Do your servers contain critical data that you don’t want to fall into the wrong hands?
These days, servers are more at risk than ever before. They are constantly being attacked by viruses, hackers with malicious intent, and by those engaging in corporate espionage.
If a server is physically reachable, it is definitely breach-able (without any need of special tools or third party applications). Take special care to ensure racks and servers are individually secured. Remember that network security starts at the physical level. All the firewalls in the world won’t stop an intruder who is able to gain physical access to your network and computers, so lock up as well as lock down and make sure to set up surveillance in case someone breaks in, or someone with authorised access abuses their trust.
Strategically, a server should never operate alone. At least, it should sit behind a firewall, which provides the first line of defence against outside attack. Regardless of how your defensive perimeter is implemented, its purpose is to be just that: a perimeter. The goal of your network-level security services is to make sure an attack never, ever reaches your line-of-business servers. If the server needs to be accessible via remote desktop over the internet for management purposes, it is a good practice to allow only specific IP addresses. Also for making connections from the public internet to your private network, instead of using the usual and well known port numbers, use ambiguous or random ones. This will protect the attacker from discovering the usual open ports for malicious intent. If you are already under constant attack from IP addresses outside your country, consider implementing firewall that supports IP geo-location for making and refusing connections. Whilst we don’t endorse any particular brands, there are plenty of free, reliable, proven and open source ones such as pfsense.
Don’t forget to protect your backups
If neglected, backups can become a double-edged sword. By making copies or stealing your backup media those interested in your company confidential data no longer need to hack in. At the very least, password-protect your backup files so that if your backup media is copied or stolen it cannot be accessed by opportunists or curious staff. As an extra precaution encrypt and zip them into an archive. Once again there are plenty of free compression software that allow password protection and encryption so there’s no excuse to forgo this essential practice.
Security and usage policy
Remember, your security is as strong as the weakest link. So have a good, strong security and usage policy as part of your employment contract. Make sure that everyone is aware of it and that the policy is enforced. Such a policy should include harsh penalties for anyone caught trying to load unauthorised software on company computers or copy data to personal storage devices or cloud services. To get you started we have included a template Acceptable Usage Policy that can be downloaded below.
Make sure to apply security patches in a timely manner. Obviously, you don’t want to wait any longer than absolutely necessary to apply the fix should a major security hole be discovered.
