How to prevent 95% of all attacks

In this newsletter I try to bring you useful, digestible information that should help prevent your company from being attacked.

In this newsletter I try to bring you useful, digestible information that should help prevent your company from being attacked. In almost every article I mention that employee training is extremely important — and statistically, that's backed up too: roughly 95% of all breaches are caused by human error. In today's article I'll walk through the most important things every employee should know and do.

Passwords and MFA

Honestly, having a unique password for everything is annoying — because it means using a password manager. Personally I recommend Bitwarden, but most of them work similarly. Another important thing: have a strong, unique password for the password manager itself. There I personally recommend a sentence with mixed-case letters, e.g. ThisIsATest1NeverUseTh1sP4ss.W0. It can be shorter, but I wouldn't go below 14 characters. MFA simply needs to be turned on wherever you can. Yes, it's annoying — but the 10 seconds you spend tapping through MFA pays off massively the day it saves your account.

Phishing

Phishing is tricky because until you've encountered it, you don't know how to spot it. For owners, there's a tool straight from Microsoft to test your staff HERE.

General caution

This is your part — you'll have to show and explain to staff what is and isn't dangerous. A few examples:

1.      Visiting unsecure sites on a work device — not safe

2.      Going to sites by typing the URL directly — very safe

3.      Letting people I don't know into the server room — very dangerous

4.      Letting someone I don't know upload/download something to/from my computer — not safe

5.      Telling someone your passwords — take a guess (not safe)