Skip to content
Aynitech Group

Cybersecurity 1.0: What if I am the only one doing it?

In cybersecurity it is normal to face the challenge of doing a lot with very little. How could one person — the one responsible for information security — handle the challenges of the complex cybersecurity landscape any organisation faces? What happens if you are the only internal resource assigned to a security role and you have been tasked with protecting an organisation?

In this article we will focus on what 'one person' can do as a security function, something that happens very often, above all in small and medium-sized businesses.

What are the protection priorities?

As with any project, and regardless of the resources available, identifying the priorities is the key. If you do not know what you are protecting, no effort spent building a programme will have a meaningful effect.

Whether it is data, customer records or intellectual property, you need a clear idea of what the rest of the programme rests on; that does not mean any other information stops being worth protecting. The first step is to prioritise sensibly, and from there we can move forward assuming that the person responsible for security has the right information in hand.

Where do you start?

One thing we definitely should not do is reinvent the wheel. With everything the security industry has spent over the last few decades, we can take advantage of the by-product by looking at the large number of frameworks and lessons learned that are free or low cost. For example: the Center for Internet Security's 20 Critical Security Controls.

That list, which is updated continuously, is a free resource providing researched methods and common sense for improving security. It is important to bear in mind that the controls are not a checklist. On the contrary, they are a framework that lets security professionals assess their current — or future — programme components against a common set of guidelines, making sure they focus on the highest-priority measures to achieve the greatest positive impact on the organisation's posture.

The basic controls

1. Know your inventory

Creating and maintaining a hardware and software inventory is not complicated, but if you do not know which resources can hold or process the organisation's critical information it will be hard to have a positive impact. Whether it is a spreadsheet or the output of some kind of scanning toolkit, get a solid list of what is within your reach before going any further.

2. Limit administrator access

Controlling administrator access is key. While it is often hard to claw back administrative permissions that were granted previously, it is worth doing. If your users have administrative rights, you cannot impose a realistic amount of control on your systems; it is that simple. Nothing else we implement will matter if a user can override it to 'play a new Facebook game' or install the latest free game downloaded from the suspicious corners of the internet. The principle of least privilege is a central approach, because it works.

3. Secure configuration

Depending on the scope of the organisation's IT team, this can be a significant task. It is often best achieved by first aligning server configurations, then moving to the network infrastructure and afterwards to the workstations. Even making sure every workstation is set to apply locally approved operating-system updates automatically — and putting a plan in place so servers get the same level of attention that mission requirements allow — is a big step in the right direction.

4. Collect and store logs

All of the 'maintenance, monitoring and analysis of logs' goes a little beyond what one team can handle. For this, however, I would insist that logs are collected in a central location and retained for the maximum duration allowed. That will make sure incident response, troubleshooting and investigative operations in general can be carried out against a trustworthy data set. It is not reasonable to expect the person responsible for security — or even a larger group — to review every log entry regularly. If, at some point in the future, there is a budget and technical opportunity to apply some form of automated analysis such as a SIEM, then that will be a big win in this resource-free scenario.

5. Vulnerability management

Continuous vulnerability management (CVM) is one of the lower-priority controls in the basic control group. The main reason is that it can require a more complicated set-up than the rest of the controls in this group, and the results can be somewhat overwhelming.

Going beyond the basics

Within the 20 controls, things get a little murkier once you move past the basic group. This is not a piece about the controls themselves, but the value the basic control group provides is too significant not to explore in detail. As for the other 16 controls, remember that some of them will support the protection of the organisation's critical data and resources — to varying degrees — and others will not. The idea is to prioritise the ones that will have the greatest positive impact protecting the resources handling the organisation's most valued data, and perhaps leave the rest for periodic reconsideration.

With the genuine fundamentals set out above in place, you would have a fairly solid base on which any number of additional capabilities can be added.

Network security

From a network perspective there are two main recommendations. First, collect NetFlow from the routing infrastructure. This session data does not include the content of network communications, but it is a summary of every communication made in the environment. Cloud-based providers also offer this in various forms. It benefits our 'one person' team by letting them quickly query months of traffic summaries on the network. Collecting network metadata is an excellent way to get fast answers to questions such as 'did any of our hosts talk to this newly identified bad IP recently?' or 'which hosts transmitted a large amount of data out of the environment?'.

From a network perspective, another important element is Network Security Monitoring (NSM) platforms. NSM provides a high-level accounting of several important network artefacts. That can include DNS queries and responses, URLs or hostnames of websites visited, and more. Zeek NSM — previously known as BRO — is the best option in the open-source field. It provides log files with artefacts from dozens of protocols, and there are numerous tools that can analyse, visualise and operationalise their content. Zeek is also integrated into many other open-source platforms such as Security Onion, which adds a great deal of extra functionality. While a full Security Onion deployment may be beyond the scope and the needs of our 'one person' team, it could be a good item on the roadmap for when more members join the team, or when the organisation's security apparatus is running smoothly and new projects can be considered.

Outsourcing

One tangent that was not mentioned directly is when to take these functions on internally and when to find an external partner to help. There is no easy recipe for this, but a plan that draws on the information priorities established at the beginning of the process is generally recommended. Identify which functions will have the most positive impact on the organisation's most critical information. From the top of that list, identify the ones that can be handled internally and the ones that cannot. If implementing secure configurations across the company is not within your team's technical scope, the task cannot simply be left undone — you need help, because this is one of the basic fundamentals.

Conclusion

Running a one-person security team is a daunting proposition, but not an impossible one. By doing a little strategic planning, focusing on the basics and developing capabilities where they will have the greatest impact, even a solo security 'team' can put together a strong programme that addresses the organisation's most important requirements.

Looking for a partner that can build, power, and protect what comes next?

Tell us what you're building—product, project, or team—and we'll propose the fastest path to outcomes.