{"id":1574,"date":"2021-06-23T15:04:20","date_gmt":"2021-06-23T19:04:20","guid":{"rendered":"https:\/\/increasec.com\/?p=1574"},"modified":"2023-10-05T13:21:18","modified_gmt":"2023-10-05T17:21:18","slug":"smb-security-maturity-levels","status":"publish","type":"post","link":"https:\/\/increasec.com\/?p=1574","title":{"rendered":"SMB Security Maturity Levels"},"content":{"rendered":"\n<p>Level 1: Free \/ easy \/ 1 hour fixes<br>-Block China, Russia, Ukraine on your firewall and email<br>-Turn on email banner for external emails<br>-make sure PCs are running a version of Windows that gets updates;  update to Win10 can still be updated for free<br>-Verify Windows Defender is on and updated automatically<br>-Verify Windows patches itself automatically.  Set Active hours to not be annoyed by reboots<br>-Invest some time in fishing and cyber-security training.  Lots of free info on YouTube.com<br>-make sure your router\/firewall and Wifi have long passwords that are NOT the default from the factory<br>-Change your router\/firewall DNS to 9.9.9.9 + 208.67.222.123<br>-while you&#8217;re in the router make sure uPNP (Universal Plug and Play) is OFF<br>-type your email address into haveibeenpwnd.com; if it says breached, change your password<br>-install a password manager; BitWarden is free, use it to generate long, complex passwords<br>-create some HoneyDocs and sprinkle them around your shared files<br>-standardize on a non-email company wide communication method; Microsoft Teams, Slack, NextCloud etc.<br>-make sure you have backups and test them<br>-ensure users are using a secure browser and not IE<br>-sign up for PayPal; don&#8217;t use credit cards online unless its thru PayPal<\/p>\n\n\n\n<p>Level 2: Cheap \/ 1 day fixes<br>-enable GeoFiltering for your email logon<br>-turn on 2FA for email and anything money related (email is used to reset passwords)<br>-turn off NetBios, LanMan, WPAD and LLMNR on PCs.  Easier if you have an AD Domain<br>-replace SSL based VPN with IPSec VPN \/ RdWeb \/ NextCloud<br>-disable macros in Office.  Easier if you have an AD Domain<br>-disable PowerShell on workstations.  Easier if you have an AD Domain<br>-setup an SPF record with your ISP\/DNS provider<br>-setup OFFLINE backups; think external harddrives + some IoT power plugs<br>-make a guest wifi network and put all cell phones and IoT devices on it<\/p>\n\n\n\n<p>Level 3: Projects that take planning but provide higher levels of security<br>-Offsite laptops; install a remote management security tool.  N-Central, SentinelOne etc<br>-Randomize Local administrator account passwords; Microsoft LAPS is free but takes time to implement<br>-collect and analyze log files<br>-setup DMARC &amp; DKIM with your ISP\/DNS provider<br><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Level 1: Free \/ easy \/ 1 hour fixes-Block China, Russia, Ukraine on your firewall and email-Turn on email banner for external emails-make sure PCs are running a version of&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[4,3],"class_list":["post-1574","post","type-post","status-publish","format-standard","hentry","category-uncategorised","tag-security","tag-smb"],"_links":{"self":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/1574","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1574"}],"version-history":[{"count":16,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/1574\/revisions"}],"predecessor-version":[{"id":2698,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/1574\/revisions\/2698"}],"wp:attachment":[{"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1574"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1574"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1574"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}