What is Cyber Essentials Plus?

Cyber Essentials Plus

If you’re a UK SME and part of a big supply chain or going for government tenders, you’re likely to be aware of the needs of Cyber Essentials. The original Cyber Essentials certification was designed to provide businesses with the basics of cyber safety and ethical business practices online; from managing firewalls and user accounts to appropriately protecting their business against malware and data theft. To remain compliant with modern UK business requirements, Cyber Essentials is – well, an essential.

But for businesses wanting to go beyond the basics and improve their safety and the security of their business online, Cyber Essentials Plus is the answer. As one of the services we offer our clients, we deliver the Cyber Essentials Plus certification through IASME and know just how important this higher compliance standard from achieving the ‘Plus’ certificate can be to your businesses.

What's the difference between Cyber Essentials and Cyber Essentials Plus?

So what exactly is the difference between the two certifications? It all comes down to the use of an independent auditor. Cyber Essentials Plus requires still requires businesses to comply with the same five factors as the non-plus model. Known as technical security controls, these include:

  • Firewalls
  • Secure Configuration
  • User Access Control
  • Malware Protection
  • Patch Management

In addition to these basic requirements to be certified, Cyber Essentials Plus goes a step further than the self-certification of Cyber Essentials and requires an independent assessment of the business's internal security controls to achieve this higher level full certification.

Why an independent assessment?

Robust credibility is the driving reason why Cyber Essentials plus uses independent assessment as this ensures companies are indeed compliant with the requirements of the Cyber Essentials scheme. The additional step ensures the safety of the business but further helps authenticate the certification. By verifying you are compliant, the resultant certification award is more trustworthy than an in-house DIY version of the Cyber Essentials certificate.

Which form of certification is best for your business? If at all possible, upgrading from Cyber Essentials to a higher-level certification is the ideal choice for any company. Each assessment includes a vulnerability scan to ensure your business data and information is well protected. If you are genuinely committed to safer online and network practices, for your business and your clients, then investing in Cyber Essentials PLUS certification could be your best move.

Looking to improve your cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.

CTA button

GDPR compliance for SMEs: Key areas to consider

One crucial area of legislation for any SME dealing with customers in the EU now is GDPR. This law came into effect on May 2018 which means businesses have now had a while to ensure ongoing compliance with it. With heavy fines imposed on any company that is found to be in breach of GDPR laws, it is certainly something that your business should pay close attention to. As businesses are now held responsible for keeping the sensitive personal information they may hold safe, you must ensure you do all you can to stay within GDPR rules. 

But what are the major things to think about here? 

Online security 

Top of the list for all businesses now is protecting themselves from online data breaches. This means that the cybersecurity measures your organisation has in place are key. If they are not robust enough and hackers breach your defences to steal sensitive data, you could well be held responsible. This makes investing in your cybersecurity arrangements essential so you have the required protection in place. It is also worth investing in training for staff around GDPR and online security. If they were to fall prey to an online scam which sees them hand over personal data to a hacker, this could also see your business held liable if you had not done enough to educate staff. 

Consent for data to be collected and stored 

Cybersecurity is one part of the GDPR regulations but what about the right your business has to collect and store data initially? This notion of consent is a huge factor within GDPR and something you must be able to show you have. Before any data is collected now, it is key to let people know what for and get their explicit consent to do so. The old days of gathering data to store without asking first or making people aware of why are long gone! 

The right of erasure 

Another major part of these laws is the right individuals have for their personal data to be removed from your systems or databases. This right to be forgotten is now open to EU citizens and must be actioned quickly by your company when they request it. This makes it essential to know where your data is stored so it can be accessed and deleted within the given timeframe. 

Data protection obligations got you in a muddle? Get on top of them quickly and easily with the CyberSmart Privacy Toolbox.

CyberSmart Privacy Toolbox

October is European Cybersecurity Month

cybersecurity month

As our dependence on online resources and internet-enabled devices grows, cybersecurity has never been more important. In the past, cybersecurity was focused on threats. Say, someone accessing your bank account and stealing money. But that's changing fast as we become more aware of threats to our data. And it's these challenges that are the theme of this edition of European Cybersecurity Month. 

European Cybersecurity Month 

European Cybersecurity Month (ECSM) is an annual event held every October. The aim of ECSM is to promote cybersecurity and improve society's awareness of threats. To do this, ECSM provides education and resources throughout the month to help individuals and companies to improve their cybersecurity. As part of ECSM, over 370 events are being held across 34 countries. Similar events are held in other parts of the world too. For instance, America has National Cybersecurity Awareness Month and Canada has Cyber Security Awareness Month. 

ECSM themes 

The theme of this year’s ECSM is the same as previous years: “Cybersecurity is a shared responsibility”. To put it more simply,  cybersecurity requires input from governments, businesses, and individuals. Businesses need to create products with built-in privacy and security measures. Individuals need to secure their data. And governments need to continually update and pass new legislation – take the EU's GDPR for example. 

Sub-themes 

ECSM is split into two sub-themes. The first, 'Cyber Hygiene’, is very close to our heart and focuses on developing daily routines for cybersecurity. Think of it like brushing your teeth or hitting the gym before work. 

The second is 'Emerging `Technology'. This tackles how new technology can pose cybersecurity challenges. The aim is to educate individuals and businesses on the issue and, ultimately, suggest some ways to overcome it.

Should you get cybersecurity certification? 

All this talk about cybersecurity challenges has probably got you thinking. What about your own organisation? What can you do to improve cybersecurity, today? Well, a great place to start is Cyber Essentials certification. It's a UK government scheme that covers all the essentials of cyber hygiene and provides a great base to work from.

CTA button

Why SMEs should automate their cybersecurity solutions

The management of cybersecurity, especially in a growing business, can both be time-consuming and challenging. However, automating your cybersecurity requirements can effectively help your business handle threats, vulnerabilities and essential certifications. Let’s take a look at some of the benefits SMEs can derive from choosing cybersecurity software such as CyberSmart Active Protect.  

Cost savings 

Automating your cybersecurity requirements can reduce your IT costs, which are usually fixed and relatively high when done internally by an individual. The costs are fixed when you choose software like CyberSmart, and even better, you don't need to train or hire in-house IT staff as the technology does it all for you. 

Step-by-step instructions 

Recruiting a qualified cybersecurity employee does not usually guarantee experience. However, with cybersecurity software from leading providers, your business is assured of how-to guides and step by step instructions, which make addressing unique cyber threats and mitigation strategies straightforward no matter your level of technical or compliance knowledge. 

Time-saving and fewer distractions 

Letting automated software handle your company’s cybersecurity requirements saves you time and other resources. CyberSmart Active Protect is probably the best way of ensuring that employees in a company focus their time, attention, and effort on core business issues. It also ensures that they are less distracted by activities involving complex cybersecurity problems and decisions. 

Competitive edge for SMEs 

Unlike large and well-established businesses, SMEs may not be able to afford in-house cybersecurity solutions and support. However, choosing to automate the search for weaknesses in your system can provide you with the same level of security as large firms. 

Remaining compliant 

Just like any other business investment, running an in-house cybersecurity solution is associated with a considerable amount of risk and regulation. However, with vast knowledge and expertise in compliance and security issues, software providers such as CyberSmart will ensure your company remains compliant throughout the year. 

Scalability with the latest technology 

Changes in market demand may necessitate the expansion of a business. Scaling up operations typically comes with its fair share of hurdles, especially from a technological perspective. Hackers have also found various ways of exploiting security measures put in place by businesses. However, with CyberSmart Active Protect, you'll get weekly reports on the status of your business, with any issues you should be aware of brought to your attention as soon as possible.

How to promote cybersecurity culture internally

Cybersecurity in your organisation goes beyond investment in the latest technology. It also requires dedication to inspiring and instilling a healthy culture. It has been established that poor and weak cultures can always open avenues for data breaches and the exploitation of unforeseen or hidden vulnerabilities. However, with a properly instilled culture, employees could as well become your most potent human firewall that protects your business network from cyber-attacks. Therefore, it is essential to weave the cybersecurity culture into the organisation’s policies and practices, which will place workers at the frontline in fighting cyber threats. How then can you foster such a culture and build a stronger front against hacking and other cyber threats? Here are four ways of creating a disruptive, engaging, rewarding, and fun cybersecurity culture with assured return on investment within your organisation. 

Involve everyone in the workplace 

Most organisations believe that cybersecurity is the sole responsibility of the IT department. However, having a sustainable cybersecurity culture requires instilling the perception that it is a shared responsibility. Such practices are vital because almost every employee uses the corporate network at some point, so it’s imperative to include them as a component of the company’s overall security culture and solution. 

Provide basic cybersecurity training 

Training your staff is a critical part of building an influential culture since it gets them talking about security issues and also helps in focusing on end-users, thus making it easier to cover the entire spectrum of cybersecurity. However, it is crucial to start with basic but relevant and engaging training before scaling your way up to more complex ones to weed out bad practices that may make your business vulnerable to cyber-attacks. The simple practices include policies related to passwords, mobile devices, data storage, remote network access, cyber vigilance, and response strategies. At the end of the training, implement a post-training assessment that will measure the effectiveness of the process based on some predetermined metrics. 

Streamline channels for threat reports 

Ensure that your security and IT department is approachable by other employees who may need to report incidences relating to cyber threats. The channels should be open for communication and interaction to promote honesty among employees, even when they’ve made mistakes without fear of being punished for human errors. Your security department should always be welcoming to encourage reporting of security breaches and at the same time, help in building a robust culture by helping employees gain a deeper understanding of what is expected of them. 

Reward good performance 

Always look for opportunities to celebrate your success by recognising and rewarding exemplary performance from employees. Simple rewards can go a long way in motivating employees to uphold cybersecurity standards and measures. You can even go a notch higher by making cybersecurity courses a choice within the company. Such programs offer the potential for the growth of your employees who are passionate about network security.

Three emerging cybersecurity threats

emerging cyberthreats

Cybersecurity is a growing concern for businesses. The cost of recovering from data breaches is simply crippling, especially with the new GDPR legislation. A recent report predicts that cybercrimes will cost the world about $6 trillion every year by 2021. 

Cyber-attacks have become more prevalent and sophisticated. Reports of online exploits, scammers and hackers are no longer top headline news. As technology evolves, cybercriminals come up with new ingenious methods of perpetrating their attacks. Every further advancement in technology provides new security loopholes and risks. Here are three trendy cybersecurity threats that have started to emerge. 

1) Internet of Things (IoT) attacks 

The inter-connectivity of smart devices via the Internet of Things infrastructure has been a growing trend in recent years. Devices such as security cameras, smart appliances, and sensors seamlessly link together to collect, analyse and act on data. IoT is an inexpensive and convenient way to automate and modernise business processes. 

However, most of these devices don’t have robust security features factored into their designs. This creates weak links that unsavoury hackers have quickly learned to exploit. The risk is much greater if the IoT devices link up to high profile networks. 

2) Cryptojacking 

Today, we have over a thousand cryptocurrencies in circulation over the internet. Mining of these currencies is a lucrative venture, although the processes are increasingly becoming harder, hence requiring more computing power. Cryptojacking is where a hacker uses personal or business computing resources such as servers and computers to carry out crypto-mining. 

The hacker may not necessarily be interested in data or vandalism, but piggybacking on enterprise systems causes some serious problems. Since crypto-mining draws a great deal of processing power, the systems slow down, consume a lot of energy, and suffer crashes and malfunctions. 

3) Intelligent hacking 

Artificial intelligence (AI) and machine learning (ML), which are a big part of advanced cybersecurity defence systems are also being used to model cyber-attacks. With these technologies, hackers can create adaptable malware that evades detection while controlling other software tools to their advantage. 

Intelligent malware poses serious threats to AI-based computer models, neural networks, and smart sensor systems. There have already been a few reports of sophisticated cyber-attacks that bare resemblance to AI manipulation. 

Bottom line 

These new cyber threats may seem scary, but cybersecurity systems are still on top of things when it comes to securing your data and resources. A lot of work goes into developing new defences against emerging threats. Your part is to keep up with security updates while exercising basic cautionary measures and good cyber-hygiene. 

Get in touch with us to learn more about cybersecurity and certification standards.

How has cybersecurity evolved?

Cybercriminals now have more tools than ever before to launch more sophisticated and devastating attacks. From artificial intelligence to the dark web, companies need to rethink their security strategies as being reactive simply isn't enough anymore. With the adoption of cloud infrastructure and the use of IoT devices increasing ten-fold each day, cyber attackers have moved inside our networks. With all this in mind, let's take a closer look at how cybersecurity has evolved over time. 

Where did it all begin? 

Cybersecurity began with a simple research project. Having realised it was possible for a computer program to move across networks, Bob Thomas designed Creeper, a program which allowed him to travel between Tenex terminals on the early ARPANET. Ray Tomlinson, the person responsible for the creation of email, saw Thomas' idea and began replicating it himself. However, he created antivirus software instead, which would chase Creeper and delete it. 

The types of attacks have changed 

We've come along way since Creeper, with some of the earliest forms of malicious cyber attacks focusing on PHI theft and credit/debit cards. Although these still occur today, we now have the threat of crypto and ransomware attacks to deal with. Phishing email attacks are still very common (phishing accounts for 90% of data breaches), but it's fair to say they've become more sophisticated over time. Other examples include: 

  • Denial-of-service (DoS) attacks 
  • Distributed denial-of-service (DDoS) attacks 
  • Password attacks 
  • Malware 
  • Man-in-the-Middle (MitM) attacks 
  • SQL injections 

Who is responsible for cybersecurity now? 

In the past, it was assumed that the sole responsibility of a company’s cybersecurity lied with the IT team. However, thanks to an increase in awareness and understanding of cyber threats, it’s becoming a company-wide practice. Phishing attacks, in particular, should be understood by every member of your team, including the risks of opening malicious emails and how to identify or report them. 

What can you do? 

While cybercriminals look to the future for ways to compromise networks, they are also using old techniques which still work. With this in mind, how can you develop effective security measures? You’ll need native solutions and adaptive security deployments which can detect unexpected events and take action to rectify issues. However, while it’s important to nurture your existing talent in regards to cybersecurity, it might be time to consider recruiting IT security professionals too. 

To find out more about CyberSmart Active Protect which provides valuable insights into the status of all your devices, contact us on our live chat, 020 8059 2106 or email us on hello@cybersmart.co.uk today. 

Key signs that your business may be vulnerable to cyber attacks

One of the crucial determinants of success and profitability in SMEs is having a loyal customer base. Building loyalty and trust with your customers starts with ensuring that sensitive information about them is protected and safeguarded from cybercriminals or hackers. SMEs have long been targets of cyberattacks. However, the situation has worsened over the years, mainly due to the widespread use of the internet, which has created more exploitable avenues for cybercriminals.

Compromised systems can lead to unprecedented losses for your business. Therefore, it is important to be adequately prepared to prevent and deal with cybercrime levelled against your business. While there are many indicators of a vulnerable system, here are some of the signs you should watch out for as part of the preparation to secure your business from potential hacking.

Slow connection

A weak and slow internet connection could be a sign that your system is already under a distributed denial of service (DDoS) or denial of service (DoS) attack. When your connection starts to chug along, the sluggishness could be due to system overload caused by an attack. Your operating systems also become slower while programs take longer to start.

System crash

The constant crashing of programs is a strong sign that you may be under a cyber-attack. While crashing is also commonly caused by technical problems, some of them are attributed to malware attacks. In case of such issues, it is advisable to seek a reliable and effective security solution from a trusted provider.

Frequent pop-ups

Pop-up windows are annoying but can also be a sign of system vulnerability. Some of the pop-ups are spyware in disguise and may originate from unsafe downloads, replies to particular emails, and clicking suspicious links.

Excessive and suspicious activity

It may be time to consider the possibility of a cyber-attack if you see suspicious and excessive activity in your system even when your business has not used the hard drive for a substantial period. Just like crashing, suspicious activity may also be caused by different factors, such as hardware problems. Nevertheless, such activities cannot be blatantly ignored. It is essential to monitor all activities on the drive as well as the consumption of space.

Disabled programs and restricted access

When vital security features such as antivirus seem to be disabled or fail to update, you may as well be having a severe cyberattack. Hackers have devised malware tools that not only disable security solutions but also block your access to some sections of your computer, such as the control panel.

Generally, understanding the signs of a vulnerable system is the first step towards protecting your business from cyber-attacks. Other indicators that you may need to look out for are unauthorised homepages, automatic starting of programs, and constant error messages. 

How long do you have to respond to a Subject Access Request (SAR)?

Subject Access Request

The ICO (Information Commissioner’s Office) has updated its guidance (August 2019) on the timescale for a Subject Access Request (SAR). But what is a SAR? And how long do you have to respond to one? 

What is a Subject Access Request (SAR)?

Under the General Data Protection Regulation (GDPR), anyone can request a copy of the data an organisation holds on them. The request can contain any of the following:

  • Why the data is being processed 
  • What type of data it is
  • Who any recipients of the data are
  • The length of time the data has been stored
  • How the data was collected
  • How the data is being safeguarded

Unlike the original legislation, which allowed for a £10 upper limit, it doesn't cost anything to lodge a SAR.

How long do you have to respond to one?

You must respond to a SAR within one calendar month*. And this includes the day you receive the request.  For example, a request received on the 3rd of September requires a response by the 3rd October.  If you'd like more detail, check out the full guidance here

The limited timescale to respond demonstrates how important it is to ensure the data you collect is well-stored, easy to manage and secure. Without these safeguards, a SAR can quickly turn into a painful, time-consuming process. Worse still, it could lead to a GDPR fine (up to 4% of annual global turnover or €20 million, whichever is greater ).

 To help demystify the process, we've put together a six-step approach to addressing a SAR

*If the end date falls on a Saturday, Sunday or bank holiday, the calendar month ends on the next working day.

Are you looking to improve cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.

CTA button

Back to School: Free tips and tricks to protect your business from cyber threats

Cyber threats

All through September, we will be sharing the free tips and tricks, that you can implement straight away to ensure your organisation protects itself from cybersecurity threats.

Currently in the UK, 32% of SMEs experience cyber-attacks every year, a figure that is increasing, with costs running into the thousands of pounds. With a few preventive measures, it is actually possible for you to fight these threats. By implementing various techniques, strategies, using free tools and being aware of the main ways your business might be targeted, you can take protect your business today.

Come back throughout September as we add more tips. It's time to become CyberSmart.

1. Use Two Factor Authentication (2FA)

Adding an extra layer of security to your accounts can never be a bad idea. With a lot of platforms these days, 2FA is available, where you either: receive an SMS (least safe), Email (medium level safety) or authenticate via an app (recommended). There are free and premium solutions available, such as 1Password, allowing you to enable higher levels of security and 2FA across all your personal and business accounts.

2. Time to have an app clear out

Do you know all those apps you have installed but you never use, they should go. If you have apps that have been installed for months, not been updated, they could be full of vulnerabilities, waiting for a cybercriminal to exploit. When you delete these apps make sure to delete your account and unlink any credentials.

3. Are your email details available on the internet already?

This can be a scary thought but more than likely, your email has been compromised before. With the introduction of GDPR, more and more companies are openly admitting cyber breaches. We recommend using haveibeenpwned.com to check if your email has been compromised in a data breach before. Simply enter your email, check for breaches and address the situation.

4. Are you really going to plug that USB in?

You should be extremely careful with USB devices. Even after formatting, malware can still be present so ensure you completely trust the source of the device or go one better, do away with using USB full stop.

5. Update, Update, Update

Updating your apps and software can prevent 85% of targeted attacks. Make your business safer by allowing all updates to be automated, you don’t even need to think about it.

Make sure your operating system (on all your devices) and all applications are updated, at all times, updates are free after all.

6. Always lock your devices

It’s often funny when you walk away from your computer to come back and find a funny background picture, right? During the time you allowed for that to happen your business could have experienced a catastrophic and business impacting data breach (and many other potential risks).

Always lock your screens, and make them only accessible by you.

7. Might be 2019, but that doesn't mean Antivirus is out of fashion

Antivirus is a necessity for all your devices, desktop and mobile. Without an antivirus, you are putting your business at risk of those pesky viruses but also of Malware, lurking in the background, dormant or actively damaging your device. There are many antivirus options out there, some may even come pre-installed with your device, others with free and premium versions. There's no excuse not to be using an antivirus.

8. Turn on your firewall

Most operating systems come with a firewall and there’s a very good reason for this. Ensure all your business devices have this on, as it’ll create a buffer zone between your network and the internet, a highly valuable preventive measure for cyber attacks.

9. Ransomware, sounds scary but what is it?

Ransomware is one of the biggest cyber threats your business faces as it encrypts ALL YOUR DATA and locks you out of your device.  Then normally it requests a ransom payment of a few hundreds of pounds in order to give you a decryption key.

How do you protect yourself?

  • Backup all your data (often and in different locations)
  • Vital business information shouldn’t be only on your computer
  • Don’t click on emails from unknown senders (and NEVER access .zip files in emails from these senders)
  • Like we mentioned earlier, UPDATE your OS and apps
  • Have an antivirus installed

10. Do you know how to spot a phishing email?

Firstly, a phishing email’s intention is an attempt to collect your personal data, and more than likely you have come across it one (or many) before.

  • Serious businesses will never display your email address in the subject line
  • Check out the sender and their email, try to spot how valid it is
  • You don’t have to open an email just because it instils some sort of urgency (the more urgent it may look, the higher the likelihood of a breach)
  • Always check links before you click.

11. Check back tomorrow

Looking to improve your cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.

CTA button