| NOTICE: A data security breach has been reported by Widgetex, exposing personal and financial information to over 100,000 customers. |
| Your skin crawls when you see that. You try to remember; did you do business with them? Was your data included in that breach? Yes? Now what? What if they use my information? How do I recover from this? Now think about if Widgetex was your company… Yes, Widgetex is a fictitious company, but the story is real and happens even more often than we hear about. If you are a business owner, you are very concerned about that very issue. If you’re not, you should be. Some business owners stick their heads in the sand because they don’t think they have a risk, or don’t know what to do, or are afraid it will cost too much to address it. The bottom line is… it could cost you everything. The good news is reducing risk starts with simple, inexpensive, common-sense actions. Here are five steps to reduce your cyber risk and start to breathe easier. 1. Training – Your employees are either your biggest risk, or your greatest defense. Train for and promote cyber healthy habits when using business computers and resources. Teach them about phishing scams and how to spot suspicious email or calls and what to do about them. Enforce strong passwords and regular password change for company systems. Limit logon attempts. 2. Keep your computers and systems updated and protected. Computers, software and devices all have potential risks that can be exploited. As those risks are identified by the manufacturer, it is important to apply new updates and patches. Where possible, turn on automatic updates. Also, ensure that all network devices have strong and unique configuration passwords. 3. Develop strong Access & Authentication processes. Require multi-factor authentication (MFA) for all accounts, especially anything related to system administration and financial systems or services. These can seem like a nuisance at times, but the impact of a successful attack goes far beyond nuisance. 4. Protect your data. Develop a routine for backing up your critical data, using encryption and secure off-site or cloud storage and ensure they actually work. Encrypt devices and data, including computers, phones, removable drives and cloud storage. 5. Create a simple written response plan, identify what to do before, during, and after a cyber incident. Require employees to report all suspected threats whether cyber or physical. Review the plan regularly with staff and encourage communication. Most of all, cultivate a company culture of Security by All. What is good for the company is good for employees. Talk regularly with employees about cyber security and how to strengthen it. Help them practice good cyber habits personally, as well. Habits at home turn into habits at work and visa versa. www.allcomm.us | 833-ALL-COMM |
Cybersecurity 101


Leave a comment