What’s Included in PC Professional’s Cybersecurity Assessment?

We pride ourselves on providing our clients (and prospective partners) with a comprehensive assessment that will test your security posture in 20 key areas. We’ll find any gaps in your security posture and make feasible recommendations that will keep you up-to-date and secure against evolving security threats.

The Key Areas We’ll Be Looking At

  • Define the roles and responsibilities of each team member from top to bottom.
  • Assign accountability to ensure cybersecurity procedures are followed.

  • Ensure all the latest security patches and firmware are in place and updated.
  • Consistently monitor updates by creating a schedule or subscribing to vendor notifications.

  • Ensure your antivirus and malware subscriptions are up-to-date.
  • Ensure auto-updates are active.

  • Have a strong password policy that is followed by all employees.
  • Enable multi-factor authentication (MFA).
  • Ensure all employees only have access to the information necessary to perform their job.

  • Employ data encryption for stored and transmitted data.
  • Manage encryption keys with strong access controls and regularly rotate and update the keys.

  • Ensure that you store log data securely to support future analysis and reporting requirements if an incident was to transpire.

  • Find the best type of firewall for your business’ specific infrastructure and needs.
  • Define the rules and policies of the firewall to determine what traffic will be blocked.
  • Monitor and update the firewall.

  • Segment users based on their roles.
  • Segments are used to restrict certain users from administrative access to computers, networks, and applications.

  • Preparation: Ready an incident response team
  • Identification: Implement detection tools to identify a breach quickly.
  • Containment: How will you isolate the affected systems or data?
  • Eradication: Cleaning up malware, applying patches, and rebuilding.
  • Recovery: Establish a process for restoring systems and data.
  • Lessons Learned: Identify the vulnerability that allowed the breach.

  • Establish clear cybersecurity expectations and obligations.
  • Ensure the vendor develops a coordinated incident response plan.
  • Implement security requirements for all contractors, cloud applications, and software licensing.

  • Identify data categories: Public, internal, confidential, and highly confidential information.
  • Establish criteria: Determine characteristics for the data in each category.
  • Assign ownership: Designate data owners to be responsible for classifying and managing data within their purview.
  • Develop guidelines: Create guidelines on the handling, storage, and sharing for each category.
  • Implement security controls: Apply appropriate security controls to protect each data category.
  • Educate your team: Ensure they know about the classification system.

  • Choose the right IDS/IPS configuration for your company to monitor and block malicious traffic.

  • Implement email filtering solutions.
  • Use email encryption.

  • Implement an encrypted and secure password logging strategy.
  • Document information from all software vendors.
  • Log data of remote user access.

  • Schedule periodic evaluations to ensure your security programs are effective and up-to-date.
  • Perform regular security and vulnerability scans.
  • Identify weaknesses and develop an action plan to address them.

Need help figuring out which solutions make sense for your organization? Or don’t know where to start? Schedule a no-cost consultation to gather more information on our cybersecurity assessment and how an IT security health check can reduce your chance of falling victim to a cybercrime.

Order Your Cybersecurity Assessment Today

If you’ve been wondering if penetration testing, or a network security assessment, web application security assessment, compliance assessment, or general risk assessment will make your data (and your business) more secure, it’s time to uncover any gaps in your security and how they could be leaving you vulnerable to cyberattack.

Let’s make sure your network is a safe place for your clients’ data—schedule your cybersecurity assessment now.