The federal government’s “30 day sprint” to shore up IT security, as ordered by federal CIO Tony Scott, is coming to a close on July 12. While it’s impossible for federal agencies to completely overhaul their IT security in just 30 days, there are steps they can take to better protect their systems.
Here are five ways federal agencies can help address security gaps in their IT networks now:
Take stock of privileged users – Privileged users include everyone from IT administrators to contractors to third-party vendors, all those who need to be granted access to networks to sustain normal business operations. Identifying who they are and properly assessing their IT permission levels is critical as hackers continually pose as these users to enter systems and hide in plain sight. In both government and private sector, monitoring privileged access is a major concern. The U.S. Office of Management and Budget estimates that as of 2014 there were more than 134,280 user accounts that had privileged, or elevated, access to federal systems, but were protected only with a username and password.
Related: Feds on ’30-day sprint’ to better cybersecurity
Audit for unsecured remote access tools – It’s an ugly truth that many times IT administrators will use free remote access tools to facilitate their work, even though these tools are unauthorized and unsecured. Auditing for where these tools are being used and blocking access from commonly used free tools can close unsecured back doors into the network.
Eliminate simple/shared credentials – Every privileged user—including contractors—should have his or her own unique login credentials. Vendors will often use simple or shared login credentials with no multi-factor requirement, making them an easy target for hackers with keystroke loggers. Once hackers have legitimate credentials for the remote access system, they can pose as legitimate users and potentially gain direct access to all systems available to that account, putting the entire organization at risk for a major data breach.
Limit VPN access– VPN credentials are attractive targets for hackers because once a cybercriminal gains VPN access, they can often easily move around the network.
Track activity – Compliance with how and when data can be accessed is critical, particularly in areas of government such as healthcare. Remote access solutions should capture and store session logs of all activity, providing a record of how the technology is being utilized—and by whom. With all remote access to IT systems centrally audited and recorded, IT has greater insight into the activities of third-party entities.
No single solution can completely insulate an organization from threats, but instead of trying to lock as many doors as possible, executives and IT professionals in federal government should embrace a layered approach to security. Leveraging a combination of proven technology and best practices, which includes preventative measures to increase controls over privileged access, can help protect the network while also ensuring productivity that allows workers to do their jobs.
Such a multi-layered approach to security provides an organization with more robust and flexible responses when a breach occurs compared to locking IT access and hunkering down. Moving forward, federal IT departments should prepare to address the implementation and use of privileged accounts as part of their security strategy.
Scott Braynard is vice president of public sector for Bomgar, a remote support and privileged access management solution provider.




