|
|
|
|
|
by neko_koneko
3436 days ago
|
|
Ok, disclaimer first: I've previously worked at Kaspersky Lab (incident response division).
Now, I want to say that many of the incidents that we have investigated, would have been prevented by anti-virus software (in many cases AV software was deliberately disabled by user).
And I'm talking about incidents that resulted in million-dollar thefts - not just cases of some user getting cryptolocker on their home computer.
I agree that AV software is bloated and has very large, messy and barely maintainable codebase, but I disagree with people who say that "I have never used any AV products and in 10 years have never been infected with malware" - this attitude is careless, to say the least, and in corporate environment could lead to huge financial losses.
There are many criminal groups that put serious effort in the development and distribution of malware - not just script kiddies, but professional programmers and hackers. BTW, there are also region-specific malware - so for example I would rely more on Kaspersky for detection of malware targeted at Russian businesses, than Symantec or Microsoft AVs. |
|
use security policies of the domain to only allow whitelisted applications to be run;
restrict internet use to whitelisted destinations;
configure mail servers to accept only whitelist sources, use DKIM/DMARC, and reject multipart messages.
Mandate usage of wired-only HID peripherals which are soldered to the port. Don't use wifi, and physically secure the access to network wires.
Glue shut all other computer ports.
Go all-out Saudi-arabian with people who don't comply with security policies and punish them by removing digits and public hangings for repeated offenses.
It's really that simple.