Cybersecurity requires a working plan for assets, risk, access, monitoring and recovery. The source page lists 12 practices, although its title says 20 tips, so this revision keeps the 12 published practices and labels the discrepancy in the editorial note below.

  1. Identify every asset you need to protect, including hardware, software, data and network components. Classify each asset by its importance to the business.
  2. Assess the risks to those assets. Estimate the likelihood and impact of each threat so you can set priorities and resources.
  3. Write a cybersecurity policy that defines security goals, risk management and incident response.
  4. Train employees on security policies, safe browsing and secure password management.
  5. Use strong access controls, including two-factor authentication, and restrict access by job role.
  6. Segment the network into smaller sections to reduce the attack surface and limit the spread of malware after a breach.
  7. Encrypt sensitive data in transit and at rest, including passwords, credit card information and customer data.
  8. Run regular vulnerability assessments and address the weaknesses they find.
  9. Monitor and analyze network traffic with tools such as intrusion detection and prevention systems, firewalls and antivirus software.
  10. Write an incident response plan for detecting, analyzing, containing and mitigating security incidents.
  11. Back up data on a regular schedule so you can recover it after a breach or system failure.
  12. Run regular security audits to check that policies and procedures are followed and that systems and networks remain secure.

Original publication on GoDaddy