2023-02-02 00:00:00

Books|Securitycrisis|cyber|eric cole|lessons|protection

10 cornerstones for managing cyber security

I recently read a book titled Cyber Crisis that has a mission to convince every business manager and a person who owns a phone, computer, game console or an electronics device that cybersecurity is everyone's business. The author Eric Cole, an industry-recognized security expert, has written an easy to read book that explains why and how absolutely every organisation and every person must protect their connected devices from online threats. Here are the 10 key points that summarize the fundamentals of a long term cyber security strategy.

You are a target.

Like it or not, but everyone who has any type of device connected to the internet is a target. Perhaps you think you don't have that much money for criminals to be interested in you, or you have a virus scanner on your PC. Wrong attitude. You probably have an online bank account, and credit or debit card. They are key targets for criminals. It is likely you have a phone where attackers can install malware that, for instance, constantly clicks ads in the background, or a home security camera connected to the internet that hackers can easily turn into a tool that they remotely utilize for attacking other targets. Every computer, phone and connected device must be protected.

Cybersecurity is your responsibility.

At work and at home, security is everyone's responsibility. Although organizations may outsource complex security projects to consultants and families may ask help from a neighbor who happens to have a reputation as a computer wiz, the person who pushes the buttons, clicks the links, and downloads files to the device makes the final decisions what happens.

Security is typically built in, but not turned on in products.

In recent years, the vast number of security incidents have convinced responsible product manufacturers and software developers to include fundamental security features in their products. There was a time when vendors didn't want to turn on security features because they feared customers would complain the products are difficult to use. Now, the tide is turning. Responsible vendors ship products with basic security features switched on, and enforce users to select reasonable passwords.

Attachments and links included in email messages are the most likely danger points.

Attachments included in email messages are the easiest way for cyber criminals to deliver harmful programs to target devices. If you click on a malicious attachment, it installs itself on your PC or phone and then it does whatever it wants. Clicking unknown links included in messages (it can be a Facebook, Whatsapp, any message) can have the same effect. How do you know if an attachment or link is dangerous? You have to assume it is. If you didn't ask to get a file, don't open it. If you didn't ask for a link, make sure you know where it is pointing before you follow it.

Beware of social engineering scams as well. If " Microsoft support" calls you and instructs you to download a program to your PC or phone, don't do it.

Understand the risks and exposure.

When an organization opens its internal network for remote workers, it makes a lot of sense to do so. From security point of view it can be done, but the risks must be carefully assessed and managed. If a family wants to install security cameras inside and outside their house, and access them on their phones while they enjoy a weekend at a resort, it is perfectly all right after the security risks are evaluated and managed.

Focus on your critical data.

All major cyber security breaches have been serious incidents because criminals have stolen millions or billions of records of data from large databases. Ransomware crime where criminals encrypt organization's data and unlock it after a ransom has been paid is a successful scheme because the victims aren't sure if they can recover all the data quickly enough to continue operating normally. Ensuring critical data is backed up and rapidly recoverable is the cheapest cyber insurance.

Always backup your critical data to a storage that is not connected to the internet.

One of the recommended data backup strategies is called 3-2-1. It means having three copies of all data. Two copies are stored on different types of storage devices as the original. One of these copies is stored off site, maybe in a cloud storage or in another safe place.

There is no delete button in cyberspace.

If you have a computer or phone that is not connected to the internet, you can remove a file from the device and it really disappears forever (without going to the technical details how someone who has physical access to the device may be able to recover the file). Since practically all devices are connected to the internet and we interact in the cyberspace, the situation is radically different today. Our photos and messages are copied from node to node until they reach their destinations. There is no way knowing if the messages are saved while in transit, or if intelligence agencies are monitoring the messages. It is possible to hide the content of those messages by encrypting them but copies still exist.

If you delete a message for instance, on Facebook or let it auto-destruct on Snapchat, it will be hidden from you, but it is not deleted. It stays in the social media service's database. In an unfortunate case when hackers manage to break in to the database, all its secrets may become public information.

Detection via monitoring is the key to security.

A key lesson from the Cyber Crisis book:
"You cannot prevent all attacks."

Which leads to conclusion:
"Prevention is ideal, but detection is a must."

It means that you should do everything you can to prevent attacks, but since 100% success rate is impossible for everyone, you must have attack monitoring in place all the time, for all systems.

Always act under the premise that you are compromised.

Another key lesson from Eric Cole:
"You are probably already compromised, and if you are not seeing the signs of compromise, it's not because it didn't happen, but because you are not looking in the right place."

A few years ago, our small business conducted a cyber security planning project that started from the assumption that we were hacked. We worked backwards from there. The project was the most valuable security exercise participants has so far contributed to. It changed the way we think about security, and how it became part of our normal daily work.

News

2025-11-05 08:19:00

Here we go - the first #AI powered #camera and you need an iphone to use it:Caira is designed to negate some of photography’s learning curve by using onboard AI that allows users to talk to the camera using natural language.https://www.digitalcameraworld.com/cameras/mirrorless-cameras/caira-ai-camera-pre-orders-open-on-kickstarter


Medieval market, although the food was prepared in this century.

2025-11-03 16:35:56

arihak

Medieval market, although the food was prepared in this century.


News

2025-11-02 08:39:00

New industry standard against, for instance, #AI image collection:LinkedIn is currently rolling out support for Content Credentials, that attaches secure, verifiable authorship and usage information directly to an image file.c #photography #copyrighthttps://www.digitalcameraworld.com/tech/social-media/new-linkedin-feature-helps-you-prove-authorship-of-your-photographs


News

2025-10-28 08:05:00

The Dog Photography Awards have just unveiled its stunning 2025 winners, proving once again why this competition is a must-watch for photographers and dog lovers alike. #photographyhttps://www.digitalcameraworld.com/photography/awards-and-competitions/this-photographer-perfectly-mastered-dog-motion-and-is-just-one-of-many-awarded-shots-that-will-make-you-smile


A small idyllic plaza in the historic center of Valencia City,

2025-10-26 15:51:54

A small idyllic plaza in the historic center of Valencia City,


A long beach with space even for a house.

2025-10-26 15:50:47

A long beach with space even for a house.


Tiny castle with a view.

2025-10-26 15:45:59

arihak

Tiny castle with a view.


It is narrow, but it is an access to the sea.

2025-10-23 13:42:53

arihak

It is narrow, but it is an access to the sea.


News

2025-10-22 09:01:00

Copper thieves have discovered #EV chargers, self-driving European van in 2026, and other #travel newshttps://klaava.com/electric-vehicle-news-summary-for-travelers-self-driving-van-lamppost-chargers-strong-ev-sales-numbers-in-2025/


News

2025-10-12 08:52:00

"Compact cameras came back in a huge way, mainly thanks to Fujifilm. The X100V just blew up on TikTok. And then #camera vendors realized, oh darn – people are buying compact cameras and none of us make them any more."https://www.digitalcameraworld.com/cameras/compact-cameras/the-compact-camera-conundrum-why-do-canon-kodak-sony-and-fujifilm-all-have-different-solutions-to-the-same-problem


Medieval fortress with a castle and village inside double walls

2025-10-07 17:56:11

Medieval fortress with a castle and village inside double walls


News

2025-10-06 18:12:00

The problem is: which country and which city is the best for retirement? Well, if you ask expats who have experience on how is it like to live in other countries, their answer is the city of Valencia on Spain’s Mediterranean coast. #expat #Europe #Valenciahttps://klaava.com/the-best-country-to-settle-down-after-your-active-working-years-are-behind/


Hidden cafeteria in the city center.

2025-10-06 14:03:42

arihak

Hidden cafeteria in the city center.


News

2025-09-26 08:36:00

But for every real innovation, there’s a graveyard of gimmicks — features and products that sounded futuristic, won headlines, and then died in obscurity. Here are five of the quirkiest gimmicks that promised to change #photography but went nowhere. #camerahttps://fstoppers.com/historical/5-photography-gimmicks-went-nowhere-711938?utm_source=FS_RSS&utm_medium=RSS&utm_campaign=Main_RSS


News

2025-09-26 06:36:00

But for every real innovation, there’s a graveyard of gimmicks — features and products that sounded futuristic, won headlines, and then died in obscurity. Here are five of the quirkiest gimmicks that promised to change #photography but went nowhere. #camerahttps://fstoppers.com/historical/5-photography-gimmicks-went-nowhere-711938?utm_source=FS_RSS&utm_medium=RSS&utm_campaign=Main_RSS


News

2025-09-23 19:22:00

Is the electric van the reason for the increased travel? I wasn’t sure, so I decided to list the pros and cons of road trips in an electric van. #EV #campervan #roadtrip #Europehttps://klaava.com/road-trips-in-an-electric-van-the-good-and-the-bad-experiences/


Steep ascent ... wish I had a scooter.

2025-09-23 18:17:05

arihak

Steep ascent ... wish I had a scooter.


News

2025-09-08 07:48:00

The impressive outer and inner walls with 52 towers are the main attractions of #Carcassonne, but it is inside the walls where local life, restaurants, bars, galleries and shops, as well as the Gothic Cathedral and the Comtal Castle await visitors. #France #travel #Europehttps://klaava.com/the-medieval-fortress-of-carcassonne-in-southern-france-features-a-complete-3-km-long-double-wall/


of Innsbruck in Austria

2025-09-02 17:49:48

of Innsbruck in Austria


News

2025-09-02 14:55:00

Excellent initiative, but will giants like Airbnb or Booking.com change behavior? #tourism #EU"Ensure the authenticity of reviews, distinguishing reviews from guests who experienced the accommodation and those who did not.https://transport.ec.europa.eu/news-events/news/commission-welcomes-code-conduct-reliable-online-reviews-tourism-accommodation-2025-09-01_en