The Cyber Essentials questionnaire: are you prepared?

In 2015, a research team at Lancaster University concluded that 99% of cyber risks could be avoided through following a set of surprisingly simple security measures. These measures, or controls, make up the basis of the government's standard for security certification, Cyber Essentials, which is what we help businesses achieve here at CyberSmart.

However, there's a lot you can do on your own to prepare yourself for the Cyber Essentials assessment or just to improve your general cyber hygiene around its guidelines. We're going to walk you through some of the processes you will need to have in place when you complete the self-assessment for Cyber Essentials before it is reviewed by an assessor.

Keep in mind that the Cyber Essentials questionnaire is asking you to evaluate every device in your company (laptops, personal computers used for work, phones, the works) and whether it complies with the rules. If it is being used for work, it should be included.

Choose the most secure settings for your devices and software

☐ Know what 'configuration' means

☐ Find the settings of your device and try to turn off a function that you don’t need

☐ Find the settings of a piece of software you regularly use and try to turn off a function that you don’t need

☐ Read the NCSC guidance on passwords

☐ Make sure you're still happy with your passwords

☐ Read up about two-factor authentication

Control who has access to your data and services

☐ Read up on accounts and permissions

☐ Understand the concept of 'least privilege'

☐ Know who has administrative privileges to your data and on which machines

☐ Know what counts as an administrative task

☐ Set up a minimal user account on one of your devices

Protect yourself from viruses and other malware

☐ Know what malware is and how it can get onto your devices

☐ Identify three ways to protect against malware

☐ Read up about anti-virus applications

☐ Install an antivirus application on one of your devices and test for viruses

☐ Research secure places to buy apps, such as Google Play and Apple App Store

☐ Understand what a 'sandbox' is

Keep your devices and software up to date

☐ Know what 'patching' is

☐ Verify that the operating systems on all of your devices are set to ‘Automatic Update’

☐ Try to set a piece of software that you regularly use to 'Automatic update'

☐ List all the software you have which is no longer supported

If you can follow this guidance now, you can pass certification quickly and with flying colours. If you struggle with any of them, CyberSmart has helped guide hundreds of SMEs of all sizes and experience through the same process, so feel free to get in touch. We offer a quick and simple step by step process so you can get Cyber Essentials certified today.

Essential cyber security terms: decoded

If you’re like most people, no one ever taught you how to use a computer. Not properly. They aren’t like cars. Rightly so, we force excitable teenagers through a host of training before we let them behind the wheel. They spend months in lessons learning the basics of how to use it, maintain it, and control it before they can be trusted to take it out on the road.

No, at some point most of us just sat down at a screen, ignored the instruction manual, and relied on some well-designed user interfaces to figure it out ourselves.

This is a dangerous game. Your computer is not an isolated piece of hardware. It is linked to that greatest of connectors and stores of information- the internet.
These computers have access to your banking details, your shopping preferences, your personal data and correspondence and most of the time we’re operating them with very little training or testing.

As the world of cyber security develops, it’s important that businesses and customers have at least a rudimentary knowledge of basic terms which they may come across as they live and work via their computers. You don’t have to be an IT technician to protect your device, just as you don’t have to be a mechanic to check your oil.

We’ve compiled a short list of some of the most common terms in the cyber security world and what they mean for you. So hopefully, next time you see a prompt for two-factor authentication, you’ll take them up on it:

Antivirus
Antivirus software is used to prevent or remove unwanted malware from infecting a computer. Using this software provides a computer user with a safer working environment and a more efficiently operating computer. There are lots of companies offering anti-virus software including Avira, Symantec and McAfee.

Breach
An incident in which data, computer systems or networks are accessed or affected in a non-authorised way. Also known as a ‘hack.’

Bring your own device (BYOD)
An organisation's policy that allows employees to use their own personal devices for work purposes.

Cloud
Where shared compute and storage resources are accessed as a service (usually online), instead of hosted locally on physical services. Resources can include infrastructure, platform or software services.

Digital footprint
A 'footprint' of digital information that a user's online activity leaves behind.

End user device (EUD) or end point
Collective term to describe modern smartphones, laptops and tablets that connect to an organisation's network.

Firewall
A network security system that monitors and controls incoming and outgoing network traffic. Establishes a barrier between a trusted internal network and untrusted external network, such as the Internet.

Malware
Malicious software - a term that includes viruses, trojans, worms or any code or content that could have an adverse impact on organisations or individuals.

Patching
Applying updates to firmware or software to improve security and/or enhance functionality.

Pentest
Short for penetration test. An authorised test of a computer network or system designed to look for security weaknesses so that they can be fixed.

Two-factor authentication (2FA)
The use of two different components to verify a user's claimed identity such as a password and text to your mobile device. Also known as multi-factor authentication.

CyberSmart's remote team: tips for staying sane

We’ve always had a strong work-from-home culture here at CyberSmart. We’ve got team members based all over the globe and encourage staff in London to work from wherever they work best. We are, in many respects, ‘remote by design.’

But this week, for the first time, we took the step along with businesses across the world to send our staff home and go fully remote in light of the spread of the coronavirus. 

As we make our way through this first week, hunkered down in our kitchens and living rooms, we’ve implemented a few new office rituals to help keep up team morale. Here are a few of the practices we’ve been using to stay sane:

One of the perks of home working - new coworkers

Stand-up and stand-down meetings

Working from home can be disorienting. You’ve got dogs begging for walks and dishes demanding to be washed while a never ending stream of work alerts is pinging from your computer screen. The line between life and work can be very difficult to see. 

To combat this ambiguity, we have implemented two standing meetings at the start and end of every day. These offer a clear marker for the beginning and end of the workday and provide an opportunity to share priorities and struggles, and to make sure we all know where we’re heading together.

Using a variety of communication channels

We haven’t changed our communication channels since transitioning to a remote setup, but we’ve quickly realised how valuable they are. Obviously, instant messaging is important in the absence of face-to-face contact, but having different messaging channels for distinct purposes is also key. 

We use Slack for real-time work messages and WhatsApp for generally aligning the team. Project management software like Monday.com or Asana provide a space for organising and scheduling tasks.

Obviously, instant messaging is important in the absence of face-to-face contact, but having different messaging channels for distinct purposes is also key.

Shared lunches

Did you know the word ‘companion’ comes from the Latin roots of ‘com-’ meaning ‘together’, and ‘panis’ meaning ‘bread’? Sharing a meal- breaking bread together- is an age-old bonding experience for us humans and our regular office team lunches were something we knew we would miss when we went our separate ways. We use Google Meet or Slack so we can dial in once a week to see each other’s faces as we devour our respective fridge leftovers.

Tavern

Every Thursday afternoon we do something called Smart Culture and Smart Work in the office. We grab a beer from the fridge or make a cuppa and talk about our company culture, our values, and the way we work. It’s a place where we as employees can help shape the development of the business.

Since we have gone remote this time has become precious. It may be the only opportunity we have in a week to reflect together on the way that we work (something that’s changing shape everyday). We have strong core values but are we living them? Who did a fantastic job this week? What’s blocking our communication between teams? What can we change to support one another better? 

Social (distance) bonding

As with team lunches, our monthly team socials have also been forced into the virtual world. Maintaining a sense of camaraderie while apart is critical right now, so we are experimenting with ways to continue to bond across the void. Online games and virtual farming are on the cards, but we’ll have to see what the next few weeks bring. 

Has your team gone remote to combat the spread of coronavirus? What are you doing to keep up spirits and ensure business continuity? As an information security company, we urge you to be aware of the vulnerability to security breaches that can come with remote working. To help address this issue, we have set up a special page for small businesses focused on resiliency during COVID-19. There you can find more information on best practices and free, downloadable checklists and policy packs for your own use.

A note from our CEO, Jamie Akhtar, on Covid-19 and business continuity

COVID-19

As the Covid-19 virus outbreak continues to escalate across the planet, I would like to update you on how the situation is being addressed at CyberSmart

First and foremost, our thoughts are with all who have been affected by coronavirus, especially the ones who have contracted the virus and to their families that support them. Our team wishes you a speedy recovery.

Our team, customers and partners

The safety of our employees, their families, and our partners and our clients, is our greatest priority. That is why we have transitioned the business to fully remote operations, effective as of Monday 16th March. 

Remote working is a practice that has been tried, tested and encouraged since the beginning of our business - we are “remote by design”. With team members across the globe, the ability to work remotely has always been an integral part of our business continuity strategy, and we are grateful for that now. This experience allows us to continue delivering our services to the highest standard, and uninterrupted, even in unprecedented times like these. 

We will be releasing these very practices we follow, alongside tips from our team, on our new dedicated small business resilience page .

We hope this information helps our customers, partners and any other members of the business community to take on remote working safely and productively.

Business as usual

CyberSmart’s daily operations are carrying on unaffected and we foresee no impact on our operations. With information security at the core of what we do, our team is particularly well-prepared to maintain business as usual, and continue to serve our customers with the highest quality of service.

Because of our remote capabilities, we are now delivering all certification fully remotely. This includes Cyber Essentials Plus which is normally conducted by an in-person auditor. However, our team of assessors is able to use the CyberSmart app to remotely test all devices who have it installed and help you achieve certification. Remote audits can be conducted regardless of if your team is in the office or working at home. We support both company provided and users own devices (BYOD) so all situations are catered for. As always, we commit to rapid turnarounds - we will get you certified in as little as 24 hours for Cyber Essentials and 7 days for Cyber Essentials Plus. 

Be aware of your security

I’d like to urge our customers and the public about the importance of cybersecurity to businesses right now as we are seeing an increase in opportunistic people using these ambiguous times to make gains for themselves through phishing and cyber breaches. 

We urge you to take a look at our content for all the tips to make your business safe and, should you have questions, please contact our team. We are here to use our in-house expertise to aid and advise, free of charge.

We urge you to take a look at our content for all the tips to make your business safe and, should you have questions, please contact our team. We are here to use our in-house expertise to aid and advise, free of charge.

CyberSmart is here to help

These are unprecedented, challenging times and I believe we will only make it through by bringing the business community together and supporting each other. As we become more socially distant, it is more important than ever that we stay connected. 

Please feel free to reach out to me and our team on hello@cybersmart.co.uk if there’s anything you think we can support with.

Stay positive, stay healthy and remember - together we are stronger.

Jamie Akhtar

CTA button

Remote working best practices: what makes a strong password?

Still using the password you conjured up for your first email account in 2002 featuring your favourite footballer? We hope not. Passwords play an absolutely essential role in the security of your company and weak passwords are some of the easiest way for hackers to breach your cyber defences through employee accounts.

In this article we'll be sharing advice on how to avoid this common, but easily avoided, security pitfall.

Minimum password length for systems

For all password-protected systems, your business should try to follow these basic steps when configuring them:

  • The minimum length for a password should be at least 8 characters including all alphabets, symbols, and numbers.
  • There should be no maximum password length.
  • The system should not allow the user to set a password that does not meet the minimum length requirements for it.

The requirements mentioned above are simple to understand but can be difficult to implement. It is important to note that these rules need to be established across all password-protected devices and software.

To meet this requirement, you need to consult with your IT manager to ensure that all devices and software (whether third-party or proprietary) enforce the minimum password length.

Enforce a secure password policy

A password policy is used to establish the rules and requirements for setting passwords. Creating a secure password policy for staff helps businesses protect themselves and allows them to meet the password requirements under the government's Cyber Essentials certification scheme.

The goal of a password policy is to take away the burden of individual users to create solid passwords. However, users should still be made aware of the password policy so that they pick sensible passwords for their email, devices, and other accounts.

Other than the minimum password length requirement mentioned above, your employees should:

  • Avoid obvious passwords that can be easily discovered or guessed such as their name, phone number, birthdays. That goes for your pet's name too.
  • Not choose common passwords such as the ‘abcdefgh’, ‘12345678’. This can also be implemented through a blacklist that prevents users from keeping common passwords.
  • Memorise their passwords instead of recording them whenever possible. Don't email them to yourself or keep them in your Notes.
  • Not use the same password for different accounts. 45% of Brits have the same password for half of their online accounts. Not great.
  • Use password management software or other secure mechanisms for storing and retrieving passwords.
  • Require the system to:
    • Protect against brute-force password guessing algorithms by locking accounts after a set number of unsuccessful attempts to enter the password.
    • Change default or common passwords to random non-guessable passwords.

If you want to see how long it would take a computer to guess your current passwords, check out HowSecureIsMyPassword.

Conclusion

Ensuring the use of strong passwords is a key step towards becoming digitally secure. 

CyberSmart helps businesses comply with Cyber Essentials by simplifying the process of compliance for them including complying with password regulations. If you would like to learn more about how to implement a password policy for achieving Cyber Essentials, get in touch with us.

Practices for maintaining cyber security every business owner should know

As the span of regulations, risks, and budget evolves and your business grows, the maintenance of cyber security shouldn’t just be an afterthought – it should be part of the bedrock of your organisation.

The Cisco 2020 CISO study demonstrated that cyber security remains a high priority among executive business leaders, with an increase in investment for security automation technologies as the scale of complexity increases. 

While it’s helpful to have an automated security team in place to combat cyber attacks, there are several steps you can take as a business to protect yourself:

Strict access control (Zero Trust)

Zero Trust is a holistic information security framework and an essential component of cyber security. Rather than assuming all people and systems operating within a secure setting should be trusted, it relies on constant verification before granting access. 

This can be implemented through a series of steps. Firstly, data access should be managed by a multi-factor authentication (MFA) system. Only 27% of businesses are making use of an MFA system. 

Secondly, employees should be prompted to update devices to combat existing vulnerabilities, and user access to data management applications should be managed through central policies.

The Cisco report demonstrated that more than half of respondents noted that mobile devices are becoming an increasing challenge to defend. It suggests a zero-trust strategy as the best way to remedy this.

Updating regularly

This report showed that 46% of organisations were faced with incidents as a result of unpatched vulnerabilities. This means that a software provider issued an update in response to an issue but an employee failed to run the update.

Breaches to data management environments can cause hefty losses of data, and when patches are rolled out it is crucial to apply them immediately to limit the timeframe in which the vulnerabilities can be exploited.

Monitoring implementations

When cyber security practices are being continually developed and regulated, it becomes important to regularly monitor connectivity on the network or data applications to review how well the security measures are faring. 

Detection utilities should always be managed and routinely updated so that when incidents do arise, they can be properly investigated. Many small and medium-sized businesses have found CyberSmart’s monitoring app helpful for this purpose. It can be installed on any device and up-to-date information on every device’s security status is available through a centralised dashboard.

Centralise security essentials

The biggest factor in the growing challenge of propagating adequate cyber security is the level of complexity as a business scales. When an organisation utilises multiple security solutions, centralising them in an integrated platform reduces the complexity which makes it easier to manage, update and review security essentials. The benchmark found that 42% of respondents were more inclined to give up on maintaining adequate cyber security due to its complexity.

CyberSmart offers several ways for the cyber security of even smaller businesses to thrive, and our Cyber Essentials and Cyber Essentials Plus certification takes complexity into consideration and simplifies the process.

Everything you need to know about user authentication

What is user authentication?

User authentication is a key part of GDPR compliance and is the process of verifying human credentials to a machine to confirm the identity of the user. This usually consists of the simple input of a user ID and password, but as this is often too weak to protect important data, other factors of authentication can be added to bolster your cybersecurity.

How can user authentication be strengthened?

User authentication can be strengthened by layering cybersecurity methods to ensure that only an authorised user has the ability to access their account. This can be achieved in a number of ways:

Two-factor authentication

Two-factor authentication is a cybersecurity method in which users are required to enter a code into the system that is sent to one of their other devices, such as a smartphone. This adds another layer of security but can make the login process take slightly longer as the code might take a minute or two to be sent.

Third-party authentication

Third-party authentication is a process by which users can log in to their account via a third-party that may already have their credentials, like their social media account, phone, or email. OAuth is typically used for third-party authentication so that users can log in to a server via Facebook, Google, Twitter or a similar site. This can be easier for some users because they don't have to memorise a different user name or password for every account they create, but it is essential that their third-party credentials are secure.

Context-based authentication

Context-based authentication is a cybersecurity method that requires the user to confirm their identity because there was suspicious activity on their account. For example, if an account was logged in via a different location or device than usual, a user will receive a notification on one of their other devices to confirm that they are the one trying to log in. This form of authentication is useful at detecting possible hackers as the user needs to provide extra security details to access their account.

If you need to bolster your security and become compliant with GDPR regulations, get in touch with Cyber Smart today and our experts can help you achieve government-backed Cyber Essentials, Cyber Essentials PLUS and IASME GDPR Certification.

The business risk that’s more worrying than Brexit

News articles have continued to highlight the impact Brexit could have on UK businesses in 2020. With everything from visas to regulations and import taxes, businesses face a lot of uncertainty in the coming years.  

However, despite Brexit continuing as a hot topic in business media, surveys have found that it is not the most pressing issue on business leaders’ agendas. Instead, data protection topped the list

The first half of 2019 saw data breaches leave 4.1 billion records across the world exposed, and they are continuing to occur on an almost weekly basis in the UK. The rapid sophistication of cyber attacks is leaving an increasing number of UK’s businesses vulnerable to these potentially devastating breaches.

80% of CEOs concerned about cyber threat

PricewaterhouseCoopers conducted a recent survey to gauge the key areas of CEO uncertainty and how they are taking action to address them. The findings found that eight out of ten CEOs are concerned about the threats posed by a cyber attack. 

This concern emerges among a growing abundance of news stories reporting enormous data and security breaches at top companies and organisations, which end up costing them hundreds of thousands in compensation. 

One of the most publicised cases of 2019 was the British Airways breach in which the details of about 500,000 customers were stolen by hackers. As a result, BA was charged a fine of £183 million.

This is a corporate example, but even small businesses are at risk of fines for violating GDPR data protection laws. If you’re wondering if you’re GDPR compliant, CyberSmart offers a simple, non-technical path to GDPR certification.

The public wants to know businesses are protecting their data

Media coverage and market research make it clear that cyber attacks are only going to increase in frequency in 2020, both in the UK and the rest of the world. But this is not just an issue for CEOs. 

The media attention garnered by cyber attack stories have made data regulations and privacy a key issue amongst the general public, who place an increasing premium on companies that take protection of their data seriously.

It’s more important than ever to show that businesses showcase their cyber security certifications and GDPR compliance. 

Pressure from consumers has been further motivation for CEOs to consider data privacy and compliance with data regulations as two of their top issues. 57% of respondents to PwC’s report cited public fears over security as a key factor.

Cyber security starts at the foundation

However, 2020 is expected to see more CEOs focusing on the configuration of their business in order to meet the requirements of cyber resilience. In the increasingly digital landscape of the future, cyber security will no longer be an added feature for organisations to incorporate as an afterthought, but rather a critical feature to be in-built into a business’ infrastructure.

As cyber attacks continue to pose a significant threat to UK businesses in 2020, it has never been more important for companies to ensure they are compliant with data protection laws and agreements. 

CyberSmart several ways that even small businesses can take precautions against cyber threats. Our Cyber Essentials and Cyber Essentials Plus certification offers simplify the process of keeping businesses up to date with UK laws while CyberSmart Active Protect secures your company devices around the clock. 

In addition, we offer products for IASME GDPR compliance enabling you and your company to meet protection standards and have peace of mind in your service.

Cyber attacks already adding up for 2020

The number of cyber attacks have been increasing year on year. So far, 2020 doesn't look much better.

January proved ominous, with a series of successful cyber attacks on organisations across the globe. Here are just some of the attacks over the first month of 2020:

Royal Yachting Association (RYA)

The UK’s national organisation for the yachting community became aware of a digital attack on 17th January. Online user account data was compromised and as a result, all members of the organisation had to change their passwords immediately.

A statement issued by the RYA said: “On 17 January 2020 we became aware that an unauthorised party accessed and may have acquired a database created in 2015 containing personal data associated with a number of RYA user accounts.

“Our investigation into this matter is ongoing and we have engaged leading data security firms, including forensic specialists, to assist in our investigation.”

Mitsubishi Electric targeted by Chinese hackers

One of Japan’s largest defence and infrastructure groups, Mitsubishi Electric, was also hit by a colossal cyber attack in the first month of this year. The attack was blamed on a Chinese group, who may have gained access to information on government agencies and business partners, as well as the personal data of 8,000 employees and job applicants.

Chief Cabinet Secretary of the group, Yoshihide Suga said in a statement that the Japanese Government was informed, while also confirming that “there is no leak of sensitive information regarding defense equipment and electricity.”

Detroit data breach exposes workers and residents

The email system of Detroit City Government was breached on 16th January. Although less than 10 email accounts were affected, some of the accounts contained sensitive information that could be exploited by cyber criminals. Luckily, most of the email data was encrypted.

The city’s Chief Information Officer, Beth Niblock said: “At this time, there is no evidence - and it is highly unlikely - that any of this personal data was accessed. However, out of an abundance of caution for privacy and security of our employees, the city will be offering credit monitoring services for a period of one year.”

Make a cyber security New Year’s resolution

If your company’s New Years resolutions didn’t include improving cyber security, then these attacks should provide a wake-up call. Being cyber resilient is critical to company health.

A surefire way to prove your house is in order is by achieving cyber security accreditation. The UK National Cyber Security Centre’s cyber essentials or cyber essentials plus accreditation schemes are the best way to do this.

3 signs you should update your cyber security immediately

What is GDPR?

Cybersecurity is an issue that most people don’t take seriously until the worse happens- from stolen customer data to electrical blackouts or paralysed information systems. And unfortunately, these incidents have been steadily rising for small businesses.

Basic controls like firewalls and strong password protections can go a long way in protecting you but if your business isn’t up-to-date in terms of security protocols and practices, then you’re likely at a far higher risk than you think of security breaches, data loss or even malicious attacks from hackers and outside sources.

Before it gets to that point, though, recognising that your system isn’t secure is an excellent place to start.

If you, or your staff, have spotted any of these red flags within your system, then it might be time to invest in better cybersecurity, or even consider our 24/7 cyber monitoring software to boost the safety of your business:

Errors or out-of-date notices on software

We’ve all been known to ignore warnings and errors related to the software we use, especially if that particular piece of software continues to work correctly. But out-of-date technology, particularly software connected to the internet or cloud, can be an open door for hackers.

If you’ve noticed errors or out-of-licence notices on company software, updating your processes and guidelines to ensure this is reported, and any updates are done swiftly, is best practice.

OS systems that are not updated to the latest version

Many employees are guilty of this particular security issue. Leaving computers on overnight and never allowing updates to occur may allow for a quicker start to the day, but it’s not worth the security risks it brings. If you find employees regularly lagging behind on the latest OS updates, completing these updates should be included in the responsibilities of your IT team to ensure your company is compliant.

An increase or influx in spam emails or potentially harmful links

Outdated or less secure email systems can lead to a significant increase in the amount of spam your business receives which could have harmful attachments and links included in them. Ensuring your firewall, spam systems, and other security measures are up-to-date can prevent problem emails from reaching you. If you’ve noticed a sudden increase, ensure all your systems are up to date.

All too often, businesses forget all about their cybersecurity requirements until problems occur – whether it’s a virus in the system, a hacking attempt or a full-on ransom demand.

That’s why CyberSmart’s simple app and dashboard alert you any time a device in your company has a firewall disabled, is behind on updates, or needs a software update. Beyond certification, we offer the kind of 24/7 protection that will keep your business, employees, and customers safe in the world of 2020.

To learn more about our software and certification services, contact CyberSmart today.