A glance back at cyber security through 2020 and some tips for 2021

This year really has shaken things up. Cyber security has become more important than ever with the widespread move to homeworking – but it isn’t easy to stay abreast of everything you should know. 

Here’s a glance back at four of our most popular blogs this year, which highlight some key areas that probably need your attention: 

Arm your team with understanding to minimise cyber risk 

Staff are often referred to as the weakest link in cyber security… they are at the top of our list of threat actors, and whether they make errors in judgement or in haste, they tend to be well-meaning – it is, after all, human to err.

Often these errors occur because of insufficient knowledge or training – or because people are easily tricked into doing something that could cause your organisation harm.

By helping our staff understand the threats out there we put them in a much better place to identify them and protect our businesses… and also protect themselves in their own personal lives. But it takes a process of raising awareness, testing them and allowing them to fail in a safe environment, then teaching them a bit more, and help them to practice so that they are confident to question things and take the time to challenge requests and emails.

Read the full blog from CEO Roz here.

Cyber security maintenance – five top tips 

Cyber security isn’t all annual one-off pieces of work that require a large amount of effort to get through. In fact, a large part of it falls under maintenance. This means making regular small changes, tweaks and enhancements to your systems or compliance requirements. Ideally, you’ll avoid a large amount of work over a short period of time. (Normally just after a breach or before a compliance audit).

Maintenance should be a regular and set function that is written into the business’s normal operational function. 

Otherwise, you could, for example, end up with vulnerabilities and exploits exposed because you haven’t maintained a thorough system level vendor patching regime. Compliance is another area that commonly suffers from lack of maintenance. Whether it’s system security frameworks, quality assurance programmes or important payment card compliance.

Read the full blog from CTO Pete here.

Your remote team should be managed to reduce cyber risk

we have to acknowledge that there is an increased risk with a remote team. Suddenly, having decent visibility of our people is nearly impossible. We have no assurance that they’re following company policies and procedures – or even using company technology with appropriate controls. 

Now, imagine a member of your staff fears they will lose their job to redundancy. They’re probably keeping an eye open – at the very least – for alternative roles. Who knows – maybe your competitor has a vacancy. 

This thought would worry me. Suddenly, you have people with privileged access to systems and data, concerned about their future and in conversations with a competitor. 

What is to stop that staff member downloading your client database from your CRM and taking it across the street, where they’ve accepted a new position with a rival company? When they’re working remotely, how would you know if they had? 

It’s not far-fetched. It happens all the time…

Read the full blog from CEO Roz here

 

Addressing 4 of the most common cyber security issues digital transformation has created

Many organisations now face the painful aftermath of rapid and reactive digital transformation.

Everyone rushed to adapt when Covid-19 hit. We had to make sure staff could work from home. For some, physical shops needed to be moved online. And this was the right thing to do; no question. But businesses now have unforeseen vulnerabilities that’ll need attention sooner rather than later.

There are the obvious issues like internet connectivity, setup of equipment and general access to systems and info. But there are also some very serious cyber security considerations for business leaders with newly remote teams…

Read the full blog from CTO Pete here