SlideShare ist ein Scribd-Unternehmen logo
1 von 10
1
Security Tips from
SolarWinds Security Week
“A Quick Recap”
© 2013, SolarWinds Worldwide, LLC. All rights reserved.
2
Agenda
» Day 1: Social Engineering
» Day 2: Unauthorized USB Access & Data Loss
» Day 3: Boisterous Network Users
» Day 4: Resetting Passwords
» Day 5: Risks with Unpatched Applications
» 5 Tips to Reduce User Administration on your FTP Server
» Top 10 Online Security Tips
2
3
Day 1: Social Engineering
» Social engineering is a human hacking tactic, that
involves unsuspected social engineers who take
advantage of the gullible nature to extract
information such as credentials, access codes,
financial and trade secrets, and any other sensitive
data that the victim is privy to.
» Tips to Stay Secure:
• Be aware of social engineering attacks. Educate your
peers, employees and friends.
• Do not divulge personal information and company
data to any untrusted source, however convincing and
genuine it may look.
• If you are suspicious of any person or specific email,
report the case to your organizational authorities and
IT security teams.
SOLARWINDS SECURITY WEEK
Learn more on Social
Engineering >>
4
Day 2: Unauthorized USB Access & Data Loss
» It refers to the loss of sensitive/confidential
information owing to usage of USB drives
and other mass storage media
» Tips to Stay Secure:
• Set up access rules & policies so only
authorized employees have USB access
• Ensure to remove sensitive information
access from employees once the purpose of
using the information is fulfilled
• Do not leave old or unattended data on end-
user systems
• Build strong BYOD usage policy and disallow
using employee-owned handheld devices as
mass storage devices for data transfer
• Monitor the log activity of all your enterprise
workstations and USB endpoints
Learn more on USB
Security threats >>
SOLARWINDS SECURITY WEEK
5
Day 3: Boisterous Network Users
» On this day, we discussed about unruly users
taking advantage and indulging in malicious
network activities
» Tips to Stay Secure:
• Create means to know who and what connects to
your network
• Keep a watch on suspicious devices in the
network
• Build alerting methods and quickly pull out
information to locate a device
• Restrict and monitor Wi-Fi access
• Maintain data to track device usage history
• Set-up mechanisms to immediately detect and
remediate rogue
SOLARWINDS SECURITY WEEK
eBook: 3 Simple Steps to take
charge of Your Network Access
Security >>
Whitepaper: Detecting and
Preventing Rogue Devices >>
6
Day 4: Resetting Passwords
» Even though it’s simple to reset a user account
password, for an IT administrator like you, who has a
ton of other critical stuff to do, it takes time. And, it’s
definitely no fun at all considering the number of help
desk tickets that you resolve for this task each day.
» Tips to Stay Secure:
• Set up automatic password change reminders that
prompt the end-users in advance of password expiry.
• Provide self-service options to end-users to reset
password using a Web interface.
• Have KB articles built into your help desk software so
that the user gets tips to reset the password on their
own.
• Institute an automated system in place that can help
reset AD password automatically when a user is locked
out of their account.
SOLARWINDS SECURITY WEEK
Whitepaper: Monitor
User Logon Actions >>
7
Day 5: Risks with Unpatched Applications
» There are several reasons, why it’s tough for IT
admins to achieve patch remediation smoothly
and one among those is surprisingly the users
themselves, who never show the lightest of
interests to keep their systems and third-party
applications patched and updated to the latest
versions.
» Tips to Stay Secure
• Auditing systems for identifying missing patches
and vulnerable systems
• Deploying updates systematically in order to
eliminate application vulnerabilities in your
endpoints.
• Automating the patch management process to
ensure the operating systems and third-party
applications are patched in a timely fashion.
SOLARWINDS SECURITY WEEK
Learn more on Mitigating the risks
of Unpatched Applications >>
8
5 Tips to Reduce User Administration on your
FTP Server
1. Authenticate Company Employees Through Active Directory
2. Authenticate External Partners Through a DB Connection
3. Allow End Users to Change Their Own Passwords
4. Send Password Expiration Notifications via Email
5. Allow End Users to Trigger Their Own Password Reminders
DO YOU HAVE OTHER SECURITY CHALLENGES?
• Be sure to check out SolarWinds Security site, or leave your thoughts and comments
below.
SOLARWINDS SECURITY WEEK
9
Top 10 Online Security Tips
1. Don't be Over-Trusting!
2. Strengthen Passwords
3. Beware of Phishing & Malware Sites
4. Keep an Eye Out for Website Certificates
5. Insecure File Sharing: A Vulnerability Gateway
6. Dangers of Insecure Wi-Fi & Unsafe Public Networks
7. Be Discreet with Social Engineering Sites
8. Remove Unused Software, Browser Plug-ins & Extensions
9. Keep Browsers, Third-party Apps & Operating System Up to Date
10. Ensure Your VoIP Communication is Foolproof
SOLARWINDS SECURITY WEEK
10
Thank You!

Weitere ähnliche Inhalte

Mehr von SolarWinds

SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...SolarWinds
 
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...SolarWinds
 
Government Webinar: Alerting and Reporting in the Age of Observability
Government Webinar: Alerting and Reporting in the Age of ObservabilityGovernment Webinar: Alerting and Reporting in the Age of Observability
Government Webinar: Alerting and Reporting in the Age of ObservabilitySolarWinds
 
Government and Education Webinar: Full Stack Observability
Government and Education Webinar: Full Stack ObservabilityGovernment and Education Webinar: Full Stack Observability
Government and Education Webinar: Full Stack ObservabilitySolarWinds
 
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...SolarWinds
 
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
Becoming Secure By Design: Questions You Should Ask Your Software VendorsBecoming Secure By Design: Questions You Should Ask Your Software Vendors
Becoming Secure By Design: Questions You Should Ask Your Software VendorsSolarWinds
 
Government and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
Government and Education Webinar: Real-Time Mission, CIO, and Command DashboardsGovernment and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
Government and Education Webinar: Real-Time Mission, CIO, and Command DashboardsSolarWinds
 
Government and Education Webinar: Simplify Your Database Performance Manageme...
Government and Education Webinar: Simplify Your Database Performance Manageme...Government and Education Webinar: Simplify Your Database Performance Manageme...
Government and Education Webinar: Simplify Your Database Performance Manageme...SolarWinds
 
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...SolarWinds
 
Government and Education Webinar: Leverage Automation to Improve IT Operations
Government and Education Webinar: Leverage Automation to Improve IT OperationsGovernment and Education Webinar: Leverage Automation to Improve IT Operations
Government and Education Webinar: Leverage Automation to Improve IT OperationsSolarWinds
 
Government and Education Webinar: Improving Application Performance
Government and Education Webinar: Improving Application PerformanceGovernment and Education Webinar: Improving Application Performance
Government and Education Webinar: Improving Application PerformanceSolarWinds
 
Government and Education: IT Tools to Support Your Hybrid Workforce
Government and Education: IT Tools to Support Your Hybrid WorkforceGovernment and Education: IT Tools to Support Your Hybrid Workforce
Government and Education: IT Tools to Support Your Hybrid WorkforceSolarWinds
 
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...SolarWinds
 
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...SolarWinds
 
Government and Education Webinar: Zero-Trust Panel Discussion
Government and Education Webinar: Zero-Trust Panel Discussion Government and Education Webinar: Zero-Trust Panel Discussion
Government and Education Webinar: Zero-Trust Panel Discussion SolarWinds
 
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...SolarWinds
 
Government and Education Webinar: SQL Server—Advanced Performance Tuning
Government and Education Webinar: SQL Server—Advanced Performance Tuning Government and Education Webinar: SQL Server—Advanced Performance Tuning
Government and Education Webinar: SQL Server—Advanced Performance Tuning SolarWinds
 
Government and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Recovering IP Addresses on Your NetworkGovernment and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Recovering IP Addresses on Your NetworkSolarWinds
 
Government and Education Webinar: Optimize Performance With Advanced Host Mon...
Government and Education Webinar: Optimize Performance With Advanced Host Mon...Government and Education Webinar: Optimize Performance With Advanced Host Mon...
Government and Education Webinar: Optimize Performance With Advanced Host Mon...SolarWinds
 
Government and Education Webinar: Conquering Remote Work IT Challenges
Government and Education Webinar: Conquering Remote Work IT Challenges Government and Education Webinar: Conquering Remote Work IT Challenges
Government and Education Webinar: Conquering Remote Work IT Challenges SolarWinds
 

Mehr von SolarWinds (20)

SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
 
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
 
Government Webinar: Alerting and Reporting in the Age of Observability
Government Webinar: Alerting and Reporting in the Age of ObservabilityGovernment Webinar: Alerting and Reporting in the Age of Observability
Government Webinar: Alerting and Reporting in the Age of Observability
 
Government and Education Webinar: Full Stack Observability
Government and Education Webinar: Full Stack ObservabilityGovernment and Education Webinar: Full Stack Observability
Government and Education Webinar: Full Stack Observability
 
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
 
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
Becoming Secure By Design: Questions You Should Ask Your Software VendorsBecoming Secure By Design: Questions You Should Ask Your Software Vendors
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
 
Government and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
Government and Education Webinar: Real-Time Mission, CIO, and Command DashboardsGovernment and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
Government and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
 
Government and Education Webinar: Simplify Your Database Performance Manageme...
Government and Education Webinar: Simplify Your Database Performance Manageme...Government and Education Webinar: Simplify Your Database Performance Manageme...
Government and Education Webinar: Simplify Your Database Performance Manageme...
 
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
 
Government and Education Webinar: Leverage Automation to Improve IT Operations
Government and Education Webinar: Leverage Automation to Improve IT OperationsGovernment and Education Webinar: Leverage Automation to Improve IT Operations
Government and Education Webinar: Leverage Automation to Improve IT Operations
 
Government and Education Webinar: Improving Application Performance
Government and Education Webinar: Improving Application PerformanceGovernment and Education Webinar: Improving Application Performance
Government and Education Webinar: Improving Application Performance
 
Government and Education: IT Tools to Support Your Hybrid Workforce
Government and Education: IT Tools to Support Your Hybrid WorkforceGovernment and Education: IT Tools to Support Your Hybrid Workforce
Government and Education: IT Tools to Support Your Hybrid Workforce
 
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
 
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
 
Government and Education Webinar: Zero-Trust Panel Discussion
Government and Education Webinar: Zero-Trust Panel Discussion Government and Education Webinar: Zero-Trust Panel Discussion
Government and Education Webinar: Zero-Trust Panel Discussion
 
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
 
Government and Education Webinar: SQL Server—Advanced Performance Tuning
Government and Education Webinar: SQL Server—Advanced Performance Tuning Government and Education Webinar: SQL Server—Advanced Performance Tuning
Government and Education Webinar: SQL Server—Advanced Performance Tuning
 
Government and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Recovering IP Addresses on Your NetworkGovernment and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Recovering IP Addresses on Your Network
 
Government and Education Webinar: Optimize Performance With Advanced Host Mon...
Government and Education Webinar: Optimize Performance With Advanced Host Mon...Government and Education Webinar: Optimize Performance With Advanced Host Mon...
Government and Education Webinar: Optimize Performance With Advanced Host Mon...
 
Government and Education Webinar: Conquering Remote Work IT Challenges
Government and Education Webinar: Conquering Remote Work IT Challenges Government and Education Webinar: Conquering Remote Work IT Challenges
Government and Education Webinar: Conquering Remote Work IT Challenges
 

Kürzlich hochgeladen

Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piececharlottematthew16
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Training state-of-the-art general text embedding
Training state-of-the-art general text embeddingTraining state-of-the-art general text embedding
Training state-of-the-art general text embeddingZilliz
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyAlfredo García Lavilla
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Enterprise Knowledge
 
The Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfThe Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfSeasiaInfotech2
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek SchlawackFwdays
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationSafe Software
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenHervé Boutemy
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 

Kürzlich hochgeladen (20)

Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piece
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Training state-of-the-art general text embedding
Training state-of-the-art general text embeddingTraining state-of-the-art general text embedding
Training state-of-the-art general text embedding
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easy
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024
 
The Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfThe Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdf
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache Maven
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 

Quick Recap (and Tips) from SolarWinds Security Week

  • 1. 1 Security Tips from SolarWinds Security Week “A Quick Recap” © 2013, SolarWinds Worldwide, LLC. All rights reserved.
  • 2. 2 Agenda » Day 1: Social Engineering » Day 2: Unauthorized USB Access & Data Loss » Day 3: Boisterous Network Users » Day 4: Resetting Passwords » Day 5: Risks with Unpatched Applications » 5 Tips to Reduce User Administration on your FTP Server » Top 10 Online Security Tips 2
  • 3. 3 Day 1: Social Engineering » Social engineering is a human hacking tactic, that involves unsuspected social engineers who take advantage of the gullible nature to extract information such as credentials, access codes, financial and trade secrets, and any other sensitive data that the victim is privy to. » Tips to Stay Secure: • Be aware of social engineering attacks. Educate your peers, employees and friends. • Do not divulge personal information and company data to any untrusted source, however convincing and genuine it may look. • If you are suspicious of any person or specific email, report the case to your organizational authorities and IT security teams. SOLARWINDS SECURITY WEEK Learn more on Social Engineering >>
  • 4. 4 Day 2: Unauthorized USB Access & Data Loss » It refers to the loss of sensitive/confidential information owing to usage of USB drives and other mass storage media » Tips to Stay Secure: • Set up access rules & policies so only authorized employees have USB access • Ensure to remove sensitive information access from employees once the purpose of using the information is fulfilled • Do not leave old or unattended data on end- user systems • Build strong BYOD usage policy and disallow using employee-owned handheld devices as mass storage devices for data transfer • Monitor the log activity of all your enterprise workstations and USB endpoints Learn more on USB Security threats >> SOLARWINDS SECURITY WEEK
  • 5. 5 Day 3: Boisterous Network Users » On this day, we discussed about unruly users taking advantage and indulging in malicious network activities » Tips to Stay Secure: • Create means to know who and what connects to your network • Keep a watch on suspicious devices in the network • Build alerting methods and quickly pull out information to locate a device • Restrict and monitor Wi-Fi access • Maintain data to track device usage history • Set-up mechanisms to immediately detect and remediate rogue SOLARWINDS SECURITY WEEK eBook: 3 Simple Steps to take charge of Your Network Access Security >> Whitepaper: Detecting and Preventing Rogue Devices >>
  • 6. 6 Day 4: Resetting Passwords » Even though it’s simple to reset a user account password, for an IT administrator like you, who has a ton of other critical stuff to do, it takes time. And, it’s definitely no fun at all considering the number of help desk tickets that you resolve for this task each day. » Tips to Stay Secure: • Set up automatic password change reminders that prompt the end-users in advance of password expiry. • Provide self-service options to end-users to reset password using a Web interface. • Have KB articles built into your help desk software so that the user gets tips to reset the password on their own. • Institute an automated system in place that can help reset AD password automatically when a user is locked out of their account. SOLARWINDS SECURITY WEEK Whitepaper: Monitor User Logon Actions >>
  • 7. 7 Day 5: Risks with Unpatched Applications » There are several reasons, why it’s tough for IT admins to achieve patch remediation smoothly and one among those is surprisingly the users themselves, who never show the lightest of interests to keep their systems and third-party applications patched and updated to the latest versions. » Tips to Stay Secure • Auditing systems for identifying missing patches and vulnerable systems • Deploying updates systematically in order to eliminate application vulnerabilities in your endpoints. • Automating the patch management process to ensure the operating systems and third-party applications are patched in a timely fashion. SOLARWINDS SECURITY WEEK Learn more on Mitigating the risks of Unpatched Applications >>
  • 8. 8 5 Tips to Reduce User Administration on your FTP Server 1. Authenticate Company Employees Through Active Directory 2. Authenticate External Partners Through a DB Connection 3. Allow End Users to Change Their Own Passwords 4. Send Password Expiration Notifications via Email 5. Allow End Users to Trigger Their Own Password Reminders DO YOU HAVE OTHER SECURITY CHALLENGES? • Be sure to check out SolarWinds Security site, or leave your thoughts and comments below. SOLARWINDS SECURITY WEEK
  • 9. 9 Top 10 Online Security Tips 1. Don't be Over-Trusting! 2. Strengthen Passwords 3. Beware of Phishing & Malware Sites 4. Keep an Eye Out for Website Certificates 5. Insecure File Sharing: A Vulnerability Gateway 6. Dangers of Insecure Wi-Fi & Unsafe Public Networks 7. Be Discreet with Social Engineering Sites 8. Remove Unused Software, Browser Plug-ins & Extensions 9. Keep Browsers, Third-party Apps & Operating System Up to Date 10. Ensure Your VoIP Communication is Foolproof SOLARWINDS SECURITY WEEK