We’re back with our monthly newsletter! As The Unite Group we love keeping our customers up to date with the latest deals, tips, industry news as well as what our fantastic team are getting up to! Read our October issue to see what we have got up to in the past month!
In this newsletter: We attended the Expo for Good in support of Grace House, we attended Fall into Networking event hosted by Network+, we welcome Jack to our team, we spotlight our clients Trust Red, share info about the Cyber Essentials scheme & explain the benefits of SharePoint in comparison to a traditional server.
To read The Unite Group’s October Monthly Newsletter, click on the image below!
Are you interested in achieving a Cyber Essentials certification but unsure as to what level of certification is best for you? In this blog, we break down the main differences between Cyber Essentials & Cyber Essentials Plus. As well as offer recommendations for which level of certification businesses should consider.
This is the basic level of certification. Achieving Cyber Essentials involves the completion of a self-assessment questionnaire. This questionnaire involves 8 sections and has a total of 70 questions. Here at The Unite Group, we can provide support before taking the assessment to ensure all expected standards are met. As well as providing assistance throughout the application. Upon completion, the business owner or board-level representative must then sign a declaration that all answers are completed correctly. This is then reviewed by a Cyber Essentials assessor and successful applicants will receive their certification.
Who do we recommend Cyber Essentials to?
We recommend the Cyber Essentials certification to all businesses who want to demonstrate that they take cybersecurity seriously. Having this certification can also open new doors for business opportunities as it is a requirement to bid for Government contracts. We recommend this to smaller corporations that want to ensure they are complying with recommended safety measures.
Now let’s compare this with Cyber Essentials Plus
The Cyber Essentials Plus certification involves the same first steps as the Cyber Essentials scheme. Therefore, meaning they both include the completion of the self-assessment questionnaire. However, Cyber Essentials Plus then goes on to further include a vulnerabilities assessment and an on-site assessment. The assessment covers the controls your organisation has in place. As well as, your employee’s work-from-home locations. Also assessing any third parties who may have access to your premises or IT infrastructure. These assessments are undertaken by a trained and qualified Cyber Essentials Plus assessor.
Who do we recommend the Cyber Essentials Plus scheme to?
Here at The Unite Group, we recommend this scheme to those businesses that want to demonstrate higher levels of cybersecurity protection. Whilst Cyber Essentials is a great starting point, the added levels of assessment included in this scheme increase a business’s protection far more. Those who hold a Cyber Essentials Plus certification can bid for Ministry of Defence contracts.
Recap
To recap, the main difference between the two schemes is that the Cyber Essentials Plus certification covers more areas of assessment. It includes a more rigorous test of an organisation’s cybersecurity systems. Experts carry out vulnerability tests and as a result, ensure organisations are well protected against basic hacking and phishing attacks. Therefore, we strongly recommend this option to businesses who want to ensure they best protect their data and that of their customers.
Let us help!
Here at The Unite Group, we can guide you through Cyber Essentials and help you protect your business. We have in-house Cyber Essentials assessors to not only approve certifications but also provide support throughout the application process. We are a friendly voice on the other end of the phone to support you through the certification from start to end.
To find out more, book a quick call with our team today!
As expected, in the first 10 months of 2022, there have been multiple major cyberattacks that have resulted in a loss of productivity, revenue or large-scale data leaks. Whilst some of the largest attacks have been in countries such as America and Ukraine. There have also been some major cyberattacks within the UK. Although these cyberattacks are the ones that receive media coverage, there are many more attacks on smaller businesses that cause major devastation. So far in 2022, 39% of UK businesses have identified cyberattacks within their business. Fortunately, this number is significantly less than in 2020, as 46% of businesses identified cyberattacks. Without further ado, here are the 6 worst cyberattacks of 2022 so far.
KP Snacks – Ransomware Attack
KP Snacks, the maker of KP Nuts, Hula Hoops, Nik Naks, Tyrell’s, Pom-Bears and more, fell victim to a ransomware attack in January of this year. The gang behind this attack was Conti, an infamous cybercrime group from Russia. Shortly after the attack was detected, KP Snacks released a statement explaining that it could not ‘safely process order or dispatch goods’ due to the incident. Following this, there were supply chain issues until the end of March.
As is now expected, the Conti gang operate double extortion, whereby they would release stolen data if KP Snacks did not pay the ransom. Initially, a small number of staff documents were posted online. These had a 5-day countdown. That when the clock hits zero, all data will be released, unless the ransom is paid. However, the post on the Conti website was removed soon after. This potentially indicates that the ransom was paid, or the two parties were in negotiation. With this being said, neither party disclosed whether or not the ransom was paid.
UKVCAS – Data Breach
In April, the UK Home Office’s visa service had to apologise for a data breach in which the email addresses of over 170 customers were mistakenly copied into an email. The email was informing a customer of a change in the time of their appointment. The emails included in this breach were a combination of personal emails and lawyers working on behalf of customers. This data breach was particularly noteworthy as UKVCAS is run on behalf of the Home Office by a private contractor. Therefore it was not directly the Home Office’s fault. The breach was likely a case of an accidental malicious insider. Businesses can decrease the likelihood of these forms of breaches through regular cybersecurity awareness training.
The Works – Presumed Ransomware Attack
UK Retail chain, The Works, was forced to shut down a number of its stores in April due to a widespread cyberattack. Although the retailer did not go into much detail about the nature of the attack, it is believed to have interrupted deliveries, extended online order fulfilment times and compromised the safety of payments on their POS systems. After the attack was remediated, it was found that no customer data was exfiltrated. However, it is believed that the attack was a ransomware attack. Although it is unknown how much the ransom amount was, or how The Works restored their systems.
The real-world impact of this attack was the fact that the share price for The Works fell by 10% the day they announced the cyberattack. There was also a loss of revenue from the stores that were unable to open due to the attack.
Crypto.com – Account Compromise
In January, one of the largest cryptocurrency exchanges, Crypto.com, released a statement explaining they were the victim of an account compromise attack that resulted in 4,836.26 Ethereum and 443.93 Bitcoin being stolen, totalling approximately $35 million. The attack affected 483 users, and the threat actors performed unauthorised withdrawals from the victims’ wallets to their own. Interestingly, the attackers were able to perform the withdrawals without the MFA authentication control being inputted by the user. After the attack, Crypto.com suspended all withdrawals and migrated to a new MFA infrastructure.
Crypto.com was able to prevent some of the unauthorised withdrawals before it was too late, and the company reimbursed customers so there was no loss of customer funds. Crypto.com has now implemented a new program, the Worldwide Account Protection Program, which will prevent this from happening again. The program includes controls such as the use of MFA and anti-phishing codes.
Ukrainian Government – Website Hacks & DDoS Attacks
Throughout the first quarter of 2022, Russian hackers targeted many Ukrainian websites, including multiple government and financial services websites. In January, around 70 websites were hacked, including the Ministry of Foreign Affairs, Cabinet of Ministers and Security and Defense Council. The majority of these hacks only involved changing the text on the website to display pro-Russia sentiments.
Shortly after, Russian threat actors targeted multiple government, non-profit and information technology organisations throughout Ukraine with a piece of malware disguised as ransomware. The malware had all the features of ransomware, but lacked a recovery feature, meaning that it simply destroyed all files on the victim’s computer.
Early in February, there were several large distributed denial of service (DDoS) attacks. These brought down the websites of the Defense Ministry, Army and Ukraine’s two largest banks. Later in the month, there were more DDoS attacks, but the organisations were able to recover quickly from these.
From March until the present day, there are still many cyberattacks being launched against Ukrainian citizens and businesses. Most of these attacks are phishing attacks, with the goal of launching widespread malware attacks.
Ronin – Account Compromise
In March, one of the largest cyberattacks in recent history occurred. A threat actor stole approximately $600 million worth of digital assets. These were stolen from a blockchain network, Ronin, that is connected to a popular online game, Axie Infinity, created by Sky Mavis. This attack was possible as there were some outdated Sky Mavis accounts with dangerous permission levels. The attacks were able to compromise these accounts and subsequent nodes. Therefore allowing them to authorise fake transactions on the network or bridge that handles converting tokens, Ronin. The hackers were able to steal 173,600 Ether and 2.5 million USD Coin, totalling over $600 million. In 2021, there were many similar attacks on bridges and Decentralised Finance platforms, totalling $2.3 billion.
Whilst this form of attack is not viable for most businesses, it acts as a cautionary reminder for businesses looking to adopt new Web 3.0 technologies.
Added Bonus – Two Largest Bug Bounties
Although the media is awash with stories of malicious actors exploiting vulnerabilities and targeting organisations, there is a community of ethical hackers actively trying to find exploits to responsibly disclose them to the affected organisation. Many organisations offer a monetary reward for finding these vulnerabilities, called a bug bounty program. So far in 2022, we have seen two of the largest bug bounties paid out. One totalling $6 million, and another totalling $10 million.
The $6 million bug bounty was awarded to the ethical security hacker by the name of pwning.eth who found a critical vulnerability in the Aurora Engine, a bridging and scaling solution for the cryptocurrency Ethereum. If pwning.eth was to have exploited the vulnerability it could have cost the company $200 million.
The $10 million bug bounty was awarded to the bug hunter Satya0x after discovering a vulnerability in Wormhole cryptocurrency bridge. Wormhole is the message-passing protocol that connects blockchains such as Ethereum, Terra and Binance Smart Chain. If the vulnerability was exploited, it could have resulted in $736 million worth of digital assets being lost forever.
How to Keep Your Business Safe
The past few years have taught us that all businesses, regardless of size, industry or location, are at risk of falling victim to cyberattacks. Although there is no way to ensure that your business is immune to cyberattacks, there are controls and solutions that can be implemented to significantly decrease your cyber risk, as well as making detection and remediation as effective as possible.
Did you know October is cybersecurity awareness month? As we shift towards a more digital way of life in 2022, cybersecurity has never been more important! This month is focused on helping businesses, their employees & customer understand the risks that we should be aware of online. As well as the measure we should be taking to reduce the risk of falling victim to such an attack.
In this blog we share our top tips to take the first steps in protecting yourself from cybercrimes.
1. Use strong passwords
One of the easiest ways internet users can fall victim to cybercrimes is through easily guessed passwords. Therefore, we recommend you create strong passwords by using the following:
A combination of upper- and lower-case letters.
Include numbers.
Include symbols.
Never include your name, birthday or other personal information.
Use different passwords for different applications.
Always create passwords with at least 12 characters.
Taking such measures should reduce the chance of a hacker gaining access to your account. If you are a business owner, you should ensure all employees have appropriate passwords to ensure your business is not vulnerable to an attack.
2. Ensure all software is up to date
We are all guilty of pressing ‘later’ when the dreaded software update pops up. However, this habit must change! Software updates do not only include new features, they are also designed to strengthen the stability of any software and tackle the latest viruses.
Not staying up to date with software updates compromises your cybersecurity massively in comparison to those who do.
This also is a part of the Cyber Essentials scheme so if your business is working towards this certification software updates must be completed.
3. Be sure to have antivirus software installed
Can you afford for your device to be slow, damaged or have important files deleted? We’re sure the answer is no. Therefore, it’s vital you have antivirus software installed. Antivirus software detects and removes files before they can do any serious damage to your device & files.
Unsure what antivirus to go for or how to install it? Our helpdesk team can help, contact us today!
4. Use public Wi-Fi cautiously
When using public Wi-Fi you should be cautious of what files you open as hackers can create unsafe networks or steal your information through an unsecure connection.
Therefore, we recommend you consider what you use public Wi-Fi for. For example, avoid accessing your online banking unless you are 100% sure your connection is safe.
Did you know, here at The Unite Group we offer Horizon Wi-Fi our safe public Wi-Fi solution? Are you sure your connection is safe & that you are protecting the data of your customers? If you are unsure get in touch today and we can best advise.
5. Regularly backup your data
Regular backups of your data are one way to protect yourself in the unfortunate situation of falling victim to an attack. For best practice, we recommend using the 3-2-1 approach.
Have three copies of your data,
On 2 different storage mediums,
With one off-site copy!
Here at The Unite Group, we offer a managed backup solution. Click here to learn more about this service!
6. For businesses, achieve a Cyber Essentials Certification
One simple way for businesses to protect themselves against 80% of the most basic cyber threats is by achieving a Cyber Essentials certification. This scheme covers 5 key areas of cybersecurity:
Access control – having managing access to administrator accounts means you can protect who has access to your data and services.
Software Updates – staying current with the latest software updates and security patches protects you against the newest cyber-attacks and vulnerabilities.
Firewalls & Routers – creating a buffer-zone’ between your IT network and other external networks. This will ensure incoming traffic is analysed to find out if you would like to allow it access to your network.
Secure Configuration – choosing the most secure setting for your device and software. As well as changing passwords and removing unused accounts and software will reduce the risk of a potential cyber-attack.
Malware Protection – using properly configured anti-malware software will protect against viruses and other malware risks. This also includes to only allow trusted applications to run.
Let’s cover why you need a cyber essentials certification?
So, why is achieving a Cyber Essentials certification so important?
In our recent blogs, we have covered the basics of a Cyber Essentials certification as well as what exactly the process of gaining the certification involves. We now move on to covering why you need a Cyber Essentials certification. As well as the opportunities that come with having the certification.
Below, we cover 4 benefits of achieving a Cyber Essentials certification.
1. Reduce the risk of falling victim to a cyber attack
With cyber-attacks and threats on the rise, it has never been more important to ensure your business protects itself from falling victim. Around 71.1 million people fall victim to cybercrimes every year! Having a Cyber Essentials certification gives you peace of mind that your business is protected against around 80% of the most basic cybercrimes.
2. Demonstrate to your customers that you take cyber security seriously
Holding a Cyber Essentials certification demonstrates to your customer base that you take both your own as well as their cyber security seriously. This is likely to attract customers to use you over a competitor as they will feel safer that their personal data is protected. No customer ever wants to feel they are at risk of a data breach. Therefore, having a cyber essentials certification will help you retain and attract customers.
3. Open your organisation to the opportunities of working with the Government and the Ministry of Defence
Did you know, that all Government and Ministry of Defence organisations require their contractors to hold a Cyber Essentials certification to even be considered as a company they can work with? Therefore, for any business that would like to put forward to win contracts within this sector, a cyber essentials certification is vital! Even if this is not an area your business is currently looking to work with, many large organisations are starting to take the same stance. So, not having a certification could hinder your chance of winning contracts.
4. Feel confident you have the basic levels of protection in place
The Cyber Essentials certification is only valid for one year and must be renewed annually. This however ensures that you are protected against the latest cybercrimes and that your measures put in place remain relevant. This therefore means you can be confident you are ensuring your cyber security is up-to-date. Achieving certification also involves ensuring all software is installed with the latest updates which further protects you from the latest, most advanced cyber threats.
Who needs Cyber Essentials?
In short, every business! After considering the above points, it is hard to find a business that would not want to first protect itself from cybercrime but also its customer base! Aside from that, the opportunity to work with larger organisations as well as bid for Government and Ministry of Defence contracts makes achieving the certification very worthwhile for a lot of businesses looking to expand and attract larger clientele.
Is it worth it?
Yes! Achieving a Cyber Essentials certification is absolutely worth it. It ensures you are protected from the vast majority of basic attacks whilst also giving your customers enhance trust in your businesses as well as opening the doors to new opportunities.
Do you want to learn more about achieving a Cyber Essentials certification? Contact us today and our friendly, knowledgeable team will be happy to explain in more detail the Cyber Essentials process or help you take the first steps to achieve your Cyber Essentials Certification!
The Cyber Essentials scheme is an ISAMW self-assessment questionnaire process. The questionnaire will then be signed off by a member of the board or an equivalent signory. After this, it is then verified by a certification body trained and licensed to certify against the Cyber Essentials scheme (like ourselves here at The Unite Group). It is important before applying you ensure your organisation meets all the requirements. This includes having evidence ready to be provided to prove you meet the requirements.
What is in the scope for Cyber Essentials?
The scope will be agreed upon between your organisation and The Unite Group, (as your certification body), before the assessment begins. Certification can apply to your full organisation’s enterprise IT or just a subset.
How long is Cyber Essentials Valid for?
All certificates are valid for 12 months. They must be renewed annually, much like your cars MOT. This works well to ensure your organisation is protected against the latest cyber-attacks. As those carrying out attacks are constantly looking for new ways to catch out and successfully breach data. If you do not reapply for your Cyber Essentials Certification as the 12-month period expires, you will no longer be able to apply for contracts that require you to hold a valid Cyber Essentials certification – like Government contracts.
What is in the Cyber Essentials certification scheme?
Having managing access to administrator accounts means you can protect who has access to your data and services.
Software Updates
Staying current with the latest software updates and security patches protects you against the newest cyber-attacks and vulnerabilities.
Firewalls & Routers
Creating a buffer-zone’ between your IT network and other external networks. This will ensure incoming traffic is analysed to find out if you would like to allow it access to your network.
Secure Configuration
Choosing the most secure setting for your device and software. As well as changing passwords and removing unused accounts and software will reduce the risk of a potential cyber-attack.
Malware Protection
Using properly configured anti-malware software will protect against viruses and other malware risks. This also includes to only allow trusted applications to run.
How long does it take between submitting the online questionnaire to receive your certificate?
The length of time it takes from application to certification can vary. Some may be verified in one or two days. Whereas, others may take around two weeks to complete the assessment. This is dependent upon your current security setup and speed of action. Those who partake in the Cyber Essentials Plus scheme should expect a longer assessment period as it involves the internal security assessment as well as an external scan.
How can we support you through the Cyber Essentials process?
Here at The Unite Group, we can provide support to you throughout the process. We are an authorised certificate issuing body for Cyber Essentials. As a result, we can manage the entire process for you from the initial audit, remedial works, and certificate issue.
Do you want peace of mind that your defences will protect you from a large amount of the most common cyber-attacks? Contact us today and our friendly, knowledgeable team will be happy to explain in more detail the Cyber Essentials certification process or help you take the first steps to achieve your Cyber Essentials Certification!
You keep hearing the term cyber essentials, but what exactly does it mean? Why should your business consider being a part of the scheme? With cyber-attacks becoming ever more common, there is no better time to understand the steps you can take to protect your business from the most basic attacks. Many cyber-attacks are carried out by low skilled individuals. So taking some basic steps can massively reduce the chance of you falling victim to one! Here at The Unite Group as your trusted technology provider we want to best advise our customers on how to protect themselves as well as their customer data. In this blog, we will explain to you the basics of Cyber Essentials. As well as how we can help & guide you through achieving the certification.
What is Cyber Essentials?
Cyber Essentials is a Government-backed and industry-supported scheme that allows businesses to protect themselves from cyber-attacks. The scheme lays out a clear statement of the basic cybersecurity measures an organisation should have in place to protect themselves from the growing threat of attacks.
Cyber essentials is a foundation level certification. This was created to provide the basic controls an organisations should have in place to reduce the risk of common cyber threats. This first step protects you from 80% of the most basic cyber security breaches.
Upon completion, organisations can then move onto Cyber Essentials Plus. This is the highest level of certification offered in the scheme, so this includes a more rigorous test of an organisations Cyber Security systems. Experts carry out vulnerability tests and ensure organisations are well protected against basic hacking and phishing attacks.
What does the certification process include?
Obtaining The Cyber Essentials certification is a relatively simple process
Choose The Unite Group as your Provider
Complete your self-assessment questionnaire and then await its review.
Once your submission is approved, you will then receive your certificate.
If for any reason you have any issues, Unite will be here to support you through the process.
Who runs Cyber Essentials?
It was developed and is operated by NCSC (the National Cyber Security Centre). It is the UK Government’s answer to a safer internet space for all organisations of all sizes.
Is Cyber Essentials UK only?
Although it was developed by the UK’s National Cyber Security Centre, it is globally recognised as a certification that enhances an organisations protection against data breaches and leaks. Therfore, organisations with global customers can complete this certification and be confident it will be recognised internationally.
Why should you get Cyber Essentials?
Having certification allows businesses to show you can trust them and take their security seriously when it comes to cyber security. This can open new opportunities as a lot of larger organisations will only work with companies who can demonstrate their cyber security protection measures. Many Government contracts require certification to be considered.
However, the benefits are not only external. Internally the scheme provides a clear picture of your organisations cyber security level. You can feel confident you have taken the necessary steps to protect your businesses. Therefore eliminating some of the risk of your organisation experiencing an attack.
Can you afford not to have certification? Are you ready to protect not only your organisation but the data of your customers by doing the Cyber Essentials certification?
How can we support you through the process?
Here at The Unite Group, we can provide support to you throughout the process. Unite are an authorised certificate issuing body for Cyber Essentials. As a result we can manage the entire process for you from initial audit, remedial works and certificate issue.
Do you want peace of mind that your defences will protect you from a large amount of the most common cyber-attacks? Contact us today and our friendly, knowledgeable team will be happy to explain in more detail the Cyber Essentials certification process or help you take the first steps to achieving your Cyber Essentials Certification!
Continuing on with introducing you to the team that make up The Unite Group. Next up we introduce Rob. We recently had a chat with Rob about his role…
Growing up, what did you want to be?
I always knew I would work in something Technology related, my family on my fathers side have been engineers or similar going back at least five generations. For about a decade I thought I would likely work in the AV field, and did a fair amount of work doing lighting or sound, starting at a youth theatre, and continuing into working in bars and clubs.
What is your role at The Unite Group and how did you end up where you are now?
At The Unite Group I am a Senior Service Engineer. In my role, I mostly work on projects. I started with Unite as an Apprentice, shadowing another engineer for a bit, and then working on the Helpdesk. Since then as the company has grown I have completed various qualifications to get to my role within the company.
What does a typical day look like at The Unite Group?
Most days start with checking the health of a few services that I manage. I’ll run though any alerts that have been generated overnight, I’ll then create support tickets for anything that requires further looking into. I also run a few health tests on demo networks that we have at the office.
From there I then move onto emails. After which it really changes on a day to day basis. I mostly work on projects and installs now. So off to client sites for installs, or planning work.
What is your most and least favourite part of the job?
My favourite part of the job has got to be the process of taking apart and re-building a system to trace down a particular fault. I’ll normally do this when there is an actual ongoing issue that needs resolved, but this can also be done when we’re onboarding a new client with limited documentation, to make sure that we can fully understand any issues that might come up.
My least favourite part of my job would be all the paperwork around the jobs. When I worked at the NHS many years ago, one of the medical leads often said “midwife means with wife, not with computer” and I can now relate.
What is your greatest achievement?
I’m very happy how I left a small theatre I volunteered at. When I started, the entire society had a budget of around £300, and about 5 working lights. It was always a fun challenge to get a production on with what we had available.
Over the next 4 years myself, and a new committee managed to improve the situation somewhat. I took over as head of the technical side of the theatre, and managed to build up that side of things, training up new technicians, and managing shows on a weekly basis.
By the time I left the society had working lights, sound system, and a budget plan for fixes and replacement going out for a decade.
What is the best piece of advice you’ve been given?
If you can’t explain it you don’t understand it. I always try to understand something well enough to be able to explain it simply to someone else. Often this is reduced to explain to a five year old, which while entertaining may take quite a long time.
Where do you see yourself in 10 years’ time?
In 10 years time, I can see my role getting a bit more specialised within The Unite Group. I’ve already started working on some more niche things and I hope to grow into more of these. One of the areas I am currently expanding my knowledge into is Cyber Essentials. I am looking forward to seeing where this takes my role within The Unite Group. As well as what opportunities it will offer to our customers to protect their organisations further against possible cyber attacks.
How do you unwind outside of work?
When left to my own devices there is nothing nicer than a glass of whisky and a good book.
What are the top cybersecurity myths you should be aware of in 2022? In this article, we’ll debunk some of the biggest misconceptions about digital security.
Thankfully, businesses are now more aware than ever of cyber threats and are starting to take cybersecurity very seriously. PwC found that nearly 64% of UK CEOs are concerned about how cyber threats could harm their ability to sell products and services.
Indeed, taking into proper account your organisation’s cybersecurity is a vital part of running a modern business. This keen focus on abating cyber threats, however, had led to many cybersecurity myths becoming commonplace.
Believing these ill-informed cybersecurity myths could leave your business vulnerable to threats and may render your security infrastructure ineffectively.
Myth 1: Hackers don’t target small businesses
We understand why some small business owners feel like cybersecurity isn’t important to them. Cybersecurity can be a big investment for smaller firms and start-ups and many decision-makers would prefer to spend that money on other sections of the business.
However, there’s no truth in the misconception that hackers don’t target small businesses. In fact, a report from Barracuda found that cybercriminals are up to three times more likely to target small businesses than larger firms.
Why? Hackers smaller businesses as ‘low-hanging fruit’ and target their inadequate security infrastructure and take advantage of insufficient security training for staff for social engineering attacks.
Furthermore, the lasting damage of cyber attacks to smaller businesses is greater than for enterprises. 60% of small businesses fail within six months of a cyber attack or data breach.
Myth 2: Antivirus and firewalls will protect my business
Firewalls and antivirus software are a brilliant first line of defence for your digital infrastructure – but attacks can and will get through them. A holistic cybersecurity strategy will need to use other methods of protection such as backups, cybersecurity awareness training and two-factor authentication.
First of all, antivirus software and firewalls are only effective if they’re regularly updated and configured correctly. Not quite sure how to make sure they’re running effectively? We recommend working with a Managed Service Provider (MSP) like ours to configure your security infrastructure for you.
Secondly, antiviruses and firewalls can only protect your business from malicious software and intrusions. They’re less effective at preventing social engineering attacks such as phishing scams, mishandled login credentials or internal threats. We’ll cover what’s needed to prevent these attacks later on!
Myth 3: Phishing attacks are easy to spot
A common misconception is that only the tech-illiterate fall for phishing attacks and that cyber awareness training is a waste of time for those who are “good with computers.”
In reality, this just isn’t the case. Phishing attacks – especially those specifically targeting your business for espionage – are becoming increasingly more convincing.
One of the most common forms of phishing is a spear phishing attack – where attackers use gathered intel about your business to make the email (or phone call) look legitimate. Over 65% of targeted attacks are done this way.
They commonly ask for payment or urgent action for a convincing reason. Attacks may also spoof a legitimate email – for example, a manager, the CFO or CEO.
Businesses need to train their staff on spotting phishing attacks and what sorts of emails to be suspicious about. However, even then, some phishing attacks may be too convincing to spot. For that reason, you’ll also need an email filter actively looking for possible phishing scams.
Myth 4: A long complex password will keep my account safe
A strong password policy is a cornerstone of a cybersecurity strategy. However, there are some other considerations to make other than having a long, complex password:
Enforce a policy to regularly change passwords. Some hackers may gain login credentials through phishing or a data breach. Changing passwords regularly removes this opportunity.
Encourage employees to remember passwords and not write them down. What’s the point of a complex password if it’s available for everyone to see on a post-it note or a text file?
Your employees should never share their passwords – even with trusted colleagues, friends and family.
Implement multifactor authentication to ensure that hackers can’t gain access to your employees’ accounts even if they have their passwords.
Myth 5: The only real concern is external threats
Insider threats pose just as much of a concern as external threats – if not, more as they’re difficult to protect against. According to Gurugul, 98% of companies are concerned about insider threats whilst only 11% believe they’re well protected from them.
Internal threats fall into three broad categories:
Negligent Insider
Stolen Credentials
Malicious Insider
Negligent insider threats are when an employee or executive negligently exposes your business to a cyber vulnerability – but unintentionally (or at least without malice). This is is the most common insider threat.
These types of threats can be prevented through cyber awareness training or a Data Loss Prevention program.
Stolen credentials involve the loss of credentials – mainly through social engineering attacks such as phishing. Protecting from these attacks involves awareness training, two-factor authentication and suspicious activity detection.
The least common type of insider threat is the malicious insider attack – where an employee or business partner causes damages or steals data intentionally. This is by the hardest to protect from as companies generally assume all their employees aren’t out to sabotage them.
The best way to protect from this is by enforcing strict access permissions (and ensuring employees can only access the data they need) and using data loss prevention (DLP) and monitoring tools.
These steps prevented a huge data incident in October 2021 when a Pfizer employee uploaded 12,000 confidential files to a Google Drive account – according to Reuters. This suspicious activity was detected and prevented by DLP software. Turns out, the employee had accepted a job offer from competitor Xencor, and this was attempted espionage.
How we can help secure your business
Cybersecurity infrastructure is a long, complex process. However, the return on investment (ROI) of cybersecurity projects is immense due to security expenses avoided is immense.
For instance, according to IBM’s Cost of a Data Breach Report 2021, the average cost of a data breach is $4.24M! That’s why we highly recommend upgrading your security infrastructure and protecting your business from increasingly dangerous cyberattacks.
Want to learn how we can help you secure your business? Looking to deliver effective cyber awareness training? Want to explore what software solutions are best for protecting your business?
So why should you have cyber essentials certification?
In recent years, it has become increasingly important for businesses to secure their IT systems to reduce the chance of falling victim to a cyberattack. In the UK alone,39% of businesses were targeted by a cyberattack in the last 12 months. Whilst most cyberattacks target large businesses and enterprises, it is also just as common to happen to small businesses. This is because they are less likely to have invested in securing their IT systems. For this reason, all SMB owners should invest in strengthening their security posture and aim to achieve a Cyber Essentials certification.
What is a Cyber Essentials certification?
It is a UK Government backed scheme that is designed to protect companies against a wide range of cyberattacks. There are two levels of certifications: Cyber Essentials and Cyber Essentials Plus. Cyber Essentials is a self-assessment, that ensures businesses have controls in place to protect against most common cyberattacks. Cyber Essentials Plus is a more in-depth certification and includes hands-on technical verification.
The certification covers many areas, including firewalls, secure configuration, user access control, malware protection, security update management and more. The Cyber Essentials certification lasts for 12 months. It is then regularly updated to make sure businesses are protected against basic attacks.
The importance of cybersecurity for SMBs in 2022
All small businesses are at risk of falling victim to a cyberattack. The most common cyberattacks being phishing, data breaches and ransomware attacks. All of these attacks can be awful for businesses, both in terms of the costs, as well as the costs associated with damages to a business’s reputation.
Thankfully, many of these attacks are carried out by relatively unskilled cybercriminals. So fortunately they can be stopped by implementing some basic security controls. In a recent blog we explained the benefits and added protection of companies outsourcing their cybersecurity to professionals. With a Cyber Essentials certification, these attacks are no longer viable.
Benefits of a Cyber Essentials certification for SMBs
Reduce the chance of falling victim to a cyberattack
The overall goal of Cyber Essentials is to reduce a business’s cyber risk. As the assessment covers most attack surfaces and the associated technical security controls, Cyber Essentials covers all the bases to protect from 80% of common cyberattacks. Although the methods that cybercriminals use are constantly changing, these technical controls will typically stop basic attack methods, especially if they are not highly targeted attacks.
Gain a competitive advantage
For small businesses within competitive industries, a Cyber Essentials certification can be a way to stand apart from the competition. The certification shows that your business takes security seriously. Therefore any customer, either consumer or corporate, doing business with you is less likely to have their data leaked as part of a customer data breach. After a business obtains their certification, they can also display the certification badge on their website and other marketing materials.
Find new business opportunities
A Cyber Essentials certification is mandatory for businesses considering submitting a bid for a contract with the NHS, Ministry of Defence, and UK Government. Many private sector businesses also look for the Cyber Essentials badge of approval when seeking new suppliers.
Improve credibility and reputation
The technical controls necessary to obtain the certification are relatively simple to implement, and the self-assessment is a quick and easy process. This simple and affordable option can add significant value to a business as it improves credibility and reputation. Having a Cyber Essentials certificate shows customers that a company is committed to protecting its data. It also shows they are taking action to reduce the chance of them falling victim to a cyberattack.
Free Cyber Liability Insurance
Once your business has gained its Cyber Essentials certification, your business is automatically entitled to free Cyber Liability Insurance to the total limit of £25,000 of indemnity. This also gives businesses access to a 24-hour hotline to report a cyber incident. This includes crisis management and incident response. For businesses that do not already have cyber insurance, this is a perfect option to recover from a small breach or incident. Many cyber insurance providers will also give discounts to businesses that are certified.
How we can help?
For businesses that are’t well versed in the world of cybersecurity, it can be difficult to implement the technical controls necessary to obtain a Cyber Essentials certification. We can help your business implement the technical controls. As well as this we provide additional security services to further reduce the chance of falling victim to a cyberattack. To find out more, contact us today.
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.