Protect Your Business From A Cyber Kill Chain

Email, Phishing compromises are more personalised whilst malicious attachments and spoofed domains are more convincing. These cyber kill chains are nuanced, and potentially devastating for targets. That’s why nowadays it’s incredibly important to have the best top-tier, layered security protocols protecting you and your business.

What is a Cyber Kill Chain?

Simply the Cyber Kill Chain is the course of actions that a cyber criminal will perform to attack their victim. Most of these kill chains follow a core structure with variations based on the attack type and personal style of the cyber criminal.

The phases usually go in the order of;

Breaking in

The first step of any cyber criminal is to access the system undetected to avoid raising any alarms. This first step normally causes no immediate damage. While there are many ways of breaking into an employees system, phishing scams has been reported as one of the most common choices of accessing a system. Malicious attachments which can lead to malware being spread throughout the system without your knowledge.

Once Malware has been integrated within the system then it is an extremely difficult and expensive endeavour to then get rid of it. In 2018 a shipping conglomerate had malware spread through the entire system costing the company £300 million.

Investigating your system

The next step a cyber criminal would take is to investigate the system familiarising themselves with it. They will use specialised tools to identify areas that have vulnerabilities or areas with valuable assets like bank details or logins. More times than not this process is completely undetectable.

A report from IBM found that the average breach goes undetected for 212 days. However, depending on the type of attack these cyber kill chains can might only span the course of a few days or even hours.

Executing an Attack

Once your system has been breached and surveyed and the cyber criminal has determined that they have enough information on your device and its contents they will execute the attack. This is when the cyber criminal decides the fate of your system. 

They could hold it for ransomware locking all your files and data until you pay a sum of money for them to release them. Even if you pay they may not release the files demanding more money.

They could just want to steal your information which can then lead to identity theft causing you problems in the long run.

Some hackers just like to destroy your system for no apparent reason. Activating software changing system code to make it unusable or removing it entirely along with all your files.

It is important to note that this is a version of a cyber kill chain, kill chains are very customisable, sequential processes. The process is all dependant on what the cyber criminal wishes to gain out of their work.

Usually the gain is always financial. Hackers can and will attack anyone, conducting small raids on individuals or more sophisticated large attacks on companies. Hackers can cause a lot of damage and trouble in an extremely short amount of time.

How to protect yourself from cyber criminals

There are two common threats that your business will face. Business email compromise (BEC) and ransomware. With a BEC attack cyber criminals harvest accounts and credentials from an executive or management team, impersonate them and persuade employees and clients to release valuable information. This can span from employee payment information and wire transfers. 

Ransomware also often starts with email, and has become the most common from of extracting money from small to medium sized businesses. In order to counter threats like these you need to have a layered security approach that can counter unique attack types and kill chains.

Security Monitoring

A solutions such as a Security Operations Service combines cutting-edge Security Information and Event Management technology and established threat intelligence to track privilege elevation, data leaks and breaches, suspicious network activity, user identity and account lockouts and real time endpoint monitoring.

Endpoint protection provides a safety net after an employee engages with potential malicious content, this catches the malicious content before it can spread into the system.

This gives your IT team a chance to intervene so they can identify and eliminate threats as well as take precautions on other machines.

Firewalls

Firewall is a word thrown around but not many people actually know what it does. Simply it stops any non-requested data from entering a network. That’s because it identifies the requested code and will only let that exact code through.

Firewalls can also be configured by your IT team so strict parameters can be set around inbound and outbound mail. They can establish certain rules that need to be met for things such as attachments, links, forwarding and geofencing. Other tools can be utilised such as single-sign-on and two factor authentication for an additional layer of behavioural analysis.

Having a strong network security can go a long way into protecting your business.

Endpoint protection

Endpoint protection identifies suspicious user actions and behavioural patterns. There are many programs such as Microsoft InTune which provides a single dashboard which your IT team can monitor and respond to. 

With InTune for example an IT team can view enrolled endpoint devices and accessed resources, ensure that the compliance meets with organisational standards, access reports on (non)compliant users and devices, remote wipe data from lost, stolen or retired devices and push certificates for easy access to WiFI or network VPNs.

Here at ATS Connection we want to ensure that your business is protected from cyber criminals trying to access your private data. The cost of setting up a great cybersecurity is far less than the costs that you could receive if you lost data. Outsourcing your cyber security have great benefits too!

We offer great cyber security packages for both businesses and individuals along with 24/7 monitoring.

Utilising RMM in Business

What is RMM?

Remote Monitoring and Management software is one of the most useful and important software programs that we use as an IT company.

It lets us support our clients wherever we are, and wherever they are.

RMM allows us to support our clients faster and address problems with minimal user interruption. Support-wise, RMM allows us to remotely control the computer, we can see the screen and perform inputs such as typing. This means we don’t have to always go on-site to resolve an issue, reducing callout charges.

More than a remote

RMM does so much more than just letting us control a computer. We can completely review the workings of the computer such as how hard certain components are working, storage space, fan speed, heat generated, and more. With this information we’re alerted to problems before something can go critically wrong, we can take actions to stop an issue progressing.

Scripts and Automation

Scripts and automation give us more time to focus on the important things. We can set certain alerts and severity scaling to warrant appropriate scripts. Usually used on low to medium scale alerts an automatic response can be made, scripts can be sent and run through the RMM to fix small issues.

We run scheduled thorough audits on many of the devices we cover to scan for problems where we can then take action based on the output. Security audits are also performed via script deployment, which return detailed security reports.

Quick jobs are also very helpful in performing pre-written scripts, this can let us administer patches and updates without interruption. We can also install some apps, which makes deploying software over a large company much quicker.

Policies

Polices can be applied globally or to certain sites, depending on how managed a company wants their devices. Policies can also be configured with scripts and automation, some companies may always require a certain software in their devices. With policies, software can automatically be downloaded and kept up to date if it were removed or if a new device was added.

Policies are also great for making sure that software programs and operating systems are up-to-date, improving the security of devices and their performance.

Reports

When requested by the client or needed by us, reports globally or per site can be generated and give us an outline of;

  • Usage over a period of time.
  • Current status of installed software programs and versions.
  • Storage capacity.
  • Average lifespan of the device.

Want more control over your business IT system?

ATS Connection can offer your business fully and partially managed IT Support. All our retainer business clients are enrolled to our RMM software, so there’s no extra costs. We always stay proactive with our clients systems, and RMM makes that easier and more precise.

Everything your business needs to know about SoGEA

What is SoGEA broadband?

SoGEA stands for Single Order General Ethernet Access, a bit of a mouthful, probably best we stick to the abbreviation. This line utilises the existing copper phone line to connect the network, these phone lines can be found in almost every building in the country. However, instead of phone calls they are repurposed to transfer data.

SoGEA is an interim solution for areas that currently don’t have access to fibre connection. SoGEA is quicker and cheaper to install than Fibre to the Cabinet (FTTC) because it doesn’t require any new infrastructure.
Also due to it being a single order line issues can be identified and resolved quickly, another perk is the better service that you’ll receive. Without the phone line interfering traffic is gone meaning you receive better connection speeds.

What’s the difference between SoGEA and FTTC?

Fibre to the cabinet is currently the most common type of broadband connection. Utilising a blend of copper and fibre wires to deliver your property broadband. However, your top speed will always be determined by the slowest part of the wire.

The main difference is mainly within the infrastructure, currently a FTTC connection has a phone line with a fibre broadband connected over the top of it.

Openreach has launched SoGEA, this means no copper phone line is needed. SoGEA broadband just needs to be ordered with no line rental to worry about.

What’s the difference between SoGEA and FTTP?

Fibre to the Premises/Property is a fully fibre connection, from the supplier to the property it is complete fibre cable. Full fibre is becoming available to both residential and business properties but Openreach faces a challenge to supply all the properties with full fibre. SoGEA provides an interim for your property if fibre is not yet available.

FTTP has un-rivalled speeds, if FTTP is available it should be the first choice. Realistically FTTP is the fastest we will be able to go for a while unless we find a way to move something faster than light.

Both are easy to install, cost-effective, and easy to fix. FTTP is an ideal solution for businesses which rely on high internet speeds especially with the move over to VOIP systems.

Do you need to move to SoGEA?

You may know that Openreach are shutting down the ISDN and PSTN network in 2025, many businesses and households still use this connection despite the shutoff being right around the corner.
If Fibre isn’t available for you then you may need to consider moving to SoGEA sooner than later.

Need to move? We can do that for you. We offer super-fast SoGEA and full fibre broadband options.

Want to know what speeds you can reach?
Get in touch today for a quote same day.