Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Security Everywhere: One Unmanaged Desktop Is All It Takes
Articles

Security Everywhere: One Unmanaged Desktop Is All It Takes

ISBuzz TeamBy ISBuzz TeamJune 18, 2014Updated:May 2, 20255 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
One Unmanaged Desktop Is All It Takes
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

An unpatched and unmonitored Windows desktop is an open gateway for viruses and trojans to sneak onto your network. Besides malware, these desktops can also act as a portal for malevolent users to steal or delete critical company data. If a criminal hacker can access your machine, they will try different options to steal company data or gain access to your network looking for bigger prizes.

Let’s look at the basic steps you need to take to secure your desktops.

OS and third party vulnerabilities

Mark the first Tuesday of every month on your calendar, this is Microsoft’s ‘Patch Tuesday,’ the day Microsoft releases new security fixes for consumers and enterprises. Microsoft recently announced the MyBulletins site to help personalize and track security updates for your MS products including IE, Office, Server and Developer tools. The My Bulletins site is a great tool for the small-medium sized business looking to track status of deployed software and save on costs.

For enterprises and mixed environments, Microsofts’ System Center Configuration Manager provides remote control, software and patch deployment/management for Windows, Unix/Linux and OS X. Other popular software management solutions include Symantec’s Altiris. But patching the base OS is only the first step…

If you don’t have your desktops locked down and allow users to install applications, then there will be unpatched third party software programs, some with malware attached, sitting on your enterprise. If you can’t restrict local admin rights, then take the necessary defensive steps to neutralize your environment:

1)    Deploy and update antivirus and anti-malware software on the desktops. Find an established product that also offers rootkit and keylogger detection. A few free Windows options include Defender on Win8, MSE on Vista & 7. For an independent summary of AV solutions, check out http://www.av-comparatives.org/

2)    Perform daily malware scans for known software threats and rootkits using a third party solution or free solutions such as Microsofts’ Malicious Software Removal Tool or Windows Defender Offline

3)    Proactively keep on top of updates for third party software, Including Java, Adobe Reader and Flash. These common applications, in use everywhere, are responsible for more than half of the vulnerabilities exploited by malware.

Set a desktop idle time-out lock

Institute a policy to lock desktops automatically after a certain number of minutes of inactivity. There are differing opinions, and situations, that call for a timeout from five minutes to fifteen. Depending on the proximity of the desktop to publicly exposed areas, and the confidentiality of the data on the desktop, best practices for timeout will vary.

Encrypt the hard drives

For Windows users, there are a few free options including BitLocker from Microsoft and CompuSec from CE-InfoSys. For OS X, the option is FileVault. For best practices, keep your encryption passwords separately stored and offsite in a secure location. In enterprise environments, look at the Bitlocker MBAM tool. it allows for detailed management, key recovery, compliance monitoring and reporting.

– Note that as of May 28, 2014, the freeware drive encryption software TrueCrypt has been deemed insecure and should not be used.

Lockdown USB ports

Unsecured USB ports are an invitation to hackers to upload key loggers or provide access to steal data. Locked USB drives should be the default rule, not the exception. With Windows registry changes or group policy objects, storage devices can be blocked from USB mounting but keyboard, mice and printers can still be plugged in and connected. For more flexible enterprise options, products such as USB Lock RP provide extended USB port management and USB encryption options.

Password Protect BIOS / Boot Loader

Modern PC’s have the ability to password protect the system BIOS. Consider this the critical first, step to take to help secure your desktops from compromise. As with all passwords, try not use one standard one across all desktops and don’t use the same BIOS password as your Windows admin password.

Add network port security

Imagine visitors coming into your workplace and plugging their personal laptop into your network. Often it’s an innocuous salesperson or contractor who only wants to get internet access at work, but unchecked, their personal pc can be act as open portal for malware and network infiltration. The easiest way to manage what machines are allowed to connect on your network ports is to configure port security at the switch. Work with your network administrators to implement a strategy for port security and you’ll have one less worry about rogue devices connecting into your LAN.

Secure Physical Access

Require use of cable locks on laptops, and in less secure public areas, desktops. Make sure the cable lock is secured to a solid, re-enforced stationary object. Looping it around the leg of a desk that can be easily moved won’t provide any protection.

Finally, implement a company-wide computer security training module and consider hosting computer security training seminars across the enterprise. Inspire employees to take a proactive approach to best practices computer use.

Happy and Safe Computing!

By Brian Thomas

Passionate professional with 17 years’ experience providing Tier-4 data solutions in all disciplines of IT including Network/Server administration and Information Security. Proven experience in HIPAA, ISO 27001 and PCI compliance.

https://twitter.com/InfoSec_Brian

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}