Cybersecurity 101: Protecting Yourself by Stopping Malicious Actors November 29, 2023 – Posted in: Cyber Security, IT Support – Tags: cybersecurity, cybersecurity 101, it support, ITServices, SmallBusiness
There are multiple methods for protecting yourself from cybercrime, the challenge is achieving a realistic balance between:
- Security
- Accessibility of data
- Cost to the business
You could require an iris scan just to get into the office and run everything on an isolated network that required people to use a separate device to access company data from the one they use to access the internet and their emails. You could put in place in depth and complex monitoring software to spot any variance in the data flow on your servers and pay someone to look at the results and analyse whether they could be a threat. You could block all outbound emails with attachments on them.
However your staff wouldn’t get a lot done without significantly more time and effort than would be cost effective, and the solution would likely cost most of your turnover.
You don’t need to go that far though. As with any safety issue you assess the risk by both the likelihood of occurrence and the potential impact, you put in place reasonable measures to prevent occurrence or mitigate impact, and you decide what level of risk you are prepared to carry.
A risk of working in a warehouse is having heavy items land on you. Wearing full armour to work would be expensive, impractical, and prevent you from working. However steel toe caps will protect the area most likely to be affected and a hard hat will protect the area which will have the most impact if damaged. Together they provide a reasonable, affordable, workable level of protection.
So what would constitute a boots and hard hat approach to cybersecurity?
Stopping Malicious Actors
The first element of cyber security is in keeping the bad actors and the malicious software out of your systems.
Software Lists and Patching
Every app or piece of software you use is a potential gateway into your system. The first way to reduce your risk – don’t have software you don’t need/use on your computer. The bits of software that ships with a new device should be removed by your IT Company before it is sent to you, but you can keep it tidy. Don’t have extra browsers on your computer unless you use more than one. Uninstall old software if the business no longer uses it. Have a list of approved software for your staff to use. You cannot risk people habitually downloading potentially damaging or vulnerable software whenever they feel like it.
To keep the software you do use secure, the most important thing is to keep it up to date. You pay for software. You likely pay quite a lot for software. Part of what you are paying for is the provider keeping the software up to date. They will be constantly reviewing reports of new exploitable interactions, or bits of code that have been broken by malicious actors, when they find one they will release the fix in the form of a patch.
Not patching your software is like leaving the doors open, when you are paying someone to upgrade them all the time. It might seem sometimes like you’re being asked to restart your computer, or download a new version of some app every other day, but it is really important to keep up.
It is particularly important in any customer facing items – including your website. A 2021 study from the Institute for Internet Security—if(is) Westphalian University of Applied Sciences discovered that only 6% of websites run on software that is fully up to date, while a whopping 47% let their entire software catalogue go out of date. An out of date website puts the data of anyone who has filled in a form on it at risk of data loss. It puts the business that owns it at risk of having malicious software embedded in their site, or even being sent to them through the form. If you run any kind of online service or online payment system, those risks increate hugely.
Make sure your IT Company are patching your servers, make sure your staff are running and accepting updates, and make sure your website provider is keeping your website software up to date.
Firewalls
The most basic level of protection for your business is to have a firewall and an antivirus solution. There are two forms of firewall, the one that sits between your network and the wider internet, your perimeter fence. Then the individual ones that surround each device, the locked door to each ‘room’ on your network. These firewalls block or allow certain types of traffic coming into, and if required going out of your network.
Your firewall acts as a barrier to malicious code and threat actors, preventing them from getting in. It can also act as a guard, checking what goes out for key information that shouldn’t be sent externally. Your IT Company should set up your firewalls for you.
Access Control
The foundation of security is making sure that those who need to can access your systems and data, and those who do not can’t. Individual accounts should be set up for each person who needs access so that they can be given access to the parts that they need, and so their activity can be logged and tracked back to one person.
The most commonly used method for controlling access is the username and password. The first key point is that any default passwords should be changed. Routers, printers, WiFi, Firewalls – all sorts of devices come with default passwords.
Your IT Company should be making sure that these are changed so that malicious actors can’t access them with no more than a quick search.
Your passwords should be hard to guess, ideally unique to each program or app and meet the following criteria:
- 12 or more characters long.
- Contain at least one uppercase letter, one lowercase letter, one number and one special character.
- Not be a single word that appears in the dictionary.
How long would it take a specialist computer to crack a password?
| # Characters | Numbers Only | Upper OR Lower Case Letters | Upper AND Lower Case Letters | Numbers, Upper & Lower Case Letters | Numbers, Upper & Lower Case Letters & Symbols |
| 3 | Instantly | Instantly | Instantly | Instantly | Instantly |
| 4 | Instantly | Instantly | Instantly | Instantly | Instantly |
| 5 | Instantly | Instantly | Instantly | 3 secs | 10 secs |
| 6 | Instantly | Instantly | 8 secs | 3 mins | 13 mins |
| 7 | Instantly | Instantly | 5 mins | 3 hrs | 17 hrs |
| 8 | Instantly | 13 mins | 3 hrs | 10 days | 57 days |
| 9 | 4 secs | 6 hrs | 4 days | 1 yr | 12 yrs |
| 10 | 40 secs | 6 days | 169 days | 106 yrs | 928 yrs |
| 11 | 6 mins | 169 days | 16 yrs | 6k yrs | 71k yrs |
| 12 | 1 hr | 12 yrs | 600 yrs | 108k yrs | 5m yrs |
| 13 | 11 hrs | 314 yrs | 21k yrs | 25m yrs | 423m yrs |
| 14 | 4 days | 8k yrs | 778k yrs | 1bn yrs | 5bn yrs |
| 15 | 46 days | 212k yrs | 28m yrs | 97bn yrs | 2tn yrs |
| 16 | 1 yr | 512m yrs | 1 bn yrs | 6tn yrs | 192tn yrs |
Data from 2012, bear in mind computers significantly faster now than they were then.
Practically this all adds up to having a lot of different, complex passwords to try to remember. One option to make it easier is to use a password vault. These are special bits of software designed to be secure, where you can store your passwords.
Another option is to use a formula to create passwords. A phrase or word you find easy to remember like lets run that up the flagpole to see who salutes would give you LRTUtFtSWS as an acronym. Switch out a couple of letters for numbers and add a special character to get 1RTUtFt5W5! then add the last three characters of the name of the app or site you are signing into. So a Sage password would be 1RTUtFt5W5age! Or a Xero password would be 1RTUtFt5W5ero!. Much easier to remember when you reuse the first part and the app you’re trying to log into gives you a clue for the second part but the password doesn’t include the rather obvious full name of the app and is still different for every use.
However you manage your passwords, the next step is MFA. Multi Factor Authentication is the single most effective way to protect your accounts, including mailboxes from hackers. In turn protecting both your data and your business reputation from the damage that a malicious actor emailing your customers a virus from your actual email address could cause. Multi Factor Authentication isn’t just having two stages to a login. It is logging in using two things from the list:
- Something you know – a password or pin.
- Something you have – a phone or a key.
- Something you are – a fingerprint or iris scan.
When you log in with a password and a code from your phone, you are proving you know your password and have your phone. Setting up multi-factor authentication is recommended for any app or site that offers it, both at work and at home. 1.2 million Microsoft accounts were compromised in January 2020 and of those 99.9% did not have MFA enabled.
Equally important is to make sure that you let your IT Company know when a staff member leaves the business. Blocking access if someone has moved on is recommended, blocking access if someone has been let go is vital.
Email Scanning
Phishing emails and scams are the top of the top five attack methods reported to the FBI globally in 2022. Preventing those emails from arriving in your mailboxes is the most reliable way to protect your business.
Microsoft has a reasonably comprehensive built in anti-spam and anti-phishing system, but if you are getting a lot of spam you may want to consider a specialised email scanning software like Mimecast or OnScan. These software solutions will scan emails for possible threats, outside links or misleading items and block those that flag as risky. No software is perfect on this, and there may be times when you need to correct it and let an over-zealously blocked email through.
You can allow list an email address, or even a domain, but this is not recommended unless it can’t be addressed by asking the sender to sort out their settings. Once you allow list an email it is not scanned, so if your supplier or client gets compromised and one of their email addresses sends you a virus, it will go straight through.
Mobile Devices
As people expect to be able to work from anywhere, and businesses expect staff to work from anywhere, it has become standard practice to connect to work emails from your personal mobile device. This means that the business has no control about whether the device is patched, or secure, or has a pin number or lock screen.
It isn’t always easy, but your best bet is to either:
- Rethink your policy – do staff really need their emails on their phones? If not, then tell them not to set it up.
- Use mobile device management – either driven by written policies and agreements, or by software that prevents emails being opened on a non-compliant device.
- Provide company mobiles – provide staff with mobile phones that you can set up correctly for them and ensure access to make updates.
The same applies to home PCs. If your staff are working from home, ideally you should give them a laptop to take with them. If the only practical option is for them to use their home PC, then talk to your IT Company about setting up remote connectors so they can connect to and work on their work PCs from their home devices.
The Human Factor
Verizon statistics report that 74% to 82% of breaches involved a human element – whether that is people falling for phishing scams, making mistakes or actively misusing company data.
Technical people tend to get wrapped up in software and hardware solutions, when often training staff can have a much bigger impact. There are a wide array of software solutions to help with training, sending mock phishing emails to test your staff’s response after initial video training – and these can be highly effective.
If you aren’t in a position to pay for a solution like that, there are plenty of other options though. Bring it up in staff meetings and send regular reminders. Find free videos on how to spot a phishing email and share them with your staff.
Every little helps, and every email that gets spotted will be one more threat your business dodges.
It is also important that you make your policies on things like what information your staff are not allowed to send outside the company, or whether staff are allowed to use their own USB sticks, or their home PCs when working from home.
When talking to your staff about security, it is important you involve them in the conversation and explain why measures are needed. Unless your staff are willingly complying with your policies, they won’t work.
If your staff struggle or are constantly trying to work around the policies and security measures, talk to your IT Company about other options. There are limits to what software can do, but IT should work for your business not constrain it.
After all of those steps to keep the bad guys out, you need to assume that at some point they will get in. In our next article we will discuss mitigating the risks when an attack lands. If you have any concerns about cybersecurity, or would like to discuss any other IT Support needs you might have please give us a call on 01245 265100.