CERT-In Advisory
CIAD-2025-0018
Essential Measures for MSMEs for Safeguarding Business Operations against Cyber Security Threats
Original Issue Date: May 10, 2025
Severity Rating: High
Description
Recently, the Indian Computer Emergency Response Team (CERT-In) has detected severe cyber threats which encompass ransomware attacks, DDoS incidents, website defacements, data breaches, and malware infections. These attack vectors, whether executed individually or in combination, pose a significant risk to the integrity, confidentiality, and availability of systems and services.
Given the constrained resources, the Micro, Small and Medium Enterprises (MSME) must implement security measures that are both cost-effective and robust to safeguard their business operations. The following are the essential security measures to safeguard business operations and sensitive data.
- Strengthen Authentication & Access Control
- Enforce strong password policies with long, complex, and unique credentials for each service.
- Consider using multi-factor authentication (MFA) to secure accounts.
- Apply role-based access control (RBAC) to restrict employee permissions based on their responsibilities.
- Keep Software & Systems Updated
- Regularly update operating systems, applications, and security tools.
- Utilize automated updates to ensure system integrity remains intact.
- Web Server & Infrastructure Protection
- Scan all web servers and infrastructure for open ports and known vulnerabilities.
- Remove or isolate unmaintained, old, or unused web applications and systems.
- Ensure rapid detection and restoration of public-facing assets, in case of website defacement attacks.
- Secure Network & Endpoint Devices
- Configure firewalls to filter incoming and outgoing traffic effectively.
- Encrypt data during transmission and storage to safeguard against unauthorized access.
- Configure email filtering to block phishing attempts and malicious attachments effectively.
- Implement Robust Data Backup Strategies
- Maintain regular, offline backups to mitigate ransomware risks.
- Regularly test backup restoration procedures to ensure data recovery remains reliable.
- Develop an Incident Response Plan
- Establish a structured response plan to effectively address breaches and cyber incidents.
- Continuously analyze log files and network activity for failed login attempts, configuration changes, new device connections or other suspicious behaviour.
- Conduct Employee Awareness & Training
- Conduct regular cybersecurity training to educate employees about phishing, social engineering, and best practices.
- Organize routine cyber drills to simulate attacks and response measures.
MSMEs are requested to strictly monitor their ICT infrastructure. If any suspicious activity is found, immediately report the incident to CERT-In (incident@cert-in.org.in).
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|