Insight ·

Choosing cybersecurity that people will actually use

Why the highest-value security controls are the unglamorous ones, and how to prioritise when the budget will not cover everything.

Security that gets in the way gets worked around, and a control everyone has found a way past is worse than no control — because it produces confidence without protection.

Start with the boring, high-value controls

Multi-factor authentication, everywhere. The single highest-value control most organisations still have not finished rolling out. It defeats the overwhelming majority of credential attacks, and modern implementations are barely an inconvenience.

Backups you have actually restored from. A backup that has never been tested is a hypothesis. Restore one, deliberately, and time it — that number is your real recovery time.

Patching you can prove. Not “we think it’s automatic”. Centrally managed endpoint protection lets you answer the question with evidence.

Do these three before anything more sophisticated.

Then the perimeter and the endpoint

Firewalls and secure Wi-Fi sized to the site, and endpoint protection managed centrally rather than installed per-machine and forgotten.

We deploy Bitdefender for endpoints, WatchGuard at the network boundary, and Cisco Duo for access — chosen because they are manageable at the scale our clients actually operate at.

If you are regulated, evidence is the deliverable

For clients holding client funds or handling personal data under GDPR, security is an obligation with evidence attached. The control matters, but so does the record proving it was in place on the day in question.

Choose tools that produce those records as a matter of course. Reconstructing them later is miserable and unconvincing.

The human part

Most successful attacks still start with a person, not a system. Awareness training is worth more than another appliance — provided it is short, frequent and specific to the scams your people actually receive.

A sensible order

  1. Multi-factor authentication everywhere
  2. Tested, offsite backups
  3. Centrally managed, provable patching
  4. Endpoint protection
  5. Network boundary
  6. Awareness training
  7. Everything else

Most organisations that get the first three right have removed the bulk of their realistic risk.