https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Tech Services Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
    • Diversity, Equity & Inclusion
  • MSP 501
    • Back
    • MSP 501 Information Center
    • 2021 MSP 501 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2021 MSP 501
    • Circle of Excellence
    • DE&I 101
    • Top Gun 51
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Tech Services Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
    • Diversity, Equity & Inclusion
  • MSP 501
    • Back
    • MSP 501 Information Center
    • 2021 MSP 501 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2021 MSP 501
    • Circle of Excellence
    • DE&I 101
    • Top Gun 51
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Best Practices


Shutterstock

Best practices

Important Security Best Practices for Spring and Beyond

  • Written by Jeffrey Crystal and Ben Nowacky
  • March 2, 2020
Here are some key security practices to add to your company's SOP.

… complete recovery of all compromised systems, from a backup prior to the intrusion, can truly guarantee your systems are no longer under control of the hackers.

Increasingly, attackers are going the extra mile to destroy your data. There’s even the possibility they retain a copy off-site to hold in ransom, which leaves you with nothing left to recover from. Backup and disaster recovery (BDR) systems are a high-priority target of such attackers, destroying backups and even hard-wiping disk storage underneath backup systems to deny you any chance of recovery.

  • First, ensure all critical systems are backed up both locally and in the cloud. Use RMM tools to periodically audit any servers without backup, and in each case, add backups or document the exception.
  • Second, create a strict SOP for securing backup systems and monitoring their ongoing health, frequency and cloud replication status.

Avoiding exploits of RMM and other tools: Several high-profile attacks are accomplished by improperly gaining access to popular remote monitoring and management (RMM) tools, then exposing hundreds of servers and thousands of workstations across multiple customers, to simultaneously attack with the click of a mouse. Partners must secure such tools to keep malicious attackers from potentially destroying your customer data. Be mindful that the client systems you’re controlling remotely may not be compromised, and attackers may be watching your every keystroke and mouse click.

Protecting Client IT Security: While it is always possible to be the victim of a zero-day attack, most security intrusions are the result of weak passwords, phishing attacks (human engineering of any kind) and well-known security vulnerabilities and malware that might have been prevented. Keep the following points in mind to protect your clients.

  • Ensure all systems with access to your MSP’s own network are company-approved devices that meet company security requirements:
  • Multiple layers of defense are better.
  • Educate users, both employees and customers. Well-educated users are less likely to be compromised, and when attacked, are more likely to detect and minimize the threat.
  • Require a virtual private network (VPN) on untrusted and public Wi-Fi networks. Users accessing these networks should always use a secure VPN connection to force forward all traffic over the VPN.

Recommendations for Cybersecurity Framework

The National Institute of Standards and Technology released a framework for improving your Critical Infrastructure Cybersecurity. The framework uses business drivers to guide cybersecurity activities and consider cybersecurity risks as part of your organization’s risk management processes. The framework offers a flexible way to address cybersecurity, including the effect cybersecurity has on physical, cyber and people dimensions. It’s applicable to organizations relying on technology, whether their cybersecurity focus is primarily on information technology (IT), industrial control systems (ICS), cyberphysical systems (CPS), or connected devices more generally, including the Internet of Things (IoT).

It’s clear that in this escalating threat environment, backup should be your last line of defense against such attacks. Your ability to recover is dependent on the vendor you choose, their security framework and their ability to recover your client’s data.

Find a vendor that takes a multilayer approach to mitigating these risks, while also applying best practices in its operations, including authentication, patching, secure software development, penetration testing and overall corporate and network security.

Jeffrey Crystal is product manager at Axcient, where he is working toward convergence with the X360 portfolio. He joined Axcient when it acquired his former company Replibit, and previously was a senior engineer with a small IT services company providing managed services and helping to develop and pilot managed backup for about 200 SMB customers. You can follow him at LinkedIn or @Axcient on Twitter. 

Ben Nowacky is senior vice president of product at Axcient, where he guides organizations in creating high-performance, scalable teams that cross-cut both product and development. You can follow him on LinkedIn or @Axcient on Twitter.

  • Page 1
  • Page 2
Tags: MSPs VARs/SIs Best Practices Networking Security Strategy

Most Recent


  • Controversy
    Microsoft Changing Partner Incentives Even as Channel Controversy Roars
    The terms take effect in October. “We are sharing updates now to help our partners plan ahead,” per Kevin McCarthy.
  • Google Cloud Starts New ‘Strategic’ Unit, Names Umesh Vemuri to Run It
    The changes coincide with yet another Google Cloud executive exit. Find out who’s leaving.
  • hire
    Kinka Joins Bridgepointe to Spur Charlesbank-Backed Organic Growth
    Scott Kinka made a name for himself in the channel working at Evolve IP.
  • Unleash
    ThreatX Unleashes Xcellerate Partner Program for API Protection
    Demand for real-time API protection is skyrocketing.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • CF Top Gun 51 with new logo
    2021 Top Gun 51 Nominations Are Open — Apply Now!
  • USB drive
    A Coup and a Theft: Why MSPs Can’t Let Clients Get Lax About USB Security
  • Ransomware skull and crossbones
    JBS Did What it 'Needed to Do' with $11 Million Ransom Payment
  • Cloud Certification
    CompTIA Updates Cloud+ Certification, Drops New AI Guide for Businesses

Upcoming Events

View all

Channel Partners Europe

June 14, 2022 - June 15, 2022

MSP Summit

September 13, 2022 - September 16, 2022

Galleries

View all

Partners Speak to Microsoft’s Rodney Clark Departure and New Requirements Controversy

May 18, 2022

The CF List: 2022’s 20 Top SD-WAN Providers You Should Know

May 18, 2022

Marketing All-Stars Share Their Focus for 2022 and Beyond

May 18, 2022

Industry Perspectives

View all

A Sneak Peek at the 2022 BrightCloud Threat Report

May 17, 2022

Build Customers for Life with CX and Lifecycle Selling

May 16, 2022

Voice Analytics Are a Must-Have as Companies Evolve COVID-Rushed Tech

May 12, 2022

Webinars

View all

Simplifying SaaS Security for MSPs

April 27, 2022

How to Supercharge The Network to Support Your IT Superhero Moves

May 3, 2022

The 2022 MSP Challenge: Scale Service Delivery Despite the Talent Gap

April 21, 2022

White Papers

View all

The New Bottom Line: How MSPs Can Meet the Healthcare Crisis While Evolving Their Businesses

April 19, 2022

How to build a Security Operations Center (on a budget)

April 4, 2022

The AT&T Cybersecurity Incident Response Toolkit

April 4, 2022

Channel Futures TV

View all

AT&T, Microsoft, Cisco, ThreatLocker on Unlocking Partner Potential

Agents Share ‘Secrets,’ Industry Opportunity

May 11, 2022

Vonage Addresses Potential Partner Opportunity via Acquisition by Ericsson

May 5, 2022

Lumen Technologies ‘Built for Growth and Scale’

May 4, 2022

Twitter

ChannelFutures

.@threatx_inc rolls out first partner program. #APIprotection dlvr.it/SQd3Pd https://t.co/X6cvbgpijr

May 18, 2022
ChannelFutures

Our MSPs weigh in on @Microsoft's Rodney Clark’s sudden exit, and the shakeups and challenges the new NCE program h… twitter.com/i/web/status/1…

May 18, 2022
ChannelFutures

[email protected] now reaches 177 countries — 80 more regions for the channel to target. And #AWS has a new #publicsector… twitter.com/i/web/status/1…

May 18, 2022
ChannelFutures

Our CMO roundtable series concludes with members’ predictions on what their primary focus will be in the months ahe… twitter.com/i/web/status/1…

May 18, 2022
ChannelFutures

“@IngramMicroInc's role is to be the enabler of an ecosystem,” @SahooSanj said at the company's cloud summit.… twitter.com/i/web/status/1…

May 18, 2022
ChannelFutures

Take a sneak peak at BrightCloud's 2022 Threat Report. #Channel Partners #CyberThreats @Webroot… twitter.com/i/web/status/1…

May 18, 2022
ChannelFutures

#GoogleCloudSummit unveils new solutions for #zerotrust, supply chain security. @googlecloud dlvr.it/SQZ2By https://t.co/37buEDQ030

May 18, 2022
ChannelFutures

.@Veeam CEO @anandeswaran is gunning for outsized share of data protection market at #veeamOn2022… twitter.com/i/web/status/1…

May 18, 2022

MSSP Insider

Business advice for MSSPs and news from the broader security channel.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2022 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X