i was about to suggest them to use physical token generator (similar to whats used by baking authentication), as well use of vpn for all external connections (outside internal vlans). and the use of certificates for authentication wherever it is possible to implement. but then i remembered about some IT security specialized consultancies that offer full analysis of the current breaches in an organization. my suggestions, then, seem to be too basic and not to cover the overall needs of such organization.
the customer had some resistances to change like "i am a manager, i dont want to use complicated passwords or two-factor auth." and so on.
please, can you help me with hints? where can i find a guideline for the minimum secure landscape to have in an organization? and how to evolve to a more advanced and secure scenario?
of course i would love to dive in deep text and learn about, but as well i need something more objective as a starting point.
thank you