People

Download the white paper

The Threat from Human Error

In addition to the threat from cyber criminals, the people within a business also play a part in cyber security incidents. This can be due to a mistake or a deliberate act.

Whilst many cyber attacks are sophisticated, they often depend on deceiving people within a business to do something. Phishing attacks rely on people to believe that a fraudulent request is a genuine one. Ransomware infections can start when a member of staff visits a website that appears trustworthy but actually installs malicious software.

Insurers Hiscox reported to the Law Society that more than two-thirds of all cyber-related insurance claims in the 18 months to September 2017 were directly caused by an employee’s mistake.

As human error is a key factor this also means that awareness-raising and training exercises are effective tools to protect against security incidents.

How a Security Culture Can Protect Your Business

In line with guidance from the National Cyber Security Centre, it is important that all businesses have a well-defined and comprehensive security policy.

However, a policy that is defined without input from all levels of staff is harder to enforce as people may not buy in to it. A better approach is to engage people from across the business. This ensures that the policy reflects how people actually work and makes it more likely to be followed.

A security-conscious culture is central to an effective security strategy. Many cyber attacks rely on people to click on harmful emails or visit fake websites. Well-trained staff who are alert to the latest threats are a necessary complement to powerful security tools.

It is also critical that staff feel empowered to speak out about security issues, whether that be proactively to improve a process, or reactively if an incident occurs.

Training and Awareness

An IT security partner can organise annual online cyber security training. This ensures that staff are up to date with the latest types of threats and what to be alert for. In addition, random phishing simulation tests can be carried out. For this, a test phishing email is sent to people in the business. Anyone who clicks the link in the phishing email undertakes extra cyber security training.

Helpdesk

Proactive monitoring of workstations and servers identifies and prevents problems before they occur. An IT security partner can run this monitoring and ensure that all equipment is up to date with the latest security patches.

However, when incidents and issues happen it is essential that they are resolved as quickly and efficiently as possible. A helpdesk is key to direct help and support to where it is needed in a business. An IT security partner can also provide support which fits the working hours of the business. The extended help covers people working late or at weekends as well as in different countries.

The Threat from Malicious or Disgruntled Staff

There are sometimes people within a business who take deliberate steps to damage or disrupt it. This can include accessing confidential information, deleting company data or financial fraud. Whilst these incidents may not involve cyber criminals the business impact can still be significant.

How a Security Controls Can Protect Your Business

Principle of Least Privilege

To limit exposure to malicious or accidental problems caused by users, employees should only have the minimum level of access they need to do their job. For example, the receptionist does not need access to the accounting systems and the accountant has no need to access the visitor logs.

In addition, people with administrator access should not use it on a day-to-day basis for regular work as many viruses follow the credentials of the logged in user.

Staff Offboarding

A comprehensive offboarding process for both employees and contractors is important to maintain a business’s security. This includes ensuring that accounts are disabled or deleted in a timely manner, remote access is revoked and shared passwords are reset. This makes sure that the only people who have access to systems are the ones who need it.

Segmentation

Separating users from business-critical applications limits the damage, accidental or malicious, someone can do. It also restricts the spread of malware, like ransomware.

Malware is much more likely to be downloaded onto an individual’s computer rather than a server, so placing a firewall between those two devices helps to control the exposure. For example, an accounting server in a business’s office should be separated from users by a firewall.

Alongside this, other internet-enabled devices are being used in businesses. From voice-controlled assistants and smart light bulbs to smart thermostats and IP cameras. The best way to protect a business from the security risk of these devices is with network segmentation. This puts these untrusted devices in a dedicated network segment, separated from both users and servers.

Cyber Security to Protect Your Business

Learn more about how to keep your business safe in the white paper: Cyber Security: How to Protect Against Complex Threats.

This plain English guide from Always Secure covers:

  • The cyber security threats facing professional services firms
  • The risks and opportunities from new technology
  • How to protect and support a business with cyber security
  • An effective strategy to protect your data, devices and systems
  • What to look for in an IT security partner