Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Prevention Is Better Than Any Cure
Articles

Prevention Is Better Than Any Cure

Dan O’FarrellBy Dan O’FarrellSeptember 28, 2022Updated:December 9, 20225 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

One of the founding fathers of the United States, Benjamin Franklin, once famously advised that an ounce of prevention is worth a pound of cure. While this statement was made nearly 300 years ago, it is still true, especially in our modern-day fight against the ongoing increase in cyber threats. Cyberattacks have become a persistent and permanent threat to organizations across all industries. Consider the following:

  • There was a 500% increase in ransomware attacks in 2021 compared to 2020.
  • 70% of all intrusions last year were malware.
  • There was an attack every 11 seconds in 2021.
  • On average, there are 90+ monthly vulnerabilities for Windows that require patching.
  • More than 1,000 slow and expensive VPN connections can be required to manage and control remote endpoints in a typical enterprise.
  • Tens of millions of dollars in fines are levied each year for non-compliance with data protection standards, such as GDPR.

To mitigate the increased exposure to these cyber risks, IT teams must act proactively and swiftly to safeguard the most vulnerable point in the network – the endpoint. Combatting these escalated endpoint threats requires organizations to look at all the ways threats could succeed and tighten up controls in each element, including user activity, policy and access controls, antivirus software, suspect or abnormal byte sequence detection, a chain of trust, and virtualization and cloud-based computing. Experts recommend a “defense in depth” strategy, or multi-layered approach to physical, technical, and administrative controls to safeguard a business from security threats.

Endpoint Security Starts at the OS

The solution to protecting endpoints, however, really starts with the device operating system (OS). Moving Windows to the data center or cloud via virtual desktops and using a lean, inherently secure Linux-based OS can instantly fortify the security posture of any endpoint. For example, moving Windows off the endpoint is the logical strategy as cloud-based apps, like Azure Virtual Desktop, Windows 365 Cloud PC, along with cloud-based offers supported by VMware and Citrix are now the virtualization standard for end-user computing. This approach also consumes less IT staff time since it streamlines patching and other security updates across an organization’s entire IT environment, greatly reducing risk at the endpoint. Users, regardless of their locations, can confidently use their endpoint devices of choice to access the data and apps they need in the cloud, all while minimizing the chances of introducing a threat.

An OS built for VDI, DaaS, and digital workspaces can be structured as a modular, read-only and tamper-proof firmware base, for optimal success. Since the endpoint OS has an extremely small “attack surface” and all the data is stored in the cloud, there is literally nothing for hackers to target on the endpoint. In addition, the inclusion of multiple security-focused features in the OS can be designed to minimize exposure and deter attackers from gaining access to an organization through the endpoint devices.

Giving users what they need to do their jobs effectively and controlling access to non-relevant apps will significantly reduce an organization’s attack surface and can help stop attacks before they even happen. IT teams can set policy controls based on end-user roles to minimize the “human factor” as well.  For example, an endpoint device can be “locked down” in appliance mode or kiosk mode to perform only one function and nothing else. Additional measures like multifactor authentication can add another layer of security and protect the organization to minimize harm, even if an endpoint device is lost or stolen.

Securing the Device and Beyond

Organizations also need to think beyond the endpoints and devices and focus on practices that reduce risk regardless of where or what devices an individual is using at the time. Recognizing that a hybrid workforce will likely introduce rogue devices at some point, security protocols must be implemented that are, at a minimum, set with a standard security baseline across devices, to support what is becoming a permanently fluid style of working.

Organizations should also think about adding a chain-of-trust process to their security strategy. A sequence of cryptographic signature verifications that ensure end-to-end integrity really adds an extra level of confidence with every device startup or reboot. A chain-of-trust process can extend from the endpoint device to the digital workspace VDI host or cloud. Every time a device is used, chain-of-trust ensures that none of the firmware and software in the startup sequence have been altered. With a chain-of-trust process in place, the end user is alerted, and IT can take the necessary steps if it detects a failure condition at any step along the way.

Some organizations still focus on the “cure” when it comes to getting hit by cyberattacks and threats. Minimizing harm after getting hit by a cyberattack is possible using the IGEL US Pocket, for example. However, the amount of damage and required work to overcome an attack can be reduced significantly if you simply take the necessary steps and precautions to provide protection in the first place. You need to help your people to have a protected and productive workday, every day, from anywhere. Taking preventative measures by implementing the multi-layered approach to endpoint security outlined in this article, you can protect endpoints with built-in security to increase the overall threat defense against ransomware and other forms of malware. Focus on the prevention rather than the cure.

Dan O’Farrell
  • Dan O’Farrell
    Windows 11: The Latest Security “Fun” For IT Professionals
  • Dan O’Farrell
    Tightening Security In The Evolving Hybrid Workplace Environment

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}