The unglamorous controls that stop most incidents
USB discipline: Unknown USB drives are literal attack vectors (dropped in parking lots, handed at conferences). Policy: no personal USBs on official systems; scan-before-open station at IT section; encrypted drives only for official transfers.
Passwords & accounts:
- Unique password per system — the reused one leaks everywhere when any service is breached
- Password manager approved by IT (open-source options exist for air-gapped use)
- Screen-lock on every walk-away (Win+L), no shared logins "for convenience" — shared logins destroy accountability in audits AND investigations
Patch reality: Unsupported Windows 7 boxes running departmental software are ticking incidents. Inventory them, isolate them on a separate VLAN, and plan migration — PKCERT advisories repeatedly flag EOL edge devices.
Email hygiene: disable auto-loading of remote images (tracking pixels), review delegation/forwarding rules quarterly (attackers persist via hidden auto-forward rules), and report — don't delete — suspicious mail.
One-page incident card for every desk: SEE SOMETHING → don't touch → call IT focal person → IT reports to PKCERT within policy timelines. Speed of reporting is the single biggest factor in containment.
