Key Security Golden Rules
Top security tips and guidelines to keep your network and assets secure.
Keep it simple, safe and secure.
Protect and encrypt sensitive data. Never store/save client data unencrypted.
By default - don’t save sensitive data that’s not needed.
Avoid phishing scams - beware of suspicious emails, links, files, phone calls.
Be careful with what you click - for example - someone sharing a great investment opportunity or client feedback via Google Drive - don’t click.
Never leave devices unattended.
Don’t use public/unknown WiFi.
Always use 2FA. Don’t use SMS as 2FA, as it’s prone to SIM Swap attacks.
All new services, software, accounts, etc. should be reviewed - conduct due diligence.
Follow the Principle of Least Privilege, Permissions and Visibility - code repos, S3 buckets and similar should always be defined as private.
Refresh passwords and remove user accounts that are default or not in use.
Report any suspicious behavior and indicators - communication is key.