Identify and Protect, Translated: Know What You Have Before You Lock It Down
Security vendors love a good acronym. If "identify," "protect," "detect," "respond," and "recover" have ever sounded like a menu you can't afford, that's the jargon talking, not you.
October is Cybersecurity Awareness Month, so for the next 31 days we're translating the jargon, one step at a time. We start with the first two.
Identify: know what you've got
Identify means keeping an honest list of what you own and who can get into it. Laptops, servers, cloud accounts, plant-floor equipment, vendor logins, the old admin account somebody forgot about. If it's on your network or touches your data, it belongs on the list.
What it costs you if it's missing: you can't defend what you don't know exists. Most attackers don't break in through something clever. They use the thing nobody was watching.
Protect: lock the doors you know about
Protect means making the things on that list harder to get into. Multi-factor authentication, giving people only the access their job needs, patching, and separating the systems that matter most from the ones that don't.
What it costs you if it's missing: the cheap stuff is usually the stuff that gets skipped. Turning on MFA and removing old accounts costs far less than a bad week of cleanup.
Identity is the part people get tangled on
"Identity" in security doesn't mean a product. It means who has the keys to what. Every login is a key, and every key is something an attacker would like to borrow. That's why Identify and Protect lean so heavily on accounts and access.
What this looks like where you work
Banking and financial services: your customers' data is the asset, and access to it is the key ring. Knowing exactly who can reach it, and why, is the first honest question.
Healthcare: patient systems have more users, shared logins, and connected devices than most people expect. A good list shows what is connected to what, and which devices need careful handling before anything automated touches them.
Manufacturing: plant-floor equipment is often the least inventoried part of the business. It was installed years ago, it runs fine, and nobody wrote down what it's connected to.
Higher education: thousands of student, faculty, and guest devices come and go, usually with a small team watching over them. You can't list every one by hand, so visibility has to scale.
MSPs: your remote management tools are the front door to every client you serve. Protecting your own environment is part of protecting theirs.
Where BitLyft AIR® fits
Lists go stale. That's the real problem with Identify and Protect is that people do them once. BitLyft AIR® connects identity, email, endpoint, and cloud activity in one place, so unusual activity on an account or device shows up instead of hiding in a spreadsheet nobody has opened since the last audit.
Next week
We move to Detect. It's the one that sounds the most expensive and usually isn't. If you want terms like these explained any time, our glossary is a good place to look, and if you'd like to see what this looks like in your environment, request a demo.