{"id":5052,"date":"2023-10-19T07:43:35","date_gmt":"2023-10-19T12:43:35","guid":{"rendered":"https:\/\/lg-staging.lougcloud.com\/?p=5052"},"modified":"2026-07-13T05:16:48","modified_gmt":"2026-07-13T10:16:48","slug":"the-nsa-and-cisa-are-begging-you-stop-making-these-cybersecurity-configuration-mistakes","status":"publish","type":"post","link":"https:\/\/lg-staging.lougcloud.com\/?p=5052","title":{"rendered":"The NSA and CISA Are Begging You: Stop Making These Cybersecurity Configuration Mistakes"},"content":{"rendered":"\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-85bp3-f856194ef33e7bc72ec0d3bf98278fce\">\n.flex_column.av-85bp3-f856194ef33e7bc72ec0d3bf98278fce{\nborder-radius:0px 0px 0px 0px;\npadding:0px 0px 0px 0px;\n}\n<\/style>\n<div  class='flex_column av-85bp3-f856194ef33e7bc72ec0d3bf98278fce av_one_full  avia-builder-el-0  avia-builder-el-no-sibling  first flex_column_div av-zero-column-padding  '     ><p><br \/>\n<section  class='av_textblock_section av-k0pon615-92ea21455f84089b14b66129c69212c2 '  ><div class='avia_textblock' ><h1>The NSA and CISA are begging you: Stop making these cybersecurity configuration mistakes<\/h1>\n<\/div><\/section><br \/>\n<section  class='av_textblock_section av-k0pop9td-bbcbe599b29853166e54fa81e9bef78a '  ><div class='avia_textblock' ><p><span data-contrast=\"auto\">The <\/span><a href=\"https:\/\/www.nsa.gov\/\"><span data-contrast=\"none\">National Security Agency (NSA)<\/span><\/a><span data-contrast=\"auto\"> and <\/span><a href=\"https:\/\/www.cisa.gov\/\"><span data-contrast=\"none\">Cybersecurity and Infrastructure Security Agency (CISA)<\/span><\/a><span data-contrast=\"auto\"> released a <\/span><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-278a\"><span data-contrast=\"none\">joint cybersecurity advisory (CSA)<\/span><\/a><span data-contrast=\"auto\">\u2014also available as a <\/span><a href=\"https:\/\/media.defense.gov\/2023\/Oct\/05\/2003314578\/-1\/-1\/0\/JOINT_CSA_TOP_TEN_MISCONFIGURATIONS_TLP-CLEAR.PDF\"><span data-contrast=\"none\">separate PDF download<\/span><\/a><span data-contrast=\"auto\">\u2014confirming the most common cybersecurity misconfigurations. The joint report includes Blue Team\u2014which typically performs strategic vulnerability appraisals\u2014and Red Team\u2014which typically performs adversary emulation by testing security controls against hackers&#8217; tactics, techniques and procedures (known as TTP)\u2014assessments and mitigation recommendations.<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\">Organizations continue perpetuating these dangerous cybersecurity mistakes<\/h2>\n<p><span data-contrast=\"auto\">According to the agencies, these are the 10 most common cybersecurity misconfiguration mistakes organizations, including small and medium businesses (SMBs), make:<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/p>\n<ol>\n<li data-leveltext=\"%1.\" data-font=\"Calibri\" data-listid=\"1\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Default configurations of software and applications<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"%1.\" data-font=\"Calibri\" data-listid=\"1\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Improper separation of user\/administrator privilege<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"%1.\" data-font=\"Calibri\" data-listid=\"1\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Insufficient internal network monitoring<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"%1.\" data-font=\"Calibri\" data-listid=\"1\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Lack of network segmentation<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"%1.\" data-font=\"Calibri\" data-listid=\"1\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Poor patch management<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"%1.\" data-font=\"Calibri\" data-listid=\"1\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Bypass of system access controls<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"%1.\" data-font=\"Calibri\" data-listid=\"1\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Weak or misconfigured multifactor authentication (MFA) methods<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"%1.\" data-font=\"Calibri\" data-listid=\"1\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Insufficient access control lists (ACLs) on network shares and services<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"%1.\" data-font=\"Calibri\" data-listid=\"1\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Poor credential hygiene<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"%1.\" data-font=\"Calibri\" data-listid=\"1\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Unrestricted code execution<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<\/ol>\n<p><span data-contrast=\"auto\">Subsequently, malicious hackers seize on these errors and commonly exploit the resulting vulnerabilities to penetrate networks, illegally access systems, steal information, corrupt networks and data and extract ransom payments from victims. The resulting damages, business interruptions and expenses often prove devastating, affecting everyone from small operators to government offices and even large multinational corporations across all industries.<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-5100 aligncenter\" src=\"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/10\/CSA-AA23-278A--236x300.png\" alt=\"\" width=\"641\" height=\"815\" srcset=\"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/10\/CSA-AA23-278A--236x300.png 236w, https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/10\/CSA-AA23-278A--554x705.png 554w, https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/10\/CSA-AA23-278A-.png 717w\" sizes=\"auto, (max-width: 641px) 100vw, 641px\" \/><\/p>\n<h5 style=\"text-align: center;\"><span data-contrast=\"auto\">\u00a0CISA and the NSA have released a joint cybersecurity advisory, available as a <\/span><a href=\"https:\/\/media.defense.gov\/2023\/Oct\/05\/2003314578\/-1\/-1\/0\/JOINT_CSA_TOP_TEN_MISCONFIGURATIONS_TLP-CLEAR.PDF\"><span data-contrast=\"none\">downloadable PDF<\/span><\/a><span data-contrast=\"auto\">, that details the top 10 cybersecurity misconfigurations organizations commonly make.<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/h5>\n<p><span data-contrast=\"auto\">It&#8217;s particularly poignant the agencies released the joint cybersecurity advisory (known officially as Alert AA23-278A) in October. A White House proclamation, seeking to prioritize information technology (IT) security, named October <\/span><span data-contrast=\"none\">Cybersecurity Awareness Month<\/span><span data-contrast=\"auto\">.<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\">Cybersecurity Mitigations Organizations Should Adopt<\/h2>\n<p><span data-contrast=\"auto\">CISA, the NSA and other respected authorities (including the <\/span><a href=\"https:\/\/www.nist.gov\/\"><span data-contrast=\"none\">National Institute of Standards and Technology<\/span><\/a><span data-contrast=\"auto\">, often referred to as the NIST) and best practices prescribe mitigating common cybersecurity misconfiguration mistakes by adopting the following recommendations, as specifically listed within the agencies&#8217; CSA.<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-5101 aligncenter\" src=\"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/10\/CSA-Detailed-Mitigations-1-238x300.png\" alt=\"\" width=\"634\" height=\"799\" srcset=\"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/10\/CSA-Detailed-Mitigations-1-238x300.png 238w, https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/10\/CSA-Detailed-Mitigations-1-560x705.png 560w, https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/10\/CSA-Detailed-Mitigations-1.png 729w\" sizes=\"auto, (max-width: 634px) 100vw, 634px\" \/><\/p>\n<h5 style=\"text-align: center;\"><span data-contrast=\"auto\">The joint CISA and NSA cybersecurity advisory lists specific and detailed mitigation recommendations for each of the top 10-most common cybersecurity misconfigurations.<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/h5>\n<p><span data-contrast=\"auto\">Note, the steps CISA and the NSA recommend for mitigating common cybersecurity misconfigurations quickly become technical. Even if you don&#8217;t fully understand all the accompanying jargon or specific technologies referenced within the agencies&#8217; mitigation recommendations, familiarizing yourself with the number and nature of these best practices can better prepare you and your organization for corresponding conversations with internal IT staff and outside technology service providers.<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/p>\n<h2>Mitigate Default Configurations of Software and Applications<\/h2>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"2\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Modify the default configuration of applications and appliances before deployment<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"2\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Change or disable vendor-supplied default usernames and passwords of services, software, and equipment<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"2\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Ensure the secure configuration of Active Directory Certificate Services (ADCS) implementations<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"2\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Review all permissions on the ADCS templates on applicable servers and restrict enrollment rights to only those users or groups requiring them<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"2\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Determine if Link-Local Multicast Name Resolution (LLMNR) and Network Basic Input\/Output System (NetBIOS) are required for essential business operations and disable them when possible<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"2\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Require Server Message Block (SMB) signing for both SMB client and server on all systems<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<\/ul>\n<h2 aria-level=\"3\">Mitigate Improper Separation of User\/Administrator Privilege<\/h2>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"3\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Implement authentication, authorization and account (AAA) systems to limit actions user can perform and review user action logs to detect unauthorized use and abuse<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"3\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><span data-contrast=\"auto\">Audit user accounts and remove inactive or unnecessary accounts regularly<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"3\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"3\" data-aria-level=\"1\"><span data-contrast=\"auto\">Restrict use of privileged accounts to perform general tasks<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"3\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Limit the number of users within the organization with an identity and access management (IAM) role possessing administrator privileges<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"3\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Implement time-based access for privileged accounts<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"3\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Restrict domain users from being in the local administrator group<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"3\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Run daemonized applications (services) with non-administrator accounts whenever possible<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"3\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Only configure service accounts with the permissions necessary for the services they control to operate<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"3\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Disable unused services and implement access control lists (ACLs) to protect services<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<\/ul>\n<h2 aria-level=\"3\">Mitigate Insufficient Internal Network Monitoring<\/h2>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"4\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Establish a baseline of applications and services and routinely audit their access and use, especially for administrative activity<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"4\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><span data-contrast=\"auto\">Look for suspicious accounts, investigate them and remove accounts and credentials of former staff<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"4\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"3\" data-aria-level=\"1\"><span data-contrast=\"auto\">Establish a baseline that represents an organization\u2019s normal traffic activity, network performance, host application activity, user behavior and investigate any deviations from that baseline<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"4\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Use auditing tools capable of detecting privilege and service abuse opportunities on systems and correct those vulnerabilities<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"4\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Implement a security information and event management (SIEM) system to provide log aggregation, correlation, querying, visualization and alerting from network endpoints, logging systems, endpoint and detection response (EDR) systems and intrusion detection systems (IDS)<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<\/ul>\n<h2 aria-level=\"3\">Mitigate Lack of Network Segmentation<\/h2>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"4\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><span data-contrast=\"auto\">Implement next-generation firewalls to perform deep packet filtering, stateful inspection, and application-level packet inspection<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"4\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"3\" data-aria-level=\"1\"><span data-contrast=\"auto\">Engineer network segments to isolate critical systems, functions, and resources<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"4\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Implement separate Virtual Private Cloud (VPC) instances to isolate essential cloud systems<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<\/ul>\n<h2 aria-level=\"3\">Mitigate Poor Patch Management<\/h2>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"5\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Ensure organizations implement and maintain an efficient patch management process that enforces the use of up-to-date, stable versions of OSes, browsers and software<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"5\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><span data-contrast=\"auto\">Prioritize patching and update software regularly by employing patch management for externally exposed applications, internal enterprise endpoints and servers<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"5\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"3\" data-aria-level=\"1\"><span data-contrast=\"auto\">Automate the update process as much as possible and use vendor-provided updates<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"5\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Consider using automated patch management tools and software update tools<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"5\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Segment networks to limit exposure of the vulnerable system or host where patching is not possible<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"5\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Evaluate the use of unsupported hardware and software and discontinue use as soon as possible<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"5\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Patch the Basic Input\/Output System (BIOS) and other firmware to prevent exploitation of known vulnerabilities<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<\/ul>\n<h2 aria-level=\"3\">Mitigate Bypass of System Access Controls<\/h2>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"6\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Limit credential overlap across systems to prevent credential compromise and reduce a malicious actor&#8217;s ability to move laterally between systems<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"6\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Implement an effective and routine patch management process<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"6\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Enable pass the hash (PtH) mitigations to apply User Account Control (UAC) restrictions to local accounts upon network logon<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"6\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Deny domain users the ability to be in the local administrator group on multiple systems<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"6\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Limit workstation-to-workstation communications<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"6\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Use privileged accounts only on systems requiring those privileges<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<\/ul>\n<h2 aria-level=\"3\">Mitigate Weak or Misconfigured MFA Methods<\/h2>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"7\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Disable the use of New Technology LAN Manager (NTLM) and other legacy authentication protocols that are susceptible to PtH due to their use of password hashes<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"7\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><span data-contrast=\"auto\">Use built-in functionality via Windows Hello for Business or Group Policy Objects (GPOs) to regularly re-randomize password hashes associated with smartcard-required accounts<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"7\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"3\" data-aria-level=\"1\"><span data-contrast=\"auto\">Implement cloud-primary authentication solution using modern open standards<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"7\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Enforce phishing-resistant MFA universally for access to sensitive data and on as many other resources and services as possible<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<\/ul>\n<h2 aria-level=\"3\">Mitigate Insufficient ACLs on Network Shares and Services<\/h2>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"8\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Implement secure configurations for all storage devices and network shares that grant access to authorized users only<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"8\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><span data-contrast=\"auto\">Apply the principal of least privilege to important information resources to reduce risk of unauthorized data access and manipulation<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"8\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"3\" data-aria-level=\"1\"><span data-contrast=\"auto\">Apply restrictive permissions to files and directories, and prevent adversaries from modifying ACLs<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"8\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Set restrictive permissions on files and folders containing sensitive private keys to prevent unintended access<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"8\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Enable the Windows Group Policy security setting, &#8220;Do Not Allow Anonymous Enumeration of Security Account Manager (SAM) Accounts and Shares,&#8221; to limit users who can enumerate network shares<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<\/ul>\n<h2 aria-level=\"3\">Mitigate Poor Credential Hygiene<\/h2>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"9\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><span data-contrast=\"auto\">Follow NIST guidelines when creating password policies to enforce use of \u201cstrong\u201d passwords that cannot be cracked<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"9\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"3\" data-aria-level=\"1\"><span data-contrast=\"auto\">Consider using password managers to generate and store passwords<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"9\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Do not reuse local administrator account passwords across systems<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"9\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Ensure passwords are \u201cstrong\u201d and unique<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"9\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Use \u201cstrong\u201d passphrases for private keys to make cracking resource intensive<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"9\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Do not store credentials within the registry in Windows systems<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"9\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Establish an organizational policy that prohibits password storage in files<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"9\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Ensure adequate password length (ideally 25+ characters) and complexity requirements for Windows service accounts and implement passwords with periodic expiration on these accounts<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"9\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Implement a review process for files and systems to look for cleartext account credentials<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"9\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Store hashed passwords using Committee on National Security Systems Policy (CNSSP)-15 and Commercial National Security Algorithm Suite (CNSA) approved algorithms<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"9\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Consider using group Managed Service Accounts (gMSAs) or third-party software to implement secure password-storage applications<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<\/ul>\n<h2 aria-level=\"3\">Mitigate Unrestricted Code Execution<\/h2>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"10\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Enable system settings that prevent the ability to run applications downloaded from untrusted sources<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"10\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Use application control tools that restrict program execution by default, also known as allowlisting<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"10\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><span data-contrast=\"auto\">Ensure that application control tools examine digital signatures and other key attributes, rather than just relying on filenames, especially since malware often attempts to masquerade as common Operating System (OS) utilities<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"10\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"3\" data-aria-level=\"1\"><span data-contrast=\"auto\">Explicitly allow certain .exe files to run, while blocking all others by default<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"10\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Block or prevent the execution of known vulnerable drivers that adversaries may exploit to execute code in kernel mode<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"10\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"5\" data-aria-level=\"1\"><span data-contrast=\"auto\">Validate driver block rules in audit mode to ensure stability prior to production deployment<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"10\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"5\" data-aria-level=\"1\"><span data-contrast=\"auto\">Constrain scripting languages to prevent malicious activities, audit script logs, and restrict scripting languages that are not used in the environment<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"10\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"5\" data-aria-level=\"1\"><span data-contrast=\"auto\">Use read-only containers and minimal images, when possible, to prevent the running of commands<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"10\" data-list-defn-props=\"{\" aria-setsize=\"-1\" data-aria-posinset=\"5\" data-aria-level=\"1\"><span data-contrast=\"auto\">Regularly analyze border and host-level protections, including spam-filtering capabilities<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/li>\n<\/ul>\n<h2 aria-level=\"2\">Is your organization vulnerable to these common cybersecurity misconfiguration errors?<\/h2>\n<p><span data-contrast=\"auto\">The nature of this latest joint cybersecurity advisory issued by CISA and the NSA is a little different from previous bulletins. This latest release is, in fact, almost a plea from seasoned cybersecurity experts for businesses and organizations to correct these errors. The mistakes, commonly exploited by cybercriminals, enable the continual perpetuation of damaging cybercrimes.<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">If your organization needs help better understanding its cybersecurity posture, making sense of the mitigation recommendations prescribed within the joint cybersecurity advisory or adopting best practices to better safeguard and protect its users, systems and data, call Louisville Geek at 502-897-7577 or email sales@lougeek.com.<\/span><span data-ccp-props=\"{\">\u00a0<\/span><\/p>\n<\/div><\/section><\/p><\/div>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":2,"featured_media":5044,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[],"class_list":["post-5052","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-news"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>NSA &amp; CISA Warn: Common Cybersecurity Config Mistakes<\/title>\n<meta name=\"description\" content=\"The NSA and CISA have issued a bulletin outlining the top ten cybersecurity misconfiguration errors. Here&#039;s how to mitigate each one.\" \/>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NSA &amp; CISA Warn: Common Cybersecurity Config Mistakes\" \/>\n<meta property=\"og:description\" content=\"The NSA and CISA have issued a bulletin outlining the top ten cybersecurity misconfiguration errors. Here&#039;s how to mitigate each one.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/lg-staging.lougcloud.com\/?p=5052\" \/>\n<meta property=\"og:site_name\" content=\"Louisville Geek\" \/>\n<meta property=\"article:published_time\" content=\"2023-10-19T12:43:35+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-13T10:16:48+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/10\/cisa.png\" \/>\n\t<meta property=\"og:image:width\" content=\"678\" \/>\n\t<meta property=\"og:image:height\" content=\"500\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"LouGeek Marketing\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"LouGeek Marketing\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NSA & CISA Warn: Common Cybersecurity Config Mistakes","description":"The NSA and CISA have issued a bulletin outlining the top ten cybersecurity misconfiguration errors. Here's how to mitigate each one.","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"NSA & CISA Warn: Common Cybersecurity Config Mistakes","og_description":"The NSA and CISA have issued a bulletin outlining the top ten cybersecurity misconfiguration errors. Here's how to mitigate each one.","og_url":"https:\/\/lg-staging.lougcloud.com\/?p=5052","og_site_name":"Louisville Geek","article_published_time":"2023-10-19T12:43:35+00:00","article_modified_time":"2026-07-13T10:16:48+00:00","og_image":[{"width":678,"height":500,"url":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/10\/cisa.png","type":"image\/png"}],"author":"LouGeek Marketing","twitter_card":"summary_large_image","twitter_misc":{"Written by":"LouGeek Marketing","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/lg-staging.lougcloud.com\/?p=5052#article","isPartOf":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=5052"},"author":{"name":"LouGeek Marketing","@id":"https:\/\/lg-staging.lougcloud.com\/#\/schema\/person\/a381cd0bd66b806f0da449297a82ce8a"},"headline":"The NSA and CISA Are Begging You: Stop Making These Cybersecurity Configuration Mistakes","datePublished":"2023-10-19T12:43:35+00:00","dateModified":"2026-07-13T10:16:48+00:00","mainEntityOfPage":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=5052"},"wordCount":1861,"publisher":{"@id":"https:\/\/lg-staging.lougcloud.com\/#organization"},"image":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=5052#primaryimage"},"thumbnailUrl":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/10\/cisa.png","articleSection":["Cybersecurity"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/lg-staging.lougcloud.com\/?p=5052","url":"https:\/\/lg-staging.lougcloud.com\/?p=5052","name":"NSA & CISA Warn: Common Cybersecurity Config Mistakes","isPartOf":{"@id":"https:\/\/lg-staging.lougcloud.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=5052#primaryimage"},"image":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=5052#primaryimage"},"thumbnailUrl":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/10\/cisa.png","datePublished":"2023-10-19T12:43:35+00:00","dateModified":"2026-07-13T10:16:48+00:00","description":"The NSA and CISA have issued a bulletin outlining the top ten cybersecurity misconfiguration errors. Here's how to mitigate each one.","breadcrumb":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=5052#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/lg-staging.lougcloud.com\/?p=5052"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/lg-staging.lougcloud.com\/?p=5052#primaryimage","url":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/10\/cisa.png","contentUrl":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/10\/cisa.png","width":678,"height":500},{"@type":"BreadcrumbList","@id":"https:\/\/lg-staging.lougcloud.com\/?p=5052#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/lg-staging.lougcloud.com\/"},{"@type":"ListItem","position":2,"name":"The NSA and CISA Are Begging You: Stop Making These Cybersecurity Configuration Mistakes"}]},{"@type":"WebSite","@id":"https:\/\/lg-staging.lougcloud.com\/#website","url":"https:\/\/lg-staging.lougcloud.com\/","name":"Louisville Geek","description":"Empowering Local Businesses and National Enterprises with Comprehensive IT Services","publisher":{"@id":"https:\/\/lg-staging.lougcloud.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/lg-staging.lougcloud.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/lg-staging.lougcloud.com\/#organization","name":"Louisville Geek","url":"https:\/\/lg-staging.lougcloud.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/lg-staging.lougcloud.com\/#\/schema\/logo\/image\/","url":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2019\/10\/lougeek_full_logo-black-1.png","contentUrl":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2019\/10\/lougeek_full_logo-black-1.png","width":1671,"height":506,"caption":"Louisville Geek"},"image":{"@id":"https:\/\/lg-staging.lougcloud.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/lg-staging.lougcloud.com\/#\/schema\/person\/a381cd0bd66b806f0da449297a82ce8a","name":"LouGeek Marketing","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/865f8a8b853c689f8443338c8f8d08b8e9a9f0bcab6dcd97b1cb63a5efeda3fa?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/865f8a8b853c689f8443338c8f8d08b8e9a9f0bcab6dcd97b1cb63a5efeda3fa?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/865f8a8b853c689f8443338c8f8d08b8e9a9f0bcab6dcd97b1cb63a5efeda3fa?s=96&d=mm&r=g","caption":"LouGeek Marketing"},"url":"https:\/\/lg-staging.lougcloud.com\/?author=2"}]}},"_links":{"self":[{"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/posts\/5052","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5052"}],"version-history":[{"count":6,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/posts\/5052\/revisions"}],"predecessor-version":[{"id":6874,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/posts\/5052\/revisions\/6874"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/media\/5044"}],"wp:attachment":[{"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5052"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5052"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5052"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}