5 most important ways to secure your company
2023 is almost over, so it's a good time to revisit the basics every company should be using without exception. Today, attackers don't care how big a company is — they'll attack regardless.
2023 is almost over, so it's a good time to revisit the basics every company should be using without exception. Today, attackers don't care how big a company is — they'll attack regardless. They can afford to thanks largely to automated attacks.
Employee training
As the first and most important tip, I'd put employee training. The vast majority of successful attacks come down to human error — which is actually good news for you, because there's something fairly simple you can do about it. Explain to your staff what to do if they spot unusual activity, how to recognize a phishing email and what to do when they get one, how to secure their accounts properly, and a number of other things.
Password management and MFA
Another massively important thing is password management. To start: every account should have a different password, with at least 10 characters, at least one of them special. Which means you'll most likely need a password manager. Also, where possible, turn on multi-factor authentication (MFA). It may feel like a waste of time, but MFA stops roughly 99% of attacks — and that's worth a few extra clicks.
Phishing
Spotting and avoiding phishing comes from experience, so unfortunately I can only give you general dos and don'ts:
· If a phishing message includes a sign-in link and you genuinely need to sign into that service, double — better triple — check the URL. With Facebook phishing it's common to see Fcebook.com or Faceb0ok.com instead of Facebook.com. Small changes that can cost you the account. If it's a service you don't need to sign into, don't click the link at all.
· If you're paying any invoice, double-check the bank account number multiple times. Literally money is on the line, and a careful check can save you from disaster.
· If you spot phishing in your inbox, report it to your IT specialist and show your colleagues what phishing looks like.
Backups
If despite all your defences someone gets through, your backups are your only lifeline. The simplest backup tip is the 3-2-1 rule: 3 backups, in 2 physical locations, 1 of them off-site. This protects you not only from attackers but also from natural disasters and other ways data gets stolen or destroyed. The last thing you want to discover after an attack is that your backups are encrypted too — and you have nothing.
Updating
As the last point I picked updating. We struggle with updates ourselves — every time you update something, something breaks — but we still do it. Why? Simple: we'd rather wrestle with software issues than wrestle with a successful attack. Most updates also bring new security benefits. So if your device allows it, turn on auto-updates; if not, regularly update everything you can. Your data will thank you.