Category: Cybersecurity

Cybersecurity

Cybersecurity focuses on protecting computer systems from unauthorised access or being otherwise damaged or made inaccessible

At The Unite Group, we take cybersecurity extremely seriously. That is why we have produced a series of blogs educating you on the latest dangers and tips to protect yourself & your business.

Cybersecurity is a crucial thing to get right, it is not one you can take any risks with due to the implications it can have on your business. We have created blogs that give you information on the Cyber essentials certification, cyber essentials plus as well as good housekeeping to keep your business in order.

Use these blogs to learn how to keep your company and personal data safe in the world of cybercrime. If you have any cybersecurity needs then please do not hesitate to get in touch. We are able to get our clients through their Cyber Essentials Certification as an awarding body of this government-backed scheme.

If there are topics you would like to see us create content around then please just send us an email or give us a call and we will get these added for you. If you find our blogs useful please let us know. You can also follow all of our blogs and content on our social media pages.

The Unite group – Cybersecurity Blog – Because technology matters.

 

  • Festive season cyber threats: Are you prepared?

    Festive season cyber threats: Are you prepared?

    Festive season cyber threats: Are you prepared?

    Have you thought about the cyber threats your business could face this festive season?

    Christmas is around the corner and most businesses are beginning to unwind and prepare for the festivities. Therefore, our minds are filled with presents, wrapping, and preparing the Christmas dinner. But as we begin to let our guards down, hackers are waiting on the sidelines for their perfect time to strike.

    It’s easy to get swept away in the Christmas cheer. But just because we stop doesn’t mean the cyber threats do. In fact, our downtime is a hacker’s dream and as we slow down, they get ready to attack. Have you stopped to think about the cyber threats your business could face during the holiday season?

    Not to worry. We’ve pulled together some things to think about during the most wonderful time of the year. We’re outlining a few of the main cyber threats you may face throughout the festive period. This means you can feel safe and enjoy the holidays with the confidence that your business is protected.

    Phishing Emails

    A phishing email is a cybercrime that contacts its target via email. The sender poses as a legitimate institution to lure individuals to hand over sensitive business information. This information is then exploited or used for financial gain.

    There are 3 types of phishing emails to look out for:

    • Spear phishing – an attempt directed at a particular individual or company.
    • Clone phishing – hackers use a legitimate, previously delivered, part of online correspondence to create almost identical emails.
    • Whaling – an attempt directed specifically at a senior executive or high-profile target within the business.

    It’s important to make your employees aware of phishing emails and teach them how to spot them.

    Weak passwords

    It’s easy to fall into the trap of using the same passwords for multiple accounts. However, this can result in leaving the business open and vulnerable to cyber-attacks.

    Amongst the hustle and bustle of the Christmas period, take some time to ask yourself the important question: Are your passwords secure?

     Do they have the complexity to make it difficult for cyber criminals to breach?

    Before locking up the office for Christmas, double-check that your passwords comply with best practices.

    We suggest you create strong passwords by following the below steps:

    • Use a combination of upper-and lower- case letters.
    • Include numbers.
    • Include special characters (symbols).
    • Never include any personal information.
    • Never use the same password for different applications.
    • Ensure your passwords are at least 12 characters long.

    Misconfiguration of Devices

    When did you last configure all your devices? Is your firewall up and working properly?

    It’s important to ask yourself these questions before getting wrapped up in all the festivities.

    When cyber security software is updated or changed, misconfigurations become the most prevalent. This leaves your business vulnerable and open to a cyber-attack.

    It is vital that your firewall is correctly configured and up to date to protect your business from hackers.

    Before leaving for Christmas, double-check everything is updated and correctly configured. This means you can enjoy the holidays and have peace of mind that your business isn’t left vulnerable to cyber threats.

    Cyber Essentials Certification

    Here at The Unite Group, we understand the many cyber threats that businesses face day in and day out. We believe businesses should go the extra mile when it comes to cyber security. One way of doing this is to obtain the Cyber Essentials certification.

    A foundation-level certificate protects your business from 80% of the most basic cyber security breaches.

    The Cyber Essentials scheme covers 5 key areas of cybersecurity:

    • Access Control
    • Software Updates
    • Firewalls & Routers
    • Secure Configuration
    • Malware Protection

    The Unite Group is a certifying body of the cyber essentials scheme. If you would like to learn more about the Cyber Essentials certification, click here!

    Keep an eye out in our newsroom for more blogs like this and be sure to keep an eye on our Facebook, LinkedIn, and Instagram for updates!

  • How can we provide Cyber Essentials support?

    How can we provide Cyber Essentials support?

    cyber essentials support man with a laptop

    In this blog we talk through the guidance you can seek for Cyber Essentials support.

    So, you’ve realised you need a Cyber Essentials certification but you are unsure where to start?

    Well here at The Unite Group, we strongly recommend using a registered, qualified Cyber Essentials awarding body. Like our team here! This is because qualified assessors can guide you through the process to ensure your company completes the certification criteria correctly. By accessing Cyber Essentials support you are likely to achieve the certification much faster. Although you could go through the process without support, it is likely to be time-consuming for you. Instead, we recommend you seek Cyber Essentials support from experts who understand the rules and regulations. As well as how to apply them to a business.

    What is a Cyber Essentials certification?

    Before we dive into how to seek support through gaining the Cyber Essentials certification. Let’s first cover what the certification is. Cyber Essentials is a scheme that helps you guard your organisation against cyber attacks. It is a government-backed scheme to provide protection against the most common cyber-attacks.

    There are two levels of certification that can be achieved.

    Cyber Essentials

    This is the most basic option. The assessment includes a self-assessment question. This certification gives peace of mind that you have the basic measures of protection in place. Click here to read more about this certification and how we can provide Cyber Essentials support.

    Cyber Essentials Plus

    This is a higher-level certification and demonstrates you are taking precautions against attacks. Achieving this certification includes the same self-assessment as Cyber Essentials as well as an external vulnerability scan & internal testing. Click here to read more about this certification.

    Can you fail Cyber Essentials?

    Yes! This certification requires an assessment and therefore it is possible to fail. However, if you are guided through the process by a qualified assessor this is unlikely. This is a further reason why we recommend seeking Cyber Essentials support.

    A fail will incur further costs to re-sit the assessment. As well as any additional support you then seek in order to do so. Therefore having support from an awarding body, such as ourselves, right from the start can prevent any additional costs.

    Do I need to renew Cyber Essentials?

    Yes! Cyber Essentials certifications must be renewed annually to ensure all procedures are up to date. This also ensures you are protected against the latest types of cyber attacks.

    Here at The Unite Group, you can take out our Cyber Essentials support on a monthly payment basis. Not only does this split the cost. This also means we will support you annually when you must renew your certification.

    Our pricing for your managed Cyber Essentials certification is £800, this can be split into 10 payments of £80.

    Cyber Essentials Plus starts at £1200, again this can be managed with 10 payments of £120.

    Cyber Essentials support

    As an awarding body with Cyber Essentials qualified assessors in-house. We can provide support throughout the whole process. From defining the scope right up to preparing for the examination. Our dedicated, friendly team is on hand to help wherever you require a little extra support.

    Are you ready to take the first steps in achieving your Cyber Essentials certification?

    Why not arrange a free consultation with our team today where we can discuss in depth the Cyber Essentials process. As well as which certification would be needed to support your business. Use the booking system below to select a time that is convenient for you.

    Alternatively, contact us today by giving us a call today or dropping us an email.

  • Computer Security Day

    computer security day

    Today marks National Computer Security Day.

    This day demands our attention every year due to the shift to a more digital way of life. Although technology has enriched our lives, it has also left us vulnerable to data security issues and cyber-attacks.

    It’s no secret that the introduction of electronic devices has made our lives easier. However, that doesn’t mean it comes without its complications.

    This unofficial holiday reminds both people and businesses to stay on top of their computer security.

    In this blog, we’ll share some tips on how to keep on top of computer security.

    1. Create strong passwords

    I’m sure we’ve all fallen victim to the memorable password of ‘Password123’ or ‘Password12345.’ Despite, this making life easier for us, it also makes you more vulnerable to cyber-attacks.

    We suggest you create strong passwords by following the below steps:

    • Use a combination of upper-and lower- case letters.
    • Include numbers.
    • Include special characters (symbols).
    • Never include any personal information.
    • Never use the same password for different applications.
    • Ensure your passwords are at least 12 characters long.

    2. Keep all software up to date

    We’re fully aware of the painstaking amount of time it takes to update software. And we’re all guilty of clicking the little ‘X’ and leaving it to a later date. However, you are taking a serious risk every time you do this!  

    Software updates have multiple benefits and they all come down to protecting your computer security.

    Software updates are specifically designed to strengthen the stability of any software and combat the latest viruses.

    3. Ensure you have antivirus software in place

    Having an antivirus software installed on your electronic device sounds like a no brainer and we agree with this notion.

    Not having this could result in a slow device, or having important files damaged or deleted. To prevent this from happening, it is vital you have antivirus software installed.

    Are you looking to download an antivirus software but don’t know where to start?

    Our helpdesk team are on hand to help, contact us today!

    4. Regularly backup your data

    Ever spent hours on an important document but the file becomes corrupted?

    This disheartening situation is easy to avoid if you regularly backup your data.

    Here at The Unite Group, we recommend using the 3-2-1 approach for best practice:

    • Make sure you have THREE copies of your data,
    • On TWO different storage mediums,
    • And with ONE off-site copy.

    5. Cyber Essential Certification

    Businesses should go the extra mile when it comes to cyber security. One simple way of doing this is to achieve the Cyber Essentials certification.

    Cyber Essentials is a government-backed and industry-supported scheme that allows businesses to protect themselves from cyber-attacks.

    A foundation level certificate protects your business for 80% of the most basic cyber security breaches.

    The Cyber Essentials scheme covers 5 key areas of cybersecurity:

    • Access Control
    • Software Updates
    • Firewalls & Routers
    • Secure Configuration
    • Malware Protection

    The benefits of obtaining the Cyber Essentials certification:

    • It prevents around 80% of cyberattacks.
    • It presents you with new business opportunities and can boost your reputation,
    • Demonstrate to your customers/clients that you take cybersecurity seriously.
    • It provides you with the opportunity to work with the Government.
    • Be listed on the NCSC’s database.
    • Demonstrate your commitment to data protection.

    Upon completion of Cyber Essentials, businesses are then presented with the opportunity to move on to Cyber Essentials Plus.

    If you would like to learn more about the Cyber Essentials certification, click here!

    Keep an eye on our newsroom for more blogs like this and be sure to keep an eye on our Facebook, LinkedIn and Instagram for updates!

  • Cyber Essentials vs ISO 27001

    Cyber Essentials vs ISO 27001

    cyber essentials vs ISO 27001

    What is the difference between Cyber Essentials vs ISO 27001?

    We often get asked by companies looking to strengthen their cybersecurity which is the better option Cyber Essentials vs ISO 27001. Here at The Unite Group we always stress how different the two schemes are and that they should not be compared but instead accepted as two very different schemes which both enhance a company’s security stance.

    In this article, we discuss the two schemes and offer further information for any business looking to improve its cybersecurity.

    Cyber Essentials

    What is it?

    The Cyber Essentials scheme is a Government backed scheme that covers 5 key areas of cybersecurity; access control, software updates, firewalls & routers, secure configuration & malware protection. The aim of this scheme is to protect against the most common forms of cyber-attacks. This certification is also required to bid for Government contracts.

    What does it aim to protect?

    By completing the Cyber Essentials certificate, your organisation is effectively protecting itself against approximately 80% of the most common cyber-attacks. This is because this scheme protects your data and programs on hardware such as computers, networks, servers and any other elements in your IT infrastructure.

    Who should consider being a part of the Cyber Essentials scheme?

    All organisations who want to protect their businesses should partake in the scheme. Not only does it protect your business. But it also demonstrates to your clients that they can be confident their data will be in safe hands. Therefore any business that is looking to implement basic cybersecurity measures should look into achieving the certification.

    Also, for any businesses that wishes to bid for Government contracts this certification is a prerequisite. Therefore, if you wish for your business to be considered for such opportunities you should begin the process of achieving this as soon as possible.

    ISO 27001

    What is it?

    ISO 27001 is a set of standards that have been designed to keep information assets secure. This certification allows you to manage the security of assets including financial information, intellectual property, employee details and any information entrusted to you from third parties. ISO 27001, therefore, has more elements within its scope. ISO 27001 has 10 clauses and 114 generic security controls grouped into 14 sections

    What does it aim to protect?

    ISO 27001 differs from Cyber Essentials as it aims to protect all information and data regardless of where it is found. Meaning the certification covers hard copies, digital & data stored within information systems.

    Who should consider achieving ISO 27001?

    Similarly to Cyber Essentials, any business that wishes to demonstrate that they take data protection seriously should work towards achieving the certification. Some organisations sometimes choose to implement the standard to ensure they are following recommended guidelines. Others however choose to complete the certification to reassure their customer’s and client’s.

    So, is Cyber Essentials the same as ISO 27001?

    In short, no. However, the two complement one another.

    We recommend anyone without both a Cyber Essentials certification and ISO 27001 consider achieving both certifications at the same time. In terms of time & money, this proves to be the most effective.

    However, if this is not an option, we suggest you opt for achieving Cyber Essentials first. This scheme follows a simpler process and will introduce you to the world of certification and data protection.

    How can we help?

    Here at The Unite Group, we are certified Cyber Essentials assessors. Therefore, we can guide you throughout the process as well as assess your application for certification. Our friendly team is on hand to assist throughout the self-assessment questionnaire.

    Want to learn more? Book an appointment with our Cybersecurity team today!

  • What is the difference between Cyber Essentials & Cyber Essentials Plus?

    What is the difference between Cyber Essentials & Cyber Essentials Plus?

    difference between CE & CE plus

    Are you interested in achieving a Cyber Essentials certification but unsure as to what level of certification is best for you? In this blog, we break down the main differences between Cyber Essentials & Cyber Essentials Plus. As well as offer recommendations for which level of certification businesses should consider.

    Let’s recap what Cyber Essentials is

    As mentioned in our previous blogs, Cyber Essentials is a government-backed scheme aimed to protect businesses from 80% of the most common cyberattacks. There are 2 levels of certification that we will discuss later; Cyber Essentials & Cyber Essentials Plus. Certification must be renewed annually and cover 5 main areas of checks. Businesses who have a Cyber Essentials certification not only can be assured they comply with the latest cybersecurity measures but also have a clearer picture of their company’s cyber security level.

    So, what is Cyber Essentials?

    This is the basic level of certification. Achieving Cyber Essentials involves the completion of a self-assessment questionnaire. This questionnaire involves 8 sections and has a total of 70 questions. Here at The Unite Group, we can provide support before taking the assessment to ensure all expected standards are met. As well as providing assistance throughout the application. Upon completion, the business owner or board-level representative must then sign a declaration that all answers are completed correctly. This is then reviewed by a Cyber Essentials assessor and successful applicants will receive their certification.

    Who do we recommend Cyber Essentials to?

    We recommend the Cyber Essentials certification to all businesses who want to demonstrate that they take cybersecurity seriously. Having this certification can also open new doors for business opportunities as it is a requirement to bid for Government contracts. We recommend this to smaller corporations that want to ensure they are complying with recommended safety measures.

    Now let’s compare this with Cyber Essentials Plus

    The Cyber Essentials Plus certification involves the same first steps as the Cyber Essentials scheme. Therefore, meaning they both include the completion of the self-assessment questionnaire. However, Cyber Essentials Plus then goes on to further include a vulnerabilities assessment and an on-site assessment. The assessment covers the controls your organisation has in place. As well as, your employee’s work-from-home locations. Also assessing any third parties who may have access to your premises or IT infrastructure. These assessments are undertaken by a trained and qualified Cyber Essentials Plus assessor.

    Who do we recommend the Cyber Essentials Plus scheme to?

    Here at The Unite Group, we recommend this scheme to those businesses that want to demonstrate higher levels of cybersecurity protection. Whilst Cyber Essentials is a great starting point, the added levels of assessment included in this scheme increase a business’s protection far more. Those who hold a Cyber Essentials Plus certification can bid for Ministry of Defence contracts.

    Recap

    To recap, the main difference between the two schemes is that the Cyber Essentials Plus certification covers more areas of assessment. It includes a more rigorous test of an organisation’s cybersecurity systems. Experts carry out vulnerability tests and as a result, ensure organisations are well protected against basic hacking and phishing attacks. Therefore, we strongly recommend this option to businesses who want to ensure they best protect their data and that of their customers.

    Let us help!

    Here at The Unite Group, we can guide you through Cyber Essentials and help you protect your business. We have in-house Cyber Essentials assessors to not only approve certifications but also provide support throughout the application process. We are a friendly voice on the other end of the phone to support you through the certification from start to end.

    To find out more, book a quick call with our team today!

  • The 6 worst cyberattacks of 2022 (so far!)

    The 6 worst cyberattacks of 2022 (so far!)

    6 worst cyberattacks

    As expected, in the first 10 months of 2022, there have been multiple major cyberattacks that have resulted in a loss of productivity, revenue or large-scale data leaks. Whilst some of the largest attacks have been in countries such as America and Ukraine. There have also been some major cyberattacks within the UK. Although these cyberattacks are the ones that receive media coverage, there are many more attacks on smaller businesses that cause major devastation. So far in 2022, 39% of UK businesses have identified cyberattacks within their business. Fortunately, this number is significantly less than in 2020, as 46% of businesses identified cyberattacks. Without further ado, here are the 6 worst cyberattacks of 2022 so far.

    KP Snacks – Ransomware Attack

    KP Snacks, the maker of KP Nuts, Hula Hoops, Nik Naks, Tyrell’s, Pom-Bears and more, fell victim to a ransomware attack in January of this year. The gang behind this attack was Conti, an infamous cybercrime group from Russia. Shortly after the attack was detected, KP Snacks released a statement explaining that it could not ‘safely process order or dispatch goods’ due to the incident. Following this, there were supply chain issues until the end of March.

    As is now expected, the Conti gang operate double extortion, whereby they would release stolen data if KP Snacks did not pay the ransom. Initially, a small number of staff documents were posted online. These had a 5-day countdown. That when the clock hits zero, all data will be released, unless the ransom is paid. However, the post on the Conti website was removed soon after. This potentially indicates that the ransom was paid, or the two parties were in negotiation. With this being said, neither party disclosed whether or not the ransom was paid.

    UKVCAS – Data Breach

    In April, the UK Home Office’s visa service had to apologise for a data breach in which the email addresses of over 170 customers were mistakenly copied into an email. The email was informing a customer of a change in the time of their appointment. The emails included in this breach were a combination of personal emails and lawyers working on behalf of customers. This data breach was particularly noteworthy as UKVCAS is run on behalf of the Home Office by a private contractor. Therefore it was not directly the Home Office’s fault. The breach was likely a case of an accidental malicious insider. Businesses can decrease the likelihood of these forms of breaches through regular cybersecurity awareness training.

    The Works – Presumed Ransomware Attack

    UK Retail chain, The Works, was forced to shut down a number of its stores in April due to a widespread cyberattack. Although the retailer did not go into much detail about the nature of the attack, it is believed to have interrupted deliveries, extended online order fulfilment times and compromised the safety of payments on their POS systems. After the attack was remediated, it was found that no customer data was exfiltrated. However, it is believed that the attack was a ransomware attack. Although it is unknown how much the ransom amount was, or how The Works restored their systems.

    The real-world impact of this attack was the fact that the share price for The Works fell by 10% the day they announced the cyberattack. There was also a loss of revenue from the stores that were unable to open due to the attack.

    Crypto.com – Account Compromise

    In January, one of the largest cryptocurrency exchanges, Crypto.com, released a statement explaining they were the victim of an account compromise attack that resulted in 4,836.26 Ethereum and 443.93 Bitcoin being stolen, totalling approximately $35 million. The attack affected 483 users, and the threat actors performed unauthorised withdrawals from the victims’ wallets to their own. Interestingly, the attackers were able to perform the withdrawals without the MFA authentication control being inputted by the user. After the attack, Crypto.com suspended all withdrawals and migrated to a new MFA infrastructure.

    Crypto.com was able to prevent some of the unauthorised withdrawals before it was too late, and the company reimbursed customers so there was no loss of customer funds. Crypto.com has now implemented a new program, the Worldwide Account Protection Program, which will prevent this from happening again. The program includes controls such as the use of MFA and anti-phishing codes.

    Ukrainian Government – Website Hacks & DDoS Attacks

    Throughout the first quarter of 2022, Russian hackers targeted many Ukrainian websites, including multiple government and financial services websites. In January, around 70 websites were hacked, including the Ministry of Foreign Affairs, Cabinet of Ministers and Security and Defense Council. The majority of these hacks only involved changing the text on the website to display pro-Russia sentiments.

    Shortly after, Russian threat actors targeted multiple government, non-profit and information technology organisations throughout Ukraine with a piece of malware disguised as ransomware. The malware had all the features of ransomware, but lacked a recovery feature, meaning that it simply destroyed all files on the victim’s computer.

    Early in February, there were several large distributed denial of service (DDoS) attacks. These brought down the websites of the Defense Ministry, Army and Ukraine’s two largest banks. Later in the month, there were more DDoS attacks, but the organisations were able to recover quickly from these.

    From March until the present day, there are still many cyberattacks being launched against Ukrainian citizens and businesses. Most of these attacks are phishing attacks, with the goal of launching widespread malware attacks.

    Ronin – Account Compromise

    In March, one of the largest cyberattacks in recent history occurred. A threat actor stole approximately $600 million worth of digital assets. These were stolen from a blockchain network, Ronin, that is connected to a popular online game, Axie Infinity, created by Sky Mavis. This attack was possible as there were some outdated Sky Mavis accounts with dangerous permission levels. The attacks were able to compromise these accounts and subsequent nodes. Therefore allowing them to authorise fake transactions on the network or bridge that handles converting tokens, Ronin. The hackers were able to steal 173,600 Ether and 2.5 million USD Coin, totalling over $600 million. In 2021, there were many similar attacks on bridges and Decentralised Finance platforms, totalling $2.3 billion.

    Whilst this form of attack is not viable for most businesses, it acts as a cautionary reminder for businesses looking to adopt new Web 3.0 technologies.

    Added Bonus – Two Largest Bug Bounties

    Although the media is awash with stories of malicious actors exploiting vulnerabilities and targeting organisations, there is a community of ethical hackers actively trying to find exploits to responsibly disclose them to the affected organisation. Many organisations offer a monetary reward for finding these vulnerabilities, called a bug bounty program. So far in 2022, we have seen two of the largest bug bounties paid out. One totalling $6 million, and another totalling $10 million.

    The $6 million bug bounty was awarded to the ethical security hacker by the name of pwning.eth who found a critical vulnerability in the Aurora Engine, a bridging and scaling solution for the cryptocurrency Ethereum. If pwning.eth was to have exploited the vulnerability it could have cost the company $200 million.

    The $10 million bug bounty was awarded to the bug hunter Satya0x after discovering a vulnerability in Wormhole cryptocurrency bridge. Wormhole is the message-passing protocol that connects blockchains such as Ethereum, Terra and Binance Smart Chain. If the vulnerability was exploited, it could have resulted in $736 million worth of digital assets being lost forever.

    How to Keep Your Business Safe

    The past few years have taught us that all businesses, regardless of size, industry or location, are at risk of falling victim to cyberattacks. Although there is no way to ensure that your business is immune to cyberattacks, there are controls and solutions that can be implemented to significantly decrease your cyber risk, as well as making detection and remediation as effective as possible.

    We strongly recommend achieving a Cyber Essentials certification to best protect your data. If you want to find out more about how your business can reduce its risk of a cyberattacks in 2022, contact us today or arrange an appointment with our team.

  • How can Cyber Essentials help protect your business?

    How can Cyber Essentials help protect your business?

    In short Cyber Essentials helps protect your business by protecting you from the most commonly known cyber-attacks. No business owner wants their company to be at risk of any complications which could compromise their ability to operate. In terms of cyber security, we highly recommend companies take the necessary actions to best protect themselves. This is why we encourage achieving a Cyber Essentials certificate.

    Let’s break down the 5 main areas of the certification and how Cyber Essentials helps protect your business.

    1.      Access Control

    Cyber Essentials covers who has access to your files. This is something businesses often overlook. It is important to consider who has access to what. Do all your staff really need access to all your files? Having managed access to administrator accounts means you can protect who has access to your data and services.

    2.      Software Updates

    The Cyber Essentials scheme also ensures all devices are kept up to date with software updates. Staying current with the latest software updates and security patches protects you against the newest cyber-attacks and vulnerabilities. Updates not only add new features they also are designed to tackle the latest threats on software. To pass the certification all devices must be kept on the latest updates.

    3.      Firewalls & Routers

    Firewalls are designed to protect businesses from users who are not authorised from gaining access. So by having a firewall in place, you create a so-called ‘buffer zone between your IT network and any other external links. This will allow you to analyse any incoming traffic. Meaning you can decide who to allow access to on your network. Therefore protecting your business from hackers.

    4.      Secure Configuration

    Secure configuration covers ensuring you choose the most secure setting for your devices and software. This includes changing passwords regularly as well as removing unused accounts and software. It is easy to forget to remove any unused users and software. However, it is very important! Taking such measures massively reduces the risk of potential cyber-attacks. Therefore, protecting you and your data from being compromised.

    5.      Malware Protection

    Malware protection is another key part of the Cyber Essentials scheme. Using properly configured anti-malware software will protect you from viruses and other malware risks. Anti-malware software will only allow trusted applications to run which reduces the risk of unsafe applications running in the background without you knowing.

    Why is protecting your business so important?

    Figures from 2021, show 39% of businesses identified a cyber-attack on their business. Of the 39%, 1 in 5 identified a more sophisticated attack type such as a denial of service, malware, or ransomware attack. With 31% of those businesses estimating they were attacked at least once a week. Overall averaging at a cost of £4,200 for small businesses rising to £19,400 for medium and large businesses. Could your business afford such a loss?

    Of course, we should also consider not only the financial impact such attacks can have. But also the damage it can do to customers’ trust in your business. As well as the likelihood of them being a returning customer. Would you trust a business if you knew they had gaps in their cyber security which meant they had fell victim to an attack?

    No measures can completely eliminate the risk. However, achieving a cyber essentials certification reduces the risk by at least 80%!

    Let us help!

    Here at The Unite Group, we can guide you through Cyber Essentials and help you protect your business. We have in-house Cyber Essentials assessors to not only approve certifications but also provide support throughout the application process. To find out more, book a quick call with our team today!

  • Cybersecurity Awareness Month

    Cybersecurity Awareness Month

    cybersecurity month

    Did you know October is cybersecurity awareness month? As we shift towards a more digital way of life in 2022, cybersecurity has never been more important! This month is focused on helping businesses, their employees & customer understand the risks that we should be aware of online. As well as the measure we should be taking to reduce the risk of falling victim to such an attack.

    In this blog we share our top tips to take the first steps in protecting yourself from cybercrimes.

    1.      Use strong passwords

    One of the easiest ways internet users can fall victim to cybercrimes is through easily guessed passwords. Therefore, we recommend you create strong passwords by using the following:

    • A combination of upper- and lower-case letters.
    • Include numbers.
    • Include symbols.
    • Never include your name, birthday or other personal information.
    • Use different passwords for different applications.
    • Always create passwords with at least 12 characters.

    Taking such measures should reduce the chance of a hacker gaining access to your account. If you are a business owner, you should ensure all employees have appropriate passwords to ensure your business is not vulnerable to an attack.

    2.      Ensure all software is up to date

    We are all guilty of pressing ‘later’ when the dreaded software update pops up. However, this habit must change! Software updates do not only include new features, they are also designed to strengthen the stability of any software and tackle the latest viruses.

    Not staying up to date with software updates compromises your cybersecurity massively in comparison to those who do.

    This also is a part of the Cyber Essentials scheme so if your business is working towards this certification software updates must be completed.

    3.      Be sure to have antivirus software installed

    Can you afford for your device to be slow, damaged or have important files deleted? We’re sure the answer is no. Therefore, it’s vital you have antivirus software installed. Antivirus software detects and removes files before they can do any serious damage to your device & files.

    Unsure what antivirus to go for or how to install it? Our helpdesk team can help, contact us today!

    4.      Use public Wi-Fi cautiously

    When using public Wi-Fi you should be cautious of what files you open as hackers can create unsafe networks or steal your information through an unsecure connection.

    Therefore, we recommend you consider what you use public Wi-Fi for. For example, avoid accessing your online banking unless you are 100% sure your connection is safe.

    Did you know, here at The Unite Group we offer Horizon Wi-Fi our safe public Wi-Fi solution? Are you sure your connection is safe & that you are protecting the data of your customers? If you are unsure get in touch today and we can best advise.

    5.      Regularly backup your data

    Regular backups of your data are one way to protect yourself in the unfortunate situation of falling victim to an attack. For best practice, we recommend using the 3-2-1 approach.

    • Have three copies of your data,
    • On 2 different storage mediums,
    • With one off-site copy!

    Here at The Unite Group, we offer a managed backup solution. Click here to learn more about this service!

    6.      For businesses, achieve a Cyber Essentials Certification

    One simple way for businesses to protect themselves against 80% of the most basic cyber threats is by achieving a Cyber Essentials certification. This scheme covers 5 key areas of cybersecurity:

    • Access control – having managing access to administrator accounts means you can protect who has access to your data and services.
    • Software Updates – staying current with the latest software updates and security patches protects you against the newest cyber-attacks and vulnerabilities.
    • Firewalls & Routers – creating a buffer-zone’ between your IT network and other external networks. This will ensure incoming traffic is analysed to find out if you would like to allow it access to your network.
    • Secure Configuration – choosing the most secure setting for your device and software. As well as changing passwords and removing unused accounts and software will reduce the risk of a potential cyber-attack.
    • Malware Protection – using properly configured anti-malware software will protect against viruses and other malware risks. This also includes to only allow trusted applications to run.

    To learn more about how Cyber Essentials can protect your business, click here!

    Throughout the month we will be sharing more top tips on our socials so be sure to keep an eye on our Facebook, Instagram & LinkedIn!

  • An interview with a Cyber Essentials assessor

    An interview with a Cyber Essentials assessor

    an interview with a cyber essentials assessor

    We recently interviewed Rob, one of our Cyber Essentials assessor’s here at The Unite Group. Rob has received his qualification to be a Cyber Essentials Assessor. This means he can assess companies for the Cyber Essentials accreditation.

    Cyber Essentials is a program from GCHQ’s National Cyber Security Centre. Achieving this accreditation gives companies security from known security vulnerabilities.

    Rob talked us through some common FAQ’s surrounding Cyber Essentials and the scheme it follows.

    What is the role of a Cyber Essentials Assessor within The Unite Group?

    As a Cyber Essentials Assessor I am accredited to assess a company to see if they will meet the requirements of the Cyber essentials certification.

    When a company wants Cyber Essentials accreditation, The Unite Group will do a quick survey to see how ready the company is for accreditation. Following this, I will advise if there are any changes likely required to meet the accreditation. After the company has applied for the accreditation, and any changes have been made in order to comply, I go through the details of a company and assess this against the Cyber Essentials specification, and will ultimately give the company there grade.

    Why is it important to get a Cyber Essentials Certification?

    Cyber Essentials is a accreditation developed in partnership with the National Cyber Security Centre, part of GCHQ. Cyber Essentials gives a company a well rounded foundation in security that will mitigate the majority of attacks that companies face. With a Cyber Essentials Certification a company can demonstrate to it’s clients or other business that they are prepared to protect themselves from a cyber attack. This can also be used to demonstrate that the company is insurable against a cyber attack coming. For some companies it would be possible to get insurance as part of the Cyber Essentials certification.

    How can Cyber Essentials help protect businesses?

    Cyber Essentials demonstrates that your business has various security practices in place. Cyber Essentials has various requirements for how to secure your business routers, firewalls, services, end user devices, and to secure users access.

    Your companies router and firewall is what keeps your companies network protected from the general internet. This is just as important as the walls and doors that prevent an attacker just walking in. You may have much of your companies information running on important services. Think of how hard it would be if you didn’t have access to emails for a day!

    What is involved in the Cyber Essentials process?

    To apply for Cyber Essentials there is a form that demonstrates that your business has all the protections in place. You have to provide evidence of the policies and processes. As well as technical measures that your business has in place to protect the business. These will demonstrate that the measures in place are sufficient to meet the requirements of Cyber Essentials.

    How can The Unite Group support businesses through the process?

    The Unite Group can help by updating your business to have all of technical measures in place to meet the requirements of Cyber Essentials. We can provide the evidence that is required. Likewise we can provide the details of any technical measures that are in place to protect your business.

    The Unite Group can go through all the questions required with you and make sure that you know what is required. We also go through what is currently in place, so you know if there are any changes that your business needs to make in order to achieve the Cyber Essentials accreditation.

    Once your business is ready to apply for Cyber Essentials The Unite Group can prepare the final document, and submit this for examination.

    Interested in learning more or perhaps you have some questions you’d like answered about Cyber Essentials? Arrange a call with Dean today!

  • Why do I need Cyber Essentials?

    Why do I need Cyber Essentials?

    why do I need cyber essentials certification
    Let’s cover why you need a cyber essentials certification?

    So, why is achieving a Cyber Essentials certification so important?

    In our recent blogs, we have covered the basics of a Cyber Essentials certification as well as what exactly the process of gaining the certification involves. We now move on to covering why you need a Cyber Essentials certification. As well as the opportunities that come with having the certification.

    Below, we cover 4 benefits of achieving a Cyber Essentials certification.

    1.      Reduce the risk of falling victim to a cyber attack

    With cyber-attacks and threats on the rise, it has never been more important to ensure your business protects itself from falling victim. Around 71.1 million people fall victim to cybercrimes every year! Having a Cyber Essentials certification gives you peace of mind that your business is protected against around 80% of the most basic cybercrimes.  

    2.      Demonstrate to your customers that you take cyber security seriously

    Holding a Cyber Essentials certification demonstrates to your customer base that you take both your own as well as their cyber security seriously. This is likely to attract customers to use you over a competitor as they will feel safer that their personal data is protected. No customer ever wants to feel they are at risk of a data breach. Therefore, having a cyber essentials certification will help you retain and attract customers.

    3.      Open your organisation to the opportunities of working with the Government and the Ministry of Defence

    Did you know, that all Government and Ministry of Defence organisations require their contractors to hold a Cyber Essentials certification to even be considered as a company they can work with? Therefore, for any business that would like to put forward to win contracts within this sector, a cyber essentials certification is vital! Even if this is not an area your business is currently looking to work with, many large organisations are starting to take the same stance. So, not having a certification could hinder your chance of winning contracts.

    4.      Feel confident you have the basic levels of protection in place

    The Cyber Essentials certification is only valid for one year and must be renewed annually. This however ensures that you are protected against the latest cybercrimes and that your measures put in place remain relevant. This therefore means you can be confident you are ensuring your cyber security is up-to-date. Achieving certification also involves ensuring all software is installed with the latest updates which further protects you from the latest, most advanced cyber threats.

    Who needs Cyber Essentials?

    In short, every business! After considering the above points, it is hard to find a business that would not want to first protect itself from cybercrime but also its customer base! Aside from that, the opportunity to work with larger organisations as well as bid for Government and Ministry of Defence contracts makes achieving the certification very worthwhile for a lot of businesses looking to expand and attract larger clientele. 

    Is it worth it?

    Yes! Achieving a Cyber Essentials certification is absolutely worth it. It ensures you are protected from the vast majority of basic attacks whilst also giving your customers enhance trust in your businesses as well as opening the doors to new opportunities.

    Do you want to learn more about achieving a Cyber Essentials certification? Contact us today and our friendly, knowledgeable team will be happy to explain in more detail the Cyber Essentials process or help you take the first steps to achieve your Cyber Essentials Certification!