Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Strengthening Corporate Governance over Cyber Security current page
Link copied

Strengthening Corporate Governance over Cyber Security

Feb 2, 2017
Author:
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor
Blog banner default
Strengthening Corporate Governance over Cyber Security
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor

Strengthen Corporate Governance

We are squarely footed in 2017, with 2016 leaving many lessons to learn. The outbreak of hacks, including the one that impacted the presidential election, IoT devices, and others have companies trying to strengthen their defenses against intrusions. To mitigate these risks, should they strengthen their corporate governance efforts, including disclosures and board committees, to focus on cyber security? The simple answer is yes, but the reasons are not obvious.

Adhere to Best Practices

Teams from the board of directors down to security engineers do not need to invent anything new (yet) to mitigate the effects of modern security risks plaguing our government, the cloud, or to our personal computers. We do not need to necessarily purchase new technology (of course some do if they are not doing anything already) to mitigate the risks. We just need to do a much better job at the security best practices we already know. Sometimes a product is needed but most of the time it’s just doing the basics and doing them very well.

Ensure These Areas are Addressed in Revised Board Reporting

Here a few areas that if every company did them backed by solid service level agreements, and leveraging existing or new tools, the vast majority of risk and attacks could be mitigated:

Vulnerability Assessment, Patch Management and Penetration Testing

If you can document your known risks, patch them or apply configuration changes, and ultimately test them like a hacker, you are removing the low hanging fruit attackers use to gain access. This is effective against web application threats to drive-by browser attacks. Keep all systems – from desktops to servers – fully up to date and do it well.

User Privileges

The crown jewels in every company should be protected from unauthorized users. This includes databases, servers, infrastructure, middleware and workstations authorized to access the information. Users should never be running as administrators anywhere, at any time, unless they absolutely need to. So remove admin rights, control access when needed, and document all privileged transactions so you know when the crown jewels are being inappropriately accessed.

Application Control

Whether you subscribe to allow listing, block listing, grey listing, reputation based controls or application risk compliance, monitoring the applications executing on your assets is critical. Simple anti-virus solutions alone do not do this. Monitor applications and identify or block the exceptions that do not fall into acceptable use parameters. This is critical to maintaining the operation integrity of your environment and if it is done well, can block or alert on any new or malicious code that attempts to execute.

Back to Basics

Years ago Burger King tried this philosophy and it saved their business. Without a solid foundation of basics, anything you try on top could crumble like a deck of cards. This means that basics like Active Directory, DNS, NTP, etc all should be working well before you layer on any tools from network management to security solutions. Without the basics operating efficiently, the reliability of any tool that uses that could be called into question and the results intentionally altered or difficult to interpret.

Training, Training, Training

Educating the masses – from executives to interns – is critical to any safe computing environment. All users should learn how to identify a phishing attempt or how to manage their passwords, smart phones, and even identification badges. The human element is the weakest link in the entire attack chain and training teams well should be a high priority for the management of any organization.

Strengthening corporate governance over cyber security is always a good thing, but there are several steps every organization should take as part of an overall governance strategy. I’ve outlined these steps above and encourage you to take a look at your organization to determine where your weaknesses might be before that report comes due to the board. Take the first steps today. Download our free Privilege Discovery and Reporting Tool and Retina IoT scanner to uncover where your biggest risks might be.

Latest Posts
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
Related
  • How Privileged Access Management Can Help You to Protect Your Big Data
    Nov 7, 2017 How Privileged Access Management Can Help You to Protect Your Big Data
    Blog
    1m
  • BeyondInsight/Retina CS 6.6: Reporting Enhancements, Docker Image Scanning, MSP Improvements
    Jul 27, 2018 BeyondInsight/Retina CS 6.6: Reporting Enhancements, Docker Image Scanning, MSP Improvements
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.