Universal Defence Framework
Overview
Section titled “Overview”While each malware type requires specific countermeasures, the following seven principles form a universal foundation for organisational cyber defence.
1. 🔧 Patch Management
Section titled “1. 🔧 Patch Management”The majority of successful attacks exploit known, patched vulnerabilities.
| Principle | Action |
|---|---|
| Speed | Critical patches within 72h (internet-facing: 24h) |
| Priority | Internet-facing → internal servers → endpoints |
| Automation | WSUS/SCCM/Intune for endpoints; Ansible/Terraform for infra |
| Testing | Staged rollout: canary → pilot → production |
| Exceptions | Documented, time-bounded, compensating controls |
Metric: % of critical patches applied within SLA
2. 🔒 Least Privilege
Section titled “2. 🔒 Least Privilege”Every user, system, and process should have only the minimum permissions necessary.
| Layer | Principle |
|---|---|
| Users | Standard accounts; admin via PAM/JIT |
| Service Accounts | Dedicated, scoped, rotated |
| Applications | No admin; constrained language modes |
| Network | Micro-segmentation; default deny |
| Cloud | IAM least privilege; boundary policies |
Metric: % of accounts with admin rights; % of overly permissive roles
3. 🛡 Defence in Depth
Section titled “3. 🛡 Defence in Depth”Layer multiple, complementary controls — no single control is infallible.
| Layer | Controls |
|---|---|
| Perimeter | Firewall, WAF, DDoS protection, DNS filtering |
| Network | Segmentation, IDS/IPS, Zeek, NetFlow, TLS inspection |
| Endpoint | EDR, AV, application control, memory protection |
| Identity | MFA (FIDO2), PAM, JIT access, tiered admin |
| Application | SAST/DAST/IAST, WAF, RASP, SBOM |
| Data | Encryption (at rest/transit), DLP, classification |
| Human | Awareness training, phishing simulations, reporting |
| Recovery | Backups, IR plan, tabletop exercises |
Principle: Failure of one layer ≠ total compromise
4. 💾 Backup & Recovery
Section titled “4. 💾 Backup & Recovery”Offline, tested, geographically distributed backups are the ultimate insurance.
| Rule | Description |
|---|---|
| 3-2-1 Rule | 3 copies, 2 media types, 1 offsite/offline |
| Immutability | WORM, Object Lock, legal hold |
| Testing | Quarterly full restore test; monthly partial |
| RTO/RPO | Defined per tier; documented |
| Air-gap | Physical or logical (immutable bucket) |
| Encryption | AES-256; keys separate from backups |
Metric: Restore test success rate; RTO/RPO compliance
5. 👥 User Awareness
Section titled “5. 👥 User Awareness”Human beings remain the most targeted entry point for malware.
| Programme | Frequency | Content |
|---|---|---|
| Onboarding | Day 1 | Policy, reporting, phishing basics |
| Quarterly | 4x/year | Phishing, social engineering, safe computing |
| Phishing Sims | Monthly | Realistic templates; no punishment |
| Role-based | Annual | Dev: secure coding; Admin: PAM; Finance: BEC |
| Reporting | Continuous | ”See something, say something” culture |
Metric: Phish click rate; reporting rate; training completion
6. 🔐 Zero Trust Architecture
Section titled “6. 🔐 Zero Trust Architecture”Never trust, always verify — threats exist both inside and outside.
| Pillar | Implementation |
|---|---|
| Verify Identity | FIDO2 MFA, certificate-based auth |
| Verify Device | Compliance posture, health attestation |
| Verify Network | Micro-segmentation, encryption everywhere |
| Least Privilege | JIT, PAM, tiered admin, zero standing access |
| Assume Breach | Monitor everything; encrypt all traffic |
| Continuous Verification | Continuous auth, risk-based auth |
Maturity Model: Traditional → Advanced → Optimal (CISA ZTMM)
7. 🚨 Incident Response Preparedness
Section titled “7. 🚨 Incident Response Preparedness”The ability to rapidly detect, contain, eradicate, and recover minimises damage.
| Phase | Key Actions |
|---|---|
| Prepare | IR plan, playbooks, tooling, team, comms plan |
| Detect | SIEM, EDR, NDR, threat intel, hunt team |
| Contain | Short-term (isolate), long-term (rebuild) |
| Eradicate | Remove artefacts, rotate creds, patch root cause |
| Recover | Restore from immutable backup, validate, monitor |
| Lessons Learned | Root cause, gap analysis, update playbooks |
| Exercise | Frequency |
|---|---|
| Tabletop | Quarterly |
| Red Team / Purple Team | Semi-annual |
| Full Simulation | Annual |
| Ransomware-specific | Semi-annual |
Metric: MTTR (Mean Time To Respond); Containment time; Recovery time
Implementation Roadmap
Section titled “Implementation Roadmap”| Phase | Focus | Timeline |
|---|---|---|
| 0 - Baseline | Asset inventory, risk assessment, gap analysis | Month 1 |
| 1 - Quick Wins | MFA, patching, backups, AV/EDR, awareness | Months 2-3 |
| 2 - Harden | Network seg, least priv, app control, monitoring | Months 4-6 |
| 3 - Mature | Zero Trust, hunt team, purple team, automation | Months 7-12 |
| 4 - Optimise | Automation, AI/ML detection, continuous improvement | Ongoing |
Related
Section titled “Related”- MITRE ATT&CK — Technique-based detection
- Incident Response — Playbooks
- Backup Strategy — 3-2-1 implementation
- Zero Trust — Architecture