With over 500,000 websites estimated to be affected by Heartbleed, businesses are starting to ask “what’s next?” In the wake of this notorious bug, one thing’s for certain: it’s just as important for organizations to protect against the unknown as it is the known.

IT departments must take a proactive stance to security in order to reduce an organization’s exposure to those next unknown attacks. Defense-in-depth security strategies should include both reactive and proactive measures, including regular patching and removing elevated privileges from all users.


Guest article by Andrew Avanessian, VP of Global Professional Services, Avecto


Certain policies will ensure businesses preemptively secure their environment, including maintaining the correct level of permissions, software white-listing, firewalls and Internet Protocol Security (IPsec). Above all else, the best means of preventing vulnerabilities is using a flexible approach to privilege management – specifically, granting administrator rights to processes and applications instead of giving them to users or computers.

There are many reasons businesses adopt this flexible privilege management approach and yet many organizations are still unaware that a solution like this even exists! In one of our recent webinars, Microsoft MVP and ethical hacker Sami Laiho recommended five top reasons to remove administrator privileges to communicate why this is so important.

1)      Prevent Malware

The more that technology blurs the lines between the personal and corporate worlds, the more sophisticated malware will become. A recent RAND study demonstrates a heightened concern that malware will take on increased anonymity capabilities and target social networks and mobile devices. This is particularly troublesome, considering that the majority of IT security professionals aren’t aware of unauthorized application downloads that welcome malware onto their network. Removing administrator rights takes away the possibility that the user account will install software that can damage the whole system – stopping malware in its tracks.

2)      Keep PCs Clean

The concept of privilege management ensures that everyone operates as a standard user. In this type of least privilege environment, users cannot write files or entries in places that administrators can. This creates a trickle-down-effect that benefits the whole IT system, including faster-responding software and more efficient computers. This translates into fewer OS re-installations and therefore, less help-desk impact. Ultimately, businesses will give their PCs a longer lifespan.

3)      Enforce Protection

An IT administrator holds significant power, including the ability to turn off protective measures like host firewall, antivirus, encryption and Group Policy. The problem is, administrators are prime targets when it comes to targeted malware exploits, so if malware takes hold of an admin account, it would assume this same control. The Ponemon Institute study also reveals the excessive power users are currently given over IT infrastructures, with an average of 31% of staff reporting administrator privileges. This opens companies up to insider threats and serious damage from malware and targeted attacks.

4)      Stay Compliant

As Microsoft’s Security Policy shows, a user belonging to the local administrator’s group has 100% control over making system-wide changes to the computer. For instance, they can deny the system from reading corporate policies and therefore disobey the preexisting rules in Group Policy. As such, all security measures are only secure when users are in standard user mode and removing administrator rights from PC users removes all unnecessary risk.

5)      Protect your Weakest Link

Enterprises can only prevent vulnerabilities if all policies, procedures, software and devices work together to build a secure environment. Even one computer on the domain running admin rights can bypass User Account Control (UAC) and gain access to the entire network. The only way to contain security holes at each and every point of entry and ensure that organizations adapt to emerging threats is to remove administrator rights altogether.

Moving Forward without Admin Rights

In today’s era of pervasive cybercrime, in which nearly half of US businesses spend their dedicated security time on the endpoint, organizations that provide excessive administrator rights are just inviting infection on their networks. But just removing these admin rights without planning to implement a robust solution to provide flexibility in how you manage privileges, is destined for failure.

The solution is to make admin rights a software-based approach – not a user-based one. Businesses can find the middle ground between security and flexibility by offering granular control over what users can and cannot do and applying privileges directly to applications, tasks and scripts.

Adopting this approach ensures that if an attacker managed to gain access to a user’s credentials via a Heartbleed-style bug, they would be limited in the damage they could cause. Once an admin account is breached, the attacker has the keys to the kingdom and can freely gain access to the core network, configurations, documents and data.

For more on this topic, read the Aberdeen report The Risk of “Free” Endpoint Security


Andrew AvanessianAndrew Avanessian is VP of Professional Services at Avecto, responsible for providing their strategic global direction for Pre/Post Sales, IT and Technical Support. His background in IT infrastructure is underpinned by a wealth of knowledge which encompasses the architecting of enterprise class solutions.  Andrew’s commercial acumen and clinical approach to problem solving, has helped major corporations worldwide resolve complex IT security issues across their Windows environments. He holds an Honors degree in Computer Science, together with a number of industry recognized qualifications, including ITIL certification and Microsoft MCP, MCSA, MCSE.