Protecting the network and its users.
WHAT THREATS EXIST
Attacks against your infrastructure Attacks passing through your network Compromised subscriber devices Unauthorised access to network equipment Theft of service
WHAT TO PROTECT FIRST
Network equipment management access.
WHAT THAT REQUIRES
Strong unique credentials Management access restricted to defined sources Two-factor authentication where available Default credentials changed on every device
WHY DEFAULT CREDENTIALS
Unchanged defaults are the commonest route into network equipment.
WHAT TO ESTABLISH
An inventory of devices and their access.
WHAT TO MAINTAIN
Firmware updates on network equipment.
WHY
Known vulnerabilities are exploited at scale.
WHAT DENIAL OF SERVICE ATTACKS DO
Saturate your capacity, affecting every subscriber.
WHAT TO ESTABLISH
Whether your upstream provides mitigation.
WHY UPSTREAM
Attacks are absorbed before your capacity, or not at all.
WHAT COMPROMISED SUBSCRIBER DEVICES CAUSE
Traffic that consumes capacity and attracts complaints against your network.
WHAT TO ESTABLISH
Detection of abnormal traffic from subscribers.
WHAT TO DO
Contact the subscriber, and suspend if necessary.
WHAT ABUSE HANDLING REQUIRES
A published contact for abuse reports A process for investigating Records of action taken
WHY IT MATTERS
Networks that ignore abuse reports are blocked by others.
WHAT TO ESTABLISH ABOUT SUBSCRIBER RECORDS
What you must retain, per the regulator.
WHY
Lawful requests require you to identify who was using an address.
WHAT TO ESTABLISH
That requests are handled properly, verified, and recorded.
WHAT TO NEVER DO
Disclose subscriber information without proper authority.