2023-02-02 00:00:00

Books|Securitycrisis|cyber|eric cole|lessons|protection

10 cornerstones for managing cyber security

I recently read a book titled Cyber Crisis that has a mission to convince every business manager and a person who owns a phone, computer, game console or an electronics device that cybersecurity is everyone's business. The author Eric Cole, an industry-recognized security expert, has written an easy to read book that explains why and how absolutely every organisation and every person must protect their connected devices from online threats. Here are the 10 key points that summarize the fundamentals of a long term cyber security strategy.

You are a target.

Like it or not, but everyone who has any type of device connected to the internet is a target. Perhaps you think you don't have that much money for criminals to be interested in you, or you have a virus scanner on your PC. Wrong attitude. You probably have an online bank account, and credit or debit card. They are key targets for criminals. It is likely you have a phone where attackers can install malware that, for instance, constantly clicks ads in the background, or a home security camera connected to the internet that hackers can easily turn into a tool that they remotely utilize for attacking other targets. Every computer, phone and connected device must be protected.

Cybersecurity is your responsibility.

At work and at home, security is everyone's responsibility. Although organizations may outsource complex security projects to consultants and families may ask help from a neighbor who happens to have a reputation as a computer wiz, the person who pushes the buttons, clicks the links, and downloads files to the device makes the final decisions what happens.

Security is typically built in, but not turned on in products.

In recent years, the vast number of security incidents have convinced responsible product manufacturers and software developers to include fundamental security features in their products. There was a time when vendors didn't want to turn on security features because they feared customers would complain the products are difficult to use. Now, the tide is turning. Responsible vendors ship products with basic security features switched on, and enforce users to select reasonable passwords.

Attachments and links included in email messages are the most likely danger points.

Attachments included in email messages are the easiest way for cyber criminals to deliver harmful programs to target devices. If you click on a malicious attachment, it installs itself on your PC or phone and then it does whatever it wants. Clicking unknown links included in messages (it can be a Facebook, Whatsapp, any message) can have the same effect. How do you know if an attachment or link is dangerous? You have to assume it is. If you didn't ask to get a file, don't open it. If you didn't ask for a link, make sure you know where it is pointing before you follow it.

Beware of social engineering scams as well. If " Microsoft support" calls you and instructs you to download a program to your PC or phone, don't do it.

Understand the risks and exposure.

When an organization opens its internal network for remote workers, it makes a lot of sense to do so. From security point of view it can be done, but the risks must be carefully assessed and managed. If a family wants to install security cameras inside and outside their house, and access them on their phones while they enjoy a weekend at a resort, it is perfectly all right after the security risks are evaluated and managed.

Focus on your critical data.

All major cyber security breaches have been serious incidents because criminals have stolen millions or billions of records of data from large databases. Ransomware crime where criminals encrypt organization's data and unlock it after a ransom has been paid is a successful scheme because the victims aren't sure if they can recover all the data quickly enough to continue operating normally. Ensuring critical data is backed up and rapidly recoverable is the cheapest cyber insurance.

Always backup your critical data to a storage that is not connected to the internet.

One of the recommended data backup strategies is called 3-2-1. It means having three copies of all data. Two copies are stored on different types of storage devices as the original. One of these copies is stored off site, maybe in a cloud storage or in another safe place.

There is no delete button in cyberspace.

If you have a computer or phone that is not connected to the internet, you can remove a file from the device and it really disappears forever (without going to the technical details how someone who has physical access to the device may be able to recover the file). Since practically all devices are connected to the internet and we interact in the cyberspace, the situation is radically different today. Our photos and messages are copied from node to node until they reach their destinations. There is no way knowing if the messages are saved while in transit, or if intelligence agencies are monitoring the messages. It is possible to hide the content of those messages by encrypting them but copies still exist.

If you delete a message for instance, on Facebook or let it auto-destruct on Snapchat, it will be hidden from you, but it is not deleted. It stays in the social media service's database. In an unfortunate case when hackers manage to break in to the database, all its secrets may become public information.

Detection via monitoring is the key to security.

A key lesson from the Cyber Crisis book:
"You cannot prevent all attacks."

Which leads to conclusion:
"Prevention is ideal, but detection is a must."

It means that you should do everything you can to prevent attacks, but since 100% success rate is impossible for everyone, you must have attack monitoring in place all the time, for all systems.

Always act under the premise that you are compromised.

Another key lesson from Eric Cole:
"You are probably already compromised, and if you are not seeing the signs of compromise, it's not because it didn't happen, but because you are not looking in the right place."

A few years ago, our small business conducted a cyber security planning project that started from the assumption that we were hacked. We worked backwards from there. The project was the most valuable security exercise participants has so far contributed to. It changed the way we think about security, and how it became part of our normal daily work.

News

2025-09-08 07:48:00

The impressive outer and inner walls with 52 towers are the main attractions of #Carcassonne, but it is inside the walls where local life, restaurants, bars, galleries and shops, as well as the Gothic Cathedral and the Comtal Castle await visitors. #France #travel #Europehttps://klaava.com/the-medieval-fortress-of-carcassonne-in-southern-france-features-a-complete-3-km-long-double-wall/


of Innsbruck in Austria

2025-09-02 17:49:48

of Innsbruck in Austria


News

2025-09-02 14:55:00

Excellent initiative, but will giants like Airbnb or Booking.com change behavior? #tourism #EU"Ensure the authenticity of reviews, distinguishing reviews from guests who experienced the accommodation and those who did not.https://transport.ec.europa.eu/news-events/news/commission-welcomes-code-conduct-reliable-online-reviews-tourism-accommodation-2025-09-01_en


News

2025-08-31 15:29:00

But these so-called “bad” photographs that break all the rules aren’t just trending; these “terrible” photographs are what’s going to save photography from AI. #photography #AI--- hmm, I don't think AI can be dismissed so easily; new skills can be taughthttps://www.digitalcameraworld.com/tech/artificial-intelligence/terrible-images-are-going-to-save-photography-from-ai-and-this-is-why


City center.

2025-08-27 16:57:04

arihak

City center.


News

2025-08-25 15:56:00

Looks like #train #travel is trending in #Europe. Here is the roundup of latest news on the development of railways, routes, and ticketing systems.https://klaava.com/european-railway-news-summary-unified-train-systems-off-the-beaten-rail-tips-mr-bean-restaurant/


Wine, women, and song. #dance #festival

2025-08-14 17:47:25

arihak

Wine, women, and song.#dance#festival


Secure parking in shade

2025-08-09 14:12:42

Secure parking in shade


News

2025-08-08 15:52:00

Other key findings in the study were that professional criminal groups are taking over business from independent amateurs, and scammers are making extra revenue by grabbing tourists’ personal data as well. #travel #scamhttps://klaava.com/vacation-apartment-scammers-grab-your-money-and-as-a-bonus-may-steal-your-identity-as-well/


News

2025-08-06 09:05:00

A new bucket list #travel destination?Chongqing’s architecture style is unique. The concrete and mountain terrain, with lots of industrial design, make it seem like a futuristic movie set, but at night, lights elevate the city into a true #cyberpunk dream.https://edition.cnn.com/travel/chongqing-china-tourism-cyberpunk-city-intl-hnk


News

2025-07-31 14:20:00

Perhaps not a bicycle for the Tour de France, but takes the rider up a steep hill to home.#streetphotographyflic.kr/p/2rjRBQvhttps://flic.kr/p/2rjRBQv


The nicest tourist information office I have seen so far.

2025-07-30 17:20:05

arihak

The nicest tourist information office I have seen so far.


News

2025-07-27 14:02:00

My first impression during a recent visit was that Innsbruck felt like a large and busy city, but pretty soon I realized that it is really quite compact. #Europe #travelhttps://klaava.com/innsbruck-may-be-renowned-for-winter-sports-but-it-really-is-a-pretty-historical-city/


News

2025-07-19 20:27:00

Star trek? No, feet on the ground in Valencia#streetphotographyhttps://www.flickr.com/photos/arihak/54479762808/in/photostream/lightbox/


News

2025-07-10 13:26:00

Behavior rules are being documented as town-specific or national-level regulation in European countries, especially in the south where sun seeking tourists may forget that the town belongs to local people who simply want to live in their home town. #travel #Europehttps://klaava.com/nitpickers-travel-journal-behave-or-else-unwritten-cultural-rules-in-europe/


But there are three fortresses on the other side of border.

2025-07-08 16:06:04

But there are three fortresses on the other side of border.


Border town safety net.

2025-07-07 18:24:59

arihak

Border town safety net.


News

2025-07-07 16:16:00

Instead of fumbling with plastic chips, you download a mobile profile directly onto the secure micro-chip already soldered inside most recent phones (think iPhone XR and newer, Google Pixel 3+, Samsung Galaxy S20 series and up). #phone #travelhttps://klaava.com/esim-the-tiny-tech-that-makes-big-adventures-stress-free/


News

2025-07-01 16:15:00

Canyon road is a magnet for cyclists and motorists.#photography #travelphotography #europeflic.kr/p/2rdW4Mfhttps://flic.kr/p/2rdW4Mf


The historic center of Krakow in Poland features castles, churches, palaces ... and tourists.

2025-06-23 13:31:04

The historic center of Krakow in Poland features castles, churches, palaces ... and tourists.