Cybersecurity • Data Protection
Business Data ආරක්ෂා කරන්නේ කොහොමද?
Business data protection එක backups එකකට සීමා වෙන්නේ නෑ. Access control, MFA, encryption, secure password storage, least privilege, backups, device/account security සහ incident recovery combine වෙන්න ඕන.
මේකේ main idea එක
CISA small-business guidance MFA සහ backups prioritize කරනවා. OWASP password/cryptographic storage guidance passwords secure hashing කිරීම සහ sensitive data at rest protection ගැන practical references දෙයි.
Practical checklist
- MFA on email/cloud/admin
- Role-based least privilege
- Password manager + unique passwords
- Encrypted HTTPS transport
- Sensitive database encryption where appropriate
- Regular offline/off-site backups
- Restore drills
- Access logs + staff offboarding process
Sri Lanka business එකකට apply කරන්නේ කොහොමද?
Business ownerගේ email එක compromise වුණොත් domain, hosting, ads, payments, cloud files reset කරන්න attackerට path ලැබෙන්න පුළුවන්. Email security “IT extra” එකක් නෙමේ—root account security එකක්.
Step-by-step plan
- Critical accounts list කරන්න
- MFA + recovery methods review කරන්න
- Backup 3-2-1 style plan consider කරන්න
- Staff permissions clean කරන්න
- Incident contact + restore steps document කරන්න
Quick Note: “Backup exists” සහ “business can recover quickly” දෙක වෙනස්. Recovery time test කරන්න.