Is your cybersecurity “all sorted”?
I’m always hearing from businesses that they have cybersecurity “all sorted”, which would be brilliant and something to celebrate… if it were true!
Over the past year, I’ve carried out many cybersecurity reviews for businesses over at Siarp and nine times out of ten, those who thought they were “all sorted” were far from it.
From misconfigured devices, out of date software, poor password hygiene, lack of controls, no visibility over access rights or even what assets the businesses own and more means that there is risk everywhere.
Here’s some statistics to consider:
- Up to 88% of UK companies have suffered a breach of some sort in the last 12 months according to Cybersecurity vendor Carbon Black.
- According to Hiscox, one small business in the. UK is successfully hacked every 19 seconds.
- It’s estimated that around 53% of SMB’s suffered a security breach in 2018.
- 37% of UK companies reported a breach to the ICO in the last year.
- 33% of UK companies reported losing customers after a data breach.
So why do businesses think they have it all under control? I find that it’s often caused by a lack of understanding of cybersecurity risks or the assumption that IT support coverage = cybersecurity. It doesn’t.
Of course, there are IT support companies out there that do provide good cybersecurity coverage, but many simply do not.
Yes, they’ll give you a firewall, but they won’t necessarily have the specialist skills or focus in-house to enable them to provide protection beyond the basics of firewalls and antivirus.
So, what can you do about it?
I truly believe that your IT provider is likely to be doing a great job of looking after your IT assets and taking care of problems you report. However, it would pay dividends to get a specialist to look over your security and make sure you’re not going to be hurt by risks that are really very easy and cheap to fix.
After all, you’ve put countless weeks, months and years into building your business, to have it all undone by making assumptions about your security measures would be tragic.
Why do people not want to get their security reviewed?
Fear of change, expense and lack of trust would be what I’d guess to be the case. Maybe a feeling that getting a review of their security could be viewed as a lack of faith in their existing provider?
The fact is, that when it comes to the security of your business and your client data, loyalty to a supplier should not enter into your thinking. Do you simply trust that your smoke detectors are working? Or do you periodically test them to make sure?
When it comes to cost, many of the biggest improvements you can make require nothing but an investment in time. Here are some examples:
- Enable Multi-factor authentication wherever possible
- Turn on encryption
- Know what you need to protect
- Create a hardware asset register
- Create a software asset register
- Create a data asset register
- Make sure that staff have access only to what they need for their jobs
- Review who has what access to your systems
- Lock down file-shares based on a “need to access”
- Get your policies in place
- Create acceptable use policies
- Create a remote working policy
- Create a bring-your-own-device policy
- Create an incident response plan
- Educate your team on good password hygiene
One last thought…
There’s also a new risk on the horizon. Ambulance-chasing law-firms are out there, actively encouraging people to report potential data breaches with the promise of compensation in the thousands of pounds!
All no-win-no-fee, so why not just throw any possible claim at them?
With difficult times ahead, this business model will encourage many to report all kinds of suspected incidents, leading to more fines or compensation claims against businesses.
Be sure to have a good cybersecurity insurance policy in place, it might just help when the worst happens.
Guest blog written by Justin Thomas of Siarp
Justin Thomas | Technical Consultant
07791 371 641
twitter | linkedin | instagram | facebook