
Information security risks for business in Kyrgyzstan: where companies are most exposed
Baisal Sheraliev, Senior Security Engineer at Green Light, on the gaps that come up most often and what is worth checking first
Which information security problems do companies run into most often?
First, legacy infrastructure. In many companies the IT core was built 7–10 years ago and has only been accumulating add-ons ever since. Old versions of operating systems and applications with no updates, hardware without vendor patches — all of this creates a large attack surface.
Second, low process maturity. There are often no written rules: who manages access and how, how to respond to an incident, who is responsible for updates. Security rests on two or three qualified people and what they personally remember.
Finally, the shortage of people. There are few information security specialists in the region and they are expensive to retain, so the role is often combined with general IT. That means monitoring and response are either absent or happen whenever someone gets round to it.
Do companies often overestimate how well protected they are?
Yes, the gap between perceived and actual protection is one of the most common things we record. The main reason is a substitution of concepts. Owning a tool is not the same as configuring and operating it properly. We regularly see expensive security products running with default policies, or with licences that have already expired.
There is often no test under fire. If a company has never had a penetration test, has had no real incident and has no external audit, then the only feedback on the state of its defences is “well, nobody has broken in yet”. That is a false sense of security: the absence of known incidents often means not that you are protected, but that you have no means of detection.
Many focus on the external perimeter and ignore internal security. A business may be confident about defence against an outside intruder, while inside the network is flat, privileged access is handed out generously, and any compromised workstation opens the way almost anywhere.
Blind spots are common too: forgotten services, contractor connections, cloud resources set up bypassing the IT department. A company assesses its protection on the basis of what it knows, while the real attack surface may be wider.
Where do the gaps in protection show up most often?
They exist in many areas, but in our experience they can be ranked by how often they occur and how severe the consequences are.
1. Access. Problems here arise almost every time. No multi-factor authentication, accounts of people who have left, excessive rights, shared administrative passwords and so on. This is the most productive area for an attacker and at the same time one of the cheapest to fix.
2. Network. For example, a flat topology with no segmentation, where the user segment, IoT devices and servers all sit in the same subnet. There are also management services exposed to the outside (RDP, SSH, web consoles) and weak control over what is connected to the network.
3. Backup. This is a critical gap specifically in the context of ransomware. Backups often exist, but: they are not isolated from the main network and their restorability is not tested, there is no principle of immutable offline copies, and RPO/RTO are not defined.
4. Contractors and the supply chain. We come across permanent contractor VPN tunnels, remote access for service organisations without proper control and logging, and trusted connections the company has long forgotten about.
5. Data. Companies have a poor understanding of where critical data sits and who has access to it. There is no classification, no encryption and no leak control (DLP). Personal and commercial data are often stored mixed together with no separation whatsoever.
What should a realistic 3–6 month risk reduction plan look like?
What matters here is prioritising by the ratio of risk reduction to cost and effort. We usually break it into stages:
1. Start (weeks 1–4). We build an up-to-date asset map — what is on the network, which services face outwards. We also run an external perimeter scan, a basic audit of accounts and rights, and check the state of the backups.
The goal of this stage is a list of specific risks ranked by criticality.
2. Quick wins (months 1–2). We take measures with high impact and low cost. For example, enabling MFA for all remote and privileged access, revoking excess rights and the accounts of former employees, making an isolated copy of critical backups, and so on.
3. Core processes (months 2–4). We move from one-off actions to manageability. We introduce a regular vulnerability and patch management process, basic network segmentation, centralised collection and storage of logs, and more. In parallel, the rules are written down.
4. Maturity and monitoring (months 4–6). Security event monitoring is set up (an in-house SOC or a service model — for Central Asia the second is often more realistic), staff awareness is raised (training, simulated phishing), and a response plan is drawn up and tested.
To close the cycle, a follow-up penetration test is useful to measure progress against the starting point.
If you want to strengthen the information security of your business and learn more about what is available from the world's vendors — leave a request and get a consultation with Green Light experts.