE
ACCOUNT AUDIT

Things we would rather not discover during an incident.

FICTIONAL ENVIRONMENT
AUD-017 PASSWORDS
CORRECTED
DISCOVERY

Same password used everywhere.

REMEDIATION

Implemented unique credentials, password-manager guidance, and multi-factor authentication.

OLD PASSWORD
COMPANYNAME2024!
SECRET STATUS
NOT VERY
AUD-031 ADMIN ACCESS
CORRECTED
DISCOVERY

Everyone was a local administrator.

REMEDIATION

Reduced unnecessary administrative privileges and established controlled elevation procedures.

USERS
41
PEOPLE WHO NEEDED ADMIN
3
AUD-052 OFFBOARDING
CORRECTED
DISCOVERY

Three former employees still had accounts.

REMEDIATION

Disabled stale access and created a documented account-offboarding process.

OLDEST ACCOUNT
19 MONTHS
EXPLANATION
"WE FORGOT"

All audit findings are fictional demonstration content. Please do not use COMPANYNAME2024! as inspiration.

SECURITY MODEL

Assume somebody will click it.

Security works better when one mistake does not immediately become an organization-wide event.

01 REDUCE

Remove unnecessary access, unsupported systems, weak configurations, stale accounts, and avoidable exposure before somebody takes advantage of them.

02 PROTECT

Use layered controls across identity, email, endpoints, devices, applications, networks, and data.

03 DETECT

Monitor suspicious activity so unusual behavior does not spend three weeks quietly becoming a much larger problem.

04 RESPOND

Know who acts, what gets isolated, which accounts are secured, how communication works, and where recovery begins when something actually happens.

USER AWARENESS / PHI-404

That email was not from the CEO.

CLUE CEO DOES NOT SELL GIFT CARDS
Message requested urgent secrecy.
Sender address did not match company domain.
Message requested twelve gift cards.
Employee considered complying because “it sounded urgent.”
Employee reported message instead.
RESULT
  • Message reported
  • Sender blocked
  • No credentials entered
  • No gift cards purchased
  • CEO still confused
REVIEW SUPPORT SERVICES →
SECURITY CONSULTATION AVAILABLE
NEXT ACTION

Make one click less exciting.

Layer the environment so a bad email, weak password, compromised account, or questionable decision does not automatically become everybody’s afternoon.

SECURITY REMINDER Unexpected MFA prompt? Do not approve it just to make it go away.