The Need to Educate Employees on Cybersecurity
When developing cybersecurity programs, many businesses focus on protecting their infrastructure perimeter and device endpoints. But it’s also important to consider what happens when a threat bypasses perimeter defenses and targets an employee in the form of a malicious email or text.
Stronger cybersecurity has become a global priority as hackers penetrate IT infrastructures with increasing frequency and sophistication. According to the FBI, phishing was the most common type of cybercrime in 2020, with incidents nearly doubling from 114,702 incidents in 2019 to 241,324 incidents in 2020. Not surprisingly, losses from business email compromise (BEC) have skyrocketed over the last year. The FBI’s Internet Crime Report shows that in 2020, BEC scammers made over $1.8 billion. Coupled with the Internet of Things (IoT) and the explosive growth of mobile devices, the potential for data leaks is even greater.
Educating employees on what it takes to protect proprietary documents and data is critical. Any data leaks—whether intentional or unintentional—could potentially damage your bottom line and your industry reputation. It only takes one incident to destroy the goodwill you worked so hard to establish.
Physical Security Precautions
The Importance of Keeping a Clean Desk
It sounds simple, but keeping a clean desk is often overlooked when talking about data security. A messy desk makes it difficult to realize something is missing, such as a folder containing printouts with customer data. A cluttered desk also leads to the discovery of any theft likely being delayed.
Encouraging employees to maintain a neat desk pays off in two ways. In addition to making paper assets more secure, employees with clean desks are more apt to be productive because they can quickly—and safely—access the tools and resources they need to do their jobs.
Common Messy Desk Mistakes
- Leaving computer screens on without password protection
- Leaving documents, mobile phones, USB drives and personal items out in the open
- Neglecting to shred documents before they go into the trash or recycling bin
- Failing to close and lock file cabinets
- Writing usernames and passwords on visible slips of paper or sticky notes
- Displaying calendars for all to see
Social engineering is a non-technical, malicious activity that exploits human interactions to obtain information with the intent to gain access to secure devices and networks. Such attacks are typically carried out when cybercriminals pose as credible, trusted authorities.
Phishing Email Compromises
One of the most common forms of social engineering is email phishing—an attempt to acquire sensitive information such as usernames, passwords and credit card data by masquerading as a trustworthy entity. Phishing is a key threat for employees. Such emails often spoof the company CEO, a customer or a business partner and do so in a sophisticated, subtle way.
Common Phishing Techniques
The scope of phishing attacks is constantly expanding, but frequent attackers tend to utilize one of these email tactics:
- Spoofing the sender address to appear as a reputable source and requesting sensitive information
How to Block Phishing Attacks
- Don’t reveal sensitive information via email.
- Check the security of the website. “http” indicates the site has not applied any security measures, while “https” means it has.
- Pay attention to variations in spellings or a different domain (e.g., .com versus .net).
- Beware of emails requesting information. Reach out directly to the business through other means.
Username & Password Management
Although it should be common sense, employees need to avoid the use of passwords that are easy for hackers to guess. Among the top ten worst passwords are those that use a series of numbers in numerical order, as well as common names and phrases.
How Attackers Exploit Weak Passwords
While most websites don’t store actual username passwords, they do store a password hash for each username. A password hash is a form of encryption, but cybercriminals can sometimes use the password hash to reverse engineer the password. When passwords are weak, it’s easier to break the password hash.
Tips to Strengthen Password Security
- Change passwords at least every three months for non-administrative users, and every 45-60 days for admin accounts.
- Use different passwords for each login credential.
- Avoid generic accounts and shared passwords.
- Conduct periodic audits to identify weak/duplicate passwords, and change as necessary.
- Use password managers and avoid the browser’s auto-fill function for passwords.
Mobile Security
Mobile security is an increasing concern as more and more companies adopt Bring Your Own Device (BYOD) environments. Businesses must secure personal endpoint devices that are not completely under their control.
Mobile Device Security Challenges
- Lost, misplaced, or stolen devices: Remote wiping is key to safeguarding sensitive information.
- Mobile malware: Hackers are now turning their attention to mobile devices and text messages.
- Unsecure third-party apps: Breaches can serve as gateways to other apps.
How Employees Can Secure Their Mobile Devices
- Set a PIN or passcode: This is the first line of defense; some manufacturers offer automatic device wiping after several unsuccessful attempts.
- Use remote locate tools: Services like “Find My iPhone” and the Android Device Manager help locate lost devices.
Secure Website Browsing
When end users venture out onto the Internet, it’s easy to get tangled up in various threats. Malvertising is a form of malicious code that distributes malware through online advertising. This type of threat can be hidden within ads or bundled with software downloads.
Website Browsing Best Practices for Employees
- Be conservative with online downloads.
- Interact only with well-known, reputable websites.
- Confirm each site is genuine and determine if it utilizes SSL (Secure Sockets Layer).
The Value of an MSP in Ensuring Employee Cybersecurity
Partnering with a Managed Services Provider (MSP) that focuses on IT security can bolster your cybersecurity defenses, especially when it comes to employee training. Viruses can also do serious harm to information, which is why MSPs provide complete endpoint management.
Education & Technology – a Winning Cybersecurity Combination
Strengthening your business’ cybersecurity posture begins with educating your employees. The tips provided can help ensure that sensitive information does not fall into the wrong hands.