Which of these mistakes are you making
Attackers are capable of running incredibly sophisticated and effective attacks, but those usually cost them a lot of time and money. So they more often attack at scale and automatically.
Attackers are capable of running incredibly sophisticated and effective attacks, but those usually cost them a lot of time and money. So they more often attack at scale and automatically. The single thing that makes those attacks possible is inadequate cybersecurity. The problem is most common in small and medium-sized businesses (SMBs). Most SMB owners neglect cybersecurity, or believe it's only for big companies and an expense they can skip. Today, that simply isn't an option. But cybersecurity doesn't have to be expensive. The majority of data breaches are caused by human error — which is good news, because it can be prevented.
Which of these mistakes are you making?
Underestimating the danger
Most small-business owners underestimate the danger that's lurking. They go in with the mindset that their company is too small to be a target. The opposite is usually true. Today most attacks are completely automated and small businesses are an ideal target. So it's very important to understand that no company is too small — and everyone gets hit eventually.
Insufficient employee training
When did you last train your employees on cybersecurity? Owners assume their staff will be at least as careful online as they are. They're very, very wrong. As an owner of any company, you can't expect anything from your employees beyond what you've prepared them for. Training prevents a large share of attacks and explains how those attacks work and how to avoid them. Good topics to cover:
· Phishing attacks and how to recognize them
· Using strong, unique passwords
· Social engineering and how to spot it
Using weak passwords
Weak, guessable passwords are one of the most common mistakes that occur in companies. Reusing the same password across multiple accounts or services is also a major issue. It really is essential to use strong, unique passwords — and where possible, multi-factor authentication.
Bad or missing backups
Backup isn't only protection against attackers. It's also protection against things you can't control: hardware failures, natural disasters, and any other event that could destroy your data. So follow the 3-2-1 rule: always keep 3 backups on 2 devices, with 1 copy off-site.
Not updating
Running outdated software is a mistake plenty of companies make. I get it — updates bring problems with them, but those problems are nothing compared to losing all your company data. Attackers can target known software bugs, which means the older the software you run, the more vulnerable you are.
Ignoring mobile devices
Most of your staff have a phone, and most of them use it for work — so it's very important to secure the part of the phone holding company data. The best way to do this is MDM (Mobile Device Management); you can read more about it in the Microsoft Intune article.
No worst-case plan
Having a plan for what to do during a cyberattack is critical. Without one, panic kicks in during an incident — the last thing you need at that moment. Build a several-step, detailed runbook for what to do during an attack and how to get back on your feet.