Mitigating Risks
BarracudaONE identifies security risks in your environment.
Each risk includes the criteria that triggered it, the steps to resolve it, and a detailed explanation of the potential exposure in your environment.
If the risk affects specific elements of your environment, such as users, accounts, or devices, you can find these elements at the bottom of the page with more detailed information.
To mitigate these risks, address the causes in your environment.
Types of risks
BarracudaONE identifies different categories of risks:
AI risks - Unauthorized and high-risk AI tool use.
Identity Security risks - Unmanaged devices, the number of administrators, and the enforcement of Multi-Factor Authentication (MFA).
Barracuda Email Gateway Defense risks - Risky allow-list policies for intuit.com and docusign.net.
For more information, see below.
AI risks
Unauthorized use of AI can put privacy, data, and business decisions in danger.
BarracudaONE identifies these AI risks:
No tool for AI usage monitoring - See Understanding the No tool for AI usage monitoring risk.
Uncontrolled AI tool usage (Shadow AI) - See Understanding the Uncontrolled AI tool usage (Shadow AI) risk.
High-risk AI tools in use - See Understanding the High-risk AI tools in use risk.
When you address the issues causing the risk, BarracudaONE automatically resolves the risk after the next scan.
Identity Security risks
Protecting your network by enforcing strong authentication and good security practices keeps your data, people, and business safer.
If you have integrated Microsoft Entra ID, BarracudaONE identifies certain identity security risks in your environment.
If you don't have Microsoft Entra ID set up, the risks below aren’t assessed in your environment. To set up Microsoft Entra ID, see Setting up Microsoft Entra ID in BarracudaONE.
When you address the issues causing the risk, BarracudaONE automatically resolves the risk after the next Entra ID scan.
BarracudaONE can identify these risks:
Privileged accounts without strong MFA - See Understanding the Privileged accounts without strong MFA Risk.
Unmanaged device access allowed - See Understanding the MFA not enabled for some users risk.
MFA not enabled for some users - See Understanding the MFA not enabled for some users risk
Phishing-resistant MFA not enforced for all users - See Understanding the Phishing-resistant MFA not enforced for all users Risk.
Excessive global administrator accounts - See Understanding the Excessive Global Administrator accounts risk.
Barracuda Email Gateway Defense risks
Protecting your email from attackers spoofing legitimate-looking domains like intuit.com and docusign.net reduces your organization’s exposure to impersonation attempts, domain spoofing, malware delivery, and unwanted email.
If you don't have Barracuda Email Gateway Defense (EGD) set up, the risks below aren’t assessed in your environment. You can purchase or set up EGD from the BarraucudaONE Home page.
When you address the issues causing the risk, BarracudaONE automatically resolves the risk after the next sync with EGD, which may take up to six hours.
BarracudaONE can identify these risks:
Risky allow-list policies for intuit.com - See Understanding the Risky allow-list policies detected for intuit.com risk.
Risky allow-list policies for docusign.net - See Understanding the Risky allow-list policies detected for docusign.net risk.