Threats

In the last year, 43pc of companies experienced a cyber security breach or attack. Where these incidents resulted in a loss of assets or data, the mean cost for small and micro businesses was £2,310, rising to £22,300 for large businesses.

What should businesses be aware of when planning their cyber security strategies? The most common cyber threats facing businesses are:

Ransomware is a form of malware that once on your computer will encrypt your data or threaten to publish it publicly unless you pay a sum of money. A number of incidents have reached the attention of the public in recent years.

Further reading:
https://www.independent.co.uk/topic/ransomware

Phishing is when an attacker attempt to trick users into doing something, such as clicking a bad link that will download malware, or direct them to a dodgy website. This website may look and feel like a legitimate website and request that you log in to change your password, restore your access depending upon the context used in the phishing email.

Further reading:
https://www.bbc.co.uk/news/technology-42958331
https://www.infosecurity-magazine.com/news/over-half-of-organizations-phished/

Internet connected devices like Amazon Echo, Ring Doorbell, Nany Cams, children’s toys, smart speakers, heating systems, and lighting systems are being rushed to market. Many of these new devices have little consideration given to security by their designers. This can present a risk to users of these devices. Imagine someone spying on you via your own webcam, listening in to your conversation, exploiting weaknesses or default passwords to access these devices and gain a foot hold onto your network, be that in your home or in your workplace. You need to be aware of these threats so that you can take measures to defend against them.

Further reading:
https://www.infosecurity-magazine.com/news/over-100-million-iot-attacks/
https://threatpost.com/serious-security-flaws-found-in-childrens-connected-toys/151020/

A supply chain attack is a cyber-attack that seeks to damage an organization by targeting less-secure elements in the supply network. A supply chain attack can occur in any industry, from the financial sector, oil industry or government sector. To protect your company from this modern day threat it is vitally important that you adopt procedures that identify any risks from cyber attack in your supply chain and make robust plans to mitigate them.

Further reading:
https://insider.zurich.co.uk/trending/cyber-data-security/cyber-attacks-and-supply-chain-continuity/
https://www.sbrcentre.co.uk/news/2019/august/cyber-attacks-in-the-supply-chain/

‘Your security is only as strong as your weakest link’ this is a simple statement that is often very true. In this case our weakest link are the employees of your company. If your employees are not security aware and know ‘good behaviour’ from ‘bad behaviour’ it’s only a matter of time before something goes wrong.Imagine an employee taking a file home at night to work on it at home and they bring it back into the office the next day. Will the USB stick they used contain malware from their home PC. What if you have confidential data and they use DropBox or Google Drive to make that file available form home to work on it remotely? Who else can access these file shares, how safe is your data.

You may have good security controls in place to protect your network. However, if an employee wants to access a web site that is blocked by your company firewall decides to connect to their mobile phone hot spot and connect directly to the Internet can you imaging the potential for malware to cross your network boundary and infect your network.

The best approach to reduce this risk educate your employees, this should not be a one off event but a sustained programme of education to ensure they keep ‘security aware’ in their every day tasks.

Deliberate malicious activities by these same employees is a different matter and one that requires a more robust set of controls to detect and mitigate the challenge they present.

Further reading:
https://www.verdict.co.uk/insider-threat-price/
https://www.scmagazine.com/home/security-news/insider-threats/

For SME’s as well as large corporates updating IT equipment can be challenge. Perhaps the laser cutter your business relies upon only works with Windows XP. As malware evolves and presents an ever changing threat to your IT systems you need to maintain the patching of your IT to mitigate the risk. However, once vendor support is withdrawn from the operating system a key business system or process is reliant upon you can no longer address the malware threat. While vendors do offer extended support agreement these can prove costly for SME’s.

To mitigate the risk to your business you need to put controls in place to contain the threat by segregating the legacy equipment from the wider company network. Ensure you track this so that you can plan to address this in the future with the replacement of the processes or equipment dependant upon these legacy systems. In short, you need to keep a close eye on any legacy IT systems to manage the threat they pose by being unsupportable.

Further reading:
https://nationaltechnology.co.uk/Legacy_Tech_Cyber_Security_Risk_Hospitals.php

No company exists in isolation, it must operate its business in compliance with the legislation and regulation associated with the business they engage in and the region in which they operate.One area of legislation that covers all industries, with very few special exemptions, is data protection. With the advent of the EU General Data Protection Regulation (GDPR) and its subsequent UK specific implementation, the Data Protection Act 2018, the financial penalties that come with them are significant. If your business wants to avoid financial penalties that may put the future of your business in jeopardy then you need to address this legislation.

Further reading:
https://www.risk-uk.com/the-gdpr-and-boards-of-directors-paying-attention-to-cyber-security/
https://ico.org.uk/for-organisations/data-protection-act-2018/

With all of the above mentioned threats as well as many others the most critical aspect for your business is subject matter guidance to enable your business to make informed choices.
Much has been made of the global Cyber Security skills gap and this remains and on going concern to businesses as whole who are reliant upon their input to make those informed choices.Those with the skills and experience to go with the skills are in demand and thus tend to command salaries that reflect the scarcity of supply in the face of ever growing demand.

Whilst the large corporates can afford to pay high salaries or pay the even higher fees of the big 4 consulting companies or large specialist consultancy firms many SME organisations simply can’t afford them.

This provides an opportunity for individuals to take their wealth of experience and skills developed over long careers in information / cyber security to establish local businesses to meet the needs of the local business community at a more cost effective price point.

This enables your business to access leading advice and guidance focused on your local needs at a price you can afford.

Further reading:
https://www.cybersecurity-professionals.com/blog/2019/09/11/the-cyber-security-skills-gap-in-the-uk/
https://www.itproportal.com/news/uk-businesses-at-risk-from-cyber-skills-gap/