Jump to content

Recommended Posts

Posted

Does anyone know of any good preferably free online cyber security training courses.

I've had a weird report from a user that's almost certainly some kind of user error at this point, but in the case that it wasn't I realize I wouldn't actually know where to start looking to investigate any potential malicious outside access to the system.

 

In this case she's claiming that someone was able to take control of her pc when she opened Microsoft remote desktop on her mac while trying to connect to our terminal server.

  • Thanks 1
Posted
Worth investing in a pen test? A report would tell you where your weak areas are so they can be fixed, and how an attacker would target your network
Posted

There's some guidance from the National Cyber Security Centre on managing an incident, but it seems to be more aimed at managers - https://www.ncsc.gov.uk/guidance/10-steps-incident-management

 

Technically, I think the main thing is to check logs for anomalies (such as a user logging in at 3am, or an interactive logon from a service account). To help this, make sure you have centralised logging of all your servers (so if one is hacked, an attacker couldn't just clear the logs).

I think generally though, if you want a blow-by-blow account of what happened in such a situation, the advice is "call in the experts"; but that's likely to be pretty costly (involving digital forensics, detailed log analysis, etc.). In that case, your LA should have a supplier they can point you to :-).

 

The Future Learn course seems to be more aimed at end users, but could be worth a look.

 

Of course prevention is always better than cure, so rrrrr's suggestion of a pen test could also be an option.

If you're most worried about internet-based attacks, a Cyber Essentials test that includes a vulnerability scan of your internet facing infrastructure could be a fairly cost-effective way of ensuring you meet the basic standard set out by the government.

More information on that can be found at https://www.cyberaware.gov.uk/cyberessentials/.

  • 4 weeks later...
  • 2 weeks later...
Posted

doing that course now, just finished week 1.

Pretty solid tbh.

More than most end users would understand, but would be great to make all staff do that first week >.<

might get it through their skulls to have decent passwords and keep their gubbins up to date

 

I did love the how to guide they did.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...