5 Ways To Limit the Damage of One Bad Phishing Click

Training related to email link avoidance is prevalent, but people still make honest mistakes.

Red phishing hook icon with code and hands typing on laptop representing cybersecurity threat
istock.com/tadamichi

The human element of cybersecurity is undoubtedly the largest, and also the most difficult vulnerability to manage. While most manufacturing leaders have been conscientious about providing training related to proper credential use, email link avoidance and more, people will inevitably make honest mistakes.

With this dynamic in mind, Danny Jenkins, CEO of ThreatLocker, says businesses should look beyond simply training employees to spot phishing emails and focus on building security controls that limit what an attacker can do when these mistakes are made. 

Here are his five practical steps to take in reducing exposure:

  1. Don't let one bad click become a breach. We spend a lot of time telling employees not to click suspicious links, but the reality is that someone eventually will. Good security isn't about expecting people to be perfect. It's about putting controls in place so one mistake doesn't give an attacker the keys to the entire organization.

  2. Make “default deny” the default. If an application or process doesn't have a legitimate reason to run, why should it be allowed to run? A default-deny approach changes the equation from trying to identify everything that's malicious to only allowing what the business has already decided it trusts.

  3. Give users and applications only the access they actually need. Least privilege is one of the simplest ways to limit the damage from a compromised account. If a user, application or service doesn't need access to a particular resource to do its job, that access shouldn't be there in the first place.

  4. Treat remote access as an attack path that needs to be controlled. Remote access is essential for modern businesses, but every remote connection is another potential path into the environment. Companies should be asking who can connect, what they can access, from which devices, and whether that access is still necessary.

  5. Reduce the attack surface before attackers find it. Security teams can't protect what they don't know they have. Unused applications, outdated software, unnecessary services and forgotten remote-access tools create opportunities for attackers. One of the most practical things a business can do is regularly remove what it no longer needs.

More in Cybersecurity