Skip to content
Security

The cheapest security wins, in order

Before you buy a firewall, three changes that cost mostly configuration time and stop most of what we see in the field.

SYSGOT Engineering· Security team9 March 20266 min read

Most security proposals a mid-sized Egyptian company receives are a shopping list: a next-generation firewall, endpoint licences, perhaps a log platform nobody will read.

Then the incident happens through a reused password on a webmail account, and none of the purchases were relevant.

Here is the order we work in, and why.

1. Multi-factor authentication on email and remote access

Cost: usually zero. Effort: an afternoon plus a fortnight of enrolment.

Compromised credentials are how the overwhelming majority of incidents at this size begin. Not a clever exploit. A password that was also used on a site that was breached in 2019.

MFA breaks that chain almost entirely. Nothing else you can do produces this much risk reduction for this little money, and if you only do one thing, do this.

While you are there: remove any direct RDP exposure to the internet. Scanning for it is continuous and automated, and an exposed RDP port with a weak password has a measurable half-life.

2. A backup you have actually restored from

Cost: modest. Effort: a day to test, then a recurring calendar entry.

An untested backup is a hope. What we find most often is a backup job that has reported success for years and cannot produce a usable restore: the wrong scope, missing transaction logs, or a retention period that shrank when the disk filled.

Test it. Time it. Write the number down. That number is your real recovery time, and it is often the first time anyone has known it.

Also make sure one copy is offline or immutable. Ransomware looks for backups, and a sync target is not a backup: it will faithfully copy the encryption too.

3. Network segmentation

Cost: mostly configuration. Effort: a design conversation and a change window.

On a flat network, one compromised laptop can reach the file server, the cameras, the machine controllers and the accounting system. That is not an attacker being clever. It is the network doing what it was built to do.

Separate staff, guests, cameras, machines and payment traffic, with explicit rules between them, and a company-wide event becomes a single-device event. In most places we walk into, this is the highest-value change available and it needs little or no new hardware.

4. Remove local administrator rights

Cost: zero. Effort: political.

Most malware needs administrative privilege to do real damage. Users who run as administrators daily hand it over on the first click.

This one is unpopular, so pair it with a fast, low-friction way to get elevation when needed. Make the right path easy, or people will find a way around it. That is true of every control on this list.

Then buy things

Once those four are done, tooling earns real money. Managed endpoint detection, log collection with someone reading it, a properly licensed next-generation firewall with a maintained rule set.

But buying those first is a better lock on a window that is open. We have seen companies with substantial security budgets breached through a shared password, and companies with almost no budget survive because they had MFA and a tested backup.

The order is the advice.

Related work

Recognise the problem in your own estate?

Happy to talk through how it maps to your situation.

  • A reply within one working dayFrom an engineer.
  • We look before we quoteA call, and a site visit if needed.
  • The recommendation is yoursYours to take elsewhere.
  • Or call +20 109 777 8090