← Learning Hub

Video Resources

How Do Organizations Defend Systems? Security Controls and Threat Mitigation

Explore how organizations defend against cyber threats. Cover security controls, IAM, network segmentation, hardening, and proactive mitigation strategies.

Frequently Asked Questions

What this playlist answers

5 questions this playlist covers — skim them for a quick takeaway, or dive into the videos above for the full picture.

Enterprise threat mitigation involves implementing strategies and controls to prevent, detect, respond to, and recover from cybersecurity threats within an organization through both proactive and reactive measures. Proactive mitigation prevents attacks before they occur through hardening, access controls, and monitoring. Reactive mitigation handles incidents after they happen through incident response, disaster recovery, and business continuity planning. Network segmentation divides infrastructure into isolated zones, limiting how far an attacker can move laterally if they breach one segment. It reduces the blast radius of a breach and protects critical systems. IAM is a security framework that manages who can access systems and data based on authentication, authorization, and least privilege principles. It reduces the risk of unauthorized access across the enterprise. System hardening controls include disabling unnecessary services, applying patches, enforcing access controls, removing default credentials, and using application allowlists to reduce the attack surface of systems.