18706_Authority_Oct
34 The Authority | October 2025 should include routers, modems, and any link that crosses from one location to another. The map should also show how those connections are secured and who has access. A hand- drawn sketch is fine, but it needs to be current and reviewed often. What data is being passed between sites, and how is it secured? Why it matters: Data that is used for system operation should be protected accordingly, but even non-critical data can create exposure. What to look for: Ask if encryption is in place and how it was added. Is it built into the device, or is it configured through software? If encryption cannot be used, what other safeguards exist? Have Access Control Lists (ACLs) been implemented to restrict communications to known devices? Who has remote access, and how is that access managed? Why it matters: Remote access is essential for operational support, but it remains one of the most common ways attackers gain entry. What to look for: Make sure every remote login is tied to a named individual or role, not a shared password - If possible, implement multi- factor authentication (MFA). Check how often individual access is reviewed and work towards keeping access disabled unless it is actively being used. Implement a periodic review of remote access usage to confirm that it is being used appropriately. Are the current configurations required for communications backed up and able to be restored if needed? Why it matters: In the event of an equipment failure, configuration backups are used to replicate security settings on replacement devices. What to look for: Configuration backups are usually small and can be made independently from data backups. It is common that the backup file names include a device identifier and a timestamp reflecting when the backup was made. Occasionally, devices will require password protection of their backups. These passwords should be documented and accessible if they are needed when restoring the configuration. How are changes to system communications coordinated? Why it matters: Security may be reduced, disabled, or altered while performing both planned and unplanned changes. What to look for: There should be a short list of individuals who have both the expertise and physical access required to make system changes. Ask if changes could affect communication security, and if so, review the future state of the system to determine the impact of the change. Require updated documentation upon completion of the change. Start Today Site-to-site communication often goes unexamined because it seems to “just work.” Unfortunately, relying on assumptions t hese actIons help you prepare rather than react . Site-to-Site article continued from page 19. and undocumented systems can lead to costly disruptions. You don’t need a major technology overhaul to make progress. These steps help uncover hidden risks and start important conversations with your team. • Create a diagram of how your devices communicate; • Know what data is passed between sites and how it is secured; • Actively monitor and maintain remote network access; • Backup communication settings and confirm they can be restored if needed; and • Proactively manage changes to communications. These actions help you prepare rather than react. They strengthen your operation without expensive tools or major changes. Lastly, consider adding cybersecurity to meeting agendas to keep it front of mind and accentuate its importance to the overall success of your organization. S
Made with FlippingBook
RkJQdWJsaXNoZXIy MjY5OTU3