CYBER SEC ACADEMY / DEFENSIVE PRACTICES ← Return to hands-on labs

Defensive practice guide

Build habits that reduce cyber risk.

A practical starting point for teams that need to protect systems, prepare for incidents, and retain useful evidence for customers, auditors, and internal leaders.

01 / GOVERN

Know what matters

Assign ownership, define acceptable risk, and keep an inventory of critical systems, data, accounts, and suppliers.

02 / PROTECT

Make access deliberate

Use phishing-resistant MFA where possible, password managers, least privilege, and regular administrator-account reviews.

03 / MAINTAIN

Patch what is exposed

Track assets, act on actively exploited vulnerabilities, and set clear patch and exception timelines.

04 / RESILIENCE

Recover with confidence

Back up important data, protect backup access, and periodically prove that a restore actually works.

05 / DETECT

See meaningful signals

Centralize appropriate logs, define who reviews alerts, and preserve enough context to investigate safely.

06 / RESPOND

Practice the first hour

Keep contacts, decision rights, containment steps, and communications paths current before an incident occurs.

The practices

Open a topic for a concise implementation checklist and the evidence that makes the practice repeatable.

1. Create an owned inventory of systems and data

List the systems that run the business, the information they hold, the person accountable for each, and whether they are internet-facing or managed by a supplier.

DoMaintain an asset and SaaS inventory with an owner.
ReviewIdentify high-value data and critical business workflows.
KeepStore review dates, approved exceptions, and system diagrams.
NIST Cybersecurity Framework 2.0 ↗
2. Strengthen identity and access

Most security programs become more resilient when access is tied to named people, protected by MFA, and limited to the level needed for the job.

DoRequire MFA for email, administrator, cloud, and remote-access accounts.
ReviewRemove stale users and unnecessary admin rights on a scheduled basis.
KeepRetain access-review records and privileged-role approvals.
CISA: Secure Our World ↗
3. Run a risk-based patch and vulnerability practice

Prioritize internet-facing, critical, and known-exploited weaknesses. Pair scanning or vendor notices with validation, assignment, remediation, and documented exceptions.

DoDefine patch timelines by business impact and exposure.
ReviewCheck CISA’s Known Exploited Vulnerabilities catalog during prioritization.
KeepTrack findings, owners, dates, fixes, exceptions, and retest results.
CISA Known Exploited Vulnerabilities Catalog ↗
4. Make data protection and recovery testable

Backups are only useful when the right people can restore the right data within the time the business can tolerate. Protect backup administration separately from everyday access.

DoBack up critical data and configurations on a defined schedule.
ReviewTest restoration and record the recovery time and gaps found.
KeepMaintain recovery objectives, restore-test results, and remediation actions.
CISA small and medium business resources ↗
5. Monitor, respond, and learn

Define the events that need attention, who owns the response, how to contain safely, and how the organization will communicate and recover.

DoCollect security-relevant logs for critical systems and identity providers.
ReviewRun a tabletop exercise for a realistic incident scenario.
KeepSave incident playbooks, contact lists, exercise notes, and improvement actions.
NIST incident response resources ↗
6. Review suppliers, cloud services, and AI tools

Third parties and new tools can introduce sensitive data, privileged connections, or business dependency. Treat adoption as a risk decision—not just a purchasing decision.

DoRecord what data each supplier receives and which integrations it holds.
ReviewAssess contractual, security, access, retention, and exit considerations.
KeepMaintain supplier reviews, approvals, data-flow notes, and reassessment dates.
NIST CSF supply-chain and governance guidance ↗

First 30 days

  1. Assign a business owner for security decisions.
  2. Inventory critical systems, accounts, data, and SaaS tools.
  3. Turn on MFA for the highest-risk accounts.
  4. Review administrator access and remove stale accounts.
  5. Prioritize exposed and known-exploited vulnerabilities.
  6. Test one restore from a critical backup.
  7. Write a one-page incident contact and escalation plan.
  8. Schedule a quarterly review of access, patches, backups, and suppliers.