Network Security Best Practices - Check Point Software

Network Security Best Practices

The modern enterprise is increasingly distributed and cloud-centric, which has dire implications for cybersecurity. The attack surface has never been greater, and now cybercriminals have become acutely adept at exploiting this new reality. The key to overcoming this challenge is following up-to-date security best practices, or zero trust security, which is based on the precept of never trusting anything (outside or inside the organization’s security perimeters) but balancing a realistic user experience.

The Importance of Network Security

Businesses, large and small, need to secure networks from the next attack. As we learned in the 2021 Security Report, threat actors are opportunists. When the pandemic began and workers shifted to a work from home model, cyber threat actors took advantage of vulnerabilities in VPNs and stepped up phishing attacks targeting remote workers.

In the report there were 5 simple, easy to remember recommendations for improving your cyber security stance:

If there is one takeaway, it is to adopt a cyber security mindset. To quote Dr. Dorit Dor, VP Products at Check Point, “security is an enabler that unlocks innovation and helps to safeguard the future – for all of us.”

5 Network Security Best Practices

With a growing and evolving cyber threat landscape, effective network security is vital for every organization. We’ve compiled a list of the top five network security best practices to help your organization protect itself against Gen V cyber threats:

1. Segment, Segment, Segment

The first best practice is to segment your network into zones. Basic network segments for a perimeter-based network firewall in a small organization are designed to isolate it from external networks, maybe creating a demilitarized zone ( DMZ) and internal network.

Internal network zones may be created using functional or business group attributes. Examples of business groups include HR, finance, Research & Development, visitor Wi-Fi access. Examples of functional groups include web, database, email, core network services (like DNS and Microsoft Active Directory), and IoT services like building management or surveillance systems. Segmented networks enable the setup of least privileged access across zone boundaries. This is the foundation for zero trust and our next security best practice.

2. Trust but Verify

In the zero trust model, data can be considered the new perimeter. Access to that data is allowed only to the people, devices, systems, and applications that need it as part of their defined role. To implement zero trust, deploy role-based access controls and identity management systems that can verify access.

This includes:

Once verified, the connection context and device can be monitored for any change in state. For example, a connection context change may occur if the client uses a network or application exploit once the connection is established. This can be accomplished using IDS/IPS technologies.

3. Secure IoT

IoT security is an extension of the “Trust but Verify” best practice. IoT devices connected to the network are ubiquitous today. Like shadow-IT, employees may connect IoT devices to the network without first getting approval. Unfortunately, there is a good chance the device is vulnerable, and, if it is exposed to the Internet, it has a good chance of being discovered and compromised by bot networks.

Companies can discover the devices when they’re connected using products that specialize in IoT for different industries, such as enterprises, healthcare, manufacturing, and utilities. All industries are vulnerable to enterprise IoT devices such as IP cameras and HVAC or building management systems. Include solutions that detect these IoT devices as well. In industries like healthcare, manufacturing, and utilities that use sanctioned IoT devices in production, apply security controls that do not impede the IoT device's normal functions.

Securing IoT involves:

4. Enable Security

Here, we get back to one of the five recommendations we mentioned above: change your security settings from detect to prevent. First, enable security that matches the data, device, user, or system that you’re securing, including:

5. Security is a Process, not a Product

Here, we revisit one of the top cyber security recommendations from the 2021 Security Report: be cyber-aware and use this threat intelligence to your advantage and what this means when applied to network security.