Cybersecurity Month
October is Cybersecurity Awareness Month, which is the perfect chance for me to remind you of the simplest and most effective ways to protect yourself from cyberattacks. What is Cybersecurity Awareness Month?
October is Cybersecurity Awareness Month, which is the perfect chance for me to remind you of the simplest and most effective ways to protect yourself from cyberattacks.
What is Cybersecurity Awareness Month?
Cybersecurity Awareness Month (CAM) is an annual event held in October. It aims to highlight the need for cybersecurity and help people implement it.
This year's theme
This year, CAM focuses on the four simplest and most effective ways to protect yourself from cyberattacks:
· Multi-factor authentication
· Using strong, unique passwords and an app to store them
· Updating
· Recognizing and reporting phishing
Multi-factor authentication (MFA)
Using MFA adds another layer of protection. It's effective even if the attacker knows your password. According to a Microsoft study, MFA stops up to 99.9% of all attacks. With that effectiveness and the relative simplicity of setup, there's no reason not to use MFA wherever possible.
Unique strong passwords and a password manager
Passwords are still one of the most important defensive layers against cyberattacks. They're the first line of defence, so you need them to be unique and strong. Avoid things like names and dates — those are very easy to guess. I recommend setting a sentence or phrase as your password with random capitalization, e.g. ThisExamplePasswordPleaseDoNotUse5. Or, if you decide to use a password manager, just generate the longest passwords you can.
Updating
Outdated software brings weaknesses in places you can't defend. So it's very important to regularly update ALL software. I know updates bring problems, but those are nothing compared to a cyberattack. A good move, where possible, is to enable auto-updates.
Recognizing and reporting phishing
Phishing is the most widespread form of cyberattack, so it's important to recognize and report it. The simplest check is to double-check the sender's email address. If the email contains an account number, double-check that too. Don't click on suspicious links and don't visit suspicious sites. Finally, report any phishing encounter to your company's IT specialist.