CISA urges organisations to harden endpoint management systems

Following a significant cyberattack on a US organisation, CISA is urging companies to harden their endpoint management systems. These platforms are attractive targets because they provide centralised control over large device fleets. CISA points to patching, tighter configuration and a clearer zero trust approach to reduce the attack surface.

What this means for your organisation

Endpoint management tooling has, by design, the right to install software and run commands on every client. If an attacker gains control of the platform, they gain the same reach as the IT department in a single step. This is the same risk that makes management tooling a favoured target in ransomware attacks, and it makes protecting the platform itself a management issue, not only an operational one.

Berigo recommends

  • Treat endpoint management platforms as critical systems with dedicated access requirements and their own patching regime.
  • Require strong authentication and use separate administrator accounts that are not used for daily work.
  • Restrict who can distribute software and scripts, and log all such operations to storage outside the platform's control.
  • Have a plan for operating the client fleet if the management platform must be disconnected.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch