Security Is Like An Onion

Like an onion, a network's security should have multiple layers, all designed to protect your data. Here are some common layers:

Antivirus

A security solution like our managed ITS Antivirus provides a monitored, continually updated security layer on each PC. A good solution goes far beyond traditional antivirus, including a firewall, network connection monitoring, scanning of HTTPS (encrypted) web connections, and application-behavior monitoring.

DNS

The Internet uses the Domain Name System to translate names (www.teamITS.com) to their IP address. DNS filtering can be used to block malicious sites, command-and-control infrastructure, or certain types of content.

Router

A company's Internet router can provide additional protections, such as enforcing use of desired DNS servers, connection monitoring, or blocking known bad IP addresses.

Wireless

An access point, or mesh (multiple APs working together) can be configured to allow only certain computers to connect, or force "guest" devices onto a separate network.

Network Access

Guests/customers/etc. who don't need to access your internal systems should be on their own network. One can also do this to isolate IoT (Internet of Things) connected devices like light bulbs or other appliances.

Access into or out of a network can be limited by geographical area, such as per country.

Ex-employees should not be able to access any systems, especially if they are being fired.

Spam Filtering

A good spam filter like ITS Mail Guard helps block malicious emails as well as spam.

Least Privilege

The entire point here is to give humans the least amount of access they need to do their job. For example, ITS recommends staff be "standard users" in Windows, which makes it harder to infect the computer, at least at lower levels of Windows.

Access Control

Similar to the prior point, restrict access as needed. Multi-factor authentication prevents password sharing and prevents stolen passwords from being useful. Unique logins facilitate audit-logging of who made a given change.

Training

Humans are often the weak link. Social engineering (talking your way past someone) works way more often than it should. Often a hacker just needs the person to click that one link...

September 2026

Send this article to a friend!
Subscribe to The ITS Connection

Related articles