Knowledgebase

Security Practices for Organisations Print

  • blockchaindigitalassets, blockchain, security, hacked, woocommerce, guide, howto, solution
  • 0

Protecting institutional holdings.

WHAT TO ESTABLISH FIRST

Who may authorise a transfer What limits apply How authorisation is verified

WHAT TO NEVER PERMIT

One person moving funds alone.

WHAT MULTI-SIGNATURE ARRANGEMENTS PROVIDE

Requiring several independent approvals.

WHAT TO DECIDE

How many signatures, out of how many holders.

WHAT TO PLAN

Loss of a key holder, through departure or incapacity.

WHY

An arrangement requiring an unavailable person is a permanent loss.

WHAT TO DOCUMENT

Who holds which key, and where The procedure for each key holder's replacement

WHAT TO STORE SEPARATELY

Keys, geographically and organisationally.

WHAT TO RESTRICT

Which addresses funds may be sent to.

WHY

It limits the damage from any compromise or coercion.

WHAT TIME DELAYS PROVIDE

An opportunity to detect and stop an unauthorised transfer.

WHAT TO MONITOR

Every transaction, with alerting Balances, against expectation

WHAT TO REHEARSE

Response to a suspected compromise.

WHAT TO TRAIN STAFF ON

That nobody legitimate asks for keys That urgency is an attack pattern That instructions to transfer must be verified independently

WHY THAT LAST POINT

Impersonation of executives requesting transfers is a common and effective attack.

WHAT TO AUDIT

The arrangement, periodically, including whether departed staff retain access.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot