Follow our 5 steps to help with Cyber Security
Stop the risk before it enters your network!
“92% of of malware attacks are via malicious emails” (source)
“78% of employees are aware of the risks of suspicious email links but still click on them” (source)
Email is important for all businesses. However it has also become a good way to attack a company. In a typical phishing attack, scammers send fake emails to thousands of people, asking for sensitive information (such as bank details), or containing links to bad websites. They might try to trick you into sending money, steal your details to sell on, or they may have political or ideological motives for accessing your organisation’s information.
Phishing emails are getting harder to spot and some will still get past even the most observant users. Whatever your business, however big or small it is, you will receive phishing attacks at some point. Whilst training your users helps them, be aware that there is a limit to what you can expect your users to do.
Website Security
“46% of websites have high cybersecurity vulnerabilities” (source)
“87% of websites have medium security vulnerabilities” (source)
Web threats have increased over the past few years. From phishing sites to drive-by downloads, the dangers have never been greater. To stay safe, you need to make sure you have advanced malware protection in place along with bandwidth monitoring, content filtering and more.
Website protection prevents users from being able to access sites that have security issues or are on a register of high risk sites due to their content. These ever-developing registers are updated regularly so you don’t need to.
“23.2 million victim accounts worldwide used 123456 as their password” (source)
“81% of data breaches are caused by compromised, weak, and reused passwords.” (source)
Passwords
Set a screenlock password, PIN, or other authentication method (such as fingerprint or face unlock).
Password protection is not just for smartphones and tablets. Make sure that your office equipment (so laptops and PCs) all use an encryption product (such as BitLocker for Windows) using a Trusted Platform Module (TPM) with a PIN, or FileVault (on macOS) in order to start up. Most modern devices have encryption built in, but encryption may still need to be turned on and configured, so check you have set it up.
Two-Factor Authentication
If you’re given the option to use two-factor authentication (also known as 2FA) for any of your accounts, you should do; it adds a large amount of security for not much extra effort. 2FA requires two different methods to ‘prove’ your identity before you can use a service, generally a password plus one other method. This could be a code that’s sent to your smartphone (or a code that’s generated from a bank’s card reader) that you must enter in addition to your password.
Never Share Passwords
Remember that your IT systems should not require staff to share accounts or passwords to get their job done. Make sure that every user has personal access to the right systems, and that the level of access given is always the lowest needed to do their job, whilst minimising unnecessary exposure to systems they don’t need access to.
Change Default Passwords
One of the most common mistakes is not changing the manufacturers’ default passwords that smartphones, laptops, and other types of equipment are issued with. Change all default passwords before devices are distributed to staff. You should also regularly check devices (and software) specifically to detect unchanged default passwords.
Training
Human error remains the leading cause of data breaches – and these breaches cause organisations a great deal of financial and reputational damage.
Your staff are at the forefront of your organisation, representing the business and dealing with personal and organisational data on a daily basis. They are the ones protecting your business and it’s assets.
A staff awareness training programme is an effective way of educating employees on particular topics to ensure proper procedures are followed, thereby reducing risk and keeping your organisation’s data safe. For example, privacy procedures according the GPDR, information security practices or payment card data handling may be included in a staff awareness programme.
Patching
“57% of cyber breaches are due to an unpatched vulnerability” (source)
“58% of organizations run on ‘legacy systems’ – platforms which are no longer supported with patches but which would still be too expensive to replace in the near future ” (source)
For all your IT equipment make sure that the software is always kept up to date with the latest versions from software developers, hardware suppliers and vendors. Applying these updates (a process known as patching) is one of the most important things you can do to improve security – the IT version of eating your fruit and veg. Operating systems, programmes, phones and apps should all be set to ‘automatically update’ wherever this is an option.
Windows operating systems will patch themselves, however this won’t patch the most vulnerable programs such as Adobe, Java or internet browsers such as Firefox and Google Chrome.
At some point updates for operating systems and software will be unavailable as the product is no longer supported. If this is the case the product should be replaced.
Application Control
Staff accounts should only have enough access required to perform their role, with extra permissions (i.e. for administrators) only given to those who need it. When administrative accounts are created, they should only be used for that specific task, with standard user accounts used for general work.
“There were 144.91 million new malware samples in 2019. As at April 2020 there are 38.48 million new samples since the start of 2020” (source)
“In 2018, 93.6% of malware observed was polymorphic, meaning it has the ability to constantly change its code to evade detection ” (source)
Anti Virus solutions have done a great job of helping to keep businesses safe for many years. However, the threat patterns are changing, and need a different type of protection to combat these increasingly sophisticated, severe attacks.
Here’s why: Anti Virus solutions rely on signatures (think of a digital fingerprint) to detect threats, but the latest threats don’t use signatures and can slip through and enter your company’s networks undetected.
“82% of SMBs say they have experienced a cyber attack that their AV systems didn’t catch” (source)
Our Managed Endpoint Detection and Response solution uses state of the art Artificial Intelligence to detect ever adapting malware and viruses so doesn’t rely on definition files like traditional anti-virus solutions.
“46% of small businesses have never tested their BDR plan” (source)
“50% of data loss is caused by hardware or system malfunction ” (source)
Data Location
Your first step is to identify your essential data. That is, the information that your business couldn’t function without. Normally this will comprise documents, photos, emails, contacts, and calendars, most of which are kept in just a few common folders on your computer, phone, tablet or network.
Backup Location
Whether it’s on a USB stick, on a separate drive or a separate computer, access to data backups should be restricted so that they are not accessible by staff nor are they permanently connected (either physically or over a local network) to the device holding the original copy
Ransomware (and other malware) can often move to attached storage automatically, which means any such backup could also be infected, leaving you with no backup to recover from. For more resilience, you should consider storing your backups in a different location, so fire or theft won’t result in you losing both copies. Cloud storage solutions (see below) are a cost-effective and efficient way of achieving this.
Cloud Backups
You’ve probably already used cloud storage during your everyday work and personal life without even knowing – unless you’re running your own email server, your emails are already stored ‘in the cloud’.
Using cloud storage (where a service provider stores your data on their infrastructure) means your data is physically separate from your location. You’ll also benefit from a high level of availability. Service providers can supply your organisation with data storage and web services without you needing to invest in expensive hardware up front. Most providers offer a limited amount of storage space for free, and larger storage capacity for minimal costs to small businesses.
Disaster Recovery Testing
It is important that you regularly test your onsite and offsite backups to ensure that should you need to the data can be recovered.