Step 1 to CE: Boundary Firewalls and internet gateways

A firewall or gateway protects internal networks and systems against unauthorised access from the internet. They are designed to provide a basic level of protection for internet users. All business networks should have a properly configured firewall in place. The firewall monitors all network traffic, whilst identifying and blocking any traffic which can be harmful.

(more…)

Step 1 to CE: Boundary Firewalls and internet gateways

A firewall or gateway protects internal networks and systems against unauthorised access from the internet. They are designed to provide a basic level of protection for internet users. All business networks should have a properly configured firewall in place. The firewall monitors all network traffic, whilst identifying and blocking any traffic which can be harmful.

(more…)

Cybersecurity standards explained

Cybersecurity standards

The cybersecurity sector is a crowded place when it comes to different standards, certifications, rules and regulations. It can also cause a lot of head-scratching and confusion for those not familiar with the best practice.

Founders and business owners often come to us and say they want to or have to get ISO 27001 certified. Hardly anyone knows when and how ISO 27001 makes sense for a small business and what other certifications can be achieved instead of ISO 27001 or used as a stepping stone towards achieving ISO 2700. Here is a brief overview of the most common cybersecurity standards in the UK: 

Cyber Essentials

In short, Cyber Essentials is a scheme designed by the UK government that aims to get all UK businesses to be able to manage their IT security to a certain level. It helps companies to implement basic levels of protection against cyberattacks, demonstrating to their customers and suppliers that they take cybersecurity seriously.

Established in 2014, the purpose of this standard is to develop necessary cybersecurity standard throughout an organisation. The standard is relatively technical and protects organisations from 80% of cyber-attacks. The most surprising factor we discovered as cybersecurity consultants was that most companies that had other standards, such as ISO 27001 or PCI-DSS implemented, would still fail under Cyber Essentials. The best use case for this standard is to implement it as a first defence and perimeter security before other standards are considered.

Cyber Essentials certification is a great first step towards GDPR. It serves as evidence that you have carried out basic steps towards protecting your business from internet-based cyber attacks.

Cyber Essentials Plus

Cyber Essentials Plus is the audited standard of Cyber Essentials. Besides including some additional controls, the implementation needs to be assessed by a Cyber Essentials Plus auditor. This obligatory audit creates additional trust in the standard and it is safe to assume that once Cyber Essentials is well-established, Cyber Essentials Plus will increasingly become mandatory.

IASME

This standard goes far beyond Cyber Essentials and can be described as a "mini version of ISO 27001:2017". Together with the government, IASME developed this standard in order to create an easily adaptable and affordable alternative to ISO 27001. The IASME standard is specially tailored towards SME’s and includes processes, people and technology. In May 2018 both IASME standards will be expanded to include GDPR readiness. Both IASME standards require Cyber Essentials as part of the readiness as well. Similarly to cyber essentials, the IASME standard can serve as proof to customers and suppliers that their information is being protected. It is provided alongside the cyber essentials certification. There are two types: the standard self-assessment and the Gold standard, which requires an audit onsite.

ISO27001

ISO 27001 is an international information security standard. Including far over 100 controls the standard is frequently implemented by corporations or businesses dealing with critical infrastructure or the public sector. ISO27001 covers areas that include security policies, access control, operations security, human resources, cryptography and compliance. It does not cover GDPR*. However, an organisation can voluntarily include GDPR in their ISMS (Information Security Management System). 

*A note on GDPR: GDPR is NOT a standard, it's a law, so we've excluded it here. 

If you have any questions about Information Security Standards or Cyber Security in general or just want to have a chat, drop us a line at hello@cybersmart.co.uk.

Looking to improve your cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.

CTA button

Here's what everyone should be doing in 2018 in terms of cybersecurity and data protection:

(more…)

Here's what everyone should be doing in 2018 in terms of cybersecurity and data protection:

(more…)

Time for the UK education sector to prioritise cybersecurity

Cyber Security Education

As you probably know already, schools and universities are not immune to attacks from disgruntled employees or other insiders. However, there is another key issue for school leadership teams that is unique to the education sector: students!

Students are often more digitally aware than most teachers and other school employees. This can lead to new digital platforms being introduced into the school environment without staff being made aware.  This insider threat to schools from students is not malicious; instead, it’s an issue of negligence in some cases or lack of awareness in other.

While students and teenagers may be tech savvy, they’re not often very security conscious. The consequences of exposing the school network to a data breach or cyber attack is often not properly understood. They are also not legally culpable for any actions that might result in a breach, so there is less of an incentive to take responsibility.

Adults are also potential insider threats; a teacher may bring a corrupted USB stick into school with their learning resources, or school admin staff may open and respond to a phishing email without understanding what it is. This is why schools must keep on top of their security policies and enforce them across the whole school community.

Awareness Of The Threat Landscape

The general lack of awareness about the types of attack a school network may be subjected to, what they look like, and where they come from is a major problem for the school as a whole.

All parties - IT departments, network managers, teachers, school employees and students - must be made aware of the threat landscape with relevance to their internet and network usage. Regular training should be part of the schools’ IT policy, raising awareness of the consequences of cyber attack to the school and individuals personally – which could include disciplinary actions.

Network Protection

School networks need robust defences in place to protect from threats such as malware or DDoS attacks. Antivirus, web filtering, firewall, device encryption, mobile data management and penetration testing should all be updated regularly and reviewed to keep pace with new threats and technologies.

Managing User Privileges

An effective way of limiting the potential damage an insider threat poses is to rigorously manage who has access to the network, and what they can and can’t do.

Both staff and students should only have limited access to the school’s network based on their requirements, reducing the opportunity for malicious or accidental misuse of the network. Managing user accounts should also include regularly reviewing what access individuals require, blocking access to some systems if individuals no longer need them, and deleting users when they leave the school.

If you have any questions about Cyber Security in general or just want to have a chat, drop us a line at hello@cybersmart.co.uk

Protecting your data and organisation is hard work — let us help you make it easier.

As CyberSmart turns 1 year old, we are taking a moment to pause and reflect. This year was huge for us, individually and as a team. We had a vague idea, built a platform, got our first paying customers and closed a Pre-Seed round. At CyberSmart we believe in transparency, not only in regards to data, but also transparency in everything we do, transparency towards our stakeholders and eco-system. Hence, without further ado - here is what happened in 2017 at the CyberSmart HQ in East London.

(more…)

As CyberSmart turns 1 year old, we are taking a moment to pause and reflect. This year was huge for us, individually and as a team. We had a vague idea, built a platform, got our first paying customers and closed a Pre-Seed round. At CyberSmart we believe in transparency, not only in regards to data, but also transparency in everything we do, transparency towards our stakeholders and eco-system. Hence, without further ado - here is what happened in 2017 at the CyberSmart HQ in East London.

(more…)

The legal sector remains a hot target for the full spectrum of threat actors. These include cybercriminals, hacktivists, state-sponsored groups. This is largely due to the wealth of sensitive data held within the industry. For example, patent data, merger and acquisition information, protected witness information and negotiation information. The scope is vast and not limited to the above list. Legal firms are equivalent to a pot of gold for any of these groups. So, what's the state of cybersecurity in the legal sector and what can be done to improve it?

(more…)

The legal sector remains a hot target for the full spectrum of threat actors. These include cybercriminals, hacktivists, state-sponsored groups. This is largely due to the wealth of sensitive data held within the industry. For example, patent data, merger and acquisition information, protected witness information and negotiation information. The scope is vast and not limited to the above list. Legal firms are equivalent to a pot of gold for any of these groups. So, what's the state of cybersecurity in the legal sector and what can be done to improve it?

(more…)

GDPR: What is it and why is it important?

What is GDPR?

The General Data Protection Regulation (GDPR) is Europe's new framework for data protection laws. GDPR replaces the previous 1995 data protection directive, which current UK law is based upon.

It introduces tougher fines for non-compliance and breaches and gives us all more say over what companies can do with our data. On top of this, it also makes data protection rules more or less identical throughout the EU.

Why was GDPR drafted in the first place?

The new law has two aims. First, the EU wants to give people more control over how their personal data is used. This is down to the practices of companies like Facebook and Google, who often swap access to their services for users' data. 

The current Data Protection Act was enacted before the internet, making it easy to exploit data using new technology. GDPR seeks to address this. By strengthening data protection legislation and introducing tougher enforcement measures, the EU hopes to improve trust in the  digital economy.  

Second, the EU wants to give businesses a clearer legal environment to operate in. It's estimated that making data protection law identical throughout the single market will save businesses a collective €2.3 billion a year.

When will it apply?

GDPR has applied to all EU member states since 25 May 2018. 

Who does it apply to?

According to the EU, 'controllers' and 'processors' of data need to follow GDPR rules. Let's dig into those terms a little. 

A data controller is the party responsible for how and why data is processed. This is usually your business itself. A processeser is the party responsible for the actual handling of the data.

Using a third-party contractor for processing your payroll is great example of this. Your business tells the payroll company when wages should be paid, how much each employee should recieve, and if anyone leaves or joins. The payroll company provides the IT system and stores your employees' data. In this situation, your business is the controller and the payroll provider the processor.

Even if controllers and processors are based outside the EU GDPR still applies, so long as they're dealing with data belonging to EU residents.

It's your responsibility as a controller to ensure the processor follows the rules. Meanwhile, processors must keep records of their processing activities. There's a big incentive to do this. Under GDPR, the penalities are much more severe than they were previously.  

How can Cyber Essentials help with GDPR?

While your organisation needs more than Cyber Essentials to comply with GDPR, it's a great first step. Cyber Essentials certification is evidence that you have taken steps towards protecting your data from cyber attacks.

Looking to improve your cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.

CTA button

How does Cyber Essentials benefit MSPs and their customers?

Cyber Essentials

Cyber Essentials is a UK-Government-backed cyber-security scheme which encourages businesses to take steps in order to prevent and protect themselves against the threat of cyber-attack. What you might not be aware of, however, is how beneficial a Cyber Essentials certification can be for managed service providers (MSPs) and their customers.

How to get Cyber Essentials certified

According to the official Cyber Essentials statistics, nearly half of businesses reported a cyber-attack in the past 12 months. And this is why the scheme dedicated to helping ensure businesses stay secure.

The Cyber Essentials certification serves as proof of your IT resilience, educating businesses across all sectors on the best way to protect themselves from a range of the most prevalent and threatening cyber threats. The Cyber Essentials certification is not just an award, but an ongoing education and protection process in which a business must put in place a range of security procedures and policies which help ensure sufficiently high levels of cyber-security within their IT infrastructure.

This helps prevent the risk of your business facing a cyber-attack, as well an ensuring that you have the infrastructure in place to appropriately counter and recover from an attack in the event of a disaster.

How does this Essentials benefit MSPs' customers?

The threat of cyber-attack is heightened as an MSP or reseller and poses a very real threat to your customers, as well as your business. In order to tackle this, IT resellers can position themselves as cyber-security specialists, working with your customers to help them achieve a Cyber Essentials certification and transform their IT resilience.

This presents an incredible opportunity for you to add value for your customers and demonstrate your technical knowledge, helping them to make changes within their IT that will build their tolerance and tackle basic weaknesses and exploits in their infrastructure, preventing thousands of pounds worth of damage and threatening the survival of their business.

If you have any questions around Cyber Essentials and our partner hub or just want to have a chat, drop us a line at hello@cybersmart.co.uk.

This article was previously published by Marathon PS - one of our first partners.

Looking to improve your cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.

CTA button

Cybersecurity and data protection can seem overwhelming. There's a glut of advice on the internet, but it's difficult to know where to start. At CyberSmart, we believe cybersecurity should be accessible and easy for everyone. So we've compiled a series of useful policies and procedures to help you find your way through the cyber-compliance jungle. This time, we're looking at how to set up an information security policy.

(more…)

Cybersecurity and data protection can seem overwhelming. There's a glut of advice on the internet, but it's difficult to know where to start. At CyberSmart, we believe cybersecurity should be accessible and easy for everyone. So we've compiled a series of useful policies and procedures to help you find your way through the cyber-compliance jungle. This time, we're looking at how to set up an information security policy.

(more…)