How SMEs can beat the cybersecurity skills gap

Cybersecurity skills gap

According to government statistics, the UK has a cybersecurity problem. More specifically, a ‘skills gap’. But what do we actually mean by a skills gap? How did we get here? And, what can smaller companies do to address it

What do we mean by a ‘skills gap’? 

Although the phrase ‘skills gap’ is a neat way to describe the problem, it’s a little vague. Whose skills are we talking about? Does it mean that every small business should have a bonafide cybersecurity expert in-house? 

Let’s dig a little deeper.

The Department for Digital Culture, Media and Sport (DCMS) defines the skills gap as businesses ‘lacking staff with the technical, incident response and governance skills needed to manage their cybersecurity.’ 

The DCMS backs this definition up with some pretty alarming statistics. 48% (some  653,000) of businesses in the UK have a ‘basic’ skills gap. This means they lack the confidence to carry out the fundamental security tasks laid out by the Cyber Essentials scheme. These include things like setting up configured firewalls, storing or transferring personal data, and detecting and removing malware. 

But the problems don’t end there. 

Approximately 408,000 businesses (30%) have more ‘advanced’ skills gaps. These include areas such as penetration testing, forensic analysis and security architecture. Another 27% have a gap when it comes to incident response. 

Looking to improve your cybersecurity but lack the skills to get started? Check out the CyberSmart platform. It's your automated, in-house cybersecurity officer.

Why does the UK have a cybersecurity skills gap? 

To get to the bottom of why the UK has a cybersecurity skills gap, we have to look back. Way back. Specifically, we’re heading to the 1990s – a decade of Britpop, Blairism and bad fashion, and when the internet began to take off as a public utility. Of course, the internet had been around in some form for much longer, but the late nineties marked the point when businesses and consumers really started to use it. 

At the dawn of the modern internet, cybersecurity knowledge was mostly confined to the experts. Universities were just beginning to offer qualifications in the subject and some of the more forward-thinking businesses were offering staff training. But, for the most part, cybersecurity expertise was the preserve of academics, tech companies and a handful of specialist firms. 

Fast forward a couple of decades and not much has changed. Even though every business and individual now uses the internet for nearly every daily task, cybersecurity teaching in schools remains in its infancy and optional most of the time. Many universities now offer cybersecurity courses but it is a niche subject, usually studied by postgraduates. Meanwhile, few businesses offer anything more than rudimentary cyber skills training that usually culminates in ‘switch your antivirus on’. 

All of these things combined have created a world in which very few of us know much about cybersecurity. In turn, this scarcity has made cybersecurity expertise one of the most sought after skills in the UK economy. 

For SMEs, hiring your own in-house expert is prohibitively expensive. And even outsourcing the problem to a specialist firm is still likely to take an almighty bite out of your IT budget. So, short of humming loudly and pretending the problem doesn’t exist or heading back to school, what can small business leaders do about it? 

What can SMEs do about it? 

Some things will always require calling in the experts. If your business is covered on the basic skills front but needs more advanced knowledge, you’re probably not the average SME and it’s worthwhile consulting with specialists or hiring an in-house guru.

However, for everyone else, there’s a lot you can do to protect your business without in-house skills or eye-wateringly expensive expert help. Let’s take a look at some options. 

Take a government-standard certification 

The UK government has been worried about our collective lack of skills for a while now. In the past few years, you’ve probably seen or read news reports about encouraging kids to study STEM subjects and learn basic coding skills. But while these are noble aims that will improve society tremendously in 10-15 years, we need a solution now. 

So, back in 2014, the UK government created the Cyber Essentials scheme. The scheme covers the essential actions every business should take to ensure it’s digital security and protection from cyberattacks. Think of it as ‘cyber hygiene’ –  a bit like washing your hands, brushing your teeth or wearing a face mask. 

And this approach really works. Research from the University of Lancaster reveals that businesses can mitigate cyber risks by as much as 99%. What’s more, the certification process is relatively straightforward. The entry-level Cyber Essentials certification is a self-assessment that can be taken and passed in as little as 24 hours. 

The more advanced version, Cyber Essentials Plus, includes an onsite or remote assessment from an expert and is a little more complex. However, this can also be completed for little cost in a few days. 

If you’re unsure of which is right for your business, take a look at our handy guide covering the differences in more detail. 

Automate the problem 

Cyber Essentials certification is a great starting point. But your business’s cybersecurity requires year-round maintenance. It’s a bit like your car or bicycle. You might put it in for a service or MOT once a year, but in the period between visits to the shop, components wear out or break, leaving your vehicle less than roadworthy.

The same is true of cybersecurity. It’s very unlikely that nothing will change in the year between Cyber Essentials certifications. Software will need to be updated, new devices are added, and previously unknown threats emerge. 

Tackling this manually is a job in itself, one that few SMEs have the skills, budget, or time for. Fortunately, you don’t need to run out and nab a recent cybersecurity graduate from your local university. Tools like the CyberSmart Active Protect can keep an eye on your cybersecurity for you all year long.

This automated software continually scans for vulnerabilities, such as out-of-date software, incorrectly configured security settings and switched off defences. All you need to do is flick a switch if something’s not right, and the platform takes care of the rest. 

The UK’s cybersecurity skills gap will shrink. Heavy investment in the sector and the generation of burgeoning experts in our schools and universities point to a more secure future. However, this doesn’t mean we all have to wait until 2030 to do business safely. There is plenty your business can do today without expert knowledge. 

Are you looking to improve cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.

CTA button

Does 5G pose a cybersecurity threat to SMEs?

5G cybersecurity

The fifth generation of wireless technology, or 5G, promises many things. But beyond grandiose pledges of hyper-connected living, truly scalable virtual reality, and a new golden age for business, 5G’s rollout has been far from smooth.

Unless you’ve (wisely) been consciously ignoring the news, it’s hard to miss the furore surrounding 5G. First, came British 5G towers being pulled down and set on fire due to COVID-19 conspiracy theories. Next, the UK’s decision to ban Chinese firm Huawei from its 5G network. Then, a backlash from environmental activists lamenting 5G’s potential footprint. 

But away from the big headline stories, there’s another side to 5G. It’s a potential gamechanger for small businesses. 

What benefits does 5G offer to small businesses? 

5G provides a host of benefits to small businesses, ranging from the simple to the fantastical. 

Speed

5G networks are engineered to be fast. Really fast. The most transformative part of 5G is its ability to reduce the time (or ‘latency’ if you prefer the techy term) it takes for data to get from one point to another. 5G promises speeds up to seven times faster than the fastest 4G browsing experience. 

For small businesses, this could improve everything from communication with customers to remote working to video conferencing. 

Smart offices

The term ‘smart office’ was all the rage a couple of years ago. We were promised a world of self-booking meeting rooms, automated energy controls and desk-monitoring software. The theory went that this would usher in a new era of happy, engaged employees, optimised office spaces,  and reduced real estate costs. 

However, at the time, the technology to truly automate the office environment wasn’t quite there. With 5G, that’s all about to change. The availability of superfast internet could finally make smart offices available, for very little cost, even to small businesses. 

Looking to improve cybersecurity in your business? Start by getting Cyber Essentials certified. 

Real-time communication

5G’s low latency could transform the way businesses communicate. Imagine a world in which your interactions with customers, staff and employees took place instantly, wherever they are in the world. 

No more waiting for emails to come through. Files uploaded to shared drives in seconds. And, video conferencing that doesn’t freeze every five minutes. That’s the future 5G promises. 

Remote working 

Unless you live in Sweden or have been extremely lucky, chances are you’re reading this at home. Most businesses have had to learn how to work remotely in the last six months. And, for the most part, we’ve all adapted well. 

However, we’re all familiar with the problems working from home presents. How well you’re able to work remotely largely depends on the quality of your internet connection. The additional capacity and speeds 5G offers could change this. Instead of playing the postcode lottery, employees will be able to access high speeds and low latency in even the worst internet black spots. 

IoT

The internet of things (IoT) is another term you’ll have heard a lot in the last few years. But beyond many of us using voice-controlled devices in our homes, it’s yet to really take off. 

5G’s improved connectivity will allow businesses to link up everything from printers and smartphones to office monitoring software.

The bottom line

In short, 5G will make small businesses more efficient, extending their ability to do more with fewer resources and in less time. And this won’t just save costs, it’ll also improve customer experience and boost revenue as a result. 

What risks does bring 5G bring for SMEs? 

Unfortunately, the benefits of 5G apply to cybercriminals as much as they do businesses. 

More attacks 

Although stronger, faster connections are a boon for small businesses, the same is true for cybercriminals. As businesses use 5G as a platform to innovate, so will the bad guys. 5G provides a better tool to launch sophisticated cyberattacks faster, more efficiently, and in greater numbers. 

More opportunities for cybercriminals 

5G enables greater use of IoT devices. And this will have huge benefits for small businesses.

Gartner predicts that there will be 20.4 billion IoT devices in use globally by the end of this year – just in time for the widespread launch of 5G. 

However, with more connected devices, comes more opportunities for the bad guys to break in. It only takes one poorly secured device for cybercriminals to find their way in. And, while it’s always been the case that one weak link is enough, IoT devices increase the risk simply because there are so many of them.

Decentralisation could lead to disruption 

This risk is a little more complex, so bear with us while we run through a short history lesson on network security. 

Traditionally, networks were hub and spoke designs. Essentially, everything flowing through a network eventually came back to the central hub, usually a data centre. This made practising good cyber hygiene pretty simple, as you could protect everything from this central point.

With 5G, these ‘hubs’ are decentralised to a web of digital routers throughout the network. This means that there isn’t a central point where everything can be checked and cybersecurity protocols put in place. Instead, this needs to be done throughout the network, upping the chances security will be overlooked and cybercriminals given a route in. 

What should you do to protect your business? 

Although some of the risks we’ve outlined above are the responsibility of internet service providers, you should never rely on secondhand security alone. There are plenty of things you can do to ensure your business reaps the rewards of switching to 5G, without exposing it to greater risks. 

Check the right security is in place 

Run regular checks to ensure every device used in your business is equipped with the best security capabilities. This includes any IoT devices you’re using such as voice assistants or smart printers. Tools like CyberSmart Active Protect can help automate this process, by running a scan of all devices every 15 mins. 

Make sure software is up to date

No one likes running software or operating system updates, but it is important. Often software providers will include patches to fix known vulnerabilities in updates, protecting you against new cyber threats. Ensure all software is configured to update automatically across all company devices or perform regular checks. 

Get Cyber Essentials certified 

According to a report from Lancaster University, the measures laid out by the UK government’s Cyber Essentials (CE) scheme can mitigate 98.5% of cybersecurity risks. If you’re not already CE certified, following the process will help you build a great base level of security before you make the jump to 5G. 

Maintain good password hygiene

We say it a lot, but setting up a password policy and ensuring everyone follows is a vital step. Always use complex passwords, change them regularly, and set up two-factor authentication, 

Clear security policies 

If you don’t have a security policy in place for 5G and the use of IoT, now’s the time. But it’s not enough just to have a security policy in place, your people also need to understand it. Check all security policies for workers are clear, easy to follow and stored in a central location everyone can access. 

5G is here. In less than four years time one billion devices will rely on it, and your business will very likely contain some of them. Of course, this brings risks. But the bad shouldn’t outweigh the good. By adopting a policy for 5G early and establishing simple, but effective security protocols you can make sure your business is primed to ride the next great wave of connectivity. 

Looking to improve your cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.

CTA button

Playing politics: customer spotlight on Play Verto

CyberSmart

‘Fun’ isn’t a word often associated with politics. Many of us tend to think of it as a game played by powerful people in oak-panelled chambers, far away from the reality of our everyday lives. And, it’s this feeling that has led to widespread disengagement from politics and distrust in our institutions.

But what if politics was a game we could all play? 

CyberSmart client, Play Verto, seeks to answer that question. The social enterprise specialises in improving community engagement through gamification. Its app, Verto, allows the public to express their political views by answering questions in a play-based format. 

By combining technology and play, Play Verto is creating a space for wider participation and plurality of opinion in politics. 

However, handling public data brings cybersecurity challenges with it. We sat down with Ben Pook, Director of Play Verto, to discuss these and how using CyberSmart Active Protect has helped overcome them.

What are the security challenges you’ve faced as a startup? 

When you are in the start-up space, you tend to play many different roles and you are thinking a million things. You quickly learn that you need to be agile to accommodate that. However, data security is not something you want to play about with. There is often a lot to consider, which can easily be forgotten or simply not considered at all.

Play Verto is a data-led decision-making company. So, inevitably, we deal with a lot of sensitive data. Our customers depend on us to safeguard this, ensuring it’s collected and stored securely. The company also emerged around the time that GDPR was coming into place, raising another challenge. 

How did CyberSmart help you resolve your security challenges?

Cybersecurity is an intimidating subject, especially when you lack rudimentary knowledge.  What we like about CyberSmart is that they ‘dumb-down’ cybersecurity and compliance for you, providing an easy step-by-step guide to make sure you have all your bases covered. They walk you through GDPR, Cyber Essentials as well as ISO27001.

It’s also helpful in the sense that it allows you to say, ‘hey, have you thought about this?’ and if not, here is what you should do. It doesn’t matter that you don’t have years of experience working in information security or the means to hire a specialist.

How far is Play Verto into setting up CyberSmart? 

We’ve gone through the whole process and we have the certificates. It’s given us a kick-start; we now use the tools and information offered by CyberSmart to constantly re-evaluate our compliance and security.

In fact, it’s become part of our routine. Whenever we onboard someone new, they go through CyberSmart’s training and install the app on their devices to ensure they meet our security standards. We also have a fortnightly team meeting on cybersecurity.

Our company culture has become much more security-focused thanks to CyberSmart. 

What role has CyberSmart played in your relationship with customers and partners?

The impact of not having the right security measures in place is massive. Our customers and partners rely on us to keep their data secure. CyberSmart offers an additional service that is critical in giving both ourselves, as well as our customers, peace of mind.

When we take on a new client, they want to understand how we collect data, how we store it, where it is stored, which servers we are using etc. With CyberSmart, all of that information is one place and easily accessible. What’s more, the certificates themselves are a demonstration that we take security seriously in the eyes of our customers. 

What cost and time benefits have you experienced since using CyberSmart? 

Well, I think it really comes down to ‘what is the cost of not using it?’. We have a pretty good security culture in our company, but it costs to be ignorant. I would rather be the fool that asked than the fool that wished he did.

CyberSmart’s monthly subscription is also perfect for those in the start-up space. Shelling out thousands of dollars in one go is tricky for a small business. The subscription model makes CyberSmart’s tools accessible to organisations in a similar position to us when we first started.

What advice would you give to someone looking to tackle similar challenges to those you’ve faced?

To be honest, I’d probably recommend CyberSmart, particularly because of their customer service. The team is amazingly responsive and there’s no such thing as a silly question.  It almost feels like a personal relationship, they do a great job of building a rapport.

Are you a start-up looking to improve cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.

CTA button

9 signs your business has been hacked and what to do about them

Hacked

It’s the stuff nightmares are made of. What started as another mundane Monday afternoon has suddenly morphed into one of your worst-case scenarios.  Your business has been hacked.

The scariest part is that you may not even notice. If you’re lucky, you may receive a ransomware notification or a good samaritan might inform you but often the telltale signs of a breach are more insidious. Here’s how to spot and tackle them.

9 warning signs you've been hacked -  and what to do about them

Unexpected changes to files 

Many modern businesses allow for organisation-wide access to documents and real-time editing. Think tools like Google Docs or your Microsoft 365 package. Telling the difference between colleagues’ tracked changes on that ten-page report you wrote and more nefarious activity can be tricky. But it’s not impossible. 

Look for revisions outside of what you’d normally expect. For example, document name changes, or files that have been mysteriously deleted. Like fingerprints at a crime scene, all of these could point to a hacker’s presence.

What to do: To keep the hackers at bay, start by changing all company passwords, installing encryption software and double-checking everyone is following your security policy. If the problem persists, consider speaking to an expert.

Spam emails sent from company email accounts 

No one likes spam. It’s annoying and nothing turns off a prospective customer more quickly than a deluge of unwanted emails. But if you suddenly start receiving complaints from customers or unsubscribe numbers start climbing, it’s also a sure sign you’ve been hacked. 

What to do: Keep a close watch on your outgoing emails. It’s likely your marketing team are already tracking emails for key metrics, so ask them to keep an eye out for anything that looks out of place. On an individual level, regularly check the sent folder in your emails for messages that you don’t remember sending or look spammy. 

If you do discover something’s wrong, follow the steps we outlined above for file changes. 

Secure your business today. Get Cyber Essentials certified.

Unusual financial activity

It’s generally known that most hackers are out for one thing: money. So one of the most important places to regularly check is company bank accounts.

Check business statements regularly for unusual withdrawals or payments from your account. If you do spot anything, there’s a very real chance you’ve been hacked. And, remember, cybercriminals won’t necessarily steal large amounts. One of the most successful small-scale hacks of recent years involved a cybercriminal stealing from multiple businesses, a few ill-gotten cents at a time. 

What to do: If you do find irregularities, change passwords for all company accounts, turn on transaction alerts and contact your bank – most will reimburse any stolen funds.

Unwelcome installations

It can be difficult to keep track of the various tools and software everyone within your business has installed. This is particularly true in the frenetic world of an SME or startup.

Nevertheless, there’s a big difference between the tools your people need and unwanted software no one remembers installing. Sometimes this software is completely harmless. We all accidentally install a browser add-on now and then. However, there’s also a chance that if someone doesn’t remember installing something, it’s been added remotely by a cybercriminal.

What to do: The fix for unwelcome installations is a simple, but time-consuming, one. Perform regular checks on the software and toolbars in use on all company devices. And, if you find any applications that look strange or aren’t in use, uninstall them. 

Random pop-ups

Like it’s equally irritating cousin, spam, we all hate pop-ups. We hate them so much that more than 600 million devices (or 11% of all the devices in the world) are currently using an ad blocker.

However, there might be something more to the pop-ups you’re seeing than an annoying sideshow. If you’re getting popups from websites that wouldn’t usually generate them – particularly, reputable ones – it could indicate your system has been compromised. 

What to do: Unfortunately, there’s no quick fix for this problem. The best way to clean up your systems is to manually delete any software or toolbars you haven’t installed yourself (see above). At this point, it’s perfectly acceptable to let out a long sigh. 

Company devices behaving strangely 

When we talk about ‘devices behaving strangely’ it’s important to stress we don’t mean the ‘Wednesday afternoon go-slow’ your laptop experiences from time to time. 

We mean really strange behaviour. For example, your mouse cursor moving of its own free will or random flickering on your monitor. Both of these things could indicate something much more serious is going on.

What to do: If you do notice your device behaving strangely, it’s time to call in the experts. Disconnect your device from the internet, power it down and turn your router off. Although these steps won’t undo the breach, they will at least stop hackers inflicting any damage before you get expert help. 

Internet searches being redirected

We mentioned earlier that most hackers are interested in making money, and stealing isn’t the only way to do it. An easier, far less risky, way for cybercriminals to make a fast buck is to redirect your browser searches somewhere you don’t want to go. By redirecting your searches to another website (often the site owner has no idea the site is being used this way) the hacker gets paid for your clicks. 

What to do: If your internet searches are being redirected then there’s a high chance you’ve also got bogus toolbars and software installed on your device. Simply follow the same process we outlined earlier for software and that should fix things. 

Changes to your security settings

Cybercriminals are clever, but that doesn’t mean they’re above crude tactics. And top of the list of ‘obvious but effective’ hacker tactics is turning firewalls, ad blockers and anti-virus tools off.

Keep a close eye on your security settings. If something is turned off that shouldn’t be, it’s most likely just down to human error. However, it’s well worth switching it back on and seeing what happens. If the same thing happens again, it could mean you've been hacked.

What to do: By far the best thing to do is back up any files that aren’t already and do a complete system restore. There’s no telling what has happened without expert help, so the first step should always be a complete reset of any affected devices. 

Confidential data has been leaked

Of all the warning signs on this list, discovering confidential company information has been found in an online data dump is the most obvious. Unfortunately, it’s also very tricky to fix.

What to do: The information is already out there, so your actions need to be more about reputation management and preventing it from happening again, rather than addressing the immediate problem. If the worst should happen, it’s time for a full audit of your security procedures, policies and infrastructure. 

Defence starts with prevention 

It might sound cliched, but the best cure for being hacked really is prevention. Relying on anti-malware tools will only get you so far. The real gains are to be made in ensuring you have clear security protocols that prevent common mistakes, using tools like encryption and two-factor authentication, and checking company devices continually. 

Don’t wait until one of these warning signs appears. Instead, think of cybersecurity as you would office security. The more often you check doors and windows are properly locked and know exactly who has access to the keys, the less likely you are to suffer a break-in. Why should your cybersecurity be any different? 

Looking to improve your cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.

CTA button

How to protect your business from brute-force attacks

According to new research from cybersecurity and antivirus protection firm, ESET, remote working has brought with it a sharp global increase in ‘brute-force’ attacks on small businesses. But what is a brute force attack? Why are they on the rise? And what can you do to protect your business? 

What is a ‘brute-force’ attack? 

Cybersecurity terms rarely do what they say on the tin, but a ‘brute force’ attack is precisely what it sounds like. Brute force attacks break into systems by trying millions of possible passwords or ciphertexts in the hope of guessing correctly.

Once upon a time, this was a time-consuming (and incredibly tedious) manual task. Think: hacker sitting in a darkened room, deep into the early hours with nothing but extra-strong coffee for company. However, new technology has made our hacker’s job much easier. 

Most modern brute force attacks use automated software or a bot that can run billions of combinations of numbers, letters and symbols repeatedly. Statistically, eventually, the combination will be correct and crack the code, granting hackers access to whatever they’re looking for.

The five most common types of brute-force attack

Brute force attacks typically take one of five approaches.

1. Simple brute-force attacks

The old school approach. Hackers attempt to logically guess your details, without the aid of software or a bot. This approach is only useful for cracking simple passwords or attacking victims the hacker knows.

2. Dictionary attacks

In this form of attack, a hacker picks a target then runs possible passwords against their username. It’s called a dictionary attack because some hackers will quite literally run through an entire unabridged dictionary, adding special characters in as they go. As you can imagine, this approach is incredibly slow work without the help of an automated program.

3. Hybrid attacks

As the name suggests, hybrid attacks combine approaches one and two. Cybercriminals use this tactic to figure out passwords that mix common words with random characters. For example, ‘padlock1234!’ or ‘opensea3me456’. 

4. Reverse brute-force attacks

A reverse attack starts with a known password rather than a username. Once they have a password, hackers will trawl millions of usernames until they find a match. This form of attack is becoming more frequent and often starts with a password sourced from existing leaks of user data.

5.  Credential stuffing

Many of us use the same password across multiple websites. We know it’s bad practice, but human memory only extends so far. Unfortunately, hackers also know this and use credential stuffing to take advantage. Once they have the password/username combination for one site, they’ll try it on anything else they can think of including your online banking, social media and email.

What’s in it for cybercriminals?

Brute-force attacks are high-effort, low reward most of the time. Until recently, many cybersecurity experts were predicting attacks of this kind would only become rarer due to their lack of sophistication and the effort involved. So what’s in it for cybercriminals?

Sensitive data – This one’s pretty simple. A successful brute-force attack can unlock a treasure trove of data. Most companies store everything from employees’ personal and bank account details to tax information and confidential corporate data – all of which can be sold on for profit or used to steal employees’ identities.

Ransomware – Brute force attacks are perfect for installing ransomware on company systems. Again, the core motivation here is profit. Once the hacker is in and has installed their malware, they can threaten to release sensitive data or cripple internal systems until you pay a ransom.

Hijacking your website and devices – There tend to be two reasons why criminals are interested in hijacking a business’s website or devices. The first is computing power. All that malicious activity takes a lot of computing power, often more than hackers have at their disposal. So, one way around it is to infect an army of unsuspecting devices with malware to form a ‘botnet’ network to power it. This army can then be used to run everything from phishing scams to more brute-force attacks. 

The second reason is advertising. With access to your website, cybercriminals can cover it in spam ads to generate profits from clicks or reroute traffic to their own site. 

Why are brute-force attacks becoming more common? 

As we tackled in a recent blog, the shift to remote working during the COVID-19 pandemic has brought with it extra cybersecurity risks. Many employees are working on unsecured or poorly secured home networks and devices. Businesses just haven’t had time to develop clear cybersecurity and password policies in all the COVID-related disruption. And, as research has shown, many employees think they can get away with riskier behaviour while working from home.

All of these factors combine to produce a hackers dream. Employees are simply more vulnerable to attack working from home, putting their employers at risk too.

How can your business protect itself?

Brute-force attacks are on the rise, but being breached needn’t be inevitable. Fortunately, attacks of this kind are quite easy to protect your business against, provided you follow a few simple principles.

Maintain good password hygiene – Making every password in your business as hard to crack as possible will protect you from all but the most sophisticated brute-force attacks. Create complex passwords, change them regularly, and use two-factor authentication and encryption for an extra layer of protection.

Ensure your policies are clear –  Many businesses are guilty of assuming staff know what bad practice looks like, without providing any guidance. This leaves too much to chance. Instead, provide your employees with clear, easy-to-follow security policies for both remote and office working. 

Create a personal vs professional divide – We all use work devices to browse the news or check our bank balance from time to time. Or use our own laptop for work. The problem is, the more sites you visit and the more entry points into corporate systems and applications, the higher the risk of a breach. Encourage your people to keep work devices for work and personal devices for everything else.

Give employees the right security – The most brilliant security policy in the world won’t save your organisation if employees are using outdated software or security tools. Check your employees are regularly installing software updates and patches and all equip all corporate devices with the latest security capabilities. 

Looking to improve your cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.

CTA button

Mythbusting: is contact tracing safe?

We have a problem. Well, more of a puzzle. Like much of Europe, the UK is gradually emerging from the lockdown of the last few months – this is great for business, collective sanity and our social lives. But opening up brings risks. If a second wave of COVID-19 is inevitable, and many scientists think it is, how should we avoid the mistakes of our first run?

Imposing another nationwide lockdown like the one this spring risks economic ruin for an already ailing UK economy. But with a vaccination a long way off, ‘keeping calm and carrying on’ would be even more disastrous. 

One solution you’ve probably heard a lot about in the last few months is contact tracing. Or, more specifically, the new NHS COVID-19 app. Some have boldly declared the technology, coupled with testing, the answer to a return to normality. Meanwhile, others have raised serious cybersecurity and data privacy concerns. 

So, how does contact tracing work? Are privacy activists and cybersecurity experts right to be worried about it? And, are your privacy and cybersecurity really in peril? 

How does contact tracing work?

Although there are many different ways apps like this could work. For simplicity, let’s stick with how the NHS app works.

The app is incredibly simple. It uses Bluetooth to ‘ping’ any other phones (with the app downloaded) in your vicinity. The app then stores a record of anyone you’ve been in close contact with over a relevant time frame. For example, the 2-14 days symptoms typically take to appear in those who come into contact with the virus. 

If anyone receives a COVID-19 diagnosis, the app notifies everyone recorded within the infection range. It then sends a message asking users to self-isolate. 

What are the privacy concerns? 

At this point, you may be wondering what the problem is. The app seems intuitive, it has the crucial benefit of simplicity, and it’s easy to scale (after all, 79% of us own a smartphone). 

Most experts are broadly in agreement that the system is needed and a good idea. Where opinion differs is in the best way to design an app to accommodate it. 

This argument centres around whether we should be building centralised or decentralised apps to tackle contact tracing. A centralised app means that in the event a user flags a positive test result, the data from their phone is sent to a centralised database run by a healthcare body or the government. This central database then unlocks the identities of the infected person and anyone they’ve been near. 

In a decentralised model, this same process is repeated on the phone itself, meaning the government or healthcare body never receives any identifying information about app users. Instead, any data they collect is depersonalised, for example, the number of people infected and their geographic spread.

Privacy and security campaigners worry about the centralised model because it’s open to ‘scope creep’. Or, to put it another way, just because the technology is being used for benign purposes now, doesn’t mean it couldn’t be applied for mass surveillance in the future. 

The UK had planned to use a centralised model. However, partly due to these concerns, and Apple and Google declaring they wouldn’t allow its use on their phones, it’s now switched to a decentralised model

What about security? 

The other big concern about any contact tracing app stems from whether its data is completely safe from cyber attacks. A recent report from two academics specialising in cybersecurity, reveals that contact tracing apps may have some unforeseen vulnerabilities.

We won’t delve too far into the technical reasons behind the findings. In essence, most of the models for apps we’ve seen from governments so far transmit encrypted and unencrypted data side-by-side. Security experts fear that this could mean would-be hackers have an ‘in’ to identify individual users and steal their data.

Are your cybersecurity and privacy really at risk? 

We’ve outlined some of the security and privacy concerns about contact tracing apps, but how at risk is anyone who uses one?

Privacy – Had the UK government pushed ahead with its plan to use a centralised model, this would have been a very different article. However, the move to a decentralised approach has mitigated most privacy concerns. 

A decentralised app won’t share any personal information about you. It won’t share your geographic location with any third party. And, from an inter-user standpoint, the design shouldn’t allow anyone to work out who in their recent contacts has become symptomatic. 

Security – This issue is a little thornier. The questions raised by the report we mentioned earlier haven’t gone away, but at this stage, they remain theoretical problems rather than something users are reporting. What’s more, the GCHQ National Cyber Security Centre (NCSC) is aware of the findings of the report and is working towards fixing them. 

Contact tracing apps aren’t perfect, but it’s a balancing act. As with any state-run technology, they face questions about privacy and security. On the other hand, the risks to privacy are small and security is only likely to improve as the technology does. More importantly, contact tracing has enormous potential to help us get back to something more like the pre-COVID world. So perhaps the real question is can we afford not to use it? 

Looking to improve your cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.

CyberSmart forges new channel partnerships to reach SMEs

We are delighted to announce two exciting new partnerships this week at CyberSmart. The first with Ingram Micro Cloud, part of one of the world’s leading channel distributors (IMUK), and the second with Synaxon UK, one of Europe’s largest channel buying groups.

Through these partnerships, we are extending our reach to allow us to help many more SMEs who are struggling to balance the demands of their business with the risks of cyber security.

“The team at CyberSmart is thrilled to be teaming up with new partners to do what we do best, and that is to defend the underdogs,” says Hugh Furness, CyberSmart’s Head of Channel Strategy.

“SMEs are often neglected in cybersecurity. With a lack of resources and expertise, they are an easy target for bad actors. With the help of these partners’ help, we hope to extend our reach and foster a strong security culture across the channel.”

The streamlined CyberSmart service makes it easy for any business to achieve the UK government-backed security certifications including Cyber Essentials, Cyber Essentials Plus, and IASME-GDPR. And the prevention of cyber attack doesn't stop at certification. A compliance software ensures every device, personal or professional, used by a business is always secure.

Timing is everything

Cyber security is more important than ever. As the UK begins to reopen and offices welcome staff back, many businesses have emerged from the crisis into a hybrid world. The mix of remote and office working adopted by many organisations brings with it new security risks.

A recent report from VMWare reveals that 91% of organisations have seen an increase in cyber attacks as a result of employees working from home. Online protection has become more important than ever before, but many businesses, especially smaller ones, still find the idea of it daunting.

"Cybersecurity is a huge issue and the importance of achieving Cyber Essentials certification and demonstrating that you are ready to protect your organisation, employees, and data, has never been greater," echoes Mike Barron, Managing Director of Synaxon UK. “Our partnership with CyberSmart has come at exactly the right time. With more companies now operating virtually and most employees working at home, that’s becoming crucial. We've received an immediate and extremely positive response from Synaxon UK members who are using CyberSmart to get certified themselves and encouraging their customers to follow their lead.”

“Adding to our Cyber Security portfolio, CyberSmart aligns perfectly with our desire to create a unique environment in which our partners get the best in-house solutions, services and support,” concurs Colin McGregor, General Manager – Cyber Security, Ingram Micro UK, “We’re excited to show our partners just how we can facilitate their cyber needs, with CyberSmart no doubt contributing to this success."

The CyberSmart team believes that every organisation should be able to easily comply with recognised standards to protect their data and infrastructure. Synaxon and IMUK will help us deliver that ability to many more businesses.

About our new partners

Ingram Micro Cloud (IMC), a division of Ingram Micro UK Ltd, was established in 2014 to help its partners realise their share of the cloud market opportunity. Ingram Micro Cloud is a master cloud service provider (mCSP), offers channel partners and enterprises access to the leading global Cloud commerce platform, expertise, solutions and enabling programmes that empower organisations to realise their potential in the digital economy. Ingram Micro Cloud is the leading Cloud aggregator in the UK and a software company that is the powering engine for the channel.

Synaxon UK was launched in the UK in 2008 and has since become firmly established as the market-leading channel services group. Synaxon is much more than a dealer buying group. It’s a thriving, dynamic and forward-thinking community that works to advance the development and growth of its members. Synaxon offer a wide range of services as well as personalised account management and business development support to help MSPs, resellers, retailers, and office products dealers thrive.

New webinar: Staying cyber secure as the UK reopens

We’ve all read the headlines about ‘unprecedented times’ and how ‘things will never be the same again’ post-COVID-19. Some of the commentary on our post-pandemic world might seem a little overblown. However, for cybersecurity at least, a lot of it rings true.

As the UK begins to reopen and offices welcome staff back, businesses have emerged from the crisis into a hybrid world. The mix of remote and office working adopted by many organisations brings with it opportunity. But it also brings new security risks too
(more on that here).

A recent report from VMWare reveals that 91% of organisations have seen an increase in cyber attacks as a result home working. In this environment, online protection has become more important than ever before. But how can businesses, particularly SMEs without large security budgets, become more cyber secure?

Join CyberSmart CEO and cybersecurity supremo, Jamie Akhtar and Guy Waller, Partnerships Manager at Starling Bank as they tackle the following questions in a short webinar.

  • What are the new and existing cyber-threats for businesses?
  • As businesses reopen, and staff are working both from home and the office, what new challenges does this pose?
  • What are the best ways businesses can protect themselves and stay one step ahead?

To learn more, watch the full webinar, for free, here or below.

If changes in working practices have got you thinking about improving your cybersecurity, a great place to start is with Cyber Essentials certification. It’s a simple, 24-hour certification process that could improve your protection from cyber-attacks by 99%. Get started today here.

Get started

How to shift to working from home permanently without compromising your cybersecurity

Coronavirus has the potential to change the world of work forever.

Unless you’ve spent the last few months consciously avoiding the media, chances are you’ve read that sentence a lot. From morning talk shows to breathless newspaper op-eds, it feels like everyone is talking about the society-wide shift to working from home.

But what started as a necessary evil that many businesses adopted reluctantly has turned into something else. First came announcements from Twitter and Facebook that employees would be allowed to ‘work from home forever’ if they chose. This was followed by a host of other businesses including Google, Amazon, JPMorgan, Captial One, Slack, Salesforce, Microsoft and PayPal extending their work-from-home options.

Why is this happening?

Well, it’s actually very simple. An increasing number of businesses are seeing the real benefits of a more permanent shift to remote working.

Why rent office space for 300 people when you could use a smaller venue for essential meetings at half the cost? Why insist staff make long commutes into the office, when they’re happier and more productive working from home? 

For many organisations, the COVID-19 pandemic has turned these questions from water cooler conversations into key pillars of business strategy. 

If your business is considering making the switch to permanent remote working, are you prepared for the risks you should be aware of? And, how can you overcome them and ensure your people are working safely? 

What risks does working from home present? 

While switching to remote working offers benefits in productivity and real estate savings, it also comes with some risks. Here are a few of the most common. 

Unsecured personal devices 

The first question to ask is: can you be sure your people will follow the same security protocols they would in the office? The networks and security tools your staff use at home are likely to be far less secure than those in the office. Home office networks are 3.5 times more likely than corporate networks to be infected by malware, according to a report from BitSight. 

There may even be a psychological element to this. As ZDNet has reported, 52% of employees believe they can get away with riskier behaviour when working from home. For example, sharing confidential files via email instead of the usual, safer channels. 

Lack of remote-working policies and procedures

Part of the reason employees are exposing themselves to risk at home is simply a lack of knowledge of these risks. The COVID-19 pandemic developed so quickly that many businesses didn’t have time to put in place clear policies and procedures for working from home so employees were literally left to their own devices.

This makes cybersecurity a bit of a guessing game, particularly for the less security-literate of your staff. 

Heightened risk of attack

Cybercriminals are smart but they’re largely opportunistic. And it hasn’t taken them long to figure out that switching to remote working has made businesses vulnerable.

VMWare’s recent Global Threat Report, reveals that 91% of global respondents have seen an increase in cyber attacks as a result of employees working from home. Meanwhile, the proportion of attacks targeting remote workers increased from 12% of all email traffic in March to 60% just six weeks later. 

91% of organisations have seen an increase in cyber attacks as a result of employees working from home.

Keen to exploit our hunger for coronavirus updates, cybercriminals have set up thousands of COVID-19-related ‘news’ sites. These double up as hosts for malware and domain names to launch phishing attacks from. Without the robust controls deployed by most corporate networks, it’s incredibly easy for people working from home to fall into the trap. 

The other area cybercriminals are targeting more regularly is VPNs. VPNs have long been a weak point for cybersecurity. They were only ever intended for small numbers of workers to use occasionally, not whole companies all the time. As a result, many VPNs are insecure and provide cybercriminals with a much wider ‘attack surface’ with which to launch threats

Reliance on the Cloud

We talked about some of the potential issues with cloud storage in a recent blog and, while it’s the safest option for businesses, it’s not invulnerable to attack. 

Working from home naturally increases your reliance on the Cloud. And this isn’t necessarily a bad thing. However, cybercriminals are becoming better all the time at breaking through providers’ defences and intercepting data as it moves between employees’ devices and the cloud. 

How can you overcome these risks? 

We’ve tackled some of the risks involved in switching to working from home, so what can you do about it?

Provide clear policies and encourage communication

This is the most important step on this list. If your people don’t know which behaviours are harmful, they can’t correct them. Ensure all security policies for workers are clear and easy to follow. If you don’t have a remote working security policy, now’s the time to draft one.

Alongside this, work to foster a culture of communication. That way, employees will feel comfortable asking for help with anything they don’t understand and reporting anything suspicious to internal security teams. All too often, security mistakes are made because staff feel ‘silly’ raising their concerns. 

Ensure the right security is in place 

Many of the most common threats can be prevented simply by ensuring your people have the tools they need. Check that all corporate-owned or managed devices are equipped with the best security capabilities. Also, make sure that the security best practices you’d use in the office are extended to the home environment. 

Maintain good password hygiene

Set up a password policy and ensure everyone follows it. Employees should always use complex passwords and two-factor authentication, as well as change passwords regularly. 

Make sure software is up to date

Your employees should regularly install updates and patches for the software on their devices, no matter how much they might enjoy not restarting their laptop for months on end. 

Keep it professional

Encourage your workers to keep work devices for work and personal devices for everything else. Limiting the number of sites employees visit can limit the risk of attack. 

Secure Wi-Fi access points

Network gateways are an underappreciated aspect of good cyber hygiene. Most of us don’t think much about our WiFi once it’s up and running. However, changing the default settings and passwords on a router can reduce the potential of attack from connected devices.

Understand the risks

Hopefully, this article has been some help in identifying some of the risks remote working presents. But it can’t be stressed enough that understanding the risks is key to preventing them. IT teams need to identify the most likely areas of attack and prioritise the protection of areas of your business that cybercriminals could do the most damage to. 

Although the switch to working from home comes with difficulties, it’s also a golden opportunity to remould the way your business functions. Alongside, the obvious real estate savings, remote working promises happier employees, more productive work and greener business practices. Don’t let poor cybersecurity stand in the way of your business embracing the future. 

Looking to improve your cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.

CTA button

New whitepaper: Cyber Essentials for Education

If you work in education and are applying for funding, you’ve probably heard the phrase ‘Cyber Essentials' mentioned. Cyber Essentials are a set of security guidelines laid out by the UK government to help organisations address the basics of cyber hygiene.

It's important to education providers because Cyber Essentials certification is now part of the security requirements for Education and Skills Funding Agreements (ESFA).

For the 2020-21 funding year, all recipients must meet the requirements for the UK’s Cyber Essentials scheme. And next year, achieving Cyber Essentials Plus certification will also be mandatory. 

However, cybersecurity and funding requirements can be confusing. So, we’ve put together a guide to help you get certified and meet the EFSA funding deadline. The guide covers everything you need to know, including: 

  • What the Cyber Essentials scheme is
  • The difference between Cyber Essentials Standard and Plus certifications
  • Why cybersecurity is important to the education sector 
  • How to get certified immediately and meet the EFSA deadline
  • How to move beyond certification and keep your organisation protected

To find out more and get prepared for the EFSA deadline, download your free copy here or follow the link below.

ESFA CTA