12/04/2019
10 tips to ensure the IT security of your SME
IT security for SMEs
Effective IT Security = Protection of ALL entry points
76% of business owners know they are criminally responsible for the use
Internet in their businesses.
Tip # 1: Secure your workstations
Use a good security suite on all devices connected to your network.
Privilege a centralized cloud management console.
Schedule a full scan of workstations and servers at least once a week.
Configure your security suite to receive alerts for update issues.
Configure your antivirus to systematically scan USB sticks
Choose complex AND different passwords for each of your employees AND for each
your applications.
Tip n ° 2: Homogenize your computer park
OS homogenization = simplified security management.
Homogenization of computer equipment = productivity gain
Regularly apply patches and updates to your apps.
Protect the antivirus with a password.
If you change the posts - make sure to use a file shredder to remove
definitively all traces of files on discarded PCs.
Tip 3: Save your data
Watch out for public sharing sites: Dropbox / Google Drive / OneDrive (these are NOT
backup solutions)
Privilege hybrid backups (local and remote) - if your local server is
damaged, you can resume your activity very quickly
Think about email backups!
Tip 4: Secure your Internet access points
Control Internet access
Block access to certain websites.
Watch for Wi-Fi hotspots within
your company.
Install a firewall on all your workstations.
Tip 5: Secure your messaging
Check the consistency between the sender and the content of the
email.
Configure your security suite to open
systematically attachments in the Sandbox.
Add a black list of senders to send their
message directly into spam.
Protect your digital identity.
Tip # 6: Secure Your Data Outside the Walls
Limit connections to Wi-Fi networks if possible
public (coffee, train station, airport ... etc).
Use a VPN connection to connect in
outside of your company.
Remember to backup your data BEFORE
your movements.
Prohibit the use of your PC Pro by a person
outside your company.
Tip # 7: Secure your transactions
Check for padlock and HTTPS in the address bar.
Privilege payments on sites that do not register your bank details.
Limit the number of people who can make transactions.
Use a virtual private browser to make your transactions and view your accounts
online.
Tip # 8: Secure your downloads
Privilege downloads on publisher sites.
Read the download procedure and
disable the installation of additional software.
Block access to download sites and
streaming / peer to peer for your employees.
Tip 9: Train your employees
IT Security = Teamwork with your employees
Make your employees aware and accountable for risks.
Do not give local administrators rights on posts.
Structuredly manage access to sensitive files through a server.
Ask your employees to trace suspicious emails or any other behavior
suspects in the IT department.
If no IT department, designate someone within your company who will be
responsible for the proper functioning of the computer system.
Tip 10: Make an inventory
Make an inventory of your computer security:
What sensitive data do you want to protect?
Who has access to this data?
What are the strengths or weaknesses of your network?
Does your security suite meet your needs?
Have you defined procedures to put in place in case of attacks?
Bonus: Action plan in case of attacks
1. Identify the source of the attack (the important thing is to work seamlessly with the
employee responsible for the infection).
2. Isolate the infected post and identify the impacted data.
3. Clean the affected station (use VirusTotal.com).
4. Inform your employees of the infection and how the infection has occurred.
5. If customer or supplier data has been compromised: Set up a plan to
communication to protect your reputation with your customers