Category: Cybersecurity

Cybersecurity

Cybersecurity focuses on protecting computer systems from unauthorised access or being otherwise damaged or made inaccessible

At The Unite Group, we take cybersecurity extremely seriously. That is why we have produced a series of blogs educating you on the latest dangers and tips to protect yourself & your business.

Cybersecurity is a crucial thing to get right, it is not one you can take any risks with due to the implications it can have on your business. We have created blogs that give you information on the Cyber essentials certification, cyber essentials plus as well as good housekeeping to keep your business in order.

Use these blogs to learn how to keep your company and personal data safe in the world of cybercrime. If you have any cybersecurity needs then please do not hesitate to get in touch. We are able to get our clients through their Cyber Essentials Certification as an awarding body of this government-backed scheme.

If there are topics you would like to see us create content around then please just send us an email or give us a call and we will get these added for you. If you find our blogs useful please let us know. You can also follow all of our blogs and content on our social media pages.

The Unite group – Cybersecurity Blog – Because technology matters.

 

  • What is the Cyber Essentials scheme?

    What is the Cyber Essentials scheme?

    Let’s breakdown the Cyber Essentials scheme.

    Now that we’ve covered the basics of Cyber Essentials in our latest blog let’s dive deeper into exactly what the scheme entails. How long it is valid for. As well as how we can support your business as you work through achieving the certification. It is very important your business achieves the cyber essentials certification. 61% of certified organisations say they are more likely to choose suppliers with Cyber Essentials or Cyber Essentials Plus certification.

    Cyber Essentials Scheme: Overview

    The Cyber Essentials scheme is an ISAMW self-assessment questionnaire process. The questionnaire will then be signed off by a member of the board or an equivalent signory. After this, it is then verified by a certification body trained and licensed to certify against the Cyber Essentials scheme (like ourselves here at The Unite Group). It is important before applying you ensure your organisation meets all the requirements. This includes having evidence ready to be provided to prove you meet the requirements.

    What is in the scope for Cyber Essentials?

    The scope will be agreed upon between your organisation and The Unite Group, (as your certification body), before the assessment begins. Certification can apply to your full organisation’s enterprise IT or just a subset.

    How long is Cyber Essentials Valid for?

    All certificates are valid for 12 months. They must be renewed annually, much like your cars MOT. This works well to ensure your organisation is protected against the latest cyber-attacks. As those carrying out attacks are constantly looking for new ways to catch out and successfully breach data. If you do not reapply for your Cyber Essentials Certification as the 12-month period expires, you will no longer be able to apply for contracts that require you to hold a valid Cyber Essentials certification – like Government contracts.

    What is in the Cyber Essentials certification scheme?

    The Cyber Essentials scheme covers 5 main areas:

    Access control.

    Having managing access to administrator accounts means you can protect who has access to your data and services.

    Software Updates

    Staying current with the latest software updates and security patches protects you against the newest cyber-attacks and vulnerabilities.

    Firewalls & Routers

    Creating a buffer-zone’ between your IT network and other external networks. This will ensure incoming traffic is analysed to find out if you would like to allow it access to your network.

    Secure Configuration

    Choosing the most secure setting for your device and software. As well as changing passwords and removing unused accounts and software will reduce the risk of a potential cyber-attack.

    Malware Protection

    Using properly configured anti-malware software will protect against viruses and other malware risks. This also includes to only allow trusted applications to run.

    How long does it take between submitting the online questionnaire to receive your certificate?

    The length of time it takes from application to certification can vary. Some may be verified in one or two days. Whereas, others may take around two weeks to complete the assessment. This is dependent upon your current security setup and speed of action. Those who partake in the Cyber Essentials Plus scheme should expect a longer assessment period as it involves the internal security assessment as well as an external scan.

    How can we support you through the Cyber Essentials process?

    Here at The Unite Group, we can provide support to you throughout the process. We are an authorised certificate issuing body for Cyber Essentials. As a result, we can manage the entire process for you from the initial audit, remedial works, and certificate issue.

    Do you want peace of mind that your defences will protect you from a large amount of the most common cyber-attacks? Contact us today and our friendly, knowledgeable team will be happy to explain in more detail the Cyber Essentials certification process or help you take the first steps to achieve your Cyber Essentials Certification!

  • Cybersecurity: Frequently Asked Questions

    [et_pb_section admin_label=”section”] [et_pb_row admin_label=”row”] [et_pb_column type=”4_4″][et_pb_text admin_label=”Text”]

    It is no surprise that the past 2 years of remote and hybrid working have significantly accelerated digital transformation for most small and medium businesses. Although the implementation of new technologies has changed the way that these businesses function, it may have also created many potential security risks. As businesses move into 2022, it is important that all small and medium businesses invest in protecting their IT systems from cybercriminals. As the cybersecurity landscape is constantly changing, it is common for SMBs to have questions about cybersecurity and what they can do to protect their businesses. In this article, we will answer some of the frequently asked SMB cybersecurity questions.

    What is cybersecurity?

    Cybersecurity is a branch of information security including the practices an organisation undertakes to reduce the risk of a cyberattack. These practices focus on technology to stop cybercriminals from accessing sensitive information. As well as from extorting money from users, or interrupting normal business procedures.

    What are the most common forms of cyberattack?

    The three most common forms of cyberattack are: phishing, malware and distributed denial of service (DDOS) attacks.

    Phishing is where a cybercriminal contacts a target by email, telephone or SMS posing as a legitimate individual, or business to deceive the victim into clicking a malicious link or providing sensitive information, such as passwords or payment card information.

    Malware is any software that is intentionally designed to cause damage to a computer, server, or network. This includes viruses, ransomware and trojan horses. Malware is most commonly sent through malicious emails, websites, and advertising.

    Distributed Denial of Service or DDOS is a malicious attack where a cybercriminal overwhelms a target server, service or network with internet traffic to disrupt normal traffic. The goal of these attacks may be to stop legitimate traffic from visiting a site. Or to overwhelm network equipment, such as firewalls, in order to launch another cyberattack.

    Which types of businesses are most like to be targeted by cybercriminals?

    All businesses are at risk of falling victim to a cyberattack. In the past, it was far more common for larger businesses to be the target of these attacks. However, it has become increasingly common for cybercriminals to target smaller businesses with ransomware. This is as they typically are easier targets with weaker security.

    What is the average cost of a cyberattack?

    In 2021, the median cost of a cyberattack was £8,460, with the most expensive cyberattack costing £15.8 million. It is important to note that the monetary cost is often not as damaging as the loss of reputation and downtime associated with many cyberattacks.

    How does the advent of hybrid work affect cybersecurity?

    The move to hybrid work has many benefits for employees and businesses as a whole. However, it can weaken a business’s security posture. The key cybersecurity associated with both hybrid work and remote work is the lack of visibility of endpoints and networks. With employees working from multiple locations, the network boundary expands drastically and an unsecure home network could lead to a cyberattack within a business.

    What are the top SMB cybersecurity mistakes?

    The most common mistake that SMBs make when considering cybersecurity is thinking that it won’t happen to them. Regardless of the size of the industry, a business operates in, they can be the target of a sophisticated cyberattack. Many of these attacks can be, using relatively simple measures, and a comprehensive cybersecurity solution will stop most attacks in their tracks.

    What should be an SMBs top cybersecurity priorities?

    The top priority for all SMBs should be to ensure they have enabled multi-factor authentication on their Microsoft 365 account. This simple action will prevent 99.9% of all account compromise attacks. After this is enabled, businesses should secure their email system, as it is the most common attack vector. Once their email system is secured, it is important to implement a backup and disaster recovery solution, so if a business does fall victim to a cyberattack, the downtime will be limited. A comprehensive cybersecurity solution should address all these priorities and more.

    What should an SMB look for in a cybersecurity solution?

    When SMBs are searching for the right cybersecurity solution, it is important to ensure that the solution provider covers all areas of the cybersecurity landscape. This includes endpoint protection, email protection, network protection, backup, and disaster recovery. Having a comprehensive cybersecurity solution will significantly decrease the chance of an attack.

    How much will a cybersecurity solution cost?

    It is difficult to know how much a cybersecurity solution will cost without understanding the needs of a particular SMB. On average, businesses spend 10% of their IT budget on cybersecurity. However, it is important for businesses to consider the potential losses associated with a cyberattack, and factor this number into the equation when deciding how much to spend on a cybersecurity solution.

    What’s Next?

    All businesses need to invest in cybersecurity in 2022 to reduce the chance of falling victim to an attack. If you are ready to take the next step in securing your IT and looking at Cyber Essentials contact us today.

    [/et_pb_text][/et_pb_column] [/et_pb_row] [/et_pb_section]
  • What is Cyber Essentials Certification and why should you get it?

    What is Cyber Essentials Certification and why should you get it?

    about cyber essentials
    We answer your questions about Cyber Essentials!

    You keep hearing the term cyber essentials, but what exactly does it mean? Why should your business consider being a part of the scheme? With cyber-attacks becoming ever more common, there is no better time to understand the steps you can take to protect your business from the most basic attacks. Many cyber-attacks are carried out by low skilled individuals. So taking some basic steps can massively reduce the chance of you falling victim to one! Here at The Unite Group as your trusted technology provider we want to best advise our customers on how to protect themselves as well as their customer data. In this blog, we will explain to you the basics of Cyber Essentials. As well as how we can help & guide you through achieving the certification.

    What is Cyber Essentials?

    Cyber Essentials is a Government-backed and industry-supported scheme that allows businesses to protect themselves from cyber-attacks. The scheme lays out a clear statement of the basic cybersecurity measures an organisation should have in place to protect themselves from the growing threat of attacks.

    Cyber essentials is a foundation level certification. This was created to provide the basic controls an organisations should have in place to reduce the risk of common cyber threats. This first step protects you from 80% of the most basic cyber security breaches.

    Upon completion, organisations can then move onto Cyber Essentials Plus. This is the highest level of certification offered in the scheme, so this includes a more rigorous test of an organisations Cyber Security systems. Experts carry out vulnerability tests and ensure organisations are well protected against basic hacking and phishing attacks.

    What does the certification process include?

    Obtaining The Cyber Essentials certification is a relatively simple process

    1. Choose The Unite Group as your Provider
    2. Complete your self-assessment questionnaire and then await its review.
    3. Once your submission is approved, you will then receive your certificate.

    If for any reason you have any issues, Unite will be here to support you through the process.

    Who runs Cyber Essentials?

    It was developed and is operated by NCSC (the National Cyber Security Centre). It is the UK Government’s answer to a safer internet space for all organisations of all sizes.

    Is Cyber Essentials UK only?

    Although it was developed by the UK’s National Cyber Security Centre, it is globally recognised as a certification that enhances an organisations protection against data breaches and leaks. Therfore, organisations with global customers can complete this certification and be confident it will be recognised internationally.

    Why should you get Cyber Essentials?

    Having certification allows businesses to show you can trust them and take their security seriously when it comes to cyber security. This can open new opportunities as a lot of larger organisations will only work with companies who can demonstrate their cyber security protection measures. Many Government contracts require certification to be considered.

    However, the benefits are not only external. Internally the scheme provides a clear picture of your organisations cyber security level. You can feel confident you have taken the necessary steps to protect your businesses. Therefore eliminating some of the risk of your organisation experiencing an attack.

    Can you afford not to have certification? Are you ready to protect not only your organisation but the data of your customers by doing the Cyber Essentials certification?

    How can we support you through the process?

    Here at The Unite Group, we can provide support to you throughout the process. Unite are an authorised certificate issuing body for Cyber Essentials. As a result we can manage the entire process for you from initial audit, remedial works and certificate issue.

    Do you want peace of mind that your defences will protect you from a large amount of the most common cyber-attacks? Contact us today and our friendly, knowledgeable team will be happy to explain in more detail the Cyber Essentials certification process or help you take the first steps to achieving your Cyber Essentials Certification!

  • 5 Common Cybersecurity Myths Your Business Should Be Aware Of

    5 Common Cybersecurity Myths Your Business Should Be Aware Of

    cybersecurity myths
    Are you aware of the top cybersecurity myths?

    What are the top cybersecurity myths you should be aware of in 2022? In this article, we’ll debunk some of the biggest misconceptions about digital security.

    Thankfully, businesses are now more aware than ever of cyber threats and are starting to take cybersecurity very seriously. PwC found that nearly 64% of UK CEOs are concerned about how cyber threats could harm their ability to sell products and services.

    Indeed, taking into proper account your organisation’s cybersecurity is a vital part of running a modern business. This keen focus on abating cyber threats, however, had led to many cybersecurity myths becoming commonplace.

    Believing these ill-informed cybersecurity myths could leave your business vulnerable to threats and may render your security infrastructure ineffectively. 

    Myth 1: Hackers don’t target small businesses

    We understand why some small business owners feel like cybersecurity isn’t important to them. Cybersecurity can be a big investment for smaller firms and start-ups and many decision-makers would prefer to spend that money on other sections of the business.

    However, there’s no truth in the misconception that hackers don’t target small businesses. In fact, a report from Barracuda found that cybercriminals are up to three times more likely to target small businesses than larger firms. 

    Why? Hackers smaller businesses as ‘low-hanging fruit’ and target their inadequate security infrastructure and take advantage of insufficient security training for staff for social engineering attacks.  

    Furthermore, the lasting damage of cyber attacks to smaller businesses is greater than for enterprises. 60% of small businesses fail within six months of a cyber attack or data breach. 

    Myth 2: Antivirus and firewalls will protect my business

    Firewalls and antivirus software are a brilliant first line of defence for your digital infrastructure – but attacks can and will get through them. A holistic cybersecurity strategy will need to use other methods of protection such as backups, cybersecurity awareness training and two-factor authentication. 

    First of all, antivirus software and firewalls are only effective if they’re regularly updated and configured correctly. Not quite sure how to make sure they’re running effectively? We recommend working with a Managed Service Provider (MSP) like ours to configure your security infrastructure for you.

    Secondly, antiviruses and firewalls can only protect your business from malicious software and intrusions. They’re less effective at preventing social engineering attacks such as phishing scams, mishandled login credentials or internal threats. We’ll cover what’s needed to prevent these attacks later on!

    Myth 3: Phishing attacks are easy to spot

    A common misconception is that only the tech-illiterate fall for phishing attacks and that cyber awareness training is a waste of time for those who are “good with computers.”

    In reality, this just isn’t the case. Phishing attacks – especially those specifically targeting your business for espionage – are becoming increasingly more convincing. 

    One of the most common forms of phishing is a spear phishing attack – where attackers use gathered intel about your business to make the email (or phone call) look legitimate. Over 65% of targeted attacks are done this way. 

    They commonly ask for payment or urgent action for a convincing reason. Attacks may also spoof a legitimate email – for example, a manager, the CFO or CEO. 

    Businesses need to train their staff on spotting phishing attacks and what sorts of emails to be suspicious about. However, even then, some phishing attacks may be too convincing to spot. For that reason, you’ll also need an email filter actively looking for possible phishing scams.

    Myth 4: A long complex password will keep my account safe

    A strong password policy is a cornerstone of a cybersecurity strategy. However, there are some other considerations to make other than having a long, complex password: 

    • Enforce a policy to regularly change passwords. Some hackers may gain login credentials through phishing or a data breach. Changing passwords regularly removes this opportunity. 
    • Encourage employees to remember passwords and not write them down. What’s the point of a complex password if it’s available for everyone to see on a post-it note or a text file?
    • Your employees should never share their passwords – even with trusted colleagues, friends and family. 
    • Implement multifactor authentication to ensure that hackers can’t gain access to your employees’ accounts even if they have their passwords.

    Myth 5: The only real concern is external threats

    Insider threats pose just as much of a concern as external threats – if not, more as they’re difficult to protect against. According to Gurugul, 98% of companies are concerned about insider threats whilst only 11% believe they’re well protected from them. 

    Internal threats fall into three broad categories: 

    • Negligent Insider
    • Stolen Credentials
    • Malicious Insider

    Negligent insider threats are when an employee or executive negligently exposes your business to a cyber vulnerability – but unintentionally (or at least without malice). This is is the most common insider threat.

    These types of threats can be prevented through cyber awareness training or a Data Loss Prevention program. 

    Stolen credentials involve the loss of credentials – mainly through social engineering attacks such as phishing. Protecting from these attacks involves awareness training, two-factor authentication and suspicious activity detection. 

    The least common type of insider threat is the malicious insider attack – where an employee or business partner causes damages or steals data intentionally. This is by the hardest to protect from as companies generally assume all their employees aren’t out to sabotage them. 

    The best way to protect from this is by enforcing strict access permissions (and ensuring employees can only access the data they need) and using data loss prevention (DLP) and monitoring tools. 

    These steps prevented a huge data incident in October 2021 when a Pfizer employee uploaded 12,000 confidential files to a Google Drive account – according to Reuters. This suspicious activity was detected and prevented by DLP software. Turns out, the employee had accepted a job offer from competitor Xencor, and this was attempted espionage.

    How we can help secure your business

    Cybersecurity infrastructure is a long, complex process. However, the return on investment (ROI) of cybersecurity projects is immense due to security expenses avoided is immense. 

    For instance, according to IBM’s Cost of a Data Breach Report 2021, the average cost of a data breach is $4.24M! That’s why we highly recommend upgrading your security infrastructure and protecting your business from increasingly dangerous cyberattacks.

    Want to learn how we can help you secure your business? Looking to deliver effective cyber awareness training? Want to explore what software solutions are best for protecting your business? 

    Get in touch with us today and see how we can level up your business’s cybersecurity with Cyber Essentials

  • Why a Cyber Essentials certification is important for SMBs

    Why a Cyber Essentials certification is important for SMBs

    cyber essentials certification
    So why should you have cyber essentials certification?

    In recent years, it has become increasingly important for businesses to secure their IT systems to reduce the chance of falling victim to a cyberattack. In the UK alone,39% of businesses were targeted by a cyberattack in the last 12 months. Whilst most cyberattacks target large businesses and enterprises, it is also just as common to happen to small businesses. This is because they are less likely to have invested in securing their IT systems. For this reason, all SMB owners should invest in strengthening their security posture and aim to achieve a Cyber Essentials certification.

    What is a Cyber Essentials certification?

    It is a UK Government backed scheme that is designed to protect companies against a wide range of cyberattacks. There are two levels of certifications: Cyber Essentials and Cyber Essentials Plus. Cyber Essentials is a self-assessment, that ensures businesses have controls in place to protect against most common cyberattacks. Cyber Essentials Plus is a more in-depth certification and includes hands-on technical verification.

    The certification covers many areas, including firewalls, secure configuration, user access control, malware protection, security update management and more. The Cyber Essentials certification lasts for 12 months. It is then regularly updated to make sure businesses are protected against basic attacks.

    The importance of cybersecurity for SMBs in 2022

    All small businesses are at risk of falling victim to a cyberattack. The most common cyberattacks being phishing, data breaches and ransomware attacks. All of these attacks can be awful for businesses, both in terms of the costs, as well as the costs associated with damages to a business’s reputation.

    Thankfully, many of these attacks are carried out by relatively unskilled cybercriminals. So fortunately they can be stopped by implementing some basic security controls. In a recent blog we explained the benefits and added protection of companies outsourcing their cybersecurity to professionals. With a Cyber Essentials certification, these attacks are no longer viable.

    Benefits of a Cyber Essentials certification for SMBs

    Reduce the chance of falling victim to a cyberattack

    The overall goal of Cyber Essentials is to reduce a business’s cyber risk. As the assessment covers most attack surfaces and the associated technical security controls, Cyber Essentials covers all the bases to protect from 80% of common cyberattacks. Although the methods that cybercriminals use are constantly changing, these technical controls will typically stop basic attack methods, especially if they are not highly targeted attacks.

    Gain a competitive advantage

    For small businesses within competitive industries, a Cyber Essentials certification can be a way to stand apart from the competition. The certification shows that your business takes security seriously. Therefore any customer, either consumer or corporate, doing business with you is less likely to have their data leaked as part of a customer data breach. After a business obtains their certification, they can also display the certification badge on their website and other marketing materials.

    Find new business opportunities

    A Cyber Essentials certification is mandatory for businesses considering submitting a bid for a contract with the NHS, Ministry of Defence, and UK Government. Many private sector businesses also look for the Cyber Essentials badge of approval when seeking new suppliers.

    Improve credibility and reputation

    The technical controls necessary to obtain the certification are relatively simple to implement, and the self-assessment is a quick and easy process. This simple and affordable option can add significant value to a business as it improves credibility and reputation. Having a Cyber Essentials certificate shows customers that a company is committed to protecting its data. It also shows they are taking action to reduce the chance of them falling victim to a cyberattack.

    Free Cyber Liability Insurance

    Once your business has gained its Cyber Essentials certification, your business is automatically entitled to free Cyber Liability Insurance to the total limit of £25,000 of indemnity. This also gives businesses access to a 24-hour hotline to report a cyber incident. This includes crisis management and incident response. For businesses that do not already have cyber insurance, this is a perfect option to recover from a small breach or incident. Many cyber insurance providers will also give discounts to businesses that are certified.

    How we can help?

    For businesses that are’t well versed in the world of cybersecurity, it can be difficult to implement the technical controls necessary to obtain a Cyber Essentials certification. We can help your business implement the technical controls. As well as this we provide additional security services to further reduce the chance of falling victim to a cyberattack. To find out more, contact us today.

  • Cybersecurity – 5 reasons why your business should outsource it

    Cybersecurity – 5 reasons why your business should outsource it

    Cybersecurity with The Unite Group

    Maintaining a strong cybersecurity posture is a significant challenge for most businesses. With complex cyberattacks becoming more common, all businesses are at risk of falling victim. To reduce this risk, businesses typically implement new technologies that focus on prevention, detection, and remediation.

    However, this technology alone will not prevent a cyberattack, it will need to be supported by skilled security professionals. Many businesses choose to outsource this to a trusted third party to ensure their business is as safe as possible. In this article, we will discuss 5 reasons why businesses should outsource their cybersecurity.

    Access to experienced professionals

    Many businesses rely on their in-house IT teams to manage their infrastructure, as well as their cybersecurity. Depending on the size of the company, and the workload of the IT department, this can be an overwhelming task. This can then result in a poor security posture and an overworked team. This is made harder as there is a cybersecurity skills shortage. This makes it difficult for businesses to employ experienced cybersecurity professionals.

    When a business outsources their cybersecurity to a trusted third party, they gain access to a team of cybersecurity specialists. Their experience ensures they will be able accurately find and plug gaps within a business’s security posture. And most importantly they are aware of the current cyberthreats, and the best way to avoid them.

    Reduce costs

    For businesses of all sizes, employing a new security professional or training an existing employee can be extremely expensive. For smaller businesses, it can sometimes be difficult to justify having an employee that is dedicated solely to security. In addition to the cost of employing or training someone, a business will still need to pay for cybersecurity technologies.

    Whereas if a business outsources its cybersecurity, the cost is typically a fixed amount per month. This includes the technology, as well as access to the team of cybersecurity professionals. Whenever a business is considering the cost of outsourcing security, they should also consider the average cost of a cyberattack. Looking at the cost to the business if this was to happen can help estimate the return on investment.

    Decrease workload for in-house IT teams

    If your business has an in-house IT department, it is highly likely they already have a full workload maintaining the IT and assisting with support requests. This often leaves them with insufficient time to work on the perfect security solution, or threat monitoring.

    With outsourced cybersecurity, the third-party provider is responsible for the planning, implementation and monitoring of a cybersecurity solution. This gives in-house IT departments more time to spend providing IT systems that help grow the business and provide better experiences for other employees and customers.

    Improved incident response time

    After a business falls victim to an attack, it is imperative that they respond quickly to reduce further damage and limit downtime. If a cybercriminal enters a network or system during the weekend, an in-house IT team may not notice until Monday morning. This will give the threat actor enough time to move laterally across a network and inflict even more damage. For example, it only takes 18 minutes for Russian nation-state hackers to move across a network.

    Many cybersecurity providers offer 24/7 protection, detection and remediation to ensure that regardless of when an attack occurs, there is someone ready to swiftly take action. This is also a more cost-effective method of around the clock protection, as it would be extremely expensive to hire an internal team to work throughout the nights and on weekends.

    Access to advanced technologies

    There are many cybersecurity technologies out there which are designed to fulfil specific roles, including endpoint protection, email protection, autonomous detection, and many more. For an in-house IT department, they will not have experience with all of these advanced technologies, and it would be too costly and time-consuming to provide training for all solutions.

    If a business chooses to outsources their cybersecurity requirements, they will be protected by a team of professionals that have experience in the cybersecurity technology. As this team live and breathes cybersecurity, they will also be able to accurately provide insights into which technologies are worth a business investing in.

    Looking to outsource your cybersecurity?

    In 2022, all businesses need to invest in cybersecurity, before it is too late. There are many advanced threats out there that most in-house IT departments are not prepared or able to defend against. For this reason, it is logical for businesses to outsource their cybersecurity to a trusted third-party provider. To find out more about how we can keep your business safe, contact us today.

  • The role passwords play in a world of cybercrime

    The role passwords play in a world of cybercrime

    protect your passwords against cyber crimes
    Protect your passwords against Cyber Crimes.

    For businesses, one weak password can be the cause of a major cybersecurity incident. Here at The Unite Group, we help businesses take measures to ensure they are doing everything possible to reduce the chance of falling victim to an account compromise attack. Whilst having a strong password is a good start. There are other technologies and processes that businesses can implement to reduce this risk. In this article, we will discuss some common methods of password attack. Including how to create a secure password and other ways that businesses can stay safe in a world of cybercrime.

    Common methods of password attack

    Brute Force

    A brute force attack is where a cybercriminal attempts to crack a password by submitting many passwords or passphrases with the hope that one of them will be correct. This is not a manual process. Instead hackers will use a tool that can submit millions of login attempts every second, each with a different credentials.

    Dictionary Attacks

    Dictionary attacks are a form of brute force attack whereby the cybercriminal runs through a list of common words in an attempt to find the correct password. More sophisticated dictionary attacks will also use words and phrases relevant to the target. This can include their name, pets’ names and birthdays.

    Past Data Breaches

    Many individuals will reuse passwords across multiple websites and systems. Therefore, if one of these websites has a data breach then all the users’ passwords are leaked. Cybercriminals can use these on other websites and systems.

    Phishing

    Phishing attacks are a form of social engineering where a cybercriminal imitates a trusted entity and tricks an individual into opening a fraudulent email, SMS, or instant message. This message is designed to deceive the victim. Often encouraging sharing sensitive information or clicking a link that will run malicious code. There are many forms of phishing attacks that range from untailored bulk emails to highly sophisticated spear-phishing attacks. Common credential phishing attacks include malicious emails that ask employees to reset or update their passwords.

    How to create a secure password

    An understanding of the common methods of credential attacks should guide how employees should create a secure password. In order to avoid brute force and dictionary attacks, passwords should be long and complex. This can include using numbers, symbols and uppercase letters, without using dictionary words or names.

    For example, the password ‘janedoe’ would take 2.4 seconds for a hacker to crack. If numbers, symbols and uppercase letters are added to make ‘JaneDoe295!’, this would take 31 hours to crack. However, if a credential of the same length but with random letters and characters, such as ‘f^Hl86$p-x$’ is used, it would take 9 billion years, making it immune to brute force attacks.

    In order to avoid a previous data breach being the cause of an account compromise attack, employees should not reuse passwords across multiple sites or services. However, the average organisation uses 80 SaaS applications, and it is unrealistic to expect an employee to remember 80 long and complex passwords. To solve this issue, and avoid credential attacks through phishing, we recommend businesses should also implement other technologies to increase security.

    Other ways businesses can stay safe

    To avoid phishing attacks, businesses should implement a comprehensive email security solution. Many modern email security solutions use AI to block such phishing attacks before they even land in an employee’s inbox. Some solutions also include web filtering. This will block any malicious URLs, further decreasing the chance of falling victim to an attack.

    It should also be noted that passwords should not be the only line of defence against account compromise attacks. Here at The Unte Group we also recommended implementing multifactor authentication (MFA). MFA is an authentication process where a user must provide two or more forms of identification to log in to their account. Typically, the forms of identification are two of the following: something the user knows (such as a password), something they are (such as biometrics) or something they have (such as a hardware key or trusted phone). Deploying multifactor authentication is simple and it prevents 99.9% of all account compromise attacks.

    As it is not possible to remember 80+ long, complex credentials, one solution is to make use of a password manager. A password manager can store passwords for an employee, which they can access with a single password. When using, it is essential that the master password is strong. Enabling multifactor authentication can improve security.

    All businesses should be taking password security seriously as the consequences of poor password hygiene can be severe. To find out more about password security, or which solution is right for your business, contact us today.

  • How does being ISO certified benefit your business?

    How does being ISO certified benefit your business?

    Here at The Unite Group, we have recently achieved ISO 9001 and ISO 27001 certification!

    This achievement is something to celebrate. Having this ensures that we are providing an excellent standard of service to our loyal customers.

    ISO 9001 is a quality management system and ISO 27001 is an information security management system.

    Meeting the standards of an ISO certificate provides your business with a number of benefits. These will improve the validity of your company’s management processes.

    ISO certification sets a standard for businesses and the daily processes which ensure customer requirements are being met.

    This also means that each business has a set of high standardised procedures. By having these procedures in place it means any new employees can easily follow them.

    Businesses that have been granted ISO certification are regulated by the BSI to ensure that any changes that have been made are still meeting the standards of the certification.

    The ISO 9001 standards was updated in 2015. It is the world’s most popular quality management system standard.

    Over one million organisations are ISO 9001 certified. Survey results have found that there is a 60% reduction in the likelihood of mistakes.

    Results have also showed that, products and services provided by these organisations have improved by 66% since being certified.

    Some customers may require that you are certified before agreeing to pay for a specific service. Therefore, showing that being certified can cause an increase in revenue.

    ISO Standards

    The ISO standards are compatible with other certifications, for example ISO 9001 is compatible with ISO 27001.

    This allows businesses, like us, to improve the quality of their management and security processes at the same time.

    This has a knock-on-effect and improves customer acquisition and retention.

    ISO 27001 minimises the risk of a security breach which could have legal implications for your business.

    By following the procedures put in place with the ISO 27001 certification, risk assessments are conducted, and security information is protected from any pre-anticipated risks.

    71% of businesses feel more protected since being ISO 27001 certified.

    BSI will work with you and your business to help you achieve improved management processes and integration with corporate risk strategies.

    In order to continue meeting the standards of the certification, you must regularly risk assess your business and its procedures.

    You must establish correct procedures throughout the company and implement internal reviews regularly.

    By being certified, we have greater protection and confidence in our management procedures, ensuring that we are providing our customers with the best possible service.

    You can call us on 0191 466 1050 or email us on info@theunitegroup.co.uk for more information.

    The Unite Group, to book your free consultation.