In the last year, 43pc of companies experienced a cyber security breach or attack. Where these incidents resulted in a loss of assets or data, the mean cost for small and micro businesses was £2,310, rising to £22,300 for large businesses.
What should businesses be aware of when planning their cyber security strategies? The most common cyber threats facing businesses are:
Further reading:
https://www.independent.co.uk/topic/ransomware
Further reading:
https://www.bbc.co.uk/news/technology-42958331
https://www.infosecurity-magazine.com/news/over-half-of-organizations-phished/
Further reading:
https://www.infosecurity-magazine.com/news/over-100-million-iot-attacks/
https://threatpost.com/serious-security-flaws-found-in-childrens-connected-toys/151020/
Further reading:
https://insider.zurich.co.uk/trending/cyber-data-security/cyber-attacks-and-supply-chain-continuity/
https://www.sbrcentre.co.uk/news/2019/august/cyber-attacks-in-the-supply-chain/
You may have good security controls in place to protect your network. However, if an employee wants to access a web site that is blocked by your company firewall decides to connect to their mobile phone hot spot and connect directly to the Internet can you imaging the potential for malware to cross your network boundary and infect your network.
The best approach to reduce this risk educate your employees, this should not be a one off event but a sustained programme of education to ensure they keep ‘security aware’ in their every day tasks.
Deliberate malicious activities by these same employees is a different matter and one that requires a more robust set of controls to detect and mitigate the challenge they present.
Further reading:
https://www.verdict.co.uk/insider-threat-price/
https://www.scmagazine.com/home/security-news/insider-threats/
To mitigate the risk to your business you need to put controls in place to contain the threat by segregating the legacy equipment from the wider company network. Ensure you track this so that you can plan to address this in the future with the replacement of the processes or equipment dependant upon these legacy systems. In short, you need to keep a close eye on any legacy IT systems to manage the threat they pose by being unsupportable.
Further reading:
https://nationaltechnology.co.uk/Legacy_Tech_Cyber_Security_Risk_Hospitals.php
Further reading:
https://www.risk-uk.com/the-gdpr-and-boards-of-directors-paying-attention-to-cyber-security/
https://ico.org.uk/for-organisations/data-protection-act-2018/
Much has been made of the global Cyber Security skills gap and this remains and on going concern to businesses as whole who are reliant upon their input to make those informed choices.Those with the skills and experience to go with the skills are in demand and thus tend to command salaries that reflect the scarcity of supply in the face of ever growing demand.
Whilst the large corporates can afford to pay high salaries or pay the even higher fees of the big 4 consulting companies or large specialist consultancy firms many SME organisations simply can’t afford them.
This provides an opportunity for individuals to take their wealth of experience and skills developed over long careers in information / cyber security to establish local businesses to meet the needs of the local business community at a more cost effective price point.
This enables your business to access leading advice and guidance focused on your local needs at a price you can afford.
Further reading:
https://www.cybersecurity-professionals.com/blog/2019/09/11/the-cyber-security-skills-gap-in-the-uk/
https://www.itproportal.com/news/uk-businesses-at-risk-from-cyber-skills-gap/