Call us now! 203-327-5700

  • Shopping Cart Shopping Cart
    0Shopping Cart
GC Infotech LLC Work Smarter!
  • Home
  • IT Services
    • Free IT Consultation Form
    • Business Continuity & Disaster Recovery
    • Cloud Computing & Virtualization
    • Computer Network Support
    • Network & Server Maintenance
    • Office IT Relocation Service
    • Website Development & Design
  • About us
    • Our Story
    • IT Consultants
    • Our Methodology
    • Competitive Advantage
  • Learning Center
  • Technology Partners
  • Testimonials
  • Customer Remote Support
  • Contact
  • Menu Menu
Data Protection

How Much Cybersecurity Is Enough?

Cybersecurity investments can be infinite: Here’s how to find your floor.

You can make unlimited investments in cybersecurity and still never achieve that nirvana of being “totally secure.” At the same time, service interruptions or losing customer data are so detrimental to your company’s reputational trust and financial bottom line that security is paramount. So, just how much time, effort, and money should your organization invest to ensure it’s secure?

Because cybersecurity perfection is elusive, it’s important to first determine your floor–the minimum amount of security your organization needs to meet your base-level requirements. These should include:

  • Recoverability of data and systems should a catastrophic breach occur
  • Meeting foundational security best practices for current threats, such as employing multi-factor authentication (MFA), deep packet inspection, lateral movement defenses, stringent password hygiene, and security operations center services/endpoint detection and response tools
  • Adequate security to meet ethical responsibilities (and be able to demonstrate due diligence in) protecting organizational/customer data
  • Meeting all regulatory requirements around data protection and privacy, pertaining to your specific industry and organization

Recoverability: The importance of backups

In our experience, few companies understand that backups are one of the most important security controls for an organization’s future. All breaches end with data exfiltration, backup/mass destruction, or both. To disrupt the breach pattern, organizations must first assume it is impossible to prevent all breaches. Threat actors target backups for encryption or destruction 93 percent of the time in attacks like ransomware, so it’s essential to ensure you can recover without resorting to paying ransoms (because even ransom payments don’t guarantee recovery).

Prioritize having stringent controls within and around your backups while also ensuring that threat actors cannot move laterally in your network to access, damage, or destroy these data stores. Also take great care that these safeguards are well-orchestrated, secure, resilient, redundant, and complete, which protects against the risk of total loss. Backups must also be “immutable,” meaning incapable of being changed, deleted, or moved outside of set retention policies or strict access procedures.

Protect sensitive data and meet regulations

Every company has–at a minimum–an ethical obligation to protect the data they hold in trust about their employees, customers, partners, and operations. Law firms must protect their clients’ private and sensitive legal case information; healthcare organizations must maintain patient data privacy; critical infrastructure and government entities are the custodians of highly sensitive data, the loss of which can have serious consequences for people’s lives and national defense.

Most industries also have a varying number of legal obligations to protect data. Regulatory frameworks like HIPAA, GDPR, FedRAMP, and others outline standards that applicable companies must meet to ensure data security and privacy. The cybersecurity rules adopted in July 2023 by the SEC further mandate additional governance, policy, and process requirements for publicly traded companies, holding C-level officers accountable. Your organization should meet applicable requirements and be able to demonstrate due diligence against ethical goals and frameworks.

Insurance carriers and clients may also dictate minimum security requirements.

How can you meet your minimum requirements?

The key to security efficiency is understanding how breaches progress, including tactics and patterns (“breach context”), and then working to disrupt the breach context with highly prioritized investments and efforts.

There is a pattern to breach progression: The attacker compromises credentials; creates persistent network access; elevates access; and then moves laterally in the environment to execute malicious acts (including exfiltrating data, encrypting, and/or destroying backups).

Effective security requires moving backwards in the chain. First, ensure that your backups are impenetrable and recoverable. Next, secure systems so that lateral movement is impossible (by rigorous application of MFA on all administrative controls). Then, focus on locking down credentials and endpoint access (and so on).

To keep this process scalable, it is important to do all these tasks with full knowledge of the tactics, techniques, and procedures of today’s threat actors–how they are compromising organizations today in real-world breaches–so you can prioritize your efforts and focus your dollars. Security frameworks like NIST and many organizational security programs are too blind to current threat patterns, tactics, and methods to be effective. By focusing on defending against in-use threat tactics and patterns, companies can hone their efforts. It’s equally important to only buy tools and solutions you or a third-party team have the skills and breadth to fully utilize, rather than purchasing expensive and complicated tools that sit idle or underutilized.

Achieve a security program that’s just the right size

Most people in IT and security understand you can’t create perfect security. But with knowledge of threat actor tactics, as they change daily, IT teams can disrupt the breach pattern at every stage and achieve relevant, timely defenses where they are the most vulnerable. While access to real-time threat actor data can be challenging, some managed security services providers can help. Coupled with a solid focus on meeting regulations for your specific industry, you can arrive at a right-sized, focused security program.

Contact our team of experts to learn more about developing a comprehensive cybersecurity training program for your business.

If you are looking for an expert to help you find the best solutions for your business talk to GCInfotech about a free technology assessment

Published with consideration from Inc.com SOURCE

January 7, 2025/by John Murray
https://gcinfotech.com/wp-content/uploads/2024/09/Sept-23-24.2.png 200 204 John Murray http://gcinfotech.com/wp-content/uploads/2018/05/gcinfotech_logo_4501-l-300x91.jpg John Murray2025-01-07 09:43:032025-01-07 09:43:04How Much Cybersecurity Is Enough?

Categories

  • Business Operations (29)
  • Cloud Computing (11)
  • Data Protection (25)
  • Equipment (18)
  • Hedge Funds IT Services (1)
  • IT Solutions (5)
  • Law Firms IT (13)
  • Mobile Workforce (10)
  • Network Support (3)
  • News (2)
  • Office 365 (10)
  • Online Backup (1)
  • Security (50)
  • Website Development (5)

Archives

  • September 2026
  • August 2026
  • July 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • November 2025
  • October 2025
  • August 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • May 2022
  • April 2022
  • March 2022
  • January 2022

Office Hours

Monday – Friday:

8:00 AM – 5:00 PM

Saturday – Sunday:

Closed

An Accredited Business

Click for the BBB Business Review of this Web Design in Stamford CT

GC Infotech LLC

2009 Summer St
Stamford, CT, United States

(203) 327 5700
info@gcinfotech.com

Categories

  • Business Operations
  • Cloud Computing
  • Data Protection
  • Equipment
  • Hedge Funds IT Services
  • IT Solutions
  • Law Firms IT
  • Mobile Workforce
  • Network Support
  • News
  • Office 365
  • Online Backup
  • Security
  • Website Development

Latest Posts

  • Essential VPN features to look forSeptember 11, 2026 - 1:44 pm
  • Elevating search rankings through smart image optimizationAugust 17, 2026 - 2:51 pm
  • Virtualization vs. cloud computing: What’s the real difference?July 15, 2026 - 10:46 am
© Copyright - GC Infotech - Enfold WordPress Theme by Kriesi
Scroll to top Scroll to top Scroll to top
  • Remote support

  • Pay a Bill

  • Call us 203-327-5700