Mythbusting: is contact tracing safe?

We have a problem. Well, more of a puzzle. Like much of Europe, the UK is gradually emerging from the lockdown of the last few months – this is great for business, collective sanity and our social lives. But opening up brings risks. If a second wave of COVID-19 is inevitable, and many scientists think it is, how should we avoid the mistakes of our first run?

Imposing another nationwide lockdown like the one this spring risks economic ruin for an already ailing UK economy. But with a vaccination a long way off, ‘keeping calm and carrying on’ would be even more disastrous. 

One solution you’ve probably heard a lot about in the last few months is contact tracing. Or, more specifically, the new NHS COVID-19 app. Some have boldly declared the technology, coupled with testing, the answer to a return to normality. Meanwhile, others have raised serious cybersecurity and data privacy concerns. 

So, how does contact tracing work? Are privacy activists and cybersecurity experts right to be worried about it? And, are your privacy and cybersecurity really in peril? 

How does contact tracing work?

Although there are many different ways apps like this could work. For simplicity, let’s stick with how the NHS app works.

The app is incredibly simple. It uses Bluetooth to ‘ping’ any other phones (with the app downloaded) in your vicinity. The app then stores a record of anyone you’ve been in close contact with over a relevant time frame. For example, the 2-14 days symptoms typically take to appear in those who come into contact with the virus. 

If anyone receives a COVID-19 diagnosis, the app notifies everyone recorded within the infection range. It then sends a message asking users to self-isolate. 

What are the privacy concerns? 

At this point, you may be wondering what the problem is. The app seems intuitive, it has the crucial benefit of simplicity, and it’s easy to scale (after all, 79% of us own a smartphone). 

Most experts are broadly in agreement that the system is needed and a good idea. Where opinion differs is in the best way to design an app to accommodate it. 

This argument centres around whether we should be building centralised or decentralised apps to tackle contact tracing. A centralised app means that in the event a user flags a positive test result, the data from their phone is sent to a centralised database run by a healthcare body or the government. This central database then unlocks the identities of the infected person and anyone they’ve been near. 

In a decentralised model, this same process is repeated on the phone itself, meaning the government or healthcare body never receives any identifying information about app users. Instead, any data they collect is depersonalised, for example, the number of people infected and their geographic spread.

Privacy and security campaigners worry about the centralised model because it’s open to ‘scope creep’. Or, to put it another way, just because the technology is being used for benign purposes now, doesn’t mean it couldn’t be applied for mass surveillance in the future. 

The UK had planned to use a centralised model. However, partly due to these concerns, and Apple and Google declaring they wouldn’t allow its use on their phones, it’s now switched to a decentralised model. 

What about security? 

The other big concern about any contact tracing app stems from whether its data is completely safe from cyber attacks. A recent report from two academics specialising in cybersecurity, reveals that contact tracing apps may have some unforeseen vulnerabilities.

We won’t delve too far into the technical reasons behind the findings. In essence, most of the models for apps we’ve seen from governments so far transmit encrypted and unencrypted data side-by-side. Security experts fear that this could mean would-be hackers have an ‘in’ to identify individual users and steal their data.

Are your cybersecurity and privacy really at risk? 

We’ve outlined some of the security and privacy concerns about contact tracing apps, but how at risk is anyone who uses one?

Privacy – Had the UK government pushed ahead with its plan to use a centralised model, this would have been a very different article. However, the move to a decentralised approach has mitigated most privacy concerns. 

A decentralised app won’t share any personal information about you. It won’t share your geographic location with any third party. And, from an inter-user standpoint, the design shouldn’t allow anyone to work out who in their recent contacts has become symptomatic. 

Security – This issue is a little thornier. The questions raised by the report we mentioned earlier haven’t gone away, but at this stage, they remain theoretical problems rather than something users are reporting. What’s more, the GCHQ National Cyber Security Centre (NCSC) is aware of the findings of the report and is working towards fixing them. 

Contact tracing apps aren’t perfect, but it’s a balancing act. As with any state-run technology, they face questions about privacy and security. On the other hand, the risks to privacy are small and security is only likely to improve as the technology does. More importantly, contact tracing has enormous potential to help us get back to something more like the pre-COVID world. So perhaps the real question is can we afford not to use it? 

Looking to improve your cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.

CyberSmart forges new channel partnerships to reach SMEs

We are delighted to announce two exciting new partnerships this week at CyberSmart. The first with Ingram Micro Cloud, part of one of the world’s leading channel distributors (IMUK), and the second with Synaxon UK, one of Europe’s largest channel buying groups.

Through these partnerships, we are extending our reach to allow us to help many more SMEs who are struggling to balance the demands of their business with the risks of cyber security.

“The team at CyberSmart is thrilled to be teaming up with new partners to do what we do best, and that is to defend the underdogs,” says Hugh Furness, CyberSmart’s Head of Channel Strategy.

“SMEs are often neglected in cybersecurity. With a lack of resources and expertise, they are an easy target for bad actors. With the help of these partners’ help, we hope to extend our reach and foster a strong security culture across the channel.”

The streamlined CyberSmart service makes it easy for any business to achieve the UK government-backed security certifications including Cyber Essentials, Cyber Essentials Plus, and IASME-GDPR. And the prevention of cyber attack doesn't stop at certification. A compliance software ensures every device, personal or professional, used by a business is always secure.

Timing is everything

Cyber security is more important than ever. As the UK begins to reopen and offices welcome staff back, many businesses have emerged from the crisis into a hybrid world. The mix of remote and office working adopted by many organisations brings with it new security risks.

A recent report from VMWare reveals that 91% of organisations have seen an increase in cyber attacks as a result of employees working from home. Online protection has become more important than ever before, but many businesses, especially smaller ones, still find the idea of it daunting.

"Cybersecurity is a huge issue and the importance of achieving Cyber Essentials certification and demonstrating that you are ready to protect your organisation, employees, and data, has never been greater," echoes Mike Barron, Managing Director of Synaxon UK. “Our partnership with CyberSmart has come at exactly the right time. With more companies now operating virtually and most employees working at home, that’s becoming crucial. We've received an immediate and extremely positive response from Synaxon UK members who are using CyberSmart to get certified themselves and encouraging their customers to follow their lead.”

“Adding to our Cyber Security portfolio, CyberSmart aligns perfectly with our desire to create a unique environment in which our partners get the best in-house solutions, services and support,” concurs Colin McGregor, General Manager – Cyber Security, Ingram Micro UK, “We’re excited to show our partners just how we can facilitate their cyber needs, with CyberSmart no doubt contributing to this success."

The CyberSmart team believes that every organisation should be able to easily comply with recognised standards to protect their data and infrastructure. Synaxon and IMUK will help us deliver that ability to many more businesses.

About our new partners

Ingram Micro Cloud (IMC), a division of Ingram Micro UK Ltd, was established in 2014 to help its partners realise their share of the cloud market opportunity. Ingram Micro Cloud is a master cloud service provider (mCSP), offers channel partners and enterprises access to the leading global Cloud commerce platform, expertise, solutions and enabling programmes that empower organisations to realise their potential in the digital economy. Ingram Micro Cloud is the leading Cloud aggregator in the UK and a software company that is the powering engine for the channel.

Synaxon UK was launched in the UK in 2008 and has since become firmly established as the market-leading channel services group. Synaxon is much more than a dealer buying group. It’s a thriving, dynamic and forward-thinking community that works to advance the development and growth of its members. Synaxon offer a wide range of services as well as personalised account management and business development support to help MSPs, resellers, retailers, and office products dealers thrive.

New webinar: Staying cyber secure as the UK reopens

We’ve all read the headlines about ‘unprecedented times’ and how ‘things will never be the same again’ post-COVID-19. Some of the commentary on our post-pandemic world might seem a little overblown. However, for cybersecurity at least, a lot of it rings true.

As the UK begins to reopen and offices welcome staff back, businesses have emerged from the crisis into a hybrid world. The mix of remote and office working adopted by many organisations brings with it opportunity. But it also brings new security risks too
(more on that here).

A recent report from VMWare reveals that 91% of organisations have seen an increase in cyber attacks as a result home working. In this environment, online protection has become more important than ever before. But how can businesses, particularly SMEs without large security budgets, become more cyber secure?

Join CyberSmart CEO and cybersecurity supremo, Jamie Akhtar and Guy Waller, Partnerships Manager at Starling Bank as they tackle the following questions in a short webinar.

  • What are the new and existing cyber-threats for businesses?
  • As businesses reopen, and staff are working both from home and the office, what new challenges does this pose?
  • What are the best ways businesses can protect themselves and stay one step ahead?

To learn more, watch the full webinar, for free, here or below.

If changes in working practices have got you thinking about improving your cybersecurity, a great place to start is with Cyber Essentials certification. It’s a simple, 24-hour certification process that could improve your protection from cyber-attacks by 99%. Get started today here.

Get started

How to shift to working from home permanently without compromising your cybersecurity

Coronavirus has the potential to change the world of work forever.

Unless you’ve spent the last few months consciously avoiding the media, chances are you’ve read that sentence a lot. From morning talk shows to breathless newspaper op-eds, it feels like everyone is talking about the society-wide shift to working from home.

But what started as a necessary evil that many businesses adopted reluctantly has turned into something else. First came announcements from Twitter and Facebook that employees would be allowed to ‘work from home forever’ if they chose. This was followed by a host of other businesses including Google, Amazon, JPMorgan, Captial One, Slack, Salesforce, Microsoft and PayPal extending their work-from-home options.

Why is this happening?

Well, it’s actually very simple. An increasing number of businesses are seeing the real benefits of a more permanent shift to remote working.

Why rent office space for 300 people when you could use a smaller venue for essential meetings at half the cost? Why insist staff make long commutes into the office, when they’re happier and more productive working from home? 

For many organisations, the COVID-19 pandemic has turned these questions from water cooler conversations into key pillars of business strategy. 

If your business is considering making the switch to permanent remote working, are you prepared for the risks you should be aware of? And, how can you overcome them and ensure your people are working safely? 

What risks does working from home present? 

While switching to remote working offers benefits in productivity and real estate savings, it also comes with some risks. Here are a few of the most common. 

Unsecured personal devices 

The first question to ask is: can you be sure your people will follow the same security protocols they would in the office? The networks and security tools your staff use at home are likely to be far less secure than those in the office. Home office networks are 3.5 times more likely than corporate networks to be infected by malware, according to a report from BitSight. 

There may even be a psychological element to this. As ZDNet has reported, 52% of employees believe they can get away with riskier behaviour when working from home. For example, sharing confidential files via email instead of the usual, safer channels. 

Lack of remote-working policies and procedures

Part of the reason employees are exposing themselves to risk at home is simply a lack of knowledge of these risks. The COVID-19 pandemic developed so quickly that many businesses didn’t have time to put in place clear policies and procedures for working from home so employees were literally left to their own devices.

This makes cybersecurity a bit of a guessing game, particularly for the less security-literate of your staff. 

Heightened risk of attack

Cybercriminals are smart but they’re largely opportunistic. And it hasn’t taken them long to figure out that switching to remote working has made businesses vulnerable.

VMWare’s recent Global Threat Report, reveals that 91% of global respondents have seen an increase in cyber attacks as a result of employees working from home. Meanwhile, the proportion of attacks targeting remote workers increased from 12% of all email traffic in March to 60% just six weeks later. 

91% of organisations have seen an increase in cyber attacks as a result of employees working from home.

Keen to exploit our hunger for coronavirus updates, cybercriminals have set up thousands of COVID-19-related ‘news’ sites. These double up as hosts for malware and domain names to launch phishing attacks from. Without the robust controls deployed by most corporate networks, it’s incredibly easy for people working from home to fall into the trap. 

The other area cybercriminals are targeting more regularly is VPNs. VPNs have long been a weak point for cybersecurity. They were only ever intended for small numbers of workers to use occasionally, not whole companies all the time. As a result, many VPNs are insecure and provide cybercriminals with a much wider ‘attack surface’ with which to launch threats. 

Reliance on the Cloud

We talked about some of the potential issues with cloud storage in a recent blog and, while it’s the safest option for businesses, it’s not invulnerable to attack. 

Working from home naturally increases your reliance on the Cloud. And this isn’t necessarily a bad thing. However, cybercriminals are becoming better all the time at breaking through providers’ defences and intercepting data as it moves between employees’ devices and the cloud. 

How can you overcome these risks? 

We’ve tackled some of the risks involved in switching to working from home, so what can you do about it?

Provide clear policies and encourage communication

This is the most important step on this list. If your people don’t know which behaviours are harmful, they can’t correct them. Ensure all security policies for workers are clear and easy to follow. If you don’t have a remote working security policy, now’s the time to draft one.

Alongside this, work to foster a culture of communication. That way, employees will feel comfortable asking for help with anything they don’t understand and reporting anything suspicious to internal security teams. All too often, security mistakes are made because staff feel ‘silly’ raising their concerns. 

Ensure the right security is in place 

Many of the most common threats can be prevented simply by ensuring your people have the tools they need. Check that all corporate-owned or managed devices are equipped with the best security capabilities. Also, make sure that the security best practices you’d use in the office are extended to the home environment. 

Maintain good password hygiene

Set up a password policy and ensure everyone follows it. Employees should always use complex passwords and two-factor authentication, as well as change passwords regularly. 

Make sure software is up to date

Your employees should regularly install updates and patches for the software on their devices, no matter how much they might enjoy not restarting their laptop for months on end. 

Keep it professional

Encourage your workers to keep work devices for work and personal devices for everything else. Limiting the number of sites employees visit can limit the risk of attack. 

Secure Wi-Fi access points

Network gateways are an underappreciated aspect of good cyber hygiene. Most of us don’t think much about our WiFi once it’s up and running. However, changing the default settings and passwords on a router can reduce the potential of attack from connected devices.

Understand the risks

Hopefully, this article has been some help in identifying some of the risks remote working presents. But it can’t be stressed enough that understanding the risks is key to preventing them. IT teams need to identify the most likely areas of attack and prioritise the protection of areas of your business that cybercriminals could do the most damage to. 

Although the switch to working from home comes with difficulties, it’s also a golden opportunity to remould the way your business functions. Alongside, the obvious real estate savings, remote working promises happier employees, more productive work and greener business practices. Don’t let poor cybersecurity stand in the way of your business embracing the future. 

Looking to improve your cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.

CTA button

New whitepaper: Cyber Essentials for Education

If you work in education and are applying for funding, you’ve probably heard the phrase ‘Cyber Essentials' mentioned. Cyber Essentials are a set of security guidelines laid out by the UK government to help organisations address the basics of cyber hygiene.

It's important to education providers because Cyber Essentials certification is now part of the security requirements for Education and Skills Funding Agreements (ESFA).

For the 2020-21 funding year, all recipients must meet the requirements for the UK’s Cyber Essentials scheme. And next year, achieving Cyber Essentials Plus certification will also be mandatory. 

However, cybersecurity and funding requirements can be confusing. So, we’ve put together a guide to help you get certified and meet the EFSA funding deadline. The guide covers everything you need to know, including: 

  • What the Cyber Essentials scheme is
  • The difference between Cyber Essentials Standard and Plus certifications
  • Why cybersecurity is important to the education sector 
  • How to get certified immediately and meet the EFSA deadline
  • How to move beyond certification and keep your organisation protected

To find out more and get prepared for the EFSA deadline, download your free copy here or follow the link below.

ESFA CTA

Mythbusting: is your data really safe in the cloud?

Cloud storage has become an indispensable part of modern business. Yet despite the cost savings, ease-of-access, and reliable data backup it offers, some people still don’t trust the Cloud. Why not? And, do they have a point?

Why are people concerned about cloud security?

It comes down to control. When you upload files to a cloud, you aren’t saving them locally to an internal server. Instead, you’re sending potentially sensitive data to another company, one that could be hundreds or even thousands of miles away, and entrusting them to keep it safe. This might sound obvious, but for some businesses, this loss of direct control is a real concern.

Looking to better protect your business? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the basics of cybersecurity. 

What are the risks?

Are businesses right to be worried about losing direct control of their data? What are the risks associated with using cloud storage?

Security

The big cloud providers – Microsoft, Google, Apple, and Amazon – spend billions of dollars on their security each year and have some of the best defences around as a result. However, that doesn’t mean they’re infallible.

The most determined cybercriminals find a way around even the tightest defences, whether that’s through guessing security questions or cracking passwords. Even the biggest providers aren’t immune to these approaches as the infamous Apple iCloud hack of 2014 and 2019’s Facebook data breach revealed.

Alongside potential breaches of cloud providers’ infrastructure, there’s some risk involved in the process of just getting your data up into the cloud. For example, let’s say you’re using Google Docs as part of your cloud package. A hacker could potentially intercept your data as it moves between your device and the cloud. Provided you’re working with a reputable cloud provider it’s unlikely, but the risk remains.

Privacy

The other major cybersecurity risk involved in using the cloud is privacy. Even if your data isn’t stolen it could still be viewed both by employees of the cloud provider and government agencies. Governments can legally request data stored by cloud providers and it’s up to each company as to whether they comply.

Although you’ll often hear people trot out the old adage ‘if you’ve got nothing to hide, there’s nothing to worry about’, the possibility of sensitive documents being read by third parties is a valid concern. 

Do the risks outweigh the benefits?

So, do the risks of storing your data in the cloud outweigh the benefits?

In short, no. To illustrate why, ask yourself whether sensitive documents and information would be safer stored locally on company-owned servers or devices? Invariably, the answer is no. 

Consider the typical IT infrastructure within a small business. It’s often housed in the same building employees work and is accessible by anyone who works for the company. This not only makes the job of cybercriminals far easier but it also increases the likelihood of a data breach due to human error.

Now contrast that with a large cloud provider. Cloud servers are housed in huge, well-guarded data centres, often far off the beaten track and a long way from providers’ central offices and staff. What’s more, the data in those servers is usually protected with complex encryption, making hacking it extremely difficult.

As for privacy, it’s again worth asking yourself a couple of questions. Firstly, would your company object to a cloud provider’s staff viewing sensitive data for troubleshooting purposes? If the answer is ‘no’, then there is little to fear. Cloud providers generally won’t view the data they store for any other reason.

Secondly, were a government agency to request access to business data would you be likely to refuse? Again, if not, there’s little difference in privacy between storing your data onsite or in the cloud. 

The verdict 

The cloud isn’t perfect. It’s far from completely secure and it’s increasingly becoming the number one target for cybercriminals who realise this. However, it is by far the best data storage option available to businesses. 

It offers a level of security sophistication streets ahead of anything a small business could afford. It’s cost-effective, allowing you to store masses of data for very little money. And, it allows your people anytime, anywhere access to the files and applications they need.

Of course, if you are concerned about the security of your cloud storage, there are extra precautions you can take. Consider setting up encryption (more on which here), two-factor authentication and implementing a strict password policy for an extra layer of protection.

Looking to improve your cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.

CTA button

Encryption explained: how does it work and why do SMEs need it?

Most of us have heard of encryption. It’s that recipe for secrecy that techy types talk about all the time. But for many of us, that’s where the knowledge ends.

However, for small businesses looking to improve cybersecurity, encryption can be a vital weapon in your arsenal- and one that isn’t so hard to understand. Here’s a simple explanation of what encryption is, why you need it, and when to use it.

What is encryption?

Although encryption, much like ‘the blockchain’, can seem like another one of those unfathomable technical terms, it’s actually pretty simple.

Encryption is most commonly used to protect data in transit and at rest. Ever sent a Facebook Messenger or WhatsApp message? That uses encryption. Or, a payment using online banking? Also encryption. How about buying something from a web store? You guessed it, encryption again.

You get the picture. Encryption is used everywhere in our daily lives, but how does it work?

In non-technical terms, encryption is a way of randomising data so that only an authorised recipient can understand the information. Encryption converts plaintext – for example, the text in an email between you and a colleague – and converts it into ciphertext, a string of random numbers and letters. To unlock the real message or data, you need an encryption key, which is a set of mathematical values that only the sender and the recipient of the message know, like so:

encryption

Photo PixelPrivacy

The principle is much the same as a password, but better (as we’ll see).

Why does your business need it?

So we’ve covered, in very simple terms, what encryption is. The next question is why should SMEs be using it? It’s easy to assume that if you’re not a huge multinational, processing reams of sensitive information, that your standard security tools such as firewalls and secure passwords are enough to protect your data. However, there are three key reasons why this isn’t the case.

Cyber attacks are on the rise

It’s likely not news to you that cybersecurity threats to SMEs are on the rise. Barely a week goes by without another news story or set of figures released to that effect. Indeed, the Federation of Small Businesses estimates that SMEs are collectively subject to almost 10,000 cyber-attacks a day.

A recent report from cybersecurity experts, Malwarebytes, reveals that detections of new malware continue to increase by 1% year-on-year.

A big part of the problem is the ever-increasing volume and variety of malware out there. A recent report from cybersecurity experts, Malwarebytes, reveals that detections of new malware continue to increase by 1% year-on-year. This might not sound like much, but when we’re talking about detections in the tens of millions, it soon adds up.

In this environment, it’s getting harder and harder to stay ahead of the threat. However, adopting encryption can act as a strong second line of defence. For instance, someone in your organisation accidentally clicks on a malware link in an email (something we’ve all done at least once), potentially exposing your data to an attacker. Using encryption means that they won’t be able to read whatever they find without a key, meaning your data is safe.

You’re using a cloud service

Cloud computing is now a vital part of the daily operations of most SMEs. And if you’re doing business entirely in the cloud, and don’t store any sensitive data on employees’ devices, you’re safe, right? After all, the likes of Amazon, Google, and Microsoft spend billions of dollars a year on the security of their cloud services.

Unfortunately, this is only partly true. Obviously storing your data in a cloud is far better than having everything on vulnerable systems, but that doesn’t mean it’s entirely safe.

To give an example, let’s say you use a cloud-based platform like Office 365 for your everyday operations. A would-be hacker can still intercept your data as it moves between your device and the cloud. As we’ve already mentioned, this is unlikely if you’re working with a reputable cloud provider, but it’s not impossible or even that uncommon. Using strong encryption can help protect you against this by adding another layer of defence.

Passwords aren’t the be-all and end-all

Now, you may be thinking ‘but my business has a clear password protection policy and we regularly change our passwords for laptops and devices, surely that’s enough?’
Not quite. While it’s true that a strong security policy can help protect your business against regular theft and even less sophisticated cyberattacks, it’s not enough to protect you from the really harmful stuff.

Hackers are always finding a way around even the strictest security policies and new methods for cracking passwords appear all the time. To be totally sure, you need an a solution that allows you to completely encode everything on your device. This means that even in the event someone does manage to break in, all they’ll be able to extract is random gobbledegook that’s little use to anyone without the right encryption key.

How do you use encryption?

Finally, let’s take a look at how you can use encryption to protect your business. Encryption can take many forms. How you use it will depend on what you need it for, but some common uses include:

End-to-end encryption – This guarantees data sent between two parties cannot be viewed by anyone else. Most of the internal communication tools such as Slack or Google Hangouts will come with this as standard, but it’s worth checking whichever messaging tool you use.

Cloud storage encryption – A service offered by cloud storage providers that transforms your data or text using an algorithm and stores it safely in the cloud.

Encryption as a Service (EaaS) – EaaS represents the next step up from cloud storage encryption. It’s the perfect tool for small businesses who want to use encryption but lack the resources to do manage it themselves. EaaS subscription models typically include full-disk, database, and file encryption.

Of course, these are far from the only uses of encryption. You can also use it to protect certain fields on your website, encrypt everything leaving or entering your web server and a hundred other things besides. The above are just the most common applications for SMEs.

Data is more important than ever to SMEs. In fact, in our data-driven economy, it’s often the most valuable asset a business possesses. Basic cyber-hygiene such as encryption can go a long way towards helping you protect it.

Show your customers you value their data by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.

Get started

A new chapter: CyberSmart raises £5.5million to fund growth

Demand from SMBs for certification drives growth to 300% per annum

We are delighted to announce that CyberSmart has raised £5.5 million which will be used to fund the growth of the company. This will enable us to continue to support small and medium-sized enterprises (SMEs) to protect themselves against cyber threats in an ever-evolving technological landscape.  The Series A funding round was led by venture capital firm IQ Capital and a group of tech-savvy individual investors.

The lockdown and shift to online working patterns means small businesses are prioritising security more than ever. CyberSmart has seen a massive increase in demand from SMEs to protect their businesses with a revenue increase of 300% over the last twelve months.

Here's what our CEO, investors, and partners have to say about this exciting news:

Jamie Akhtar, CEO CyberSmart says, “We are delighted to have closed our series “A” funding round with £5.5 million to fund our next stage of growth. Our investors have seen that we have built a great technology and also a great team. The SME market has not been easy to protect until now, and business owners have so many issues to deal with they often wait until it is too late, losing all their customer data or even cash in a cyber-attack. We take all the effort out from a business becoming secure, so it’s not as painful, time-consuming, or as expensive as one might think. People can have effective, comprehensive security and risk-reduction from a team that is there to support them through the challenges of transforming into a digital business.” 

Kerry Baldwin, Partner IQ Capital says, “What we like about CyberSmart was the automated solution to secure companies and make them compliant with certifications like Cyber Essentials, and that it reaches the underserved SME market that we felt just wasn’t being protected. When we see signs that a company has found product market fit, is way ahead in hitting its targets and is finding innovative partnerships with managed security service providers to deliver massive market penetration then we know it is a great time to invest and secure our position.  In the current situation there has never been a greater need for making sure that remote teams and small teams working from home are protected in an automated, effective affordable way.   Obviously the UK has got Cyber Essentials, but other countries have other similar certification requirements, so they solve a problem that is faced in many countries so this company will be going global as soon as possible.

Przemek Pardel, Startup Acceleration Programs Lead Europe, Google says, “CyberSmart is working hard to provide clear and simple cyber security solutions to small and medium enterprises across the globe. They have shown great determination to better their technical capabilities and further scale their product, which has been evident from their participation at our accelerator program for cyber security startups and their recent Series A funding success. We are excited to see how they will evolve and grow after they graduate from the accelerator.”

Joanna, Program Lead at CyLon says, “Great product, dedicated team and seamless execution. These three aspects of CyberSmart put together create an exceptional combination with plenty of room to grow in the future. We at CyLon as proud early adopters of CyberSmart can’t imagine our organisation without it.”

Akhtar continued, “I set up CyberSmart was after witnessing first-hand how SMEs suffer data breaches and realising that hundreds of thousands of businesses were suffering cyberattacks.  When we started, 74% of SMEs had a breach that year, if 74% of buildings caught fire, there would be fire stations on every corner.  The technology is now there that enables us to automate protecting SMEs and by implementing a cloud-based platform that is both simple and cost effective to deploy, backed by a Cyber Essentials Certification. Businesses have gone through two stages, the first phase was rapid, digital transformation which was all about connectivity, communication, basically getting your team and your company back online remotely, or online remotely.

Phase two is now. We have spent all these years building our secure, corporate infrastructure or drilling into people these secure working practices, but that has all gone out the window because everyone is now working remotely. The new focus is on how to secure teams working out of the office. So that’s the big wave which we are seeing now that has been driving demand from all types of companies. Because our technology is automated, certified, comprehensive and can be deployed, managed and monitored remotely, it's an ideal solution.

CyberSmart are working with many different types of channel partners. This represents a good opportunity to reach the SMBs. For partners there are many benefits- an income stream that also prevents churn, it makes customers more sticky. Most importantly, it makes customers more secure which helps with cyber hygiene across the whole UK business supply chain.”

The Cyber Essentials certification is recommended by the ICO and Federation for Small Businesses, and it’s required of suppliers to central and local government. Implementing its security controls can mitigate up to 99% of cyber attacks.

Akhtar continued, “Technology and automation are the way forward. By deploying a smart application that runs on all the devices no matter where people are or which device they are using, we can ensure security 24/7. This is what we mean by automated compliance. We offer a simple path to certification, but we also make sure you are compliant with that certification every day. The application essentially does all the technical bits, so people don't have to be cyber security experts themselves. 

Chris Ensor from NCSC said: “The NCSC is proud of the success achieved by CyberSmart, which was one of the first participants in our NCSC Cyber Accelerator programme. It has won a deserved reputation for producing innovative software and for encouraging businesses to seek Cyber Essentials certification.  

“The Accelerator programme is currently seeking new start-ups and we would encourage anyone with fresh ideas to apply and help us continue to drive innovation in UK cyber security.”

About CyberSmart

Born out of the GCHQ / NCSC Cyber Accelerator in 2017, CyberSmart was created by a group of forward-thinking security experts, who noticed that many companies needed to secure themselves and achieve information security standards, but ultimately found the process too complicated or were limited by financial or human resources.

We believe that every organisation should be able to easily comply with recognised standards and protect their data and infrastructure. Through making security accessible, we have achieved tremendous growth and enabled thousands of users to protect themselves against cyber attack.

The journey of a customer query at CyberSmart

Inside the CyberSmart customer support experience with Francis Kontor, our Technical Support Lead.

One of the things we are most proud of at CyberSmart is the feedback we get from our customers about the personal support we offer them. We work hard at it because we know how important it is for our clients. We are working with small businesses, some with only a few employees and no real IT staff or expertise.

Francis Kontor, Technical Support Lead

The world of cybersecurity can look daunting from the outside and our job is to make the process of protection as easy and understandable as possible. We do this in a few ways.

We get all kinds of requests from our customers and over time we've had to expand the skillsets we use to respond to them. That has meant creating both a general customer support team and a more technical one for product-specific queries. During the course of my career, I have noticed the misconception end users have in regards to what technical supports role is within an organisation and what customer support role is and if they are the same.

Of course, from a customer experience perspective, these appear as one and the same. After all, customers don’t mind who they speak to about their issue, they just want it resolved as quickly as possible so they can move on with their day.

In this article, we give a bit of a behind the scenes look at how we process customer queries at CyberSmart so we can make sure the right expert is addressing the right questions as quickly as possible.

Customer Support vs Technical Support

Our customer support is split into two main areas: Customer Success and Technical Support.

Customer Success are the friendly team answering our phones and online chats. They do the initial fielding of questions and offer support on everything non-technical within the non-technical customer experience (payment, planning, general questions).

Any questions relating to our product (how to install it, how to configure, etc.) are answered by the Technical Support team in order for our customers to get the best value out of our product.

First-line support

When a customer gets in touch, the first level of support they receive is from the Customer Success team. They manage our FAQs page and knowledge base and use it as a tool to help customers find the answers they need for common queries. First-line support handles 40%-60% of end-user queries. They have a basic understanding of the product and the business but they aren't technicians so if there's a question they can't answer about the product, they pass it on to the second-line of support.

Second-line support (Complex Queries/Problems)
When a ticket is escalated to second line support this usually means the query or problem requires more in-depth technical knowledge of the product.

Third-line support (Bespoke support)
Third-line support largely deals with tickets that require a bespoke solution for the organisation which is experiencing technical difficulties with our product. This means we might work directly with the engineering team to build a solution to a problem for a customer. After all, if they have that need, it's likely others do too.

What is Technical Support?

Technical support is what product-focused organisations like CyberSmart use to help our MSPs & direct partners get the most out of our product. Typically, we receive queries via live chat, emails, or phone calls. We resolve technical issues such as installation (PC, MAC & mobile), dashboard login errors, and other technical issues that are causing headaches for our customers.

A third-line of support question might be something around need to do a mass installation of our app to many sites but not knowing how to configure their RMM. If we got a request like this from an MSP, we would work to build them a custom solution for mass installation that they could use for our apps and others.

In summary, CyberSmart's support team is not a call centre stocked with rote answers to simple questions. We also have the capacity to help the vision of our customers come true by making the CyberSmart product fit their needs.

Cyber security is essential for business today but the process of protection doesn't have to be difficult, time-consuming, or expensive. CyberSmart was built for non-technical businesses to serve as a full cyber security team in one product with top-notch customer support. Start protecting your business today.

Securing a remote workforce: customer spotlight on LegalEdge

LegalEdge had a remote workforce back when it was still a choice. For ten years, LegalEdge has made in-house legal services accessible to small businesses and start-ups using a uniquely flexible model and a completely remote team of lawyers.

Helen Goldberg, COO Legal Edge

We sat down with Helen to learn more about her security needs and how she uses CyberSmart Active Protect with her remote team.

What were the security and/or compliance challenges you were looking to overcome?

For the most part, the challenges we faced stemmed from the fact that all our lawyers work flexibly. On the one hand, with all that is going on now, this has put us in a fortunate position to continue business as usual. However, with everyone working from home or the coffee shop as well as using their own personal devices, this has the potential of leaving many loose ends that threaten our company’s security – a fairly unique challenge that may not be unique for long, and which CyberSmart really worked with us on.

How is security important to your organisation?

As a law firm, we’re obviously incredibly risk averse – Therefore, security has always been important to our company and is something we actively wanted to get better at. Unlike a lot of businesses, most of the people we work with are freelancers, though we have some employed staff. So, we wanted to ensure that we had that extra layer of protection, particularly as they all use their own devices.

How did you discover CyberSmart and why did you select it as your solution?

I’m on a COO network with a lot of fast growth tech companies, which has been a fantastic network for me and for a lot of the COOs on it too. That is how we heard about CyberSmart . There was a lot of discussion around GDPR at the time. The guys at CyberSmart came in and did a presentation for us. As is typical in our industry, we are fairly slow to update on tech, but we just really liked the way CyberSmart did things and how they talked about their product. Because we’ve got a fairly unique setup, it was really important for us to up our game on cybersecurity: they were just really good and helpful for us in what otherwise could have been a bit of a painful process.

Which of CyberSmart’s capabilities are most valuable to you and why?

Just that extra layer of security for our remote workforce. Our model was always flexible, but the CyberSmart guys have really enabled us to embed security into this flexibility. When I used to travel on the tube and log in at the stations to check my emails, there was always that worry that I wasn’t secure. Now I know that I’ve got the level of security that I can have, or that I need to have, to protect myself . You hear about hacking, but you don’t really worry about it until something bad happens – now we don’t have to.

When I used to travel on the tube and log in at the stations to check my emails, there was always that worry that I wasn’t secure... You hear about hacking, but you don’t really worry about it until something bad happens – now we don’t have to.

It has helped us up our game. With less tech-savvy people, you’re never sure what is or is not okay. We might think we’re secure and actually not be. CyberSmart has eliminated this ambiguity for us.

I’m working from a MacBook; some people are working from old PCs... everybody’s on different devices, including iPhones. Regardless, the guys at CyberSmart have all our bases covered. We have some IT support now, but we didn’t when we first started this journey and they were there every step of the way to help us implement it. In order to get the Cyber Essentials certification, we had to pass an important questionnaire.

This required us to put in place a fairly complex policy that explained to our people what they had to do or stop doing. For example, they could not log into their devices from a coffee shop without a secure connection. But then we brought in a VPN, which helped to resolve that issue and the team at CyberSmart worked with us to make sure we were doing all the right stuff along the way.

What kind of cost savings or benefit have you found from increased security?

It was important for us to do better with our cybersecurity, so whilst it is an investment, the cost is reasonable for a business of our size and nature. We liked what CyberSmart offered and how they conducted themselves; the fact that they came recommended from another business we knew was also very reassuring.

What advice can you give someone seeking security solutions around remote working?

Give CyberSmart a call! They have been a hugely helpful partner and their customer service is outstanding. We have clients who say: “I need somebody who’s got my back on these things” and that’s when you outsource to the right people for the right price; that’s exactly what these guys have done for us.

Learn more about how to secure your remote workforce using CyberSmart Active Protect.