01
Start with visibility and boundaries
Maintain an inventory of devices, network services, administrators, remote-access paths, cloud dependencies, and sensitive data flows. Security policies are difficult to enforce when ownership and normal behavior are unknown.
- Remove unknown and unsupported devices
- Use unique administrative accounts
- Document inbound and outbound dependencies
02
Use defense in depth
A firewall is one layer, not the entire program. Combine least privilege, MFA, secure configuration, segmentation, endpoint controls, DNS and email protections, logging, vulnerability management, backups, and user training.
| Layer | Purpose | Example evidence |
|---|---|---|
| Identity | Limit who can connect | MFA and access reviews |
| Segmentation | Limit lateral movement | Documented VLAN and firewall rules |
| Monitoring | Detect abnormal behavior | Central logs and alerts |
| Recovery | Restore operations | Tested offline backups |
03
Connect security to continuity
Security controls should preserve essential operations during an incident. Define decision owners, isolation steps, communication methods, evidence handling, restoration priorities, and outside contacts before an emergency.
- Test backup restoration
- Maintain out-of-band contact methods
- Review provider DDoS and escalation options