Emerging IT

The Lab·Published on

Business cybersecurity: which protections are truly essential?

EDR, firewall, MFA, backups, updates… Discover the essential protections to strengthen your company’s cybersecurity.

cybersecurity

Illustration: a laptop showing a security dashboard, connected to a padlock at the centre of a network sphere

Antivirus, EDR, firewall, MFA, backups, email filtering… With so many cybersecurity solutions on offer, it is not always easy to know which protections are truly necessary.

Yet an organisation’s cybersecurity does not rest on a single tool. It requires several complementary layers of protection to secure users, identities, workstations, the network and data.

Why is antivirus alone no longer enough?

For a long time, installing antivirus software on computers could be one of the main protection measures for an IT estate.

Today, threats are far more varied: phishing, credential theft, malware, ransomware, exploitation of vulnerabilities and account compromise.

IT security must therefore be seen as a set of complementary layers.

An attacker who fails to compromise a workstation directly may, for example, try to obtain a user’s credentials. Conversely, a compromised account should not automatically grant access to the entire information system.

This principle of defence in depth is what limits the consequences when a first security barrier is breached.

Key takeaway

No single solution can secure an entire company. Effective protection relies on several complementary technical and organisational measures.

Protecting workstations and servers

Computers and servers are particularly important entry points into the information system.

First of all, they must be kept up to date. Security patches address known vulnerabilities that could be exploited.

On top of this maintenance come endpoint protection solutions.

Traditional antivirus remains a first building block of security, but companies can now rely on more advanced solutions such as EDR — Endpoint Detection and Response.

Unlike protection that relies mainly on identifying known malicious files, an EDR also monitors endpoint activity in order to detect certain suspicious behaviours and make it easier to respond to an incident.

Protecting workstations also involves hardening them: limiting administrator rights, disabling unnecessary services, applying appropriate security policies and keeping control of installed software.

Securing the company network

The network is another essential layer of cybersecurity.

A professional firewall controls communications between the organisation’s network and the outside world according to defined rules.

But its presence alone is not enough.

Depending on the architecture and size of the environment, it may be worth segmenting the network so that a compromised device cannot communicate freely with the whole information system.

Wi-Fi access, connections between sites and remote access must also be secured.

This approach is particularly important when the organisation has several sites, mobile staff or remotely accessible resources.

Protecting identities and access

Credentials are now a major security issue.

An attacker does not necessarily need to get around a firewall if they manage to obtain a valid username and password.

Multi-factor authentication, or MFA, adds an extra verification step at sign-in and reduces the risk associated with the theft of a password alone.

But identity management goes further.

The rights granted to users must match their actual needs. Administrator accounts require particular attention, and former employees’ access must be removed promptly.

In environments such as Microsoft 365, additional mechanisms can also define conditions for accessing company resources, based for example on the user, the device or the sign-in context.

Securing email and collaboration tools

Email remains a favourite vector for trying to deceive users.

An email may try to harvest credentials, prompt the download of a malicious attachment or redirect to a fake website.

Email protection must therefore combine several elements: anti-spam and anti-phishing mechanisms, account security, MFA and user awareness.

With the growth of Microsoft 365 and cloud tools, protection no longer stops at the workstation.

Email, OneDrive, SharePoint, Teams and other collaboration services can hold a large amount of business data. Securing identities and access then becomes central.

Backing up data… and checking it can be restored

Backup plays an essential role in an organisation’s ability to cope with certain incidents.

A cyberattack, human error, a failure or accidental deletion can make information unavailable.

But simply seeing that a backup job has run does not necessarily guarantee that the company will be able to resume operations under the expected conditions.

Backups must therefore be monitored, protected and regularly checked.

Restore tests make it possible to verify that data can actually be recovered when needed.

For critical systems, this thinking should be part of a broader Disaster Recovery Plan (DRP) or Business Continuity Plan (BCP).

Monitoring to detect incidents faster

Prevention is essential, but you also need to be able to see what is happening when unusual behaviour appears.

Monitoring and centralising certain security events can help detect anomalies: unusual activity on a workstation, an unavailable service, a device with a problem or a security event requiring analysis.

Depending on the size, risks and criticality of the information system, the means deployed can range from relatively simple monitoring to much more advanced incident detection and response capabilities.

The goal remains the same: reduce the time between a problem appearing, its detection and its handling.

Don’t forget the human factor

Even with many technical protections in place, employees are directly exposed to fraud attempts.

A particularly convincing email, a fake Microsoft 365 portal or an urgent request that seems to come from a manager can be enough to fool a user.

Cybersecurity awareness is therefore an integral part of the protection strategy.

Employees should in particular be able to recognise the main phishing attempts, follow good practices with their credentials and know whom to alert quickly about an unusual situation.

The aim is not to turn every user into a cybersecurity expert, but to give them the right reflexes.

Do all companies need the same protections?

No. And this is probably one of the most important points.

A small business with a few workstations does not necessarily need the same security architecture as a multi-site manufacturer, a local authority or an organisation running critical infrastructure.

The level of protection should be defined according to several factors:

  • the size and organisation of the structure;
  • the nature of the data processed;
  • the applications and infrastructure used;
  • the number of sites and users;
  • remote access;
  • any regulatory constraints;
  • the potential consequences of a business interruption;
  • the IT resources already available in-house.

The goal is therefore not to pile up cybersecurity solutions, but to build a coherent setup proportionate to the organisation’s real risks.

Effective cybersecurity relies on several layers

Users
↓
Identities & access
↓
Workstations & servers
↓
Network
↓
Applications & email
↓
Data & backups
↓
Monitoring & detection

None of these building blocks replaces the others: they complement each other.

Cybersecurity is an ongoing process

Deploying security tools is a first step. But infrastructure evolves: new employees arrive, devices are added, usage changes and new vulnerabilities emerge.

Cybersecurity must therefore be seen as an ongoing process, including system maintenance, monitoring, evolving protections and user awareness.

An organisation that already has an IT department or team can also draw on external skills for certain areas of expertise, while a structure without in-house IT resources can outsource a larger share of this management.

Is your level of protection suited to your environment?

Emerging-IT’s teams support companies, local authorities and organisations in securing their information systems, from workstations and identities to the network, infrastructure and backups.

The goal: identify the risks, keep the protections that are truly necessary and build an architecture consistent with your business.

→ Talk to our team

Frequently asked questions about business cybersecurity

What protections are essential for a company?

There is no universal list that applies to every organisation. Protection generally relies on several complementary building blocks: workstation security, updates, network protection, identity and rights management, MFA, backups, monitoring and user awareness.

Is antivirus enough to protect a company?

No. Antivirus is one layer of protection, but on its own it does not protect against credential theft, phishing, misconfigurations, unauthorised access or all the other risks an information system may face.

What is the difference between antivirus and EDR?

Antivirus aims in particular to identify and block malware. An EDR adds monitoring, detection and investigation capabilities on endpoints to identify certain suspicious behaviours and make it easier to respond to an incident.

Why enable MFA?

MFA adds an extra verification factor on top of the password. It strengthens the protection of an account when a password has been compromised.

Do backups protect against cyberattacks?

A backup does not prevent a cyberattack. It is, however, an essential element of resilience: when properly designed and protected, it provides data that can be restored after certain incidents.

Sources and further resources

All articlesBack to top