While it’s certainly true that we are facing a higher quantity of cybersecurity threats than ever before, an OTA report concluded that 93% of data breaches in 2017 were entirely avoidable (source: OTA report, page 4). Even if you have taken the basic recommended precautions, it is still likely that your business and data are at risk. These are critical steps you need to take to protect your business today and in the immediate future.
Improve Security Awareness
The Problem: We often assume that in order to protect ourselves from hackers, we need a suitably complex computer solution. A huge chunk of data breaches, however, can be explained by PEBKAC (problem exists between keyboard and chair!). According to a 2015 study that analysed over 500 data breaches, 29% were traced back to careless employee behaviour.
The Solution: It is your responsibility to ensure your employees are aware of the most common data risks. It is critical that your business holds regular training sessions that cover, at the very minimum, best practice for basic security issues such as passwords and phishing attacks.
For example, passwords should have a combination of letters and symbols, and we recommend changing them every 4-8 weeks. Using software solutions such as LastPass is another potential avenue.
Encrypt Customer Data
The Problem: Last year, Forever21 admitted a data breach, which included sensitive information such as customer credit card details. While major retailers suffering from hacks isn’t news these days, what’s astounding about this particular breach is that the company admitted that it failed to enable encryption on POS terminals.
The Solution: Encrypt customer data at all times. So what’s encryption exactly, you ask? To put it simply, it’s the process of converting data into so-called ciphertext. This turns your customer credit card number, for instance, into unreadable gibberish.
It is an absolute must that you use SSL authentication on your website, which encrypts data that flows from the user to your business. Ideally, you should also try and avoid storing any customer data at all. Credit card data, in particular, should never be stored; instead, let a third-party payment provider (such as PayPal) deal with that aspect of your business.
Penetration Testing
The Problem: You invested in the latest security software. Encryption was no longer an issue. Your employees were fully trained and took all necessary precautions to avoid data risks.
Yet your company was still a victim of a hack and your client data was compromised.
The Solution: Companies are becoming increasingly aware of data risks. However, the steps are taken to protect businesses usually only cover the most glaring problems. Hackers intent on compromising your businesses are able to circumvent basic security.
To cover the less obvious security holes, we recommend employing penetration testing as part of your security audit. Otherwise known as ethical hacking, this method identifies weaknesses in your system and allows you to implement solutions for a more resilient system.
Protect the Traveling Target
The problem: According to a recent study by British Telecom, over 40% of respondents claimed to have suffered a device security breach in the past year. Worryingly, 34% of businesses do not have a mobile security policy. As more businesses embrace BYOD (bring your own device) and COPE (Corporately Owned Personally-Enabled), leaks are becoming more prevalent.
The solution: The first step is having a concrete BYOD and COPE policy. This will entrench expectations amongst employees, and your company will be better equipped to deal with potential risks. In addition, companies should take the necessary precautions to protect devices. This includes the implementation of a hybrid cloud, for example, to store and access sensitive data. If an employee loses a device, access to files stored on the cloud can be revoked, keeping your data safe. You should make an effort to separate and contain business data and applications, focusing on encryption and security in case of theft or loss.