<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>threat management on Much Ado About IT</title><link>https://it.knightnet.org.uk/tags/threat-management/</link><description>
Recent content about threat management from Much Ado About IT |
Ramblings and rantings from IT Architect &amp; Designer, Julian Knight</description><generator>Hugo | gohugo.io | Theme twenty-sixteen</generator><language>en-gb</language><copyright>This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.</copyright><lastBuildDate>Mon, 24 Apr 2023 21:27:28 +0000</lastBuildDate><atom:link href="https://it.knightnet.org.uk/tags/threat-management/feed.xml" rel="self" type="application/rss+xml"/><item><title>Cloudflare Now Active</title><link>https://it.knightnet.org.uk/2014/10/cloudflare-now-active.html</link><guid isPermaLink="true">https://it.knightnet.org.uk/2014/10/cloudflare-now-active.html</guid><pubDate>Fri, 17 Oct 2014 08:50:05 +0000</pubDate><guid>https://it.knightnet.org.uk/2014/10/cloudflare-now-active.html</guid><description><div/><div>&lt;p>After the recent high-profile vulnerabilities, I decided to turn on the free version of &lt;!-- raw HTML omitted -->CloudFlare&lt;!-- raw HTML omitted --> for this domain.&lt;/p>
&lt;p>CloudFlare provides a reverse proxy service that sits in front of your domain. It will serve content where it can on your behalf (caching), optimise content where it can (e.g. minimising JavaScript, HTML, CSS, etc.). But even more important from my perspective is their ability to protect against a number of vulnerabilities.&lt;/p>
&lt;p>The most obvious protection – because this is where CloudFlare started – is DDOS protection. DDOS is a way of throwing very large numbers of requests at your domain, preventing legitimate access. But CloudFlare also now provide protection against other threats and it is interesting to look at the dashboard and seeing a bunch of threats being filtered out every few days.&lt;/p>
&lt;p>A recent add-on, especially to the free service, is the ability for CloudFlare to provide &lt;!-- raw HTML omitted -->SSL security for free&lt;!-- raw HTML omitted -->. This means that your whole site can present as HTTPS (encrypted HTTP) &amp;amp; you can even enforce this so that visitors cannot connect without encryption. This is easily done without the hassle normally associated with creating and maintaining SSL security.&lt;/p>
&lt;p>Kudos to CloudFlare for providing this excellent service and for providing a useful free version. I’m happy to recommend it to everyone who runs a web site or service.&lt;/p>
&lt;h2 id="update-2018-05-04">Update 2018-05-04&lt;/h2>
&lt;p>I still use CloudFlare for most of my published endpoints.&lt;/p>
&lt;p>However, this blog has now been moved from self-hosted WordPress to
a Hugo-based site hosted by Netlify. Netlify allows me to set all manner of security headers and has inbuilt support for
Let&amp;rsquo;s Encrypt certificates.&lt;/p>
&lt;p>So Cloudflare protection is no longer required for this blog.&lt;/p></div></description><author>Julian Knight</author><category domain="https://it.knightnet.org.uk/categories/blogging">Blogging</category><category domain="https://it.knightnet.org.uk/categories/development">Development</category><category domain="https://it.knightnet.org.uk/tags/security">Security</category><category domain="https://it.knightnet.org.uk/tags/security-threats">security threats</category><category domain="https://it.knightnet.org.uk/tags/threat-management">threat management</category><category domain="https://it.knightnet.org.uk/tags/vulnerabilities">vulnerabilities</category><category domain="https://it.knightnet.org.uk/tags/web">Web</category></item><item><title>Stay Secure! The Latest Recommendations for IT Security</title><link>https://it.knightnet.org.uk/2013/08/stay-secure-the-latest-recommendations-for-it-security.html</link><guid isPermaLink="true">https://it.knightnet.org.uk/2013/08/stay-secure-the-latest-recommendations-for-it-security.html</guid><pubDate>Tue, 27 Aug 2013 21:07:14 +0000</pubDate><guid>https://it.knightnet.org.uk/2013/08/stay-secure-the-latest-recommendations-for-it-security.html</guid><description><div>Individuals and enterprises do not understand the value of their Information nor how to protect it. This article attempts to reveal simple and practical ways to protect IT assets and outlines some of the latest thinking and tools from industry experts.</div><div>&lt;p>IT Security changes over time and it is important to stay abreast. New threats are appearing all the time and so threat management also needs to change.&lt;/p>
&lt;p>Here are some tips and pointers to the current thinking in IT Security.&lt;/p>
&lt;p>Back in February of this year (2013), the &lt;!-- raw HTML omitted -->Centre for Strategic and International Studies (CSIS) in the USA published a short but to the point paper&lt;!-- raw HTML omitted --> on how to successfully combat the majority of current cyber security threats. The paper gives an excellent background to the latest threats without getting too technical. But the great thing is the 4 steps that they give to combating the majority of current threats.&lt;/p>
&lt;p>These are summarised as:&lt;/p>
&lt;!-- raw HTML omitted -->
&lt;pre>&lt;code>&amp;lt;li&amp;gt;
&amp;lt;div dir=&amp;quot;ltr&amp;quot; data-font-name=&amp;quot;g_font_p0_1&amp;quot; data-canvas-width=&amp;quot;152.32256276321408&amp;quot;&amp;gt;
&amp;lt;em&amp;gt;Patch operating system vulnerabilities, for the same reasons discussed above&amp;lt;/em&amp;gt;.
&amp;lt;/div&amp;gt;
&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;
&amp;lt;div dir=&amp;quot;ltr&amp;quot; data-font-name=&amp;quot;g_font_p0_1&amp;quot; data-canvas-width=&amp;quot;613.1027311220175&amp;quot;&amp;gt;
&amp;lt;em&amp;gt;Minimize the number of users with administrative privileges, the highest level of authority to make changes or undertake actions on a network&amp;lt;/em&amp;gt;.&amp;lt;br /&amp;gt; Users with administrative privileges are the goldmine for the bad guys. They are the easy back door into the heart of your enterprise systems.
&amp;lt;/div&amp;gt;
&amp;lt;/li&amp;gt;
&lt;/code>&lt;/pre>
&lt;!-- raw HTML omitted -->
&lt;!-- raw HTML omitted -->
&lt;!-- raw HTML omitted --></div></description><author>Julian Knight</author><category domain="https://it.knightnet.org.uk/categories/general">General</category><category domain="https://it.knightnet.org.uk/tags/anti-virus">anti virus</category><category domain="https://it.knightnet.org.uk/tags/cyber-security">cyber security</category><category domain="https://it.knightnet.org.uk/tags/enterprise-systems">Enterprise Systems</category><category domain="https://it.knightnet.org.uk/tags/patching">patching</category><category domain="https://it.knightnet.org.uk/tags/security">Security</category><category domain="https://it.knightnet.org.uk/tags/security-threats">security threats</category><category domain="https://it.knightnet.org.uk/tags/software">software</category><category domain="https://it.knightnet.org.uk/tags/threat-management">threat management</category><category domain="https://it.knightnet.org.uk/tags/vulnerabilities">vulnerabilities</category><category domain="https://it.knightnet.org.uk/tags/whitelisting">whitelisting</category></item></channel></rss>