It must be good, someone posted about it on LinkedIn!
Ok this isn’t my normal jam, normally I’d just write something that’s hopefully good advice/practise and that would be that. But today let’s try something different!
This was inspired by a twitter convo which evolved into this: https://twitter.com/UK_Daniel_Card/status/1522138771789123584?s=20&t=dL9OkicTY2Orj5hfBtDvVQ
So… what are some cyber security myths that ended up being good practise or “good advice”? Well here’s what I came up with, supported by some awesome cyber community people!
- Rotating passwords every 30 days is a “good” idea
- 8-character passwords with Uppercase, Lowercase, Numbers and Symbols make good/strong passwords!
- Systems don’t need external logging systems as they store logs on the device!
- You aren’t a bank, so you don’t need “good” cyber security
- You can do cyber security at scale without budget and resources
- You can just add more specialist workload to the IT team, and it will just be taken care of
- Cyber security is simple/easy
- Doing a CBT for security awareness is highly effective
- Phishing simulations increase employee trust
- Telling people to not click on “suspicious” or “malicious” links works (thanks @Dave_Maynor)
- Macs can’t get viruses (thanks @jlphamill)
- The vendor says their solution is secure, so just trust them!
- Security teams don’t need to understand the technology, architecture, and engineering elements (or the business environment (thanks @spyblog))
- Just deploying EDR will solve all the security problems
- If a vendor says a solution needs “domain admin rights” it must be true! (thank @jlphamill)
- Simply removing admin rights makes an environment “easy” to manage
- Admin rights are ok if you trust your people, or they are advanced/clever (thanks @_4_d_4_m_)
- Simply by following a list of TOP 18/20 controls you will achieve “good posture”
- Zero trust solves everything (especially when you use SaaS) (thanks @js_opdebeeck)
- By deploying more products “Security management” gets simpler
- Getting Cyber Essentials/ISO27001:2013 is a good endgame for a security program
- Buying policy packs is a good way to implement cyber security policies, cultures, and practises into organisations
- Just patch everything (thanks @WilRockall)
- You don’t need a SOC/Logging if you have an EDR
- If you don’t have a TLS grade A+ your security is “TOTALLY COMPROMISED”
- Exposing RDP to the Internet is fine, if you change the port number, because nobody will expect that! (thanks @wright_de)
- Don’t install Microsoft products (thanks @stautistic)
- Just deploy Linux
- Security doesn’t require specialist training
- Not Training a workforce gives good outcomes and they are less likely to leave
- Attackers only have to be right once (thanks @DrewHjelm)
- Un monitored Passive network taps reduce residual risk and increase secrity (thanks @ron_brash)
Now I’m sure there are more! feel free to join in a convo on twitter!
The good part about knowing “bad” is that we can at least use this to help us contextualise and understand what “good” might look like for our scenario. Remember, one size often does not fit all, if it did your business woulnd’t have a product or service that differentiates itself in the market!