4 ms·
2FA is fine. Don't bother with VPN's if you're SaaS-based. Just take the zero-trust route with mandatory MFA everywhere, invest in Yubikeys for all employees a
by Mandatum 4y ago
2FA is fine.
Don't bother with VPN's if you're SaaS-based. Just take the zero-trust route with mandatory MFA everywhere, invest in Yubikeys for all employees and set up a SIEM box to ingress audit logs from your various systems.
Setting up an Elastic box for this should be relatively straightforward. For many people it's easier to keep SIEM locally hosted (pulling data, no external access) and then periodically push encrypted backups offsite).
You'll probably end up setting up business metrics monitoring from this eventually too, at least in the early days before you start the "data lake" approach.
DNSSEC is a waste of time right now.