Skip to content
Cybersecurity

Protection Against Hacker Attacks: 12 Concrete Measures for Companies, Hotels, Hospitals and Public Authorities

Twelve measures against cyber attacks: segmentation, firewalls, MFA, zero trust, 3-2-1 backups, patch management, awareness and emergency planning.

Published on 4 min read

Grid of twelve glass panels on a white wall in an office with a city view.

The BSI and BKA situation reports have shown the same pattern for years: most successful attacks exploit missing basics, not spectacular vulnerabilities. Remote access without a second factor, a server without updates, a backup on the same network as the encrypted data. The following twelve measures cover these basics and are feasible with reasonable effort in an SME, a hotel, a hospital or a public authority.

The twelve measures

  1. Segment the network. A flat network turns one infected workstation into a company-wide incident. Zones for workstations, servers, backups, management, building services and guests, with a firewall and explicit rules at every transition.
  2. Operate firewalls actively. Modern firewalls inspect at application level, detect attack patterns and control outbound connections. Rules are reviewed regularly and firmware updated promptly, because firewalls and VPN gateways are themselves popular targets. In customer projects we use the HPE Juniper Networking SRX series.
  3. Multi-factor authentication on all remote access. Stolen credentials are the most common entry point. Mandatory for VPN, remote desktop, webmail, Microsoft 365, administrative accounts and remote maintenance, where possible phishing-resistant with FIDO2 or passkeys.
  4. Zero trust as a principle. No device and no user is trusted simply because it is on the company network. Least-privilege rights, administrative rights separated from working accounts, unpatched devices denied access to sensitive systems.
  5. Backups on the 3-2-1 rule. Three copies, two media, one off site, and at least one copy immutable or physically separated so that an attacker with administrative rights cannot delete it. An annual documented restore test is part of it.
  6. Patch management on a fixed schedule. In 2024/2025 the BSI counted an average of 119 new vulnerabilities per day. Operating systems and standard software on a fixed schedule, publicly reachable systems within a few days for critical vulnerabilities.
  7. Awareness. Phishing remains the most common attack path and is becoming more personal and error-free with AI. Short, regular training with sector examples, simulated phishing emails with an explanation and a simple reporting channel. Changes to bank details follow the four-eyes principle.
  8. An emergency plan that works without the affected IT. Printed, with contacts for the crisis team, IT service provider, cyber insurer, the police cybercrime contact point and the data protection authority, plus decision paths and restart order. Data breaches must be reported within 72 hours.
  9. Monitoring and detection. Central collection of logs from firewalls, servers and identity services, alerts on unusual data volumes, logins at unusual times, new administrative accounts and mass deletions.
  10. Harden the Wi-Fi. Corporate Wi-Fi with WPA3 or at least WPA2-Enterprise and login via certificates or personal credentials. Guest Wi-Fi in its own segment with client isolation, administrative access to access points only from the management network.
  11. Include suppliers and service providers. A single compromised access opens many customers, as the 2025 data incident at a service provider of Berlin’s transport operator BVG showed. Contracts include minimum requirements, MFA, personalised accounts, deletion deadlines and a 24-hour incident reporting obligation.
  12. Cyber insurance as a supplement. It covers forensics, recovery, business interruption and liability, but replaces none of the eleven previous measures. Insurers check before signing whether MFA, separated backups, patch management and an emergency plan exist. The insurer’s questionnaire is a useful checklist.

Sector-specific points

In hospitals, medical devices belong in their own zone because they often run old operating systems and cannot be patched. The emergency plan also needs paper-based operation for admissions, wards and pharmacy.

In hotels, tills, access systems, guest Wi-Fi and administration are strictly separated. Cloud-managed access points such as Juniper Mist flag rogue access points and configuration deviations.

Public authorities separate specialist applications from office operations and remove shared accounts and local administrative rights. Construction and property companies give building controls their own segment without internet access and revoke subcontractor roles automatically at project end. Critical infrastructure operators and NIS-2 entities have additional reporting deadlines.

The order of implementation

Tackling all twelve points at once achieves none of them. Proven practice: first MFA on all remote access and a separated, immutable backup, because both are quick to implement and intercept the most common damage scenarios. Then patch management and segmentation, then monitoring and the emergency plan. Awareness and supplier management are ongoing tasks; cyber insurance completes the process once the basics stand.

Key points

  • Most successful attacks exploit missing basics: remote access without a second factor, missing updates, backups on the same network.
  • MFA on all remote access and a separated, immutable backup come first, followed by patch management, segmentation, monitoring and an emergency plan.
  • Cyber insurance supplements these measures but does not replace them; insurers check them before signing.

How DEVACON supports companies with firewalls, segmentation, multi-factor authentication and emergency planning is described on the page Cybersecurity.

Topics Ransomware Network Juniper Zero Trust Backup

This article comes from the DEVACON blog and was editorially revised for the new website.