3 Security Tips From an Ex-NSA Hacker

This year, a key theme at the annual ITNATION conference was cybersecurity for Managed Services Providers (MSPs) and IT departments. A growing trend in 2019 is criminal organizations gaining access to important system management tools, and using them to compromise several organizations at once.

Criminal organizations are realizing that if they can gain access to important system management tools, they are able to multiply the effectiveness of ransomware and phishing attacks. By hitting one organization, they can gain access to several more.

Today we’re bringing you 3 tips to mitigate these attacks from cybersecurity experts Chris Inglis (Former Deputy Director of the NSA, current member of the Blackpoint Cyber Board of Directors) and Jonathan Murchison (former NSA and now CEO of Blackpoint Cyber).

During a Q&A of the conference, Murchison was asked “What tactical strategies can help mitigate against these attacks?” Here’s the three pieces of advice he gave:

1. Implement Two-Factor Authentication (2FA)


Two-factor authentication (2FA) involves adding an additional credential to gain access to a system. Typically this is implemented as a PIN code which frequently changes. This additional layer means that simply having the correct username and password is not enough. The attackers job has now become much more difficult. 2FA also helps curb the threat of password reuse. If a password was used on multiple systems, 2FA can still deny an attacker access.

2. Restrict Outside Access

The move to cloud-based applications has also touched the IT management world. It is increasingly common for organizations to have cloud-based Remote Management and Monitoring (RMM) tools. This opens up the risk of an attacker logging in remotely and deploying malicious software to potentially thousands of computers. Murchison recommended that administrators should incorporate two safety measures to restrict access to their RMM.

  1. Restrict access to their RMM based on source IP. Only allow access from your authorized places of business.
  2. Require users to use a VPN into the office in order to use the RMM

By creating these restrictions, an outside attacker must go through several more layers before he is able to gain access to such a critical system.

3. Carefully Store Script Secrets

While many organizations rely heavily on IT management systems, it is common to also employ home-brewed scripts to fill in areas of automation where the existing tools lack a capability.

However, Murchison cautioned that IT providers can become careless with using administrator level credentials in these scripts. The result is that these passwords can show up in places like Windows event viewer. An attacker that has access to any computer using the script can obtain these unencrypted passwords and use them to cause havoc.

DNSFilter is committed to helping organizations secure their network by using A.I. to detect and deny access to internet threats. Our full support of industry standards like two-factor authentication and DNS-over-TLS give you total control over your organization’s DNS. Start a free trial today and enjoy the speed and security of DNSFilter.

START FREE TRIAL

Search
  • There are no suggestions because the search field is empty.
Latest posts
Migrating from Cisco Umbrella to DNSFilter: It Pays to Make the Switch Migrating from Cisco Umbrella to DNSFilter: It Pays to Make the Switch

Navigating the complexities of cybersecurity challenges today means more than just being alert; it requires a readiness to adapt and embrace superior technologies for better protection of your digital assets. The recent announcement of Cisco Umbrella Roaming Clients end-of-life (EOL) on April 2, 2024, and its end-of-support (EOS) on April 2, 2025, has encouraged several organizations to consider the next steps in maintaining robust cybersecurity ...

Zero-Day Attacks: What Are They? Zero-Day Attacks: What Are They?

The term “zero-day attacks” is thrown around frequently with a lot of concern—and rightfully so. In today’s world where even the most menial tasks are conducted online, there is always some cyber threat lurking in the dark shadows of the internet. Picture this: A burglar finds a secret doorway to your house and decides to pay you a visit. All your assets are now accessible to him, even without your knowledge.

Mid-Winter Nights Hallucinations: Some Thoughts on Our New GenAI Category Mid-Winter Nights Hallucinations: Some Thoughts on Our New GenAI Category

AI, LLM, generative content, NLP, big data, neural processing, machine learning, GPT. In 2023 it's undeniable that these were some of the most heard terms from various businesses, news outlets and the social media sphere. Ultimately this alphabet soup can mean just as much as it sometimes doesn’t—and, as often is the case, the internet leans into the trend.Sites popped up everywhere—some reputable while others less so—promising cyberpunk profile ...

Explore More Content

Ready to brush up on something new? We've got even more for you to discover.