Endpoint: detection and response
Signature-based blocking is not sufficient on the endpoint; behavioral detection and remote response capability are required. Isolating a device, stopping a process and collecting evidence should all be possible from one interface.
- Isolation can be applied remotely and quickly
- Evidence is collected without powering the device down
- Exception lists carry a reason and an expiry
- Server and workstation policies stay distinct
Network: segmentation and visibility
On a flat network, one compromised device reaches everywhere. Segmentation raises the cost of lateral movement; traffic between segments opens only in the required direction and on the required ports.
- Segments follow business function, not floor plans
- Inter-segment rules are few and each is justified
- Visibility into encrypted traffic is planned deliberately
- The management network is separated from the user network
Email: the most used entry point
Most attacks still begin with email. Authentication records, attachment and link analysis, external sender marking and a user reporting path are built together — and a report must land in an analysis queue.
- SPF, DKIM and DMARC are published and in enforcing mode
- External senders are marked visibly in the interface
- One click sends a user report into the analysis queue
- Messages found late are retracted from mailboxes
Web and cross-layer coherence
Web access and the layer in front of the application must share the same identity and the same event stream as the other three. Coherence comes from events converging in one place, not from products sharing a brand.
- Events from all four layers converge into one stream
- Identity context carries across the layers
- The same indicator does not differ between two consoles
- Gaps between layers are tested on a regular basis