How To Secure Your IT Services

Trust is a fundamental cornerstone in business, painstakingly earned yet easily lost. While essential for organisational success, excessive trust can lead to negligence and oversight.

Don't make it easy for "bad actors" and naughty elves to take advantage of your systems and become embroiled in their activities, protect your hard earned trust and your reputation with your customers and your suppliers.

Here are some easy steps to harden the IT that you use to conduct that business.

We would much rather engage to protect your business, than have an engagement for damage control of remediating a Cyber incident.  If you would like a more personal engagement then please book a meeting with us.

Want To Know More?

Book a free Cyber Heath Check with us,
get a free attack surface report

Firstly DNS, this is the foundation of all internet services, we sell, use and recommend Cloudflare.  There are various levels of account and the good news is that the FREE service will provide better service.

Cloudflare signup - https://www.cloudflare.com/en-gb/plans/

Yes you can always upgrade from the Free Plan at a later time.

Move your DNS to CloudFlare - https://developers.cloudflare.com/dns/zone-setups/full-setup/setup/

Turn On DNSSEC Encryption.   DNS is insecure, so yes the foundations of the Internet are security flawed.

DNSSEC improves the security. See: DNSSEC – What Is It and Why Is It Important? - ICANN

How - https://developers.cloudflare.com/dns/dnssec/

Next Email,  You may know that most attacks start with EMail, Deloitte list this as “91% of all cyber-attacks begin with a phishing email to an unexpected victim”.   This victim could be your business but it could also be a customer or supplier, with the phishing email being thought to have come from you.

The NCSC has a tool for checking see: https://checkcybersecurity.service.ncsc.gov.uk/email-security-check/

This will give the explanation of any issues, in normal non technical English, and what that a particular issue could lead to, and then technically provide what your IT folks need to do to correct it.

Now that you have Cloudflare deployed, turn on the email DMARC management.

How https://developers.cloudflare.com/dmarc-management/enable/

That will provide you with a reporting dashboard and reporting endpoint, allowing you or your IT folks to monitor what is happening with email addressed from your business and monitor the policy enforcement.

Secure Email, M365, Exchange Online - has the free capabilities for

DKIM How https://learn.microsoft.com/en-us/defender-office-365/email-authentication-dkim-configure
Trusted ARC sealers How https://learn.microsoft.com/en-us/defender-office-365/email-authentication-arc-configure
MTA-STS How https://learn.microsoft.com/en-us/purview/enhancing-mail-flow-with-mta-sts
DANE How https://learn.microsoft.com/en-us/purview/how-smtp-dane-works

Exchange Online also Anti-spam, anti-malware, and anti-phishing protection in Exchange Online Protection (EOP) see https://learn.microsoft.com/en-us/defender-office-365/recommended-settings-for-eop-and-office365

This can be tricky to get right, so we have a service to do this. Check GET Managed Email The NCSC tool can be use to check that your IT folks have deployed this.

On a serious note, in all the Cyber Law in the UK it is the directors responsibly that they meet the lawful requirements, you can outsource the task, but not the responsibility or accountability.  So do ensure that you can evidence your checks, for when regulators and barristers come knocking.

Risk profile, it's your business and consider your customers and suppliers.  You are part of a business supplier chain.  Do not be the weakest link.  The UK minimum security standard is Cyber Essentials for all business dealing with GDPR data, and by default you are - from internal and email addresses.  Have a chat with CaPS Ltd - Surrey Based Compliance and Privacy Solutions

And if only you knew a Cyber Essentials Assessor - oh wait, that's me.

Assess your customers and suppliers - see the IASME Cyber Essentials Guide to working with a third-party provider This doesn't just cover your IT provider, but applies to all service providers - imagine getting an email that looks like it's from your accountant or solicitor, telling you to pay something - and that turns out to be from a hacker in their systems.  Do not let them, make you the weakest link and risk your business.

Most businesses use Microsoft 365, and for most business we suggest the minimum (assuming that they are under 300 users) is Business Premium, but as the threat level increases, this recommendation is becoming E3 / E5.  The enterprise plans have features that are not enabled in the business plans, the key one is the ability to remediate devices quickly.

I would hope that you have licenced M365 to E5 level and that you have phishing resistant MFA and Conditional Access based on user risk deployed.   Microsoft aren't daft, they want your money, the packages are better value than trying to sort out addons and third-party middle products

M365, like the majority of IT services, is not secure by default and requires configuration to meet the users security design.  We have developed in house tools that test these configurations.

For ALL admin/privileged accounts we recommend the use of security keys (Yubico 5C and above)

The Website(s), Web Design Companies design, they are not security experts.  I on the other hand clearly have an eye for making a shiny design perfect website - not.  Consumer volume hosting providers, provide cheap hosting.  Theres a simple test, does your hosting provider help you secure your website or test that it is secure, or help to remove the malware infecting your site?  Hopefully you scored a yes on that one.

We use and sell SiteGround hosting together with various WordPress plugins, and yes we're happy to move your site to siteground and harden it for you.

Cloudflare can "proxy" the DNS requests essentially getting in the middle, and allowing Cloudflare to manipulate and operate on the traffic between your website and who, or what is trying to connect to it.  It has a Web Application Firewall or WAF function.
How Overview · Cloudflare Web Application Firewall (WAF) docs

Make sure that your services are as anonymous as possible, and that you secure your content.   This may be a good reason to upgrade to the PAID PRO plan as this allows the easy deployment of managed rules.

How WAF Managed Rules · Cloudflare Web Application Firewall (WAF) docs

With these deployed it should make it harder for those "bad actors" and naughty elves to affect you, it won’t mean you’re secure.  These are measures that will mean the "bad actors" will have to work around some defences, rather than metaphorically “seeing an open door”.

Should you wish to engage with us, we will provide you with an Attack Surface Report, if you look at the list of technologies in the report, IT systems and services that were identifiable in 2 minutes.  Those naughty elves will be putting in some time and effort reconnoitring the attack surface, phishing, and will then identify known exploits against those technologies.  So it is crucial to keep all elements with any internet access, patched and up to date.  Addressing these known exploits ASAP and making it harder for that bad actor to gain any foothold that could be used or sold on to other bad actors.

Again please don't be the weakest link, your business, your time and effort deserves better as do your customers and suppliers.

Hopefully this gift of knowledge will assist you in what 2025 brings, it can be difficult to find a route through the plethora of IT options and product choices, this is one route that will save you time and money, allowing you focus on your business sucsess.

Some light reading - Spoiler Alert - Read it after Christmas - NCSC Annual Review 2024 - NCSC.GOV.UK