If your email was compromised in a notable breach these services will let you know.
BreachAlarm, DeHashed and Have I been Pwned.
Not being aware can leave organisations vulnerable to attack.
1 Identify your top risks.
Properly identifying your risks will help shape the messaging, delivery, and effective targeting of your Cyber Security awareness program.
Targeting employees with the wrong training can result in information overload.
2 The common denominator behind all attacks is human error.
Some of the biggest threats across the board include phishing, malware, and poor security practices. Phishing is behind 71% of all cyber-attacks worldwide.
Human error is responsible for 95% of breaches.
3 Cybersecurity bad habits you must avoid:
- Poor Password Management: 59% of people use the same or similar password for multiple accounts.
- Not Using 2FA/MFA: Two factor 2FA or Multifactor Authentication MFA is a great tool- is easy to implement and provides layered security, which is a must for every business.
- Not Setting A Disaster Recovery Plan: No security software guarantees 100% immunity to cybersecurity threats. Given the risk that loss of data poses, a reliable data backup and recovery solution is a must-have for every business.
- Treating Cybersecurity as A One Time Project: Cybersecurity threats are always evolving. With the advancement in technology, cyber-criminals are also becoming more advanced in their attacks.
- Not Updating Employee Knowledge/Cybersecurity Awareness: A little education can prevent cyber-attacks as most are identifiable.
- Over Confidence – Thinking it cannot happen to me. Most small businesses tend to think that they are too small a target for cybercriminals. But for a cybercriminal, you are never too small or too big. According to the 2019 Data Breach Investigations Report by Verizon, 43% of cyber-attacks were targeted at small businesses.
4 Change behaviour.
For training to resonate, it needs to be specific, tailored, fun, and address the challenges that staff face on a day-to-day basis. Providing your employees with easy to consume content that is relevant to their role is a critical step in changing their behaviour.
To effectively change employee behaviour and create a culture of enhanced Cyber Security awareness, organisations should create an annual security awareness campaign that encompasses engaging videos, policies, quizzes, and surveys which stresses the importance of their role in the overall security of the organisation.
Regular education about cybersecurity threats, preventive measures and password hygiene should be part of your IT security plan. Periodically discuss your company’s IT policy along with your employees. Spear phishing attempts rely on the gullibility of your employees that may lead them to share sensitive information via email to a spoofed account of an authority figure. If employees know that the IT security policy prohibits them from sharing sensitive information via email or phone, then they are less likely to fall prey to such phishing attacks.
No matter how careful we are about phishing, hacking, ransomware, etc. there is always the possibility that a threat may slip through the cracks. When educated properly and frequently, employees recognize the threats posed by a wide range of cybercriminal activities. Cybersecurity education should not just be about external threats but also about internal policies and security protocols. A well-informed workforce is a huge asset in our worldwide battle against cybercriminals.
We partner with the best in the world to provide exceptional cyber awareness training and have a solution for small and medium enterprises as well as large organisations.
