·

Celebrate the Wins

4–6 minutes
women having a toast at the party
Photo by RDNE Stock project on Pexels.com

Like our tagline says, working in IT is hard. No matter what stage of the ladder you are on. If you’re new to the field, there’s more to see than can ever be seen. More to do than can ever be done. More to learn…you get the idea.

If you’re in a more senior position, you’ve been there done that. But no matter how much you learn, there’s still things to stay up to date on. Microsoft and Google with their ever changing user interfaces for the sake of modernization. Cloud computing and its impact on system administration. Reverse cloud migrations where we need to get out of the cloud because it’s too dang expensive!

flock of migrating birds against stunning sunset
Photo by dalia nava on Pexels.com

As an aside, why are these servers always migrating? Can’t they just stay where they are for a while? it’s not like they cost $45,000 or anything.

But we’re getting off track.

Very recently, my work had a bad actor walk right in through the front door due to compromised credentials. They were able to sign in as a user and start poking around in our network. Seeing what all they could see. Thankfully we had a few things going for us. We already had pretty strong file level security in place that prevented them from most attacks they were trying to do.

Along with that, what they were able to run our security team was able to isolate the server they were working from. Preventing them from lingering and doing who knows what. These scenarios are scary, and nothing that anyone ever wanted to deal with.

Not to mention, I’m not a security specialist. We don’t even have one on our core team. After the incident, we were engaged to review and survey what damage had been done. A few of us spent time looking through and mitigating anything that looked suspicious.

Side note, I have huge respect for anyone who has to go through looking at file hashes and tracing bad actors through an environment. I had to do it for one day as an untrained resource. I learned a lot about this process, but I’m sure there’s even more that I haven’t even scratched the surface on. If you do this for a living, good on you. I owe you a beer/coffee for doing what you do.

Despite being completely new and spending more than a day learning about this incident response process, it did not end there. Once we finished the incident response came the next project. “What do we do to make sure they can do even less next time this happens?”

If you are running a Windows Server environment, you can use a tool like AppLocker. It performs similar to ThreatLocker, but is built into windows. If you have a valid Server license then you can use this tool at no additional cost. Like all things Microsoft, the documentation appears a little out of date. The tool mentions a lot of Server 2016 and Windows 10. However it does still work on Windows Server 2022.

Before the holiday weekend here in the United States, I set this up in audit mode to track what applications are being run. After activating this product, it logs everything from executables to scripts. Then it tells you if it would be allowed to run, or if it would be blocked by policy. This gives you an opportunity to put all the puzzle pieces in place before turning it on. I’ve already added quite a number of hashes, publishers, and others. Soon we will be able to turn this on and have it block anything except for what we have said can run. An invaluable tool on a public facing resource. Honestly it’s something we should have had before, but we didn’t have the experience in house to set it up.

Despite the bad situation where I was forced to learn on the fly (again), it is very hard to take a step and realize that I just did multiple days worth of work having no experience or knowledge in how to get from point A to point B. Honestly that should be celebrated. If you did something difficult, new, or difficult and new this week then treat yourself. You have earned it.

In this grind culture that seems to have taken over everything, we need to remember to prioritize our own wins. Sure your boss might congratulate you, and they should. After all, you just saved them when they get to explain to upper management what has been done to prevent this from happening again. If they give you a little something extra then even better.

But you. You reading this. You writing this. Remember to take time for yourself. Guilt free. I don’t like the term work hard play hard, but there is some truth in those words. If you’re the kind of person who goes above and beyond. Then do the same for yourself.

Get yourself a treat, whether that is a favorite meal, a new book, or time with someone that has been put off. Remember that when you do amazing things at work, you also need to do amazing things for yourself. No one else will do it for you.

So hang that achievement up on the shelf. You’ve earned it. Then go out for a beer to celebrate. You’re doing great things. Let’s keep you rested and in the game.

Advertisements
person holding a trophy on wooden table top
Photo by cottonbro studio on Pexels.com


Discover more from Sprint to Where?

Subscribe to get the latest posts sent to your email.

Leave a Reply

Discover more from Sprint to Where?

Subscribe now to keep reading and get access to the full archive.

Continue reading