Remote working best practices: what makes a strong password?

Still using the password you conjured up for your first email account in 2002 featuring your favourite footballer? We hope not. Passwords play an absolutely essential role in the security of your company and weak passwords are some of the easiest way for hackers to breach your cyber defences through employee accounts.

In this article we'll be sharing advice on how to avoid this common, but easily avoided, security pitfall.

Minimum password length for systems

For all password-protected systems, your business should try to follow these basic steps when configuring them:

  • The minimum length for a password should be at least 8 characters including all alphabets, symbols, and numbers.
  • There should be no maximum password length.
  • The system should not allow the user to set a password that does not meet the minimum length requirements for it.

The requirements mentioned above are simple to understand but can be difficult to implement. It is important to note that these rules need to be established across all password-protected devices and software.

To meet this requirement, you need to consult with your IT manager to ensure that all devices and software (whether third-party or proprietary) enforce the minimum password length.

Enforce a secure password policy

A password policy is used to establish the rules and requirements for setting passwords. Creating a secure password policy for staff helps businesses protect themselves and allows them to meet the password requirements under the government's Cyber Essentials certification scheme.

The goal of a password policy is to take away the burden of individual users to create solid passwords. However, users should still be made aware of the password policy so that they pick sensible passwords for their email, devices, and other accounts.

Other than the minimum password length requirement mentioned above, your employees should:

  • Avoid obvious passwords that can be easily discovered or guessed such as their name, phone number, birthdays. That goes for your pet's name too.
  • Not choose common passwords such as the ‘abcdefgh’, ‘12345678’. This can also be implemented through a blacklist that prevents users from keeping common passwords.
  • Memorise their passwords instead of recording them whenever possible. Don't email them to yourself or keep them in your Notes.
  • Not use the same password for different accounts. 45% of Brits have the same password for half of their online accounts. Not great.
  • Use password management software or other secure mechanisms for storing and retrieving passwords.
  • Require the system to:
    • Protect against brute-force password guessing algorithms by locking accounts after a set number of unsuccessful attempts to enter the password.
    • Change default or common passwords to random non-guessable passwords.

If you want to see how long it would take a computer to guess your current passwords, check out HowSecureIsMyPassword.

Conclusion

Ensuring the use of strong passwords is a key step towards becoming digitally secure. 

CyberSmart helps businesses comply with Cyber Essentials by simplifying the process of compliance for them including complying with password regulations. If you would like to learn more about how to implement a password policy for achieving Cyber Essentials, get in touch with us.

Practices for maintaining cyber security every business owner should know

As the span of regulations, risks, and budget evolves and your business grows, the maintenance of cyber security shouldn’t just be an afterthought – it should be part of the bedrock of your organisation.

The Cisco 2020 CISO study demonstrated that cyber security remains a high priority among executive business leaders, with an increase in investment for security automation technologies as the scale of complexity increases. 

While it’s helpful to have an automated security team in place to combat cyber attacks, there are several steps you can take as a business to protect yourself:

Strict access control (Zero Trust)

Zero Trust is a holistic information security framework and an essential component of cyber security. Rather than assuming all people and systems operating within a secure setting should be trusted, it relies on constant verification before granting access. 

This can be implemented through a series of steps. Firstly, data access should be managed by a multi-factor authentication (MFA) system. Only 27% of businesses are making use of an MFA system. 

Secondly, employees should be prompted to update devices to combat existing vulnerabilities, and user access to data management applications should be managed through central policies.

The Cisco report demonstrated that more than half of respondents noted that mobile devices are becoming an increasing challenge to defend. It suggests a zero-trust strategy as the best way to remedy this.

Updating regularly

This report showed that 46% of organisations were faced with incidents as a result of unpatched vulnerabilities. This means that a software provider issued an update in response to an issue but an employee failed to run the update.

Breaches to data management environments can cause hefty losses of data, and when patches are rolled out it is crucial to apply them immediately to limit the timeframe in which the vulnerabilities can be exploited.

Monitoring implementations

When cyber security practices are being continually developed and regulated, it becomes important to regularly monitor connectivity on the network or data applications to review how well the security measures are faring. 

Detection utilities should always be managed and routinely updated so that when incidents do arise, they can be properly investigated. Many small and medium-sized businesses have found CyberSmart’s monitoring app helpful for this purpose. It can be installed on any device and up-to-date information on every device’s security status is available through a centralised dashboard.

Centralise security essentials

The biggest factor in the growing challenge of propagating adequate cyber security is the level of complexity as a business scales. When an organisation utilises multiple security solutions, centralising them in an integrated platform reduces the complexity which makes it easier to manage, update and review security essentials. The benchmark found that 42% of respondents were more inclined to give up on maintaining adequate cyber security due to its complexity.

CyberSmart offers several ways for the cyber security of even smaller businesses to thrive, and our Cyber Essentials and Cyber Essentials Plus certification takes complexity into consideration and simplifies the process.

Everything you need to know about user authentication

What is user authentication?

User authentication is a key part of GDPR compliance and is the process of verifying human credentials to a machine to confirm the identity of the user. This usually consists of the simple input of a user ID and password, but as this is often too weak to protect important data, other factors of authentication can be added to bolster your cybersecurity.

How can user authentication be strengthened?

User authentication can be strengthened by layering cybersecurity methods to ensure that only an authorised user has the ability to access their account. This can be achieved in a number of ways:

Two-factor authentication

Two-factor authentication is a cybersecurity method in which users are required to enter a code into the system that is sent to one of their other devices, such as a smartphone. This adds another layer of security but can make the login process take slightly longer as the code might take a minute or two to be sent.

Third-party authentication

Third-party authentication is a process by which users can log in to their account via a third-party that may already have their credentials, like their social media account, phone, or email. OAuth is typically used for third-party authentication so that users can log in to a server via Facebook, Google, Twitter or a similar site. This can be easier for some users because they don't have to memorise a different user name or password for every account they create, but it is essential that their third-party credentials are secure.

Context-based authentication

Context-based authentication is a cybersecurity method that requires the user to confirm their identity because there was suspicious activity on their account. For example, if an account was logged in via a different location or device than usual, a user will receive a notification on one of their other devices to confirm that they are the one trying to log in. This form of authentication is useful at detecting possible hackers as the user needs to provide extra security details to access their account.

If you need to bolster your security and become compliant with GDPR regulations, get in touch with Cyber Smart today and our experts can help you achieve government-backed Cyber Essentials, Cyber Essentials PLUS and IASME GDPR Certification.

The business risk that’s more worrying than Brexit

News articles have continued to highlight the impact Brexit could have on UK businesses in 2020. With everything from visas to regulations and import taxes, businesses face a lot of uncertainty in the coming years.  

However, despite Brexit continuing as a hot topic in business media, surveys have found that it is not the most pressing issue on business leaders’ agendas. Instead, data protection topped the list. 

The first half of 2019 saw data breaches leave 4.1 billion records across the world exposed, and they are continuing to occur on an almost weekly basis in the UK. The rapid sophistication of cyber attacks is leaving an increasing number of UK’s businesses vulnerable to these potentially devastating breaches.

80% of CEOs concerned about cyber threat

PricewaterhouseCoopers conducted a recent survey to gauge the key areas of CEO uncertainty and how they are taking action to address them. The findings found that eight out of ten CEOs are concerned about the threats posed by a cyber attack. 

This concern emerges among a growing abundance of news stories reporting enormous data and security breaches at top companies and organisations, which end up costing them hundreds of thousands in compensation. 

One of the most publicised cases of 2019 was the British Airways breach in which the details of about 500,000 customers were stolen by hackers. As a result, BA was charged a fine of £183 million.

This is a corporate example, but even small businesses are at risk of fines for violating GDPR data protection laws. If you’re wondering if you’re GDPR compliant, CyberSmart offers a simple, non-technical path to GDPR certification.

The public wants to know businesses are protecting their data

Media coverage and market research make it clear that cyber attacks are only going to increase in frequency in 2020, both in the UK and the rest of the world. But this is not just an issue for CEOs. 

The media attention garnered by cyber attack stories have made data regulations and privacy a key issue amongst the general public, who place an increasing premium on companies that take protection of their data seriously.

It’s more important than ever to show that businesses showcase their cyber security certifications and GDPR compliance. 

Pressure from consumers has been further motivation for CEOs to consider data privacy and compliance with data regulations as two of their top issues. 57% of respondents to PwC’s report cited public fears over security as a key factor.

Cyber security starts at the foundation

However, 2020 is expected to see more CEOs focusing on the configuration of their business in order to meet the requirements of cyber resilience. In the increasingly digital landscape of the future, cyber security will no longer be an added feature for organisations to incorporate as an afterthought, but rather a critical feature to be in-built into a business’ infrastructure.

As cyber attacks continue to pose a significant threat to UK businesses in 2020, it has never been more important for companies to ensure they are compliant with data protection laws and agreements. 

CyberSmart several ways that even small businesses can take precautions against cyber threats. Our Cyber Essentials and Cyber Essentials Plus certification offers simplify the process of keeping businesses up to date with UK laws while CyberSmart Active Protect secures your company devices around the clock. 

In addition, we offer products for IASME GDPR compliance enabling you and your company to meet protection standards and have peace of mind in your service.

Cyber attacks already adding up for 2020

The number of cyber attacks have been increasing year on year. So far, 2020 doesn't look much better.

January proved ominous, with a series of successful cyber attacks on organisations across the globe. Here are just some of the attacks over the first month of 2020:

Royal Yachting Association (RYA)

The UK’s national organisation for the yachting community became aware of a digital attack on 17th January. Online user account data was compromised and as a result, all members of the organisation had to change their passwords immediately.

A statement issued by the RYA said: “On 17 January 2020 we became aware that an unauthorised party accessed and may have acquired a database created in 2015 containing personal data associated with a number of RYA user accounts.

“Our investigation into this matter is ongoing and we have engaged leading data security firms, including forensic specialists, to assist in our investigation.”

Mitsubishi Electric targeted by Chinese hackers

One of Japan’s largest defence and infrastructure groups, Mitsubishi Electric, was also hit by a colossal cyber attack in the first month of this year. The attack was blamed on a Chinese group, who may have gained access to information on government agencies and business partners, as well as the personal data of 8,000 employees and job applicants.

Chief Cabinet Secretary of the group, Yoshihide Suga said in a statement that the Japanese Government was informed, while also confirming that “there is no leak of sensitive information regarding defense equipment and electricity.”

Detroit data breach exposes workers and residents

The email system of Detroit City Government was breached on 16th January. Although less than 10 email accounts were affected, some of the accounts contained sensitive information that could be exploited by cyber criminals. Luckily, most of the email data was encrypted.

The city’s Chief Information Officer, Beth Niblock said: “At this time, there is no evidence - and it is highly unlikely - that any of this personal data was accessed. However, out of an abundance of caution for privacy and security of our employees, the city will be offering credit monitoring services for a period of one year.”

Make a cyber security New Year’s resolution

If your company’s New Years resolutions didn’t include improving cyber security, then these attacks should provide a wake-up call. Being cyber resilient is critical to company health.

A surefire way to prove your house is in order is by achieving cyber security accreditation. The UK National Cyber Security Centre’s cyber essentials or cyber essentials plus accreditation schemes are the best way to do this.

3 signs you should update your cyber security immediately

What is GDPR?

Cybersecurity is an issue that most people don’t take seriously until the worse happens- from stolen customer data to electrical blackouts or paralysed information systems. And unfortunately, these incidents have been steadily rising for small businesses.

Basic controls like firewalls and strong password protections can go a long way in protecting you but if your business isn’t up-to-date in terms of security protocols and practices, then you’re likely at a far higher risk than you think of security breaches, data loss or even malicious attacks from hackers and outside sources.

Before it gets to that point, though, recognising that your system isn’t secure is an excellent place to start.

If you, or your staff, have spotted any of these red flags within your system, then it might be time to invest in better cybersecurity, or even consider our 24/7 cyber monitoring software to boost the safety of your business:

Errors or out-of-date notices on software

We’ve all been known to ignore warnings and errors related to the software we use, especially if that particular piece of software continues to work correctly. But out-of-date technology, particularly software connected to the internet or cloud, can be an open door for hackers.

If you’ve noticed errors or out-of-licence notices on company software, updating your processes and guidelines to ensure this is reported, and any updates are done swiftly, is best practice.

OS systems that are not updated to the latest version

Many employees are guilty of this particular security issue. Leaving computers on overnight and never allowing updates to occur may allow for a quicker start to the day, but it’s not worth the security risks it brings. If you find employees regularly lagging behind on the latest OS updates, completing these updates should be included in the responsibilities of your IT team to ensure your company is compliant.

An increase or influx in spam emails or potentially harmful links

Outdated or less secure email systems can lead to a significant increase in the amount of spam your business receives which could have harmful attachments and links included in them. Ensuring your firewall, spam systems, and other security measures are up-to-date can prevent problem emails from reaching you. If you’ve noticed a sudden increase, ensure all your systems are up to date.

All too often, businesses forget all about their cybersecurity requirements until problems occur – whether it’s a virus in the system, a hacking attempt or a full-on ransom demand.

That’s why CyberSmart’s simple app and dashboard alert you any time a device in your company has a firewall disabled, is behind on updates, or needs a software update. Beyond certification, we offer the kind of 24/7 protection that will keep your business, employees, and customers safe in the world of 2020.

To learn more about our software and certification services, contact CyberSmart today.

How does GDPR protect your customers?

How does GDPR protect your customers?

The General Data Protection Regulation, or GDPR, was brought in by the European Union in 2018. The intention was to update data protection laws across all member states and ensure that companies would become compliant in their handling of data. A lot of businesses, however, still see GDPR as a nuisance. In fact, it acts to protect customers and businesses alike. Here, we discuss exactly how that is the case.

Security of data

Under GDPR, the data of individuals became much better defined. Anything identifiable to an individual is their personal data, and under GDPR users have the right to know who is in possession of their data and which organisations are using it. Customers have to agree to actions being taken with their data, so they have a far greater level of control over what companies are doing with their personal information. If they don't like what a company is doing, they can simply withdraw their consent and request that a company deletes the data. This not only protects the customer but also benefits the business in that it ensures individuals can have a greater feeling of comfort that their data is being used legitimately.

Transparency of data

Customers are also given the right to be informed of what the purpose their data is being used for, exactly what data is collected, and if there have been any data security breaches. These wide-ranging reforms, designed to allow for a much greater level of transparency, ensure that customers are not only more secure but are also more aware of what exactly their data entails. When individuals are allowed to download all of the data that international companies hold about them, they have a better idea of what their data actually is, and can get a better idea of what sort of access they want to let companies have. Customers, therefore, are more likely to be trusting of what exactly a company does, since data is no longer an abstract concept but something more tangible. Two-thirds of Europeans have now heard of GDPR, demonstrating the reach of the regulation and its impact in boosting awareness. Compliant companies are therefore likely to benefit from the implementation of GDPR.

With the implementation of GDPR across Europe, companies are now considering data to be an intrinsic part of cyber essentials. Data handling is key to modern business operations, and to ensure that your company is completely compliant, you may need expert help. CyberSmart can help make a complicated bit of regulation, much simpler with our Privacy toolbox, click here to find out more.

Data privay toolbox

Keeping safe on social media

For many businesses, social media is now just a fact of life - a major sales channel that puts products directly into the laps of customers. It's rare for a business to not have some kind of social media presence, but along with the benefits of being more connected to customers comes the risks of being exposed to people that you don't want to get attention from such as hackers and online criminals. Here are a few tips that can keep your organisation safe.

Use a VPN

Your businesses' social media account is a goldmine of potentially useful information for cybercriminals or just good old fashioned fraudsters. Everything from bank details and passwords to personal details of employees and company performance can be found there, so it must be kept safe. A Virtual Private Network (VPN) is a server separate from your own that you can connect to in order to access the internet, and it makes your internet connection much more secure and much harder to track. Think of it as an extra layer of security between you and the bad guys, enabling them to track your activity back to your VPN and no further. Paid-for VPNs also typically have a high level of encryption and security provided by large tech companies, which may be better than your own network's protection.

Pay attention to privacy

On a business social media page, it's likely that the user won't know the majority of people who interact with it personally, so it's harder to manually spot suspicious people or activity than it is for an individual on their personal page. One important point is to keep your privacy settings up to date, so you're always sure that you're not oversharing details about your business with fans, you're changing your passwords regularly and you have all possible security measures in place like backup addresses and two-factor authentication. You should also train your staff to spot fraudulent messages and phishing, so they don't inadvertently become the back door.

Protect yourself

No matter how diligent you are, there's always the chance you'll still be a victim of an attack, and you don't want to be defenceless if you are. Achieving cybersecurity certification with IASME issued Cyber Essentials or Cyber Essentials Plus, can ensure you have basic cyber hygiene and protect your business from most sources of threats. By ensuring this level of protection is in place you can be sure you have done all you can to protect your business, customers and suppliers.

What the Internet of Things means for cybersecurity

IoT Security

The Internet of Things is a revolution that has been well underway for some time. As devices and basic home necessities become connected to the internet, people's lives are becoming more interlinked and easier. However, whilst progress is being made in all sorts of devices becoming connected, it provides a significant emerging data security threat.

What is the Internet of Things?

The Internet of Things is a global movement, based around allowing usually mundane objects to connect to the internet. This means that items such as fridges, televisions and watches have started to transmit and record your personal data. The expansion of IoT doesn't seem to be a trend that's going away. By 2022, it's expected that 18 billion IoT devices will be in use, so the security of all this data is paramount.

Much more data is collected on people

When almost every device in your house is collecting data on your actions, you're almost certain to produce much more information. If each and every decision you make is recorded by global corporations, what they know about you expands and people can get a complete idea of who you are as a person. When your fridge knows what you like to eat, your social media knows exactly who or what you like, and your car knows your favourite places, it's easy to fill in the gaps. Whilst regulations such as GDPR ensure that companies remain compliant and don't release this data to other companies, it can still get out through less legitimate means.

Devices can never be perfectly secure

Whilst the internet of things has allowed more devices to become interconnected, this means that a vulnerability in any of these devices could lead to issues for data security. For example, consider a case in which you have several devices connected to a single account and the account becomes compromised. All of the data, from what is in your fridge, to your physical data from a smartwatch, to your chat logs from your phone, could fall into the wrong hands. This would leave everything about your life in the hands of a complete stranger.

How can CyberSmart help?

CyberSmart is a certified cyber essentials company, with years of experience working with data security. CyberSmart's expert team can help your company to work towards Cyber Essentials Plus certification, to make sure that your company is ready for all of the pitfalls that could potentially arise with the Internet of Things. Get in touch through our website, or call us on 020 7993 6990 for a quote.

Cybersecurity in 2020: what to expect from a volatile world

Cybersecurity in 2020

It's no secret that the world of cybersecurity online is becoming more dangerous as more and more people, and things, across the globe, get connected in ever more sophisticated ways. However, while criminal individuals and gangs are an ever-present threat online, the real threat growth area is from national governments who are increasingly turning to the internet as a means to attack their enemies. So what should you expect from cybersecurity in 2020? We take a look.

Government services

Countries have long used underhand methods of attacking their enemies as a proxy for military conflict, but the Internet has created a powerful way for rogue actors to cause unprecedented levels of damage to civilians without ever firing a shot. Examples of tit for tat attacks are common, and targets from the UK's NHS to the Iranian nuclear industry have been hit in recent years with catastrophic results.

Government services from your local council website all the way to the police and health services could be attacked, and while they might not be targeting you specifically, often the malware and viruses they unleash are indiscriminate in who they affect. It's a good idea to make sure your antivirus is up to date before using Government sites and portals, just in case, and to be suspicious of any emails you receive from public services unless you can verify the source.

Election fever

Most of the attention around election security in recent years has been focused on the potential for fraudulent social media posts and fake news to mislead voters, but old fashioned cyber fraud is also expected to increase in the run-up to the US elections this year and in the aftermath of the UK elections last December.

Legitimate online identities are valuable to hackers looking to commit fraud, so it is important to be alert in case they try to steal your details in a way that could be damaging professionally or financially - particularly the theft of email databases or sensitive details. For a business, it is essential that you are compliant with GDPR in the event that this does happen, or the fallout from an attack could be much worse.

Supplier woes

While government agencies are particularly vulnerable to cyber warfare, the damage doesn't stop there. Many governments use private companies to help deliver public services, and the contagion from an attack on a government can easily spread down supplier networks to your business even if you don't deal directly with the Government yourself.

As a result, it's essential that you have robust software with IASME certification in place, like Cyber Essentials or Cyber Essentials Plus to give your customers the peace of mind that they won't become victims if you are attacked.

Looking to improve your cybersecurity in 2020 but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.

CTA button