Cybersecurity Published 2 min read

Security Starts at the Core: Six Practices Before Any New Tool

Before buying another security tool, make sure the basics that stop most common incidents are in place: asset inventory, patching, MFA, least privilege, tested backups, and logs.

Conversations about cybersecurity tend to start with tools: a new monitoring platform, an advanced protection suite, an AI-driven threat detection system. These tools are useful, but they sit on a foundation. If the foundation is weak, no tool, however advanced, will make up for it.

Many common security incidents don't begin with a sophisticated attack. They begin with a known vulnerability that was never patched, a leaked password on an account with no second factor, or permissions far broader than anyone needed. Those are foundation problems, not tooling problems.

Here are six basic practices worth having in place before any new security investment.

1. Know what you're protecting

You can't protect a device or system you don't know exists. Start with a clear, current inventory of assets: servers, devices, applications, accounts, cloud services, and the owner of each.

Forgotten systems, like an old test server or the account of someone who left, are often the easiest way in, because nobody is watching them.

2. Patch on a regular cycle, not when it's convenient

Once a vulnerability is published, everyone knows about it, attackers included. Patching needs a steady, clear cycle:

  • Inventory: which systems need updates?
  • Prioritize: start with critical vulnerabilities, especially on internet-facing systems.
  • Test: try the update in a limited environment before rolling it out.
  • Apply and verify: install the update, then confirm it actually succeeded.

3. Multi-factor authentication (MFA) on everything that matters

A password alone is no longer enough. It can be leaked, guessed, or phished. MFA adds a layer that makes a stolen password insufficient on its own.

Start with the most sensitive accounts: email, administrator accounts, remote access, and cloud management consoles. Prefer authenticator apps or security keys over text messages where you can.

4. Least privilege

Every account gets only the permissions it needs to do its job, and no more. Administrator accounts are used for administrative tasks only, not for everyday email and browsing.

Review permissions regularly, and disable accounts as soon as people leave. Excess permissions only show their cost when someone exploits them.

5. Tested backups

A backup you've never restored from is an assumption, not a plan. The well-known 3-2-1 rule is a good starting point:

  • Three copies of your data.
  • On two different types of storage.
  • At least one copy off-site or isolated from the network.

Most importantly, test restores regularly and know how long they take.

6. Logs you can rely on

When an incident happens, the first question is: what happened, and when? The answer depends on logs. Make sure logging is enabled on important systems, collected in a central place, kept long enough, and actually reviewed by someone.

The takeaway

None of these practices are new or exciting, but they are the foundation every other security tool stands on. Before asking about the next tool, ask: Do I know my assets? Are my updates regular? Is MFA enabled? Are permissions limited? Have I tested a restore? Do the logs exist?

If the answer to all of them is yes, a new tool will add real value. If not, the right place to start is the core.