Skip to main content
Institute of Advanced Technological and Commercial Studies

Resources

The first cybersecurity reflexes

Five measures cover the vast majority of incidents faced by a mid-sized organisation: controlled identities, applied updates, tested backups, network segmentation and team awareness.

Five measures, in order of their return

Identity control comes first: every account has a holder, a justified permission level, and multi-factor authentication on sensitive access. Then come updates applied on a schedule, backups whose restore has been tested, and segmentation preventing a compromised workstation from reaching the servers. Awareness closes the list and makes it effective: it turns every colleague into a sensor.

  • One account per person, with justified and reviewed permissions
  • Multi-factor authentication on access to sensitive data
  • An update schedule that is kept, systems and applications included
  • An offline backup whose restore is tested every quarter
  • Network segmentation isolating workstations, servers and industrial equipment

What each measure prevents

Controlled identities

A shared account makes every trace unusable. A named account turns a log into evidence.

Updates

They close known vulnerabilities, the very ones automated attacks look for first.

The tested backup

It reduces an incident to a short interruption. The restore test is what makes it real.

Segmentation

It limits a compromised workstation's reach and buys the team time to respond.

The cybersecurity programme, block by block

From fundamentals to incident response, by way of penetration testing. Hour counts state the depth given to each skill.

Teaching blockYearHoursCredits
Security fundamentals1220 h22
Network and systems security1220 h22
Application security1120 h12
Penetration testing2220 h22
Incident response and digital forensics2180 h18
Governance, risk and compliance2100 h10
Technical English and methodology180 h8
Professional dissertation and sixteen-week placement260 h6

Common questions

Where do I start with limited means?

With an inventory of accounts and multi-factor authentication on sensitive access: both are done in house, cost little and close the most-used entry route. The tested backup comes immediately after.

What place for team awareness?

It multiplies the effect of every other measure: a team that reports a suspicious message saves hours of detection. The programme devotes a full strand to awareness in its governance block.

How often should permissions be reviewed?

At every staffing change, and through a general review twice a year. Access accumulated across successive roles is the most common situation, and the simplest to correct.

The first cybersecurity reflexes — Resources | IHETC — IHETC