Four signs that your business is vulnerable to being hacked

-

According to the UK Government’s Cyber Security Breaches Survey 2022, 39 percent of UK businesses have been hacked at least once in the last twelve months.

Cyber security threats are growing year on year.

Despite this, only 23 percent of businesses have a documented cyber security strategy in place.

Also, only 17 percent have carried out a vulnerability audit. This means that most businesses aren’t even aware of serious security flaws in their IT ecosystem – let alone how to fix them.

HRreview Logo

Get our essential weekday HR news and updates.

This field is for validation purposes and should be left unchanged.
Keep up with the latest in HR...
This field is hidden when viewing the form
This field is hidden when viewing the form
Optin_date
This field is hidden when viewing the form

 

Innovative cyber security consultancy firm FoxTech runs security analyses on hundreds of companies every year using open-source intelligence, picking up on the most common security problems that make companies particularly vulnerable to being hacked.

Here, FoxTech provide their insights into four of their most frequently identified issues to help businesses become more aware of the problems they might have, and what to do about them.

 

Issue 1: You don’t know what devices your employees are working on

The UK government’s Cyber Security Breaches Survey 2021 found that organisations have found it more difficult to keep track of their endpoints since home working has become a widespread practice.

Not only have the number of endpoints in the average business increased, but so have the type. Many employees now conduct business on a number of devices each day, including office desktops, company-owned laptops, personal computers and smartphones.

Why is having a lot of devices a problem? Anthony Green, CTO of FoxTech discusses:

“It isn’t a problem in itself,” says Anthony, “but it becomes an issue because today’s model of working can mean that business owners or IT managers don’t even know what devices are being used to access sensitive company data, or how secure these devices are.

“Problems such as working with unsupported versions of Windows and not updating malware protection and firewall software increased markedly in 2021, compared to 2020, and the Cyber Security Breaches Survey 2021 attributes the decline in proper endpoint security measures to large and diverse device profiles.”

What to do:

  • Minimise the amount of sensitive data stored on both company and personal devices by making sure employees can access only the data they need.
  • Create a ‘bring your own device’ (BYOD) policy.

 

Issue 2: You haven’t kept track of your online assets

“When we run our security analyses, one of the most common things we find are forgotten assets such as website domains and databases.

Often, these are exposed to the internet – completely unbeknownst to the company. Forgotten assets are an easy entry point for hackers – they can use them to jump to software, files and devices that you are using in an attempt to steal your data.”

What to do:

  • Remove/take down any unused assets to ensure your online presence is limited to only what is necessary and manageable.
  • Invest in professional cyber security monitoring for existing assets to ensure any suspicious activity is spotted.

 

Issue 3: You don’t have DMARC set up

Domain-based Message Authentication Reporting and Conformance (DMARC) is an email authentication, policy, and reporting protocol.

This protects you from email spoofing (people sending emails on behalf of your domain), spam and phishing scams.

“According to security software firm Trend Micro, 91 percent of breaches start with a phishing email, so setting up DMARC is one of the best ways to prevent anyone from successfully targeting your email database.”

What to do:

  • Configure DMARC. The good news is, it’s not expensive. Installing it yourself is free, and getting it set up by a trusted third-party cybersecurity firm comes at a low cost.

 

Issue 4: You put off installing software updates 

Installing software updates is a fast and free way to strengthen company system security. Software updates offer a number of benefits and revisions including patching security flaws, removing bugs and getting rid of any outdated features from your device.

Anthony says: “Installing software updates is incredibly important. Outdated software versions will have security flaws, and hackers look for these types of vulnerabilities because they can be exploited and used to gain access to your device, and eventually, your data. Luckily, this one is an easy fix, once you know what devices need updating.”

What to do:

  •  Locate devices that are still running on outdated software.
  • Don’t just rely on alerts. Not all devices give adequate software update alerts, so it is good practice to manually check for updates at least once a month.

Educate employees on the importance of software updates, and create a company policy around regularly checking for, and installing updates across all your devices and software packages.

Latest news

Exclusive: London bus drivers’ ‘dignity’ at risk as strikes loom over welfare concerns

London bus drivers raise concerns over fatigue and lack of facilities as potential strikes escalate long-standing welfare issues.

Whistleblowing reports ‘surge by up to 250 percent’ at councils as new rights take effect

Whistleblowing cases are rising across UK councils as stronger workplace protections come into force, though concerns remain about underreporting of serious issues.

Bullying and harassment to become regulatory breaches under new FCA rules

New rules will bring bullying and harassment into regulatory scope, as firms face rising reports of workplace misconduct.

Personalising the Benefits Experience: Why Employees Need More Than Just Information

This article explores how organisations can move beyond passive, one-size-fits-all communication to deliver relevant, timely, and simplified benefits experiences that reflect employee needs and life stages.
- Advertisement -

Grant Wyatt: When the love dies – when staying is riskier than quitting

When people fall out of love with their employer, or feel their employer has fallen out of love with them, what follows is rarely a clean exit.

£30bn pension savings window opens for employers ahead of 2029 reforms

UK employers could unlock billions in National Insurance savings by expanding pension salary sacrifice schemes before new limits take effect in 2029.

Must read

Katy Meves and Nick Jupp: What can all employers learn from Manchester United dismissing Louis Van Gaal?

Following his dismissal by Manchester United Football Club it has been reported that Louis Van Gaal is likely to receive compensation between £4.5 and £5 million. Any senior, well paid executive is likely to have a significant claim for compensation if they are dismissed in breach of contract. With stakes high, employers need to make sure they are properly prepared for a parting of the ways by drafting adequate protections in their employment contracts.

Arran Heal: Why good workplace cultures keeps winning over cash for employees

"In the challenging years to come, it is toxic cultures that will destroy businesses over time."
- Advertisement -

You might also likeRELATED
Recommended to you