The purpose of this article is to discuss the top 5 must have cybersecurity solutions in 2023, which include the following:
- MFA with conditional access
- End User Security Training
- Enterprise Network Firewall (or Next Gen Firewall)
- Endpoint Detection and Response
- Backup with Air Gap

Top 5 Cybersecurity Solutions
The post-COVID world has changed the environment for IT and cybersecurity. Most organizations still have a work-from-home presence at some capacity and some will have it indefinitely. What this does is move the management of security from primarily being a corporate physical location straight to the edge and end user. Additionally, organizations who are leveraging IoT and cloud workloads need to secure those locations as well. In order to do so, investments need to be made to address these different models of change. These top 5 must have cybersecurity solutions are needed to help you mitigate risk in 2023.
MFA with Conditional Access
By now, most organizations have implemented multi-factor authentication (MFA) to prevent a threat actor from access if they have credentials. Modern cybersecurity insurance providers require MFA for anyone accessing the network and for all privileged accounts. Especially for end users and depending on the type of setup has led to MFA fatigue. That has led to a new type of attack where users are tricked into giving access to threat actors access due to overload of push notifications. Cybersecurity and IT Directors can mitigate MFA fatigue risk by implementing conditional access.
Conditional access works by building trusted zones and allowing access to users that meet the criteria of a trusted zone. For example, a user who logs in from a specific device or IP address will only be prompted for MFA every 30 days unless those criteria are not met.
End User Security Training
End user security training is one of the most critical tools in your cybersecurity arsenal. It allows you to create an initial baseline by testing the cybersecurity awareness of your end users by phishing them and reporting back to you who failed. Initially when this is deployed for the first time at an organization, you can expect to see upwards of a 20% failure rate for phishing. As time progresses over a year that number can drop down to about 1-2% as end users get trained by watching the training videos provided.
Enterprise Network Firewall
Enterprise network firewalls or next-gen firewalls (NGFW) are still needed in a post-covid world where work from home is prominent. The difference today is that firewalls need to be extended to the edge. This can be accomplished by either forcing VPN connections from an endpoint with solutions like Fortinet’s FortiGate and FortiClient or by implementing a solution like Cisco Umbrella, which is a Cloud Access Security Broker (CASB) and provides firewall-like services at the edge. In either case, the enterprise network firewall provides a lot of benefits and should be implemented wherever you have an internet circuit and end users.
Endpoint Detection and Response
Endpoint Detection and Response (EDR) solutions have gained massive market share over the past two years. For one reason, incident response teams implement it to hunt for threats that still exist in the environment and use it for forensics. Another reason that is gaining ground is that insurance companies are starting to require it for their cyber insurance policies. Companies can also save money on their insurance policies by showing their insurance carrier they are being proactive with cyber security posture.
EDR solutions are very different from antivirus solutions in that they:
- Do forensics and threat hunting
- Record events for analysis
- Have playbooks that automatically integrate with other security tools to isolate and remove threats
Backup with Air Gap
Backups have long been a solution to recover from a security incident like ransomware. Hackers have caught on to this though and are now encrypting backup repositories as well. This makes an organization’s response completely futile. That is, unless they have an air gapped backup copy. An air gapped backup copy is a backup copy that is completely offline. Many organizations have resorted going back to tape backups. Others are choosing more sophisticated solutions like Dell’s Cyber Recovery with PowerProtect.
Conclusion
Many IT Directors and IT Managers read articles like this and go straight to their vendors to look at solutions without first doing a security assessment. You should do a security assessment to understand where your risks are and where you are most vulnerable. This will point you in the right direction of which tools to look at first for protection. Once you have done that, you should plan on doing a security assessment annually to test the efficacy of these tools. That will enable you to make sure your tools are working properly the way you intended it.
Contact a Cybersecurity Specialist
If you would like to contact a Cybersecurity Specialist to discuss any of the solutions mentioned, please fill out the form below (U.S. Based Only).