Skip to main content
Aynitech Factory
EN ES
background-header
Insights / Cybersecurity 1.0: What Do I Do If It’s Just Me?

Cybersecurity 1.0: What Do I Do If It’s Just Me?

In this article, we will focus on what a "one-person" security component can accomplish. This is a scenario that happens very often, particularly in small and medium-sized enterprises (SMEs).

Cybersecurity 1.0: What Do I Do If It’s Just Me?

In cybersecurity, it is common to face the challenge of doing a lot with very little: How can a single person—the one in charge of IT security—manage the complex challenges of the cybersecurity landscape facing any organization? What happens if you are the only internal resource assigned to an IT security role and tasked with protecting an entire company?

In this article, we will focus on what a “one-person” security component can accomplish. This is a scenario that happens very often, particularly in small and medium-sized enterprises (SMEs).

What Are the Protection Priorities?

As with any project, regardless of available resources, identifying priorities is key. If you don’t know what you are protecting, no effort put into building a program will have a meaningful impact.

Whether it involves sensitive data, customer records, or intellectual property, you must have a clear idea of what the rest of the program is built upon. That does not mean other information ceases to be important to protect. The first step is to prioritize reasonably, assuming the person in charge of security has the right information at hand to move forward.

Where to Begin?

One thing we definitely should not do is reinvent the wheel. Given everything spent in the security industry over recent decades, we can leverage the byproduct by looking at the vast array of free or low-cost frameworks and lessons learned. For example: the Center for Internet Security’s (CIS) 20 Critical Security Controls.

This continuously updated, free resource provides research-backed, common-sense methods to improve security. It is important to note that these controls are not a simple checklist; rather, they form a framework that allows security professionals to evaluate current (or future) program components against a common set of guidelines, ensuring they focus on high-priority measures that yield the greatest positive impact on the organization’s posture.

Basic Controls

Know Your Inventory

Creating and maintaining a hardware and software inventory is straightforward, but if you don’t know which assets hold or process the organization’s critical information, making a positive impact will be difficult. Whether using a spreadsheet or a scanning toolkit, obtain a solid list of everything within your scope before moving forward.

Limit Administrative Access

Controlling administrative access is vital. While managing previously granted admin rights can be difficult, doing so is well worth the effort. If users have administrative rights, you cannot enforce a realistic degree of control over your systems—it’s as simple as that. Nothing else implemented will matter if a user can override it to “play a new Facebook game” or install the latest free game downloaded from suspicious corners of the internet. The concept of least privilege is a core focus because it works.

Secure Configuration

Depending on the scope of the organization’s IT team, this can be a major task. It is often best accomplished by first aligning server configurations, then moving to network infrastructure, and finally addressing workstations. Even ensuring all workstations are set to automatically apply locally approved OS updates (and implementing a plan to ensure servers receive the same level of attention as mission requirements permit) is a major step in the right direction.

Collect and Store Logs

Full log maintenance, monitoring, and analysis go slightly beyond what a single-person team can handle. However, logs should ideally be collected in a central location and retained for the maximum allowable duration. This ensures that incident response, troubleshooting, and investigative operations can be conducted on a reliable dataset. It is unreasonable to expect the person in charge of security (or even a larger team) to review every log entry periodically. If a budgetary and technical opportunity arises to apply automated analysis—such as a SIEM—it will mark a major win in this resource-constrained scenario.

Vulnerability Management

Continuous Vulnerability Management (CVM) is one of the lower-priority controls within the basic control set. The primary reason is that it can require a more complex setup than other controls in this group, and the initial results can feel overwhelming.

Going Beyond the Basics

Beyond the core framework, things get slightly murkier once you look past the basic group. While this is not an article about the controls themselves, the value provided by the basic control set is too significant not to explore in detail. Regarding the remaining 16 controls, remember that some will support the protection of critical data and resources (to varying degrees), while others will not. The goal is to prioritize those that yield the highest positive impact by protecting the resources handling the organization’s most valuable data, leaving the rest for periodic review.

With the true fundamentals established above, you will have a solid foundation upon which additional capabilities can be added.

Network Security

From a network perspective, there are two primary recommendations. First, collect NetFlow data from the routing infrastructure. This session data does not include the content of network communications, but it provides a summary of every communication within the environment. Cloud-based providers also offer this functionality in various forms. This benefits a one-person team by allowing rapid queries across months of network traffic summaries. Collecting network metadata is an excellent way to get fast answers to questions like, “Did any of our hosts communicate with this recently identified malicious IP?” or “Which hosts transmitted large amounts of data out of the environment?”

Another key network element is Network Security Monitoring (NSM) platforms. NSM provides high-level accounting of several key network artifacts, including DNS queries and responses, visited website URLs, hostnames, and more. Zeek NSM (formerly known as Bro) is a top choice in the open-source field. It generates log files containing artifacts from dozens of protocols, and numerous tools can analyze, visualize, and operationalize its content. Zeek is also integrated into many other open-source platforms, such as Security Onion, which adds extensive additional functionality. While a full Security Onion deployment may exceed the scope and immediate needs of a one-person team, it serves as a solid roadmap item for when more members join or when the organization’s security apparatus is running smoothly and new projects can be considered.

Outsourcing

A related consideration is when to handle these functions internally versus when to find an external partner. There is no simple formula, but a recommended strategy relies on the information priorities established at the start of the process. Identify which functions will have the most positive impact on your most critical information. From the top of that list, determine which can be managed internally and which cannot. If implementing secure configurations enterprise-wide is outside your team’s technical scope, the task cannot simply be ignored—you will need external assistance, as this is a fundamental requirement.

Conclusion

Operating a single-person security team is a daunting endeavor, but it is not impossible. By engaging in strategic planning, focusing on the basics, and building capabilities where they deliver the highest impact, even a solo security “team” can build an effective program that addresses the organization’s most vital requirements.