Some Tenets of Security for Your Organization

Gonna put these quick’n’dirty then a little wordier:

  1. Hide your screen
  2. Use a password manager
  3. Don’t use a personal address or phone number for work stuff
  4. MFA MFA MFA†
  5. No MFA by text
  6. All passwords are different and long and random and unmemorable
  7. All passwords go in the password manager
  8. Never share logins
  9. If something looks suspicious, it is

Now longer:

  1. Always assume your screen is being viewed by someone else unless you are taking active measures to prevent that. Shoulder-surfers are a real and present danger. Never reveal a password onscreen or type your passcode unless you are certain no one can see
  2. Always sign up for work-related services using your @yourworkdomain.com email address
  3. Always use multi-factor authentication† via an authenticator app. If you use a password manager (you use a password manager, right?) then using it for MFA is likely your best choice, but if someone on your team ends up using another one, that’s totally fine.
    • Never choose to receive MFA via SMS text or a mobile number
  4. Always use a password generated by your password manager
  5. Never share login information with anyone, including the boss. If the boss asks, it should be to test the user’s security acumen.
  6. Always assume that if something looks suspicious, it is. Otherwise put, careful what you click. AI-generated spam and deep-fake voices are real and cheaply-accessible things now, and people are getting scammed constantly. Real communication looks and feels real, and most importantly, is verifiable by a real person. 

†It is known by many names so I list them. These all refer to the same fundamental idea: two-factor authentication, multi-factor authentication, 2FA, MFA, one-time password, time-based one-time password, OTP, TOTP

Author: jjmarcus

Apple Specialist, Mac Whisperer, Cloud Wrangler - Your Remote CTO

Leave a comment