Here are 7 key things you can do right now:
- Immediately Implement a Strong Password Policies: It is still incredible how many people use their birth date and surname as a password. If you think that is stupid in 2023, the most common password worldwide was ‘123456’, used more than 4.5 million times. Second came ‘admin’, reaching more than four million uses. It is vital that you enforce complex passwords and regular updates to minimize unauthorised access.
- Conduct Employee Training: Regularly educate staff on recognizing phishing attempts and safe internet practices to reduce human error risks; Email phishing is the most popular type of phishing. Attackers send emails that appear to come from reputable sources, such as banks, social media platforms, or online services. These emails often contain a sense of urgency, prompting the recipient to click on a malicious link or download an attachment.
- Establish Incident Response Plans: Develop a clear plan for responding to breaches, including communication protocols and recovery steps.
- Use Firewalls and Anti-Malware Software: Protect your network with firewalls and keep anti-virus software updated to defend against external threats.
- Regularly Back Up Data: Perform offline backups frequently to ensure data recovery in case of an attack. Keep these back-ups separate from your organisations network and ideally back-up in 2 separate places.
- Ensure that staff are always diligent by sending emails from your company that appear to be phishing attempts – thus monitoring their awareness. Invest in a good cybersecurity awareness and simulation testing program with regular updates to ensure your employees are always fully aware of the threats faced.
- Get an external consultant to check your systems – this service is generally free as part of a campaign to market their services. Many SMEs do have the in-house resources and expertise to access their security so it’s a very good investment to use external cybersecurity consultants. Consider getting certified with a cybersecurity accreditation program such as ISO 27001 or Cyber Essentials.
Contact Archway Securities for a short consultation which will help you decide how vulnerable you are and what we can do for you. We offer free penetration testing to check your systems.