CyberNetwork Asset Inventory Before Deployment of Solutions ⬇ Presentation Slide

t12.png

CyberNetwork_Endpoint_Protection.pptx

This document above shows a walkthrough how CyberNetwork moved from limited endpoint visibility to a centrally monitored and managed environment. It follows the work in the order it was carried out, from the initial scenario through architecture, Wazuh deployment, and Action1 patch management.

1. Scenario

Your Team {CyberNetwork} is a healthcare supply chain company operating 4 endpoints across three office locations - Windows workstations, Linux workstations and a linux server. You have never run a vulnerability scan. They have antivirus on some machines and nothing on others. Their IT team handles patches manually when they remember. Last month a competitor in the same sector was hit with ransomware that entered through an unpatched Windows machine with an exposed RDP port. Your team has 14 days to implement a full endpoint protection and vulnerability management program before the board meeting.

1.1 Endpoint estate

The resulting inventory is four endpoints. Each endpoint is designed to run both a Wazuh Agent and an Action1 Agent while one of the endpoints will run as the Wazuh server and will also host an Action1 agent.

1.2 Initial security problem

Before the project, the organisation lacked a reliable endpoint inventory, a measured vulnerability baseline and a consistent way to prove that security updates had been installed. Patching was manual and endpoint behaviour was not centrally monitored. This created exposure to unpatched vulnerabilities, malicious activity, unauthorised file changes and delayed response.

1.3 Project Objectives