By Mitchell Scherr, CEO, Assured Cyber Protection®
We are living in the largest upheaval of modern life in generations. Worldwide, governments have enforced lockdowns in response to the pandemic, placing limitations on our movement to reduce the risk of infection. As a result, businesses have swiftly transitioned to remote working models. Whilst this move is challenging for organisations of all sizes, SMEs are particularly exposed as only 46 per cent report having a formal cyber security policy in place. This has created new opportunities for cyber criminals to exploit vulnerabilities in a company’s cyber defence system. At this time of heightened risk, it is crucial that cyber security is front of mind for businesses of all sizes and they take steps to improve their cyber hygiene.
Risks of going remote
Whilst remote working has been a necessary measure in the fight against COVID-19, it has denuded several layers of security normally provided by the office environment. Many employees are now working across multiple devices, including personal ones connected to shared networks. They have become reliant on video conferencing and collaborative platforms to share sensitive communications.
Home Wi-Fi networks frequently use basic or factory-standard passwords which are more vulnerable to hacking, whilst shared network environments open the possibility of multiple unprotected connections. This risk is heightened by the strain that such a sudden influx of remote endpoints can cause to a company’s infrastructure. Cyber criminals, aware of these vulnerabilities, are using them as fresh avenues for exploitation and extortion. In March alone, there was a reported 400 per cent rise in cyber attacks globally.
Spotlight on SMEs
With remote working causing unexpected strain upon a company’s cyber defence system, SMEs may find their cyber security protocols are no longer capable of supporting and protecting their operations. Firstly, to address this growing problem, businesses should conduct a thorough vulnerability assessment. This will show where the business stands in terms of their cyber security exposure by assessing the current state of their security infrastructure. This will inform of the necessary steps required to secure their data.
The first step is to ensure the use of a Virtual Private Network (VPN), which is a simple, yet highly effective way to enhance digital security. A VPN establishes a secure, private connection between the organisation’s servers and the home and encrypts all the data sent between the points. This ensures the integrity of the data and that the connection is bona fide. The added advantage is that the connections can be disabled quite easily and so if there is a network problem, endpoints can be isolated and removed from the equation.
Endpoint Detection and Response (EDR) software should be implemented in tandem with the VPN
EDR software is a relatively simple and cost-effective way of warning and alerting of potential cyber attacks. Deploying automated detect and response software means that IT departments can concentrate on responding to everyday IT issues while trusting that EDR is guarding the network’s distended perimeter.
The weakest link
Whilst this is a solid starting point, the greatest weakness in a company’s digital armour is often its own employees. More often than not, a cyber security breach is the result of human error or phishing attacks, which rely on ignorance or naivety for success. Usually taking the form of an email, they can be constructed swiftly and distributed widely within seconds. Such emails deploy social engineering tactics to manipulate the recipient into engaging with links or downloads that contain damaging code. This was already a major issue before the coronavirus pandemic and in 2019, 80 per cent of businesses were targeted.
Now, cyber criminals are harnessing the confusion of the current climate and posing as official bodies such as the World Health Organisation (WHO), the UK government and the NHS. By offering financial aid, relief or information about coronavirus, scammers lure employees into downloading malicious software or revealing sensitive data such as login credentials and credit card details.
The fallout from such an attack can be financially devastating and cause lasting reputational damage. A key part of mitigating this risk is equipping employees with the knowledge and tools to protect themselves, and the business. Robust and comprehensive training empowers employees to spot, report and remove suspicious emails, protecting their company’s digital integrity. Most recently, the Government’s National Cyber Security Centre (NCSC) launched a suspicious email reporting system. This, combined with a strong understanding of the company’s cyber security policies and escalation procedures, will foster the growth of an organic internal security system.
Yet these simple measures are not always implemented. Despite the growing risk and dangerous outcomes, a Make UK survey revealed that one in three businesses do not provide any form of cyber safety training to their employees and 50 per cent lack the means of tracking their security infrastructure. Cyber security is not being taken seriously by board members. This is particularly prevalent in SMEs where only 38 per cent have board members or trustees responsible for cyber security. With the move to remote working and increased reliance on digital structures for communication, operations and financial transactions, it is paramount that cyber security is a top priority for senior management and the board. Just one compromised account could bring productivity and operations to a halt. When this happens, it is the board who will be held accountable. The fact is, the average cost of a cyber attack to SMEs is £162,000, with one in ten reporting costs of more than £20,000. Given the current reliance on digital infrastructure, this cost would likely be even higher today. The question for board members then, is whether this is a risk they can afford to take.
It is critical that SMEs fully consider the steps outlined above and implement them in order to establish appropriate cyber security awareness and protect themselves from risk of breach. The move to home working has raised concerns about our digital health, as criminals ramp up operations to exploit the vulnerabilities exposed by remote working. Network insecurities and phishing attacks are preventable threats, but they need to be treated with the seriousness that they warrant. In doing so, businesses protect their cyber health and safeguard their future.