My answer would be quite boring I guess but it does the job to improve resilience:
- Analyse your system and identify potential vulnerabilities; - Analyse you vulnerabilities against your risk model (identify the most crucial ones); - Mitigate risks from most important to least one; - Rinse, repeat regularly;
What I mean is, system and network architecture on it's own often creates vulnerabilities for that risk model. Let's say you have product X,it is well patched and well configured. Except!, anyone can access it from the intranet and internet. Is this a vulnerability? Can a random attacker password spray product X ,gain access and leverage that access for $profit? It's not exactly a CVE but it can be a vulnerability.
I say invest in good security/IT architects.
2) Log as much as possible and do something with the logs. Log everything and continue to improve your SIEM or security stack based on new threat intel.
3) Low effort,high ROI low hanging fruits. 2FA everything. Mutual certificate auth where i can. Turn on bitlocker. Make people use password managers,ssh pubkey auth. If you have typical corporate firewall/proxy: block any domain that isn't categorized or newly registered.
4) this is what I think will be good ,haven't done it IRL: segment network well. Remote management can only happen from jump boxes. Be hostile against removable drives. 5) Taking first step of NIST's incident response lifecycle seriously,preparation: Playbooks(Online and Offline),checklists,emergency communication channels. Document important assets and related contact when SHTF. And actually have a routine table top excercises and penetration tests (as the corporate wallet allows)
6) I hate that I put this last,but: good security tooling. Typical stuff like an in-house sandbox,dedicated DFIR platform.
This should go without saying: you need people to do this and it really does start from the top (leadership).
This is a good one. If you have a SIEM + Log Aggregation setup and you don't have robust logging and/or aren't feeding those logs into it, you should have saved yourself some time and burned the money you spent on it.
- Risk analysis with business stakeholders (maybe they care nothing for confidentiality, but tons for integrity, or there are market regulations a security expert has no knowledge of)
As said by jesterson, there's no silver bullet in security, only adequate counter-measure given a threat model.
Set up live early warning system for spoofed/deep fake news feeds https://news.ycombinator.com/item?id=20748195
Patch and have configuration standards.
Segmentation is harder. Keep systems separated and minimize admin privilege.
It must be a regular thing. Threats change, people forget, people lower their guard.