AI is great but let's make sure we got Cybersecurity Basics Right first

Artificial Intelligence (AI) solutions are getting popular fast, and organizations are often tempted to use the latest “shiny tool” believing it will magically secure their environment. But without solid cybersecurity fundamentals, no AI tool — no matter how advanced — will protect your business effectively. In this blog, we explain five essential cybersecurity pillars you must establish before investing in AI‑driven tools. These foundational practices will strengthen your security posture, reduce risk, and help protect your business in today’s evolving threat landscape.

CYBERSECURITY

12/15/20254 min read

1. Phishing Training & Awareness Program

Despite technological advancements, phishing remains the most common initial access method used by threat actors. In fact, according to the Verizon Data Breach Investigations Report, over 80% of breaches involve the human element. Threat actors have moved beyond simple emails with malicious PDF attachments. Instead, they now use sophisticated techniques:

  • Credential phishing via malicious URLs that mimic Microsoft 365 or banking portals.

  • CAPTCHA-bypass tricks such as click-fix campaigns, where users are misled into thinking they are performing routine security tasks.

  • Use of legitimate-looking third-party tools like SharePoint or DocuSign to increase trust.

A modern phishing training program must:

  • Evolve with current tactics, not rely on outdated simulations.

  • Include frequent, randomized phishing simulations tailored to job roles.

  • Educate staff on MFA bypass, QR code phishing, and deepfake voice or video attacks.

  • Create a culture where employees feel safe reporting phishing attempts, even if they clicked.

An effective program can drastically reduce your organization’s exposure to credential theft, ransomware, and business email compromise (BEC).

2. Vulnerability Management Program

Most organizations struggle with timely patching. Some don’t even conduct regular vulnerability scans. And yes — we get it. People are busy. Patches can break functionality. But the reality is: not every vulnerability needs to be patched immediately, and that’s where a structured program helps.

A strong vulnerability management process includes:

  • Deploying a vulnerability scanner (like Tenable, Qualys, or OpenVAS) to continuously scan your environment.

  • Setting Service Level Agreements (SLAs) for remediating vulnerabilities based on severity.

  • Factoring in likelihood of exploitation — public-facing web apps need higher priority than internal systems.

  • Integrating with a ticketing system to assign remediation tasks and track progress.

  • Building an exception process for legacy systems or high-impact assets that can’t be patched.

The goal is to prioritize risk — not just blindly patch everything. Done right, this saves time, reduces risk exposure, and improves your overall cybersecurity posture.

3. Endpoint Detection and Response (EDR) Health & Coverage

Having an Endpoint Detection and Response (EDR) solution is great — but it’s only effective if it’s actually installed, working, and up-to-date across all your endpoints. This is often overlooked.

Here’s what happens:

  • New servers are spun up without EDR agents.

  • Devices go offline or bypass policies.

  • The EDR client gets disabled (intentionally or not).

To maintain strong EDR health:

  • Conduct regular audits of your EDR deployment.

  • Verify that EDR is installed and active on all endpoints.

  • Identify and close gaps in coverage.

  • Apply mitigating controls where full EDR installation isn’t possible (e.g., operational tech).

EDR is your last line of defense. It’s what stops that malicious .exe your HR employee downloaded — or alerts you before ransomware spreads across your network. Don’t assume it’s working everywhere. Validate it.

4. Multi-Factor Authentication (MFA)

You’ve probably heard the phrase, “The bad guys are just logging in.” Unfortunately, it’s true. If you don’t enforce Multi-Factor Authentication (MFA), attackers can walk right into your environment using stolen credentials from previous breaches.

What you need:

  • MFA enabled for all cloud accounts, especially Microsoft 365, Google Workspace, and key SaaS apps.

  • MFA for VPNs, admin portals, and any external-facing login.

  • Ideally, use phishing-resistant MFA like FIDO2, hardware tokens, or authenticator apps with push notifications.

  • Disable legacy protocols that bypass MFA (IMAP, POP, SMTP Basic Auth).

Even if MFA is bypassed using man-in-the-middle tools, combining MFA with phishing training (from point #1) and conditional access policies strengthens your defense.

MFA is a non-negotiable baseline control — it’s one of the simplest and most effective things you can implement.

5. Perform Regular Penetration Testing

Environments are constantly changing. Technology is becoming more complex. And deadlines sometimes force us to deploy before security catches up. That’s why penetration testing is essential.

Even if you have a skilled internal IT or security team, you need third-party validation. Here’s why:

  • External testers think like threat actors.

  • They uncover forgotten legacy systems, over-permissive accounts, or poorly secured assets.

  • They provide a report with prioritized vulnerabilities and remediation advice.

  • They simulate real-world attack paths from both internal and external positions.

Regular testing (at least annually) helps reduce your attack surface, confirms the effectiveness of your controls, and keeps your team accountable.

Pen tests don’t just find issues — they help you build a strategy to avoid those same vulnerabilities in the future.

Conclusion

There you have it — the five pillars of cybersecurity that every organization should implement before buying another AI-powered Cybersecurity tool:

  1. Phishing training to defend against human-targeted attacks.

  2. Vulnerability management to patch what matters most.

  3. EDR coverage to ensure detection and response works as intended.

  4. MFA enforcement to block stolen credentials.

  5. Penetration testing to reveal what you’re missing.

At Prairie Logic, we help organizations put these foundational pieces in place. If you need help implementing any of these pillars or validating your current security posture, our certified professionals are here to support you.

Build your foundation before chasing the next AI trend. Let’s make cybersecurity resilient, together.

Services

Your trusted Medicine Hat team for comprehensive Managed IT Services and strategic IT Consulting, designed to empower Southern Alberta's small and medium-sized businesses.

Email:
sales@prairielogic.net

Call or Text:
403-458-4935

© 2025. All rights reserved.

Let us know how we can help