CyberWire Daily

Breached but not broken.

Dec 19, 2024
Jeff Krull, principal and practice leader of Baker Tilly's cybersecurity practice, shares insights on mitigating internal cyber threats through effective employee access controls. He discusses recent alarming trends, including heightened cyberattacks targeting government officials and Ukrainian soldiers, and vulnerabilities found in popular tech products. Krull emphasizes the importance of the zero trust model and stringent permission management to enhance security within organizations, particularly in sectors like healthcare. Tune in for practical strategies to navigate access management challenges.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ADVICE

Limit Access, Not Productivity

  • Limit employee access to only what's necessary for their current tasks, aligning with the principle of least privilege.
  • Implement real-time access adjustments based on schedules and responsibilities to minimize risk.
INSIGHT

Balancing Security and Usability

  • Access limitations can erode due to operational friction and complaints, so strong enforcement and adaptable processes are crucial.
  • Striking a balance between security and usability is key, often requiring exception processes.
ADVICE

Promote Security Awareness

  • Explain potential security risks associated with broader access to foster a security-conscious culture.
  • Emphasize that limited access benefits everyone, not just IT, especially in the event of cyberattacks.
Get the Snipd Podcast app to discover more snips from this episode
Get the app