#37: Cyber Security Series Pt. 5 – Conducting Security Audits

In this episode of The Power Up Project, we cover:

>Part 5 of our five-part cyber security series – Conducting Security Audits

>What is a cyber security audit?

>A wrap up of our cyber security podcast series

Transcript:

In this episode, we talk about conducting security audits.

Welcome back to the Power Up Project. It’s fantastic to have you here as we round out the final episode in our five-part series on our top cybersecurity defences for your business. So far in this series we have spoken about intelligent firewalls. We’ve spoken about cyber insurance. We have spoken yet again about multi-factor authentication. And in our last episode, we spoke briefly about cybersecurity awareness training for your staff.

So in this episode we’re going to talk about security audits. Now, this is a very open-ended discussion. A security audit can be very simple, and cheap, and easy. A security audit can be very in-depth, and prolonged, and expensive. So it really is a bit of a piece of string here as to how you perceive the risk to your business, if you have any particular requirements for compliance with any particular regulations for example, or if you have a board who are concerned about this and need to be put at their ease.

So at the simple end of the process, there are a number of routine scheduled checks that you can conduct yourself if you like, every three months perhaps, maybe more, maybe less, and check on some of the most common areas that can be a threat to your business. For example, one of the really easy ones that we see is user accounts left in place for staff who have left the business.

So of course we all have a seamless process in place where our HR is tied into our IT department, so as soon as a staff member leaves the business, of course that automatically triggers down closure requests to the IT department to close down all the user accounts. We all have that, right? Of course we do. But sometimes a user account can slip through the cracks and be left in place when it shouldn’t be.

So it’s a very simple matter then to run some reports, to log onto your systems, to check the user accounts in place, and tick them off against maybe a payroll report or something similar to make sure there are no extraneous user accounts left by the by. Now, that is just one simple example of how you can run these routine checks yourself to pick up on some of the low hanging fruit I guess, the easier and most common areas that are worth checking with a bit of a routine audit.

As we climb up the scale in terms of sophistication and also, therefore, expense, we get into more technical audits, until we get to the high end of the scale when we’re talking about things like penetration testing, we’re talking about real-time monitoring of infrastructure with intrusion detection, we’re talking about a lot of these big words here. And when you get to that end of the scale, this is when we start talking, probably not to your generalist IT partner, but this is when we start talking to specialist cyber security firms who live and breathe this type of audit, and protection, and defence, and activity.

So, again, it depends what end of the scale you would like to take this, but at the very simple end, it’s pretty easy for you to put in place a little reminder in your calendar, and maybe every quarter you run through a list of checks, run some reports on some key systems, make sure the things are the way they are. And you would be surprised how effective these routine audits can be in order to tease out some of those gaps that we inadvertently leave in our security.

That brings us to the end of our five-part series on our top most effective cybersecurity defences. I do hope that everybody got some value out of this. It really is a constantly changing and rapidly evolving landscape though. So it is something that, as business people, business owners, business managers, we do need to be staying in touch with and well aware of at all times. This is not simply a matter that we can leave to the IT people. This is a business-level issue, and we need to make sure we understand it at a business level, and not simply just delegate it down.

Thanks for joining us at the Power Up Project over the past five episodes to talk about the important topic of cyber security. Have you got any questions? Please, make sure you pop over to the website or the Facebook page and send us a message. We’d love to hear from you.

Thanks for listening to this episode of the Power Up Project, brought to you by Grassroots IT and Digit IT. Please leave us a review wherever you get your podcasts, and until next time, keep powering up.

Let's continue the conversation! Leave a comment below.