October is our favourite time of year. It’s not the crisp mornings, autumnal colours, or even Halloween that gets us all of a flutter. No, it’s because October is European Cybersecurity Month (ECSM).
What is European cybersecurity month?
ECSM is an annual cybersecurity awareness campaign, coordinated by the European Union Agency for Cybersecurity (ENISA) and the European Commission. It’s supported by all EU member states and more than 300 corporate partners.
The campaign aims to promote online security among EU citizens. Each year, hundreds of activities such as conferences, workshops and webinars take place across Europe throughout October. From Ljubljana to Lisbon, businesses, governments and NGOs come together to provide the latest cybersecurity information and best practices.
2020's official slogan is ‘Cybersecurity is a Shared Responsibility’. However, under this broad title, ENISA chooses some relevant themes each year. And this edition’s themes are very close to our heart.
What are the themes for 2020?
This year’s ESCM campaign tackles security issues surrounding the ‘digitalisation of everyday life.’ In simple terms, that’s the switch many of us have made to working remotely during the COVID-19 pandemic, and the problems it raises.
Encouraging EU citizens to ‘Think Before U Click’, the 2020 campaign digs into a couple of important themes to help people guard against cyber threats.
The first theme is ‘Cyber Scams’. Activities and events will focus on phishing, attacks on business email accounts, and online shopping fraud. The goal is to give everyone the knowledge to identify scams and navigate online life safely.
The second theme, and the one we’re most excited about, is ‘Digital Skills’. It tackles e-privacy matters such as personal data protection, cyber-bullying and cyber-stalking. Sessions in this category will promote proper cyber hygiene and good online practices.
We’re particularly pleased about the cyber hygiene element of the ‘Digital Skills’ theme. We're on a mission to make cyber hygiene part of everyday life. A bit like brushing your teeth or leaving the house with a facemask.
How can you get involved?
Getting involved in ECSM 2020 couldn’t be easier. Simply head over to https://www.cybersecuritymonth.eu/ and book yourself onto some of the activities on offer. There’s everything from webinars to workshops and you’re bound to be able to find something to suit your business in your home country. Alternatively, why not join the conversation on social media by searching for the hashtag ‘#cybersecuritymonth’?
Let’s make 2020 the year we all improve our understanding of cybersecurity.
Looking to improve your cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.
Today is a very proud day at CyberSmart. In a time where we could all do with cheer, we’ve got great news. We’ve won UK Innovative Vendor of the Year at the 2020 CompTIA UK Spotlight Awards.
Who is CompTIA?
CompTIA is a global not-for-profit trade association, promoting excellence in the tech industry. As part of CompTIA’s mission to elevate the best the tech world has to offer, it hosts an annual award ceremony celebrating outstanding contributions from the previous year.
What’s the award for?
CompTIA’s Innovative Vendor of the Year award is open to any tech business that has demonstrated innovation – whether within their own business, working with clients or impacting the wider industry.
For 2020, the awards had an extra element. Candidates who have shown leadership in their community or industry during the pandemic have been given special consideration.
We’re honoured to have won Innovative Vendor of the Year. Our mission has always been to address the ‘cyber privilege gap’ between large enterprises who can afford the best in cybersecurity and SMEs who are often left behind.
The COVID-19 crisis has made our work more important than ever. As many SMEs switch to permanent remote working, they’ve become a prime target for cybercriminals. And good cyber hygiene and access to cybersecurity knowledge have never been more vital to protecting small businesses.
To win an award which recognises our own small contribution to a safer digital world is an honour. But it's also a great motivation to double down on our efforts in 2021.
We’d like to thank our backers, everyone at CyberSmart who made this nomination possible and, of course, small businesses everywhere.
Are you a start-up looking to improve cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.
According to government statistics, the UK has a cybersecurity problem. More specifically, a ‘skills gap’. But what do we actually mean by a skills gap? How did we get here? And, what can smaller companies do to address it?
What do we mean by a ‘skills gap’?
Although the phrase ‘skills gap’ is a neat way to describe the problem, it’s a little vague. Whose skills are we talking about? Does it mean that every small business should have a bonafide cybersecurity expert in-house?
Let’s dig a little deeper.
The Department for Digital Culture, Media and Sport (DCMS) defines the skills gap as businesses ‘lacking staff with the technical, incident response and governance skills needed to manage their cybersecurity.’
The DCMS backs this definition up with some pretty alarming statistics. 48% (some 653,000) of businesses in the UK have a ‘basic’ skills gap. This means they lack the confidence to carry out the fundamental security tasks laid out by the Cyber Essentials scheme. These include things like setting up configured firewalls, storing or transferring personal data, and detecting and removing malware.
But the problems don’t end there.
Approximately 408,000 businesses (30%) have more ‘advanced’ skills gaps. These include areas such as penetration testing, forensic analysis and security architecture. Another 27% have a gap when it comes to incident response.
To get to the bottom of why the UK has a cybersecurity skills gap, we have to look back. Way back. Specifically, we’re heading to the 1990s – a decade of Britpop, Blairism and bad fashion, and when the internet began to take off as a public utility. Of course, the internet had been around in some form for much longer, but the late nineties marked the point when businesses and consumers really started to use it.
At the dawn of the modern internet, cybersecurity knowledge was mostly confined to the experts. Universities were just beginning to offer qualifications in the subject and some of the more forward-thinking businesses were offering staff training. But, for the most part, cybersecurity expertise was the preserve of academics, tech companies and a handful of specialist firms.
Fast forward a couple of decades and not much has changed. Even though every business and individual now uses the internet for nearly every daily task, cybersecurity teaching in schools remains in its infancy and optional most of the time. Many universities now offer cybersecurity courses but it is a niche subject, usually studied by postgraduates. Meanwhile, few businesses offer anything more than rudimentary cyber skills training that usually culminates in ‘switch your antivirus on’.
All of these things combined have created a world in which very few of us know much about cybersecurity. In turn, this scarcity has made cybersecurity expertise one of the most sought after skills in the UK economy.
For SMEs, hiring your own in-house expert is prohibitively expensive. And even outsourcing the problem to a specialist firm is still likely to take an almighty bite out of your IT budget. So, short of humming loudly and pretending the problem doesn’t exist or heading back to school, what can small business leaders do about it?
What can SMEs do about it?
Some things will always require calling in the experts. If your business is covered on the basic skills front but needs more advanced knowledge, you’re probably not the average SME and it’s worthwhile consulting with specialists or hiring an in-house guru. However, for everyone else, there’s a lot you can do to protect your business without in-house skills or eye-wateringly expensive expert help. Let’s take a look at some options.
Take a government-standard certification
The UK government has been worried about our collective lack of skills for a while now. In the past few years, you’ve probably seen or read news reports about encouraging kids to study STEM subjects and learn basic coding skills. But while these are noble aims that will improve society tremendously in 10-15 years, we need a solution now.
So, back in 2014, the UK government created the Cyber Essentials scheme. The scheme covers the essential actions every business should take to ensure it’s digital security and protection from cyberattacks. Think of it as ‘cyber hygiene’ – a bit like washing your hands, brushing your teeth or wearing a face mask.
And this approach really works. Research from the University of Lancaster reveals that businesses can mitigate cyber risks by as much as 99%. What’s more, the certification process is relatively straightforward. The entry-level Cyber Essentials certification is a self-assessment that can be taken and passed in as little as 24 hours.
The more advanced version, Cyber Essentials Plus, includes an onsite or remote assessment from an expert and is a little more complex. However, this can also be completed for little cost in a few days.
If you’re unsure of which is right for your business, take a look at our handy guide covering the differences in more detail.
Automate the problem
Cyber Essentials certification is a great starting point. But your business’s cybersecurity requires year-round maintenance. It’s a bit like your car or bicycle. You might put it in for a service or MOT once a year, but in the period between visits to the shop, components wear out or break, leaving your vehicle less than roadworthy. The same is true of cybersecurity. It’s very unlikely that nothing will change in the year between Cyber Essentials certifications. Software will need to be updated, new devices are added, and previously unknown threats emerge.
Tackling this manually is a job in itself, one that few SMEs have the skills, budget, or time for. Fortunately, you don’t need to run out and nab a recent cybersecurity graduate from your local university. Tools like the CyberSmart Active Protect can keep an eye on your cybersecurity for you all year long. This automated software continually scans for vulnerabilities, such as out-of-date software, incorrectly configured security settings and switched off defences. All you need to do is flick a switch if something’s not right, and the platform takes care of the rest.
The UK’s cybersecurity skills gap will shrink. Heavy investment in the sector and the generation of burgeoning experts in our schools and universities point to a more secure future. However, this doesn’t mean we all have to wait until 2030 to do business safely. There is plenty your business can do today without expert knowledge.
Are you looking to improve cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.
But away from the big headline stories, there’s another side to 5G. It’s a potential gamechanger for small businesses.
What benefits does 5G offer to small businesses?
5G provides a host of benefits to small businesses, ranging from the simple to the fantastical.
Speed
5G networks are engineered to be fast. Really fast. The most transformative part of 5G is its ability to reduce the time (or ‘latency’ if you prefer the techy term) it takes for data to get from one point to another. 5G promises speeds up to seven times faster than the fastest 4G browsing experience.
For small businesses, this could improve everything from communication with customers to remote working to video conferencing.
Smart offices
The term ‘smart office’ was all the rage a couple of years ago. We were promised a world of self-booking meeting rooms, automated energy controls and desk-monitoring software. The theory went that this would usher in a new era of happy, engaged employees, optimised office spaces, and reduced real estate costs.
However, at the time, the technology to truly automate the office environment wasn’t quite there. With 5G, that’s all about to change. The availability of superfast internet could finally make smart offices available, for very little cost, even to small businesses.
5G’s low latency could transform the way businesses communicate. Imagine a world in which your interactions with customers, staff and employees took place instantly, wherever they are in the world.
No more waiting for emails to come through. Files uploaded to shared drives in seconds. And, video conferencing that doesn’t freeze every five minutes. That’s the future 5G promises.
Remote working
Unless you live in Sweden or have been extremely lucky, chances are you’re reading this at home. Most businesses have had to learn how to work remotely in the last six months. And, for the most part, we’ve all adapted well.
However, we’re all familiar with the problems working from home presents. How well you’re able to work remotely largely depends on the quality of your internet connection. The additional capacity and speeds 5G offers could change this. Instead of playing the postcode lottery, employees will be able to access high speeds and low latency in even the worst internet black spots.
IoT
The internet of things (IoT) is another term you’ll have heard a lot in the last few years. But beyond many of us using voice-controlled devices in our homes, it’s yet to really take off.
5G’s improved connectivity will allow businesses to link up everything from printers and smartphones to office monitoring software.
The bottom line
In short, 5G will make small businesses more efficient, extending their ability to do more with fewer resources and in less time. And this won’t just save costs, it’ll also improve customer experience and boost revenue as a result.
What risks does bring 5G bring for SMEs?
Unfortunately, the benefits of 5G apply to cybercriminals as much as they do businesses.
More attacks
Although stronger, faster connections are a boon for small businesses, the same is true for cybercriminals. As businesses use 5G as a platform to innovate, so will the bad guys. 5G provides a better tool to launch sophisticated cyberattacks faster, more efficiently, and in greater numbers.
More opportunities for cybercriminals
5G enables greater use of IoT devices. And this will have huge benefits for small businesses.
Gartner predicts that there will be 20.4 billion IoT devices in use globally by the end of this year – just in time for the widespread launch of 5G.
However, with more connected devices, comes more opportunities for the bad guys to break in. It only takes one poorly secured device for cybercriminals to find their way in. And, while it’s always been the case that one weak link is enough, IoT devices increase the risk simply because there are so many of them.
Decentralisation could lead to disruption
This risk is a little more complex, so bear with us while we run through a short history lesson on network security.
Traditionally, networks were hub and spoke designs. Essentially, everything flowing through a network eventually came back to the central hub, usually a data centre. This made practising good cyber hygiene pretty simple, as you could protect everything from this central point.
With 5G, these ‘hubs’ are decentralised to a web of digital routers throughout the network. This means that there isn’t a central point where everything can be checked and cybersecurity protocols put in place. Instead, this needs to be done throughout the network, upping the chances security will be overlooked and cybercriminals given a route in.
What should you do to protect your business?
Although some of the risks we’ve outlined above are the responsibility of internet service providers, you should never rely on secondhand security alone. There are plenty of things you can do to ensure your business reaps the rewards of switching to 5G, without exposing it to greater risks.
Check the right security is in place
Run regular checks to ensure every device used in your business is equipped with the best security capabilities. This includes any IoT devices you’re using such as voice assistants or smart printers. Tools like CyberSmart Active Protect can help automate this process, by running a scan of all devices every 15 mins.
Make sure software is up to date
No one likes running software or operating system updates, but it is important. Often software providers will include patches to fix known vulnerabilities in updates, protecting you against new cyber threats. Ensure all software is configured to update automatically across all company devices or perform regular checks.
Get Cyber Essentials certified
According to a report from Lancaster University, the measures laid out by the UK government’s Cyber Essentials (CE) scheme can mitigate 98.5% of cybersecurity risks. If you’re not already CE certified, following the process will help you build a great base level of security before you make the jump to 5G.
Maintain good password hygiene
We say it a lot, but setting up a password policy and ensuring everyone follows is a vital step. Always use complex passwords, change them regularly, and set up two-factor authentication,
Clear security policies
If you don’t have a security policy in place for 5G and the use of IoT, now’s the time. But it’s not enough just to have a security policy in place, your people also need to understand it. Check all security policies for workers are clear, easy to follow and stored in a central location everyone can access.
5G is here. In less than four years time one billion devices will rely on it, and your business will very likely contain some of them. Of course, this brings risks. But the bad shouldn’t outweigh the good. By adopting a policy for 5G early and establishing simple, but effective security protocols you can make sure your business is primed to ride the next great wave of connectivity.
Looking to improve your cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.
CyberSmart to lead research on cybersecurity in the post-COVID workplace
As lockdown measures tighten once more, many organisations are considering a future where workers may never fully return to the office.
The COVID-19 crisis hit suddenly and with little warning. As a result, many businesses made the transition to working from home suddenly, without remote working policies and little real guidance for their employees.
There’s no doubt these hybrid home-office workplaces bring challenges when it comes to privacy and security. But with such a rapid transition, do we understand exactly what those risks are?
The three-month project is part of SPRITE+, a consortium funded by the Engineering and Physical Sciences Research Council. The project was one of several selected for funding through a SPRITE ‘sandpit'. It aims to bring together industry experts and academics involved in research, practice, and digital policy.
Why is CyberSmart getting involved?
Many SMEs are struggling to protect their people and operations in our changing world. So we've chosen this project because of its relevance to our customers. We hope it'll help us better understand new risks and develop the strategies to counter them.
As our own Ben Koppelman, CyberSmart’s Head of Research and Innovation put it:
“This is important research for CyberSmart to be involved with. We want to provide an evidence-based approach to understand what new security risks have emerged due to the dramatic shift to home working. And we want to explore the new measures taken to manage these risks.”
We’ll also be looking at how businesses can balance the security of the company with the private lives of employees. Ben added, “We want to know if employers are placing new security demands on their employees and if these demands create tensions with employees' privacy needs.”
The project group, made of academics from four different universities and two industry experts, will begin with a literature review. We'll follow this up by gathering evidence directly from organisations and their employees. To gain a picture of the whole economy, we won't just be focusing on SMEs. We'll try to compare how home working has affected both large and small enterprises.
The academics will take the reins on research. However, we’ll offer support as an industry partner, provide access to SMEs, and contribute to the risk analysis.
Looking to the horizon
The project is part of our horizon scanning work. We’ve been hard at work behind the scenes to better understand how COVID-19 is impacting digital transformation. In time, this research will inform our own innovation plans. But, more importantly, it'll help us offer new security guidance to our customers.
Are you looking to improve cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.
CyberSmart nominated for UK Innovative Vendor of the Year
We’re proud to announce CyberSmart has been nominated in the UK Innovative Vendor of the Year category at the 2020 CompTIA UK Spotlight Awards.
Who doesn’t love an awards ceremony? The sense of camaraderie with the other nominees. The tension. And the chance to celebrate this year’s greatest innovations in a room full of like-minded people.
So we’re delighted to have been invited to the 2020 Comp TIA Awards. CompTIA is a global not-for-profit trade association, promoting excellence and standards within the tech industry.
What's the award for?
The Innovative Vendor of the Year award is open to any tech business demonstrating innovation or an approach that has transformed their organisation, a client's, or the wider industry. For 2020, candidates who have shown leadership in their community or organisation during the COVID-19 crisis will be given special consideration.
We’re particularly excited to be nominated in the innovation category. The COVID-19 crisis has brought the importance of good cyber hygiene into sharp focus. With many small businesses working remotely, cyber threats are on the rise. And these conditions have made our mission to help SMEs better protect themselves more crucial than ever.
What does the future hold?
We started CyberSmart with the goal of innovating a much-neglected part of the UK economy: cybersecurity for SMEs. This nomination is confirmation that we’re on the right track.
But we won’t stop here. We’re determined to be a force for good in the world. We won’t rest until good cyber hygiene is part of every SME's daily routine – much like brushing your teeth or washing your hands.
We’d like to thank our backers, everyone at CyberSmart who made this nomination possible and, of course, our customers.
Are you a start-up looking to improve cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.
Playing politics: customer spotlight on Play Verto
‘Fun’ isn’t a word often associated with politics. Many of us tend to think of it as a game played by powerful people in oak-panelled chambers, far away from the reality of our everyday lives. And, it’s this feeling that has led to widespread disengagement from politics and distrust in our institutions. But what if politics was a game we could all play?
CyberSmart client, Play Verto, seeks to answer that question. The social enterprise specialises in improving community engagement through gamification. Its app, Verto, allows the public to express their political views by answering questions in a play-based format.
By combining technology and play, Play Verto is creating a space for wider participation and plurality of opinion in politics.
However, handling public data brings cybersecurity challenges with it. We sat down with Ben Pook, Director of Play Verto, to discuss these and how using CyberSmart Active Protect has helped overcome them.
What are the security challenges you’ve faced as a startup?
When you are in the start-up space, you tend to play many different roles and you are thinking a million things. You quickly learn that you need to be agile to accommodate that. However, data security is not something you want to play about with. There is often a lot to consider, which can easily be forgotten or simply not considered at all.
Play Verto is a data-led decision-making company. So, inevitably, we deal with a lot of sensitive data. Our customers depend on us to safeguard this, ensuring it’s collected and stored securely. The company also emerged around the time that GDPR was coming into place, raising another challenge.
How did CyberSmart help you resolve your security challenges?
Cybersecurity is an intimidating subject, especially when you lack rudimentary knowledge. What we like about CyberSmart is that they ‘dumb-down’ cybersecurity and compliance for you, providing an easy step-by-step guide to make sure you have all your bases covered. They walk you through GDPR, Cyber Essentials as well as ISO27001.
It’s also helpful in the sense that it allows you to say, ‘hey, have you thought about this?’ and if not, here is what you should do. It doesn’t matter that you don’t have years of experience working in information security or the means to hire a specialist.
How far is Play Verto into setting up CyberSmart?
We’ve gone through the whole process and we have the certificates. It’s given us a kick-start; we now use the tools and information offered by CyberSmart to constantly re-evaluate our compliance and security.
In fact, it’s become part of our routine. Whenever we onboard someone new, they go through CyberSmart’s training and install the app on their devices to ensure they meet our security standards. We also have a fortnightly team meeting on cybersecurity.
Our company culture has become much more security-focused thanks to CyberSmart.
What role has CyberSmart played in your relationship with customers and partners?
The impact of not having the right security measures in place is massive. Our customers and partners rely on us to keep their data secure. CyberSmart offers an additional service that is critical in giving both ourselves, as well as our customers, peace of mind.
When we take on a new client, they want to understand how we collect data, how we store it, where it is stored, which servers we are using etc. With CyberSmart, all of that information is one place and easily accessible. What’s more, the certificates themselves are a demonstration that we take security seriously in the eyes of our customers.
What cost and time benefits have you experienced since using CyberSmart?
Well, I think it really comes down to ‘what is the cost of not using it?’. We have a pretty good security culture in our company, but it costs to be ignorant. I would rather be the fool that asked than the fool that wished he did.
CyberSmart’s monthly subscription is also perfect for those in the start-up space. Shelling out thousands of dollars in one go is tricky for a small business. The subscription model makes CyberSmart’s tools accessible to organisations in a similar position to us when we first started.
What advice would you give to someone looking to tackle similar challenges to those you’ve faced?
To be honest, I’d probably recommend CyberSmart, particularly because of their customer service. The team is amazingly responsive and there’s no such thing as a silly question. It almost feels like a personal relationship, they do a great job of building a rapport.
Are you a start-up looking to improve cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.
9 signs your business has been hacked and what to do about them
It’s the stuff nightmares are made of. What started as another mundane Monday afternoon has suddenly morphed into one of your worst-case scenarios. Your business has been hacked. The scariest part is that you may not even notice. If you’re lucky, you may receive a ransomware notification or a good samaritan might inform you but often the telltale signs of a breach are more insidious. Here’s how to spot and tackle them.
9 warning signs you've been hacked - and what to do about them
Unexpected changes to files
Many modern businesses allow for organisation-wide access to documents and real-time editing. Think tools like Google Docs or your Microsoft 365 package. Telling the difference between colleagues’ tracked changes on that ten-page report you wrote and more nefarious activity can be tricky. But it’s not impossible.
Look for revisions outside of what you’d normally expect. For example, document name changes, or files that have been mysteriously deleted. Like fingerprints at a crime scene, all of these could point to a hacker’s presence.
What to do: To keep the hackers at bay, start by changing all company passwords, installing encryption software and double-checking everyone is following your security policy. If the problem persists, consider speaking to an expert.
Spam emails sent from company email accounts
No one likes spam. It’s annoying and nothing turns off a prospective customer more quickly than a deluge of unwanted emails. But if you suddenly start receiving complaints from customers or unsubscribe numbers start climbing, it’s also a sure sign you’ve been hacked.
What to do: Keep a close watch on your outgoing emails. It’s likely your marketing team are already tracking emails for key metrics, so ask them to keep an eye out for anything that looks out of place. On an individual level, regularly check the sent folder in your emails for messages that you don’t remember sending or look spammy.
If you do discover something’s wrong, follow the steps we outlined above for file changes.
It’s generally known that most hackers are out for one thing: money. So one of the most important places to regularly check is company bank accounts. Check business statements regularly for unusual withdrawals or payments from your account. If you do spot anything, there’s a very real chance you’ve been hacked. And, remember, cybercriminals won’t necessarily steal large amounts. One of the most successful small-scale hacks of recent years involved a cybercriminal stealing from multiple businesses, a few ill-gotten cents at a time.
What to do: If you do find irregularities, change passwords for all company accounts, turn on transaction alerts and contact your bank – most will reimburse any stolen funds. Unwelcome installations
It can be difficult to keep track of the various tools and software everyone within your business has installed. This is particularly true in the frenetic world of an SME or startup. Nevertheless, there’s a big difference between the tools your people need and unwanted software no one remembers installing. Sometimes this software is completely harmless. We all accidentally install a browser add-on now and then. However, there’s also a chance that if someone doesn’t remember installing something, it’s been added remotely by a cybercriminal. What to do: The fix for unwelcome installations is a simple, but time-consuming, one. Perform regular checks on the software and toolbars in use on all company devices. And, if you find any applications that look strange or aren’t in use, uninstall them.
Random pop-ups
Like it’s equally irritating cousin, spam, we all hate pop-ups. We hate them so much that more than 600 million devices (or 11% of all the devices in the world) are currently using an ad blocker. However, there might be something more to the pop-ups you’re seeing than an annoying sideshow. If you’re getting popups from websites that wouldn’t usually generate them – particularly, reputable ones – it could indicate your system has been compromised.
What to do: Unfortunately, there’s no quick fix for this problem. The best way to clean up your systems is to manually delete any software or toolbars you haven’t installed yourself (see above). At this point, it’s perfectly acceptable to let out a long sigh.
Company devices behaving strangely
When we talk about ‘devices behaving strangely’ it’s important to stress we don’t mean the ‘Wednesday afternoon go-slow’ your laptop experiences from time to time.
We mean really strange behaviour. For example, your mouse cursor moving of its own free will or random flickering on your monitor. Both of these things could indicate something much more serious is going on. What to do: If you do notice your device behaving strangely, it’s time to call in the experts. Disconnect your device from the internet, power it down and turn your router off. Although these steps won’t undo the breach, they will at least stop hackers inflicting any damage before you get expert help.
Internet searches being redirected
We mentioned earlier that most hackers are interested in making money, and stealing isn’t the only way to do it. An easier, far less risky, way for cybercriminals to make a fast buck is to redirect your browser searches somewhere you don’t want to go. By redirecting your searches to another website (often the site owner has no idea the site is being used this way) the hacker gets paid for your clicks.
What to do: If your internet searches are being redirected then there’s a high chance you’ve also got bogus toolbars and software installed on your device. Simply follow the same process we outlined earlier for software and that should fix things.
Changes to your security settings
Cybercriminals are clever, but that doesn’t mean they’re above crude tactics. And top of the list of ‘obvious but effective’ hacker tactics is turning firewalls, ad blockers and anti-virus tools off.
Keep a close eye on your security settings. If something is turned off that shouldn’t be, it’s most likely just down to human error. However, it’s well worth switching it back on and seeing what happens. If the same thing happens again, it could mean you've been hacked. What to do: By far the best thing to do is back up any files that aren’t already and do a complete system restore. There’s no telling what has happened without expert help, so the first step should always be a complete reset of any affected devices.
Confidential data has been leaked
Of all the warning signs on this list, discovering confidential company information has been found in an online data dump is the most obvious. Unfortunately, it’s also very tricky to fix. What to do: The information is already out there, so your actions need to be more about reputation management and preventing it from happening again, rather than addressing the immediate problem. If the worst should happen, it’s time for a full audit of your security procedures, policies and infrastructure.
Defence starts with prevention
It might sound cliched, but the best cure for being hacked really is prevention. Relying on anti-malware tools will only get you so far. The real gains are to be made in ensuring you have clear security protocols that prevent common mistakes, using tools like encryption and two-factor authentication, and checking company devices continually.
Don’t wait until one of these warning signs appears. Instead, think of cybersecurity as you would office security. The more often you check doors and windows are properly locked and know exactly who has access to the keys, the less likely you are to suffer a break-in. Why should your cybersecurity be any different?
Looking to improve your cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.
After months of preparation, countless workshops and a fair few late nights, we’re delighted to announce the launch of our new branding and website.
What’s changing?
Everything. We’re unveiling a brand new look, website and vision to take us forward into the next stage of our development. Here’s CyberSmart CEO and co-founder, Jamie Akhtar on what the rebrand means:
“Our mission has been and always will be to make security accessible for every organisation. We want to see a world where every business, no matter how small, can be cyber secure. Our new branding aspires to reflect this.”
Why the rebrand?
The last few months have really brought home the importance of good cyber hygiene. With businesses from Tyneside to Truro working from home due to COVID-19, it’s never been more crucial that everyone has access to the tools they need to stay cyber secure.
So, it’s time our branding reflected our vision, as our Chief Growth Officer, Sam Soares explains: “We have gone beyond the look, the logo, the colours. The CyberSmart brand has been reimagined from the ground up, looking into where we are heading in the future. COVID has ushered us into a new world- one where proper cyber hygiene is no longer an option for businesses. Our new vision is to build a safe and healthy digital society.”
We couldn’t have done it without our friends over at Outfly, a pioneering design agency who, like us, specialise in helping SMEs achieve their vision.
What does this mean for our customers?
For the time being, the way you access the CyberSmart Dashboard won’t change. And neither will the functionality within it. However, we’ve got big plans for the future and the rebrand is only the beginning. We’ll be revealing more over the next few months, so keep your eyes peeled for news. In the meantime, if you haven’t seen the branding, take a look around our new site.
How to protect your business from brute-force attacks
According to new research from cybersecurity and antivirus protection firm, ESET, remote working has brought with it a sharp global increase in ‘brute-force’ attacks on small businesses. But what is a brute force attack? Why are they on the rise? And what can you do to protect your business?
What is a ‘brute-force’ attack?
Cybersecurity terms rarely do what they say on the tin, but a ‘brute force’ attack is precisely what it sounds like. Brute force attacks break into systems by trying millions of possible passwords or ciphertexts in the hope of guessing correctly. Once upon a time, this was a time-consuming (and incredibly tedious) manual task. Think: hacker sitting in a darkened room, deep into the early hours with nothing but extra-strong coffee for company. However, new technology has made our hacker’s job much easier.
Most modern brute force attacks use automated software or a bot that can run billions of combinations of numbers, letters and symbols repeatedly. Statistically, eventually, the combination will be correct and crack the code, granting hackers access to whatever they’re looking for.
The five most common types of brute-force attack
Brute force attacks typically take one of five approaches. 1. Simple brute-force attacks
The old school approach. Hackers attempt to logically guess your details, without the aid of software or a bot. This approach is only useful for cracking simple passwords or attacking victims the hacker knows.
2. Dictionary attacks
In this form of attack, a hacker picks a target then runs possible passwords against their username. It’s called a dictionary attack because some hackers will quite literally run through an entire unabridged dictionary, adding special characters in as they go. As you can imagine, this approach is incredibly slow work without the help of an automated program.
3. Hybrid attacks As the name suggests, hybrid attacks combine approaches one and two. Cybercriminals use this tactic to figure out passwords that mix common words with random characters. For example, ‘padlock1234!’ or ‘opensea3me456’.
4. Reverse brute-force attacks
A reverse attack starts with a known password rather than a username. Once they have a password, hackers will trawl millions of usernames until they find a match. This form of attack is becoming more frequent and often starts with a password sourced from existing leaks of user data. 5. Credential stuffing
Many of us use the same password across multiple websites. We know it’s bad practice, but human memory only extends so far. Unfortunately, hackers also know this and use credential stuffing to take advantage. Once they have the password/username combination for one site, they’ll try it on anything else they can think of including your online banking, social media and email.
What’s in it for cybercriminals?
Brute-force attacks are high-effort, low reward most of the time. Until recently, many cybersecurity experts were predicting attacks of this kind would only become rarer due to their lack of sophistication and the effort involved. So what’s in it for cybercriminals?
Sensitive data – This one’s pretty simple. A successful brute-force attack can unlock a treasure trove of data. Most companies store everything from employees’ personal and bank account details to tax information and confidential corporate data – all of which can be sold on for profit or used to steal employees’ identities.
Ransomware – Brute force attacks are perfect for installing ransomware on company systems. Again, the core motivation here is profit. Once the hacker is in and has installed their malware, they can threaten to release sensitive data or cripple internal systems until you pay a ransom. Hijacking your website and devices – There tend to be two reasons why criminals are interested in hijacking a business’s website or devices. The first is computing power. All that malicious activity takes a lot of computing power, often more than hackers have at their disposal. So, one way around it is to infect an army of unsuspecting devices with malware to form a ‘botnet’ network to power it. This army can then be used to run everything from phishing scams to more brute-force attacks.
The second reason is advertising. With access to your website, cybercriminals can cover it in spam ads to generate profits from clicks or reroute traffic to their own site.
Why are brute-force attacks becoming more common?
As we tackled in a recent blog, the shift to remote working during the COVID-19 pandemic has brought with it extra cybersecurity risks. Many employees are working on unsecured or poorly secured home networks and devices. Businesses just haven’t had time to develop clear cybersecurity and password policies in all the COVID-related disruption. And, as research has shown, many employees think they can get away with riskier behaviour while working from home. All of these factors combine to produce a hackers dream. Employees are simply more vulnerable to attack working from home, putting their employers at risk too.
How can your business protect itself?
Brute-force attacks are on the rise, but being breached needn’t be inevitable. Fortunately, attacks of this kind are quite easy to protect your business against, provided you follow a few simple principles. Maintain good password hygiene – Making every password in your business as hard to crack as possible will protect you from all but the most sophisticated brute-force attacks. Create complex passwords, change them regularly, and use two-factor authentication and encryption for an extra layer of protection.
Ensure your policies are clear – Many businesses are guilty of assuming staff know what bad practice looks like, without providing any guidance. This leaves too much to chance. Instead, provide your employees with clear, easy-to-follow security policies for both remote and office working.
Create a personal vs professional divide – We all use work devices to browse the news or check our bank balance from time to time. Or use our own laptop for work. The problem is, the more sites you visit and the more entry points into corporate systems and applications, the higher the risk of a breach. Encourage your people to keep work devices for work and personal devices for everything else.
Give employees the right security – The most brilliant security policy in the world won’t save your organisation if employees are using outdated software or security tools. Check your employees are regularly installing software updates and patches and all equip all corporate devices with the latest security capabilities.
Looking to improve your cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.