Securing Your Organisation’s Office 365 Environment

The number of cyber-attacks targeting Office 365 (O365) are on the rise. However, despite warnings from the UK’s National Cyber Security Centre, many organisations aren’t fully aware of the risks or struggle to know how to best defend their business against them. By Chester Avey

If your business uses O365 or is considering migrating to the service, then here’s some top tips to help keep your business secure.

Enforce multi-factor authentication 
It is often the smallest things that make the biggest difference to your cyber security – and one of the best, and simplest, ways to secure O365 is through the use of multi-factor authentication (MFA). With MFA enabled, all your organisation’s O365 users will be sent a code to their mobile phone when they try to log in to their account; meaning that in the event that a criminal is able to obtain a user’s password, the person will not be able to access to the account.

It is actually very easy to set up multi-factor authentication in O365 and while it elongates the procedure of logging in, it is certainly worth it due to the extra layer of security it provides. 

Manage from dedicated admin accounts
Some businesses make the mistake of using a single account to administrator O365. While this is often more convenient way of working it actually significantly increases overall cyber security risk. If an administrator account is compromised, criminals will likely obtain access to the whole environment.

It is a much better idea then, to keep administrative accounts separate to the ones used on a day-to-day basis. To reduce the risk of an admin falling foul of a phishing, it’s also advisable that these accounts are not set up with a licensed mailbox. 

Use full mailbox audit logging
Another way to improve O365 security is to activate full audit logging – which will help to improve visibility of user actions across your whole environment. This includes visibility of which users are logging in and from where. 
You can then use network and endpoint monitoring systems like SIEM in order to help detect threats and respond to them by improving the effectiveness of the identification of tactics and techniques used by cybercriminals.  

Provide staff with training
One of the most valuable things that any organisation can do to improve the security of O365, is to provide cyber awareness training to staff. People continue to be the weak link in the cyber security chain so improving knowledge can be an extremely valuable thing to do. 

Of course, it is essential that this training is regularly updated to recognise the latest security risks, such as phishing attacks against O365 users. 

Disable email auto forwarding
In the event that a hacker is able to gain access to a user’s O365 account and mailbox, a common tactic is to send copies of any incoming emails to another address. This allows them to continue to eavesdrop on communications should they lose access to the account.

Nevertheless, this kind of attack could mean the loss of sensitive data. Thankfully this type of action can easily be prevented by the creation of a mail transport rule in the O365 admin centre to block users from being able to auto-forward emails to external accounts. 

Check Cloud Solution Provider access

If your organisation bought its O365 subscription through a Cloud Solution Provider (CSP), check to see whether that partner has access to the environment. Many CSPs receive access by default and are now being targeted by cyber criminals for this reason.  One recent example is an attack on PSM, a US cloud company.

Additional steps to take

Before you decide upon whether to invest in supplementary technology from Microsoft to further improve the security of O365, it is worth evaluating the many third-party tools available. To help you do this, consider consulting with cloud management and monitoring specialists who can provide the extra technology, support and expertise you need to further enhance your organisation’s security.

It could also be hugely beneficial to commission penetration testing to help detect and address vulnerabilities such as those relating to insecure network and system configurations.

Chester Avey is an independent business consultant:     

You Might Also Read: 

Dealing With Malicious Emails:

 

 

« Cyber Crime In Britain
Psycho-Cyberchology »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Venable

Venable

Venable is an American Lawyer 100 law firm with nine offices across the USA, Practice areas include Cybersecurity.

AdNovum Informatik

AdNovum Informatik

AdNovum Informatik provides a full set of IT services, ranging from consulting, the conception and implementation of customized business and security solutions to maintenance and support.

Secusmart

Secusmart

Secusmart provide highly secure and encrypted speech and data communication solutions.

Procilon Group

Procilon Group

Procilon Group specialize in the development of cryptographic software as well as strategic advice on information security and data protection.

SQN Banking Systems

SQN Banking Systems

SQN Banking Systems fraud detection software products are a critical step towards overcoming the growing problem of fraud across the various payment channels.

Absio

Absio

Absio provides the technology you need to build data security directly into your software by default, and the design and development services you need to make it happen.

GuardRails

GuardRails

GuardRails provides continuous security feedback that empowers developers to find, fix, and prevent vulnerabilities.

DreamIt Ventures

DreamIt Ventures

DreamIt Ventures is an early stage venture fund that accelerates startups building transformative tech products in the fields of Healthtech, Securetech, and Urbantech.

PatrOwl

PatrOwl

Automate your SecOps with PatrOwl, and start defending your assets efficiently.

InfoExpress

InfoExpress

InfoExpress provides network security solutions that enhance productivity and security through better visibility, improved security, and automating device and mobile access to the network.

Hassans International Law Firm

Hassans International Law Firm

Hassans is the largest law firm in Gibraltar, providing a full range of legal services across corporate and commercial law including Data Protection and GDPR compliance.

InferSight

InferSight

InferSight can help you design an architecture that takes into account security, performance, availability, functionality, resiliency and future capacity to avoid technological lock in and limitations

Query.ai

Query.ai

At Query.AI, we are committed to helping companies unlock the power of their security data, so they are empowered to meet security investigation and response goals while simultaneously reducing costs.

Mage Data

Mage Data

Mage (formerly Mentis Software) is a leading solutions provider for data security and data privacy software for global enterprises.

CyberUp

CyberUp

CyberUp is a nonprofit organization created to strengthen the cybersecurity workforce. We help employers reimagine how they grow and scale their cybersecurity workforce.

BitLyft

BitLyft

BitLyft is a managed detection and response provider that is dedicated to delivering unparalleled protection from cyber attacks for organizations of all sizes.