This is all nice in enterprise, but for a lot of the people reporting an incident, they are OVH customers who used the one-click installation of proxmox with zero knowledge outside of that. Some are restricted to IPMI / WireGuard / CF being their only options for true isolation.I 100% agree with the patching, backups and firewall requirements. This has been the absolute minimum for perhaps 30+ years. But there are also some additional aspects, such as network isolation, PAWs/SAWs, the concept of least privilege, IDS/IPS, etc. These are becoming more and more critical as the years go by.
- VLANs and firewall rules to fully isolate users, IT staff, wireless guests, etc. from each other and from all core systems.
- Management of infrastructure should only be accessible by using dedicated workstations with accounts separate from daily-use accounts (MFA preferred), and everyone only has permissions/access to the absolute minimum to do their job.
- Set up alerts for unusual activity, as well as automatically block any repeated attempts to gain access.
- Hire someone to do pen-testing or at least an audit to help catch any blind spots or shame management decisions made for political reasons (I'm the boss, give me admin on everything!). There is also end-user training which can be critical to detect and prevent various attacks.
Given this was the shape of a 0-day, where the CVE was only now just issued, many were just caught blind.