MSP Security Masterclass
Webinar 2 of 3
Tyler Wrightson
Leet Cyber Security
Twitter: @tbwrightson
@tbwrightson
Takeaway
Last Week Recap
• Hackers Target MSPs
• Risk is Bidirectional
1. Admin policy & Training to avoid password reuse
2. MFA Everything (of value)
3. Minimum Necessary & Least Privilege
4. Complacency
Agenda
• Pragmatic Guidance on Controls for your clients
– No sales pitch, no ‘academic bs’
• Foundations
• Top Five controls
Small Business
Double Edged Sword
Small Business
Strength in Size
Small Business is
Manageable
Foundations – Pragmatism
Quantify Specifics of This
Not This
Business Impact
Vulnerability != Risk
What do you think of X control?
Top Five Controls
Top Five Controls - 1
MFA
https://bit.ly/LCS-Legacy
MFA
– “Other Sites”
• Wiki, Project Management, CRM, etc
• Don’t forget forgotten sites (pun intended)
– Assume adversary can find everything
• DNS, public records, social engineering
Top Five Controls - 1
MFA
– Email & VPN
– Legacy Protocols
• https://bit.ly/LCS-Legacy
– “Other Sites”
• Wiki, Project Management, CRM, etc
• Don’t forget forgotten sites (pun intended)
– Assume adversary can find everything
• DNS, public records, social engineering
Top Five Controls - 2
Important App
Internal Network
Junk App Internal App
DC
Access Everything – Bad
Important App
Internal Network
Junk App Internal App
DC
Access Servers Only - Good
Important App
Internal Network
Junk App Internal App
DC
Access Only Necessary - Best
Important App
Internal Network
Junk App
Internal App
DC
Access Workstation RDP - Bad
Important App
Internal Network
Junk App
Internal App
DC
Access Workstation RDP – Better
TCP Port 3389
Important App
Internal Network
Junk App
Internal App
DC
Access Workstation RDP – Best
TCP Port 3389
Internal Network
Most Networks
Internet
DMZ App
DMZ
Good
Internet
DMZ App
Internal Network
DMZ
Good – No Internal Access from DMZ
Internet
DMZ App
Internal Network
Nothing Inbound
DMZ
Good – No Internal Access from DMZ
Internet
DMZ App
Internal Network
Nothing Inbound
DMZ
Better – No WKS Access from Servers
Internet
DMZ App
Servers
Nothing Inbound
Workstations
Minimal Inbound
DMZ
Better – No WKS to WKS
Internet
DMZ App
Servers
Nothing Inbound
Workstations
Private VLAN
Minimal Inbound
DMZ
Better – No WKS to WKS
Internet
DMZ App
Servers
Nothing Inbound
High Priv
Low Priv
DMZ
Better – No WKS to WKS
Internet
DMZ App
Servers
Nothing Inbound
General Pop
Finance
Manufacturing
Poll – VPN Configuration
Top Five Controls - 4
Local Administrators Group
Local Administrators Group
Domain Users
Local Administrators Group
Primary User
Credential Reuse
SuperSecretPass99$$
Most Networks
SuperSecretPass99$$
SuperSecretPass99$$
Same Local Admin Everywhere
SuperSecretPass99$$
aad3b435b51404eeaad3b435b51404ee
Pass The Hash
aad3b435b51404eeaad3b435b51404ee$$
ServerManagerPass1!
Not Much Better
WorkstationPass99$$
Credential Reuse - LAPS
Microsoft PAWs
Privileged Users
• Less is More
• ANY privileges
• Domain Admins, Enterprise Admin, Schema Admins
• Password Reset
Top Five Controls - 4
• Local Administrator Configuration
• Local Administrative Passwords
– Unique for each host
• LAPS & PAWS
• Limit priv users
– DAs (ent admins, schema admins)
Top Five Controls - 5
MDR
– Specifically Managed
– Not NSM
Questions
MSP360 Cybersecurity Master Class part 2

MSP360 Cybersecurity Master Class part 2