Businesses
Change default administrative password on firewalls
A minimum password length of at least 12 characters, with no maximum length restrictions - use automatic blocking of common passwords using a deny list, promote the use of strong password standards (education)
Authenticate users before granting access to applications or devices
Ensure appropriate device locking controls - biometric, password or PIN before gaining access to the services. Biometric tests, passwords and PINs.
Ensure devices and software (especially antivirus) are set to auto update
Install Antivirus on staff PCs
Implement MFA, where avaliable
Enforce Two-Factor Authentication across your Organisation.
Remove or disable unnecessary software
Manual backup to separate device, kept elsewhere
Lock accounts after no more than 10 unsuccessful attempts
Wait between attempts increases with each unsuccessful attempt. This should permit no more than 10 guesses in 5 minutes
Disable any auto run feature which allows file execution without user authorisation
Configure regular scans of devices and the network for malware.
Remove or disable user accounts when no longer required, in particular special access accounts
Use separate accounts to perform administrative activities only
Providing usable secure storage for passwords, e.g password manager
Automatic cloud backups
Create a log of all of the data that is important to the organisation
Block unauthenticated inbound connections by default
Every device in scope must have a firewall.
Scan web pages automatically when they are accessed through a web browser
Allow access to a specific set of websites, block everything else.
Prevent access to the administrative interface from the Internet, unless there is a clear and documented business need.
Disable remote administrative access to firewalls entirely
Multi-Factor Authentication on Firewalls
Use IP Allowlists (Whitelists) on Firewalls and block all other connections by default.
Do not allow applications that are unsigned, have an invalid signature or do not match your organisations software whitelist.
Sandbox applications