---
title: CSA 12 Days of Cyber Christmas
description: As the end of the year fast approaches, we wanted to share a little refresher on ways to ensure your technology and data remains as safe as possible over the festive period and well into 2022. To stay in the spirit of the season, we’ve opted to share our top security tips in the style of a 12 Days of Cyber Christmas list!
image: https://csacyber.com/hubfs/12-days2.png
---

[Skip to content](https://csacyber.com/blog/csa-12-days-of-cyber-christmas#main-content)

[![CSA Cyber - Cyber Security Solutions to Protect your People](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=300&height=108&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber - Cyber Security Solutions to Protect your People")](https://csacyber.com/)

- Services 
    - [Offensive Security Services](https://csacyber.com/offensive-security-services) 
          - [Penetration Testing](https://csacyber.com/penetration-testing)
          - [Red Teaming and attack simulations](https://csacyber.com/offensive-security-services#red-teaming)
          - [Continuous testing](https://csacyber.com/offensive-security-services#continuous-assurance)
          - [Managed offensive security](https://csacyber.com/offensive-security-services#managed-offensive)
    - [Consultancy Services](https://csacyber.com/cyber-consultancy-services) 
          - [Frameworks & assessments](https://csacyber.com/cyber-consultancy-services/frameworks-and-assessments)
          - [Data protection](https://csacyber.com/cyber-consultancy-services#data-protection)
          - [Virtual leadership](https://csacyber.com/cyber-consultancy-services#virtual-leadership)
          - [Technical security consulting](https://csacyber.com/cyber-consultancy-services#technical-consultancy)
          - [Governance, Risk & Compliance (GRC)](https://csacyber.com/cyber-consultancy-services/governance-risk-and-compliance-services)
    - [Extended Managed Security Services](https://csacyber.com/extended-managed-security-services) 
          - [Microsoft Sentinel SIEM](https://csacyber.com/extended-managed-security-services#microsoft-sentinel)
          - [SOC services](https://csacyber.com/extended-managed-security-services#soc-services)
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/extended-managed-security-services#cyber-helpdesk)
    - [Incident Response Services](https://csacyber.com/incident-response-services) 
          - [Emergency Incident Response](https://csacyber.com/urgent/emergency-incident-response)
          - [Incident Response Retainer](https://csacyber.com/incident-response-services)
          - [Cyber Incident Readiness & Response Planning](https://csacyber.com/incident-response-services)
          - [Tabletop Exercises & Live-Range Engagements](https://csacyber.com/incident-response-services)
    - [Specialist Security Services](https://csacyber.com/specialist-services) 
          - [AI Security](https://csacyber.com/cyber-services-for-ai)
          - [Operational Technology (OT)](https://csacyber.com/specialist-services#operational-technology)
          - [Cyber security for Private Equity](https://csacyber.com/specialist-services#mergers-and-acquisitions)
          - [Cyber training and education](https://csacyber.com/specialist-services#training-and-education)
          - [Virtual leadership](https://csacyber.com/specialist-services#leadership)
    - [Cyber Technologies](https://csacyber.com/cyber-technologies) 
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/cyber-technologies#sentinelone)
          - [AppGuard Endpoint & Server Zero Trust Protection](https://csacyber.com/cyber-technologies#appguard)
          - [Qualys Vulnerability Management as a Service (VMaaS)](https://csacyber.com/cyber-technologies#qualys-vmaas)
          - [Lookout Mobile Device Protection](https://csacyber.com/cyber-technologies#lookout)
          - [ThreatER DNS Protection](https://csacyber.com/cyber-technologies#threater-dns)
          - [Cyber Security Awareness & Training platform](https://csacyber.com/cyber-technologies#boxphish)
- [About](https://csacyber.com/about-us) 
    - [Careers](https://csacyber.com/careers)
    - [Certifications](https://csacyber.com/certifications-and-awards)
- [Blog](https://csacyber.com/blog)
- [Support Centre](https://csacyber.com/support)
- Resources 
    - [Case Studies](https://csacyber.com/case-studies)
    - [Downloads & Reports](https://csacyber.com/downloads-and-reports)
    - [Webinars](https://csacyber.com/webinars)
    - [Partners](https://csacyber.com/partners)
    - [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)
- [Contact](https://csacyber.com/contact-us)

- Search Search
  
  Search

 December 8, 2021

 5 min read time

# CSA 12 Days of Cyber Christmas

![Cyber Security Associates](https://app.hubspot.com/settings/avatar/d41d8cd98f00b204e9800998ecf8427e) [Written by: Cyber Security Associates -](https://csacyber.com/blog/author/cyber-security-associates)

[Article](https://csacyber.com/blog/tag/article) 

![](https://csacyber.com/hubfs/12-days2.png)

### Executive Summary

As the end of the year fast approaches, we wanted to share a little refresher on ways to ensure your technology and data remains as safe as possible over the festive period and well into 2022. To stay in the spirit of the season, we’ve opted to share our top security tips in the style of a 12 Days of Cyber Christmas list!

### Day 1: Ensure the Principle of Least Privilege

If you manage the security of your organisation’s IT infrastructure, it’s likely you also manage a domain with plenty of users - each requiring a unique set of permissions. It can be a lot to juggle! To stay secure, we recommend you double check accounts on the domain only have access to the devices and resources that they need to access. Doing so could stop malicious actors in their tracks. And, if an account is compromised, you’ll suffer far less collateral damage due to the limited access to lateral movement.

### Day 2: Backups

This might be news to some, but hackers don’t always want to steal your data. They might want to remove or destroy it instead. Therefore, it is always good to create backups of your critical data should a disaster strike. Having multiple copies of your data, both online and offline, whilst keeping it backed up and protected could help your organisation should it need to recover from a worst-case scenario.

### Day 3: Encrypt Your Data

Whilst your cyber security solutions should prevent your data from being stolen in the first place, in the unfortunate event that it does end up in the hands of a malicious actor, the best way to ensure its continued security is through encryption. Luckily, there are many solutions for encrypting data, such as archiving a file and adding an encrypted password or opting for a full-disk encryption solution. No matter what method you choose, encryption will make it much harder for malicious actors to gain access to your data and will help you work towards better cyberculture.

### Day 4: Manage Your Digital Footprint

We’ve all made mistakes online, such as sharing an embarrassing photo on social media or posting some content with a spelling mistake. When was the last time you searched your name or investigated your digital footprint? Many will say a very long time ago, or never! Looking at your digital footprint and removing anything you come across that you wouldn’t like others to see should give you some peace of mind, save you from embarrassment and remove any potential ammunition a malicious actor could use against you.

### Day 5: Vulnerability Scans

In 2020, over 18,000 vulnerabilities were recorded on the National Vulnerability Database, a figure that has only continued to grow over the last year. Unpatched vulnerabilities can provide malicious actors with an easy door for entry into your systems and information. Implementing a solution that regularly scans for vulnerabilities and shares alerts on necessary patch updates will protect you from malicious actors that lurk in the shadows waiting to pounce on any given vulnerability.

### Day 6: Patch Management

But, how do you ensure that the correct updates and patches are completed on time? In comes patch management. With the right solution, worrying about patching your systems can be a thing of the past. There are plenty of patch management solutions out on the market at the moment, from the big heavy hitters like ManageEngine and Avast. Though, regardless of which provider you choose, having a solution for patch management is sure to mitigate one attack vector at a time giving you peace of mind.

### Day 7: Enable 2-FA (Two Factor Authentication)

This past year we’ve seen 2-FA here, there and everywhere - and with good reason. Using 2-FA provides more control over who gets access to your accounts as it provides another layer of protection on top of passwords and/or a passphrase. 2-FA can come in multiple forms, though the most common type is requesting and receiving a one-time code via text or authenticator app that’s valid for a limited time only. Whilst we have to acknowledge that 2-FA is not bulletproof and some methods are better than others, having 2-FA puts you in a much better position than you would be without it, which is why it’s one of our top security recommendations.

### Day 8: Check Your Password

On the topic of passwords and passphrases, have you considered how strong yours are? As computers become more technologically advanced, brute force attacks become more favoured by malicious actors since they’re easier to carry out. The less complex your password or passphrase, the more likely you could be compromised. At CSA, we recommend you use a strong password or passphrase in combination with the advice in our next tip to help decrease the chance of being compromised via brute force.

### Day 9: Password Management Tools

There are many password management tools out there, but what do they actually do? Secured with a master password, these tools allow users to generate and store passwords and/or passphrases ready for when needed. Before you start thinking password management tools sound counter-intuitive, research has shown that memorising multiple strong passwords can be difficult, and as a result, users will tend to opt for weaker and weaker passwords as time goes on. However, users will find themselves in a much stronger position if they need to only memorise one very strong password and can generate unrelated passwords from the management tool.

### Day 10: Remain Aware of Current Threats

When it comes to cyber security, knowledge is power. Keeping tabs on malicious actor groups and how they think is a great way to protect yourself from them. If you can mitigate a common attack method used by a malicious group and understand how they operate and identify their indicators of compromise (IoC), then you’ll be better equipped to defend yourself than if you weren’t aware of the threats you could face. How do you keep up to date on the latest threats? Make sure to follow us on LinkedIn and Twitter for regular updates and keep an eye out for our regular Threat Reports that share further details on what you could face.

### Day 11: Remain Vigilant About Phishing Methods

Whilst phishing methods do come under current threats, as mentioned in the tip above, protecting yourself against phishing scams is another kettle of fish that needs to be addressed separately. Why? Well, research shows that 94% of malware is sourced by email, with some of these attempts disguised as exclusive shopping discounts or deal scams over the festive period. Scammers take advantage of this being a more stressful time of the year than most, with people more likely to fall victim to a phishing attack. Once someone is compromised, it’s incredibly easy for malicious actors to steal personally identifiable information (PII) and other valuable information. Furthermore, attackers can gather emails and contact information, making these types of attacks quite dangerous, so it’s important to stay vigilant and aware of how scammers are currently operating. If you manage a mail server, implement a good spam filter to prevent the issue before it has a chance to land in your inbox.

### Day 12: Active Monitoring

Whether internal, external or software-based, having active monitoring, if possible, is a priceless asset to have within your arsenal. A third eye to monitor events, alert you to any issues and inform you if your data is found on the internet as it happens is crucial if you want to react quickly and efficiently to any security breaches. With active monitoring, you can receive quick, detailed investigations into what’s going on behind the scenes with your data, or you can request active vulnerability scanning to provide you with more potential for your cyberculture.

If you would like to take action on any of these top tips, then you’re in luck! At CSA, we provide solutions to each of these issues, which you can learn more about on our services page or get in touch with one of the top experts to discuss what solutions will work best for you.

Related Posts

## You may also like this

[Similar Articles](https://csacyber.com/blog)

[![](https://csacyber.com/hs-fs/hubfs/20230510-N1005919-Edit1.jpg?width=624&height=427&name=20230510-N1005919-Edit1.jpg)](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 August 24, 2026

 2 min read

### [FluidOne Group appoints Charly Davis as Managing Director of CSA Cyber to advance its security-first strategy](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 Experienced industry leader joins FluidOne to strengthen integrated cyber, IT and secure networking...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Untitled%20design.jpg?width=624&height=427&name=Untitled%20design.jpg)](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 August 20, 2026

 2 min read

### [CSA Cyber and FluidOne named as suppliers on G-Cloud 15](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 CSA Cyber (CSA), part of the FluidOne Group, has been named as a supplier on Government Commercial...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Engineered%20to%20Endure%20Campaign%20Assets%20(2).png?width=624&height=427&name=Engineered%20to%20Endure%20Campaign%20Assets%20(2).png)](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 August 20, 2026

 6 min read

### [Why organisations lose security visibility without realising it](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 Before an organisation can understand risk, maintain control or respond effectively to emerging...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![CSA Cyber Logo FNL_Full Logo](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=3463&height=1248&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber Logo FNL_Full Logo")](https://csacyber.com/)

Established in 2013, Cyber Security Associates Limited trading as CSA Cyber provides cyber consultancy and cyber managed services which help to detect, protect and educate against the ever-changing cyber threat. We have built our team from a foundation of Government (ex-Military) and Commercially experienced specialists all holding current and relevant cyber certifications. Today our core services are based around a 24/7 Security Operations Centre (SOC) based in Gloucester.

#### News & Resources

- [Blog](https://csacyber.com/blog)
- [Case Studies](https://csacyber.com/case-studies)
- [Downloads & Reports](https://csacyber.com/downloads-and-reports)
- [Webinars](https://csacyber.com/webinars)
- [Careers](https://csacyber.com/careers)
- [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)

#### Quick Links

- [About Us](https://csacyber.com/about-us)
- [Certifications](https://csacyber.com/certifications-and-awards)
- [Our Parent Company](https://www.fluidone.com)
- [Partners](https://csacyber.com/partners)
- [Contact Us](https://csacyber.com/contact-us)
- [Anti Bribery Policy](https://csacyber.com/hubfs/CSAAnti-BriberyPolicy.pdf)
- [Complaints Policy](https://csacyber.com/hubfs/CSAComplaintsPolicy.pdf)
- [Corporate Social Responsibility Policy](https://csacyber.com/hubfs/CSACorporateSocialResponsibilityPolicy.pdf)
- [Slavery and Human Trafficking Statement](https://csacyber.com/hubfs/CSASlaveryandHumanTraffickingStatement.pdf)
- [NCSC CHECK Status Verification](https://www.ncsc.gov.uk/organisation/csa-cyber/check-penetration-testing)
- [CREST Approved Certification Verification](https://www.crest-approved.org/member_companies/csa-cyber/)

#### Contact Information

**United Kingdom - London**

Cyber Security Associates Ltd

5 Hatfields, London, SE1 9PG

 

**United Kingdom - Gloucester**

Cyber Security Associates Ltd

Unit 11, Wheatstone Court, Waterwells Business Park, GL2 2AQ

 

**Phone:** [+44(0) 300 303 4691](tel:03003034691)

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

**United States of America**

Cyber Security Associates Inc.

6010 W. Spring Creek Pkwy, Plano, Texas, 75024

 

**Phone:** [+1 469 750 1695](tel:14697501695) 

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

[![trust-pilot](https://csacyber.com/hs-fs/hubfs/trust-pilot.png?width=178&height=104&name=trust-pilot.png)](https://uk.trustpilot.com/review/csa.limited)

 

---

- [Website Terms of Use](https://csacyber.com/website-terms-of-use)
- [Website Privacy Policy](https://csacyber.com/privacy-notice)
- [Website Cookie Policy](https://csacyber.com/cookie-policy)

 Copyright 2026. Cyber Security Associates Ltd [Follow us on Facebook](https://www.facebook.com/CSALIMITED/) [Follow us on LinkedIn](https://www.linkedin.com/company/csa-cyber/) [Follow us on Twitter](https://twitter.com/cybersecurityis) [Follow us on Facebook](https://www.youtube.com/@cybersecurityassociateslim) [Follow us on Facebook](https://www.instagram.com/cybersecurityassociates)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Cyber Security Associates",
    "url" : "https://csacyber.com/blog/author/cyber-security-associates"
  },
  "dateModified" : "2024-12-06T15:58:21.202Z",
  "datePublished" : "2021-12-08T05:00:00.000Z",
  "headline" : "CSA 12 Days of Cyber Christmas",
  "image" : [ "https://csacyber.com/hubfs/12-days2.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://csacyber.com/blog/csa-12-days-of-cyber-christmas",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://csacyber.com/hubfs/csacyber-logo-black-01.svg"
    },
    "name" : "Cyber Security Associates Ltd"
  }
}
```