The Cybersecurity and Infrastructure Security Agency (CISA) issued an alert and recommendations related to Office 365 for organizations to ensure their environment is configured to protect, detect, and respond against would-be attackers of Office 365. As the COVID-19 pandemic swept across the world, companies had to adapt on the fly and support a ‘work from home’ system even though most were not set up for this challenge. Office 365 provides cloud-based email capabilities, as well as chat and video capabilities using Microsoft Teams – perfect for creating collaboration among employees spread out and isolating at home. However, numerous organizations did not implement the necessary security for the Office 365 implementation in a rush to deploy and keep business interruptions to a minimum. Unfortunately, many of those companies are at severe risk for data security breach.
The CISA provided recommendations to ensure that your installation of Office 365 is protected and not vulnerable to attacks. Without taking these steps, you’re running the risk of unauthorized access to confidential company information, personal information, trade secrets and overall data breach. Specifically, CISA recommends that administrators implement the following mitigations and best practices:
- Increase your organization’s overall security
- Use multi-factor authentication.
- Protect Global Admins from compromise and use the principle of “Least Privilege.”
- Enable unified audit logging in the Security and Compliance Center.
- Enable Alerting capabilities.
- Integrate with organizational security incident event management solutions.
- Disable legacy email protocols, if not required, or limit their use to specific users.
- Create a custom mail flow to stop the auto-forwarding of emails.
VIP IT has helped companies transition from office to home office with ease during the past two months. Enjoy peace of mind and let our team review your security position and address any concerns before they become an issue for your team, clients or customers.
Protect your data. Contact VIP IT today to make sure your employees and corporate information is kept safe.