Indian CERT-In Issues High-Severity Advisory on Safeguarding Business Operations against Cyber Threats
The Indian Computer Emergency Response Team (CERT-In) has issued a high-severity advisory to industries on essential measures for safeguarding business operations against cyber security threats. The advisory emphasizes the increasing frequency and sophistication of cyberattacks, including ransomware, DDoS incidents, website defacements, data breaches, and malware infections that threaten the confidentiality, integrity, and availability of business systems and services.
The advisory highlights the need for industries to implement several safeguarding measures, including strengthening authentication and access control, web server and infrastructure protection, data protection, incident response planning, employee awareness and training, supply chain monitoring, and zero-trust architecture.
Key Takeaways:
- Industries need to enforce strong password policies with long, complex, and unique credentials for each service to strengthen authentication and access control.
- Multi-Factor Authentication (MFA) should be implemented to secure accounts, while role-based access control (RBAC) should be applied to restrict employee permissions based on their responsibilities.
- Regular offline backups should be maintained to mitigate ransomware risks, and regularly tested backup restoration procedures should ensure data recovery remains reliable.
- Employee awareness and training should be conducted regularly to educate employees about phishing, social engineering, and best practices.
- Simulated phishing attack exercises and routine cyber drills should be organized to improve user awareness and response measures.
- Continuous monitoring of vendor and supplier activities should be established to secure supply chain resilience.
- Zero trust architecture should be implemented to enforce strict identity verification and authorisation for every network activity.
- All suspicious cyber activity must be reported to CERT-In at incident@cert-in.org.in, and logs should be preserved in accordance with CERT-In's 28th April, 2022 Directive and submitted with the incident report.
Statistics:
- Ransomware attacks increased by 97% in 2020 (Source: CERT- In Advisory)
- Data breaches can result in the loss of sensitive and confidential information, impacting business operations and reputation.
- 71% of businesses have experienced a cybersecurity incident in the past year (Source: PwC Global Economic Crime Survey)
- Regular cybersecurity training and employee awareness programs can reduce the risk of phishing and social engineering attacks by up to 80% (Source: IBM Security).
- Zero-trust architecture can reduce the risk of cyber attacks by up to 90% (Source: Forrester)
Sources:
- CERT- IN Advisory: "Essential Measures for Industry for Safeguarding Business Operations against Cyber Security Threats"
- CERT- In Directive: 28th April, 2022 (unreferenced in the text, but mentioned as a directive by CERT- In)