Ten Simple IT Security Rules for Early-Stage Startups
chris-haarburger.com
chris-haarburger.com
One admin proactively put a Baywatch photo as wallpaper : - )
We also "got Hoffed".
At another place I worked, the devs took a screenshot of their desktop and made it the lock screen image, so it looked like it was unlocked, just to annoy security (i.e. me!).
Overall the "buy treats for the office" rule helped to establish the habit even though I think we never followed through with it. We mostly just told newcomers that this is the rule and they locked their screen as expected. And ofc it turned "Hey, lock your screen!" into "Oh, you want to treat us?" which makes for a more cheerful way to remind people.
You are legally liable for the messages you send; the access rights you have etc;
This is why shared accounts are one of the first thing a CISO/CIO will try to kill. It makes liability lie with the company and not the individual.
You will not be able to hide behind the fact you refuse or fail to secure your devices if someone sends a threatening message from your email account or if someone deletes the prod database.
Where shared credentials are required there is usually an access log associated: which ties individual named accounts to shared access rights in the event of eDiscovery or forensics.
Some trust is good, but if we really believed in trust then we wouldn't even both having access accounts with our names on them.
I recommend Deviant Ollam’s YouTube channel for an entertaining way to expand your assumptions
The real reason for the policy is so when some dumbass sends a dick pic from their work computer and gets fired for it, they can't claim "it wasn't me" and expect to keep their job.
If you can't trust your coworkers in the same office, you should absolutely have private rooms that get locked, and shut down your machine completely every time you leave it.
And it gives some incentive to everyone to watch each others backs and keep each other honest. Which is how actual trust gets built IMO.
Knowing someone will catch and make sure you know you screwed up on something important before it became a bigger problem, rather than ignoring it and letting it fester.
Higher stakes areas, but most military combat MOS, LEO, skydiving, and climbing groups do similar things - always check that everyone around you has their act together (and give them shit if they miss something) so that there isn’t something serious that gets missed and gets someone or the group killed.
Or in this case, something serious gets missed and the company gets ‘killed’.
Think of it as tough love. And if they can dish it out, they’d better be able to take it or that is a whole nother level of ribbing that’s coming.
Precisely. So if you want to be safe, shut down completely the machine. Then all of the people you listed can't access it.
Suspend adds major security issues above and beyond either of these scenarios.
The majority of scenarios, none of those folks are able to do much to a locked machine without powering it off, which resets it to the state you were referencing.
They could install a hardware keylogger of course, and none of these protections would help.
It’s all tradeoffs. SCIF’s are better still after all, and a nightmare productivity wise.
The price of security is always wasted time.
> The majority of scenarios, none of those folks are able to do much to a locked machine without powering it off
But they are able to unlock it if they saw you unlock it yesterday.
If you have an encrypted hard drive and the key is in a usb you carry with you, they can't do anything.
Ah yes, the excellent security practice that if you see someone messing with someone else's equipment that's completely normal - praiseworthy, even - and if you don't challenge them on it, you get donuts.
(1) Store everything in a cloud, not on the laptop? You've got to work on the stuff, so it needs to be on the laptop. You should have automatic synchronization, and the user shouldn't really have to worry about it.
(2) You shouldn't use a commercial cloud. Hosting your private cloud is incredibly easy (OwnCloud & Co), and whoever is responsible for your IT should ensure that backups happen. Cloud providers don't really provide backups. When iCloud loses your files, good luck with that. Someone accidentally deleted a file some unknown number of weeks ago? If you have your own backup system, finding it is easy. Relying on Google or Dropbox? Maybe you'll find it in the version history (if you have versioning turned on), and maybe not...
I’ll use Microsoft as an example since that’s what I’m familiar with:
- Users store personal files in OneDrive (stored on their device, automatically synchronized)
- Shared files in Sharepoint or Azure File Share
- Enable Azure backup of the file share, or use a cloud service that runs Veeam for you (iLand, etc) to backup your Office 365 environment (including Sharepoint and OneDrive)
The founder is the “IT person” usually, and they don’t need to worry about running backups. That’s a recipe for “hey I need this file restored” followed by “oops our backups haven’t run for 9 months” (seen this first hand, far too often).
I don't believe managing my own cloud is anywhere near the top of my list of things that matter most. We pay something like $8.50 a month to just have the devices backed up using a backup service. It would cost significantly more for me to maintain OwnCloud.
1. We are a Microsoft 365 shop, so OneDrive stores versions of files and all that. Admittedly this is not a "backup" necessarily, but it does serve a portion of the purpose of backups and are far more easily accessible to users themselves.
2. We also have a backup service running on every company issued laptop that backs up to a backup service.
What I am not advocating is that a small team should setup their own cloud for the purpose of backups. That's a lot of work and maintenance. I am an IT team of 1. My time is better spent on actually getting work done, not playing around with self hosting stuff and maintaining that.
Backups are important, otherwise I wouldn't be spending thousands of dollars on it in my tiny little budget each year. But I disagree pretty strongly with the priority of _how_ to do backups.
This is really good advice though: "Encrypt your hard drives using FileVault (macOS) or Bitlocker (Windows) and never leave your machine without locking it."
shouldn't we follow the 3-2-1 backup rule?
"The 3-2-1 backup strategy simply states that you should have 3 copies of your data (your production data and 2 backup copies) on two different media (disk and tape) with one copy off-site for disaster recovery"
What is the point of having a 2nd factor, if you then put the 1st and 2nd factor into the same place again (password manager)?
It’s a trade off of practicality, in that both in one place is still (usually) an improvement for less technically inclined users who will do well to just use the password manager.
Most people's threat model doesn't really include having to worry about having both of them in the same tool. If your threat model does, absolutely keep them separate. But I can say, that at least for my team, my biggest issue is really just getting people to use a password manager... I have two users, both of them executive level, that haven't opened their password manager in nearly 4 months.
I'd be far far happier if they used a password manager, even if their 2FA codes were in that same password manager, it would be a significant increase in security over whatever is currently happening.
For shared accounts this is often critical, where say, IT staff need to have 2FA access to manage some line of business cloud app, but you don’t want to setup 20 named users in your IT department in 30 different apps (Adobe, CRM, etc).
Password managers geared toward IT will have good audit trail, so each employee still 2FA’s into the password manager, and it’s logged who viewed passwords/codes when, so you still have named visibility into which IT staff are making which changes.
PassPortal (by N-able) is one I’ve used that did this for IT teams.
Personally and at work, I've started to think about two-ish security classes.
The first are the top security things, e.g. my password manager or my github account. For these, I want my password and my second factor far away from each other and I won't add this second factor to my password manager to make it hard to compromise both of them at once.
But then there are less important accounts and at work, shared accounts even. Here you get a small benefit: Unless you compromise the secret behind the TOTP (which is the one kind you'd generally store in a password manager), if you can see my password + token for some reason, you only have access for a minute or so. Like I can finally type my password into slack without the account being immediately compromised.
And I can get this small edge of security for these less important accounts for almost no effort from the PW manager.
Put differently - if you manage to break into my password manager, you'd get access to my less secure accounts either way, no matter if I store the TOTP or not. But having the TOTP active might make some attack scenarios harder, like if you MITM a login request.
Like google voice or similar doesnt exist.
Google voice and other "non-traditional"/VoIP services are sometimes blocked by websites sadly.
P.S. dishonorable mention: Apple Business Manager uses SMS 2FA only, at least you can have multiple admin accounts
1) no mention of U2F; vastly superior to OTP
2) “watch out for phishing” is near useless advice. A well-written phishing email will catch the most seasoned security professional. The only fix is: see #1 above
I disagree, this "most seasoned security professional" won't reply to that e-mail if "nobody will ever ask for your credentials on any channel" is part of the hygiene. No matter how well written it is, even if the CEO got his actual legit e-mail hijacked it should not work. Follow proper procedures or fuck off is the only valid answer.
A well-timed, creative phishing campaign can include things like a “regarding your employment status” right after the company announces layoffs, if you’re talking malicious actor and not watered-down security awareness exercise
1. The primary employee auth system (we use Google Workspace which is common among startups, but this is certainly not a requirement) should be protected with passkeys (preferred) or as a U2F hardware key second factor.
2. For other SaaS products that your company uses, if they offer OAuth with your primary provider (and many/most do), use that.
3. If they don't, only then use a new password stored in an approved PW manager (which should obviously not be LastPass). The order of preference for second factor should be hardware key -> TOTP -> SMS 2FA based on what that provider allows.
I work in an office, among colleagues: if I cannot trust them, the company has a huge problem, independently of my unlocked screen.
Asking Karen in accounting to give 2 flips about filevault is absurd. Create a corp policy that encrypts by default.....this is what I'm talking about
If this is the case then their first rule should be "1. Get some new IT."
Although some posts are clearly AI generated.
Youre incorporated so "early stage" is over; grow up. you have investors and you have a legal duty to protect them from risk. IT Security is part of risk managent including the impact and severity of threats and exploits. take some time to educate yourself about what this all means, or do one better and hire an infosec person. you should also have a disaster recovery plan and business continuity plan for things like ransomware attacks and disasters.
Be an adult and use a risk management framework communicated to senior leadership and endorsed as part of your operating model. https://csrc.nist.gov/Projects/risk-management/about-rmf
https://blog.lastpass.com/2022/12/notice-of-recent-security-...