Celebrating Cybersecurity Awareness Month
For many, October means spooky season. The time of year for jack-o-lanterns, ghost stories, and trick or treating. October also represents another important time of year, Cybersecurity Awareness Month, a time for individuals and businesses to evaluate their security practices and ensure proper cyber hygiene.
The US federal agency CISA (Cybersecurity and Infrastructure Security Agency) chose "Securing the Next 250" as this year's theme, in concurrence with the United States 250th anniversary, focusing on building digital resilience that will last for years to come. Their principles they have outlined apply to every business that depends on technology, which, in today's world, is almost all of them.
When it comes to cybersecurity, it is never a matter of if a cyber incident will occur, but when. The big questions businesses need to ask themselves are how will operations come back online, how will this affect client trust, and what will extend downtime cost?
Starting With the Basics
The core advice of cybersecurity has not changed much over the years for one simple reason, they work. Many successful attacks occur because of simple, and preventable, gaps. CISA has outlined these 4 actions as the basis for any proactive security plan:
Recognize the signs, and know how to report, phishing.
- Scam emails, texts, and phone calls are more convincing than ever with the power of AI behind them. When a request for money, passwords, sensitive files, or something you find odd and unexpected comes through, verify it through a known, and previously used, communication method.
Use strong passwords and a password manager.
- Every account should have a long and unique password. A password manager can create and store them for you, allowing for ease of mind.
Turn on multifactor authentication (MFA).
- MFA is one of the most effective protections available for your accounts. It should be enabled on emails, remote access of systems, and any business application.
Keep your software up to date.
- Attackers can exploit known gaps in unpatched systems within hours of the vulnerability becoming known. Updated should be done regularly and consistently.
Have a Plan in Place
It's not just about preventing attacks, having a plan on how to respond to one is just as important. For businesses, CISA has put an emphasis on additional priorities such as regular data backups, encrypting data, being able to flag and report incidents, and having a tested incident response plan in place.
When it comes to an incident response plan, simply having one is not enough. A useful plan is regularly reviewed, easily accessible and known by your team, and answers these practical questions:
- Who do you call when something goes wrong, and how do you contact them?
- Who is in charge of relaying relevant information to clients, staff, or insurance carrier?
- What are your legal notification requirement and timelines for completion?
- How do you, as an employee or business owner, immediately respond to mitigate damage?
Best practices dictate that your plan should be reviewed with your team at least once per year, address any gaps, and determine solutions for addressing them.
The 3 R's: Reduce, Replace, Recover
CISA also promotes practicing the 3 R's of Cybersecurity.
Reduce your Exposure - Every device, account, and application is a potential door for cyber attackers. Take inventory of what you have and set user permissions so only the employees and vendors who need access to certain data have access.
Replace anything Outdated - Computers, firewalls, and software that no longer receive security updates should be retired and replaced with an up-to-date version. Without regular security patches, gaps are left that can be easily accessed by malicious attackers.
Recover Quickly - Recovery is paramount, the longer your systems are down, the more it costs you financially and reputationally. Make sure you have at least 1 copy of your backups in an offsite and secure location. Perform full restore tests regularly so ensure your backup is working and know what systems are priority when performing a backup to get you up and running as quickly as possible.
Security for the Long Haul
Cybersecurity Awareness Month may only be for 31 days, but practices and reviews should be happening all year round. The businesses that bounce back from a cyber-attack or data breach aren't necessarily the ones with the biggest budgets or most sophisticated tools. They are the that took the time to cover the basics, plan ahead, and always improving.
In honor of the month, we are offering a free resource, providing businesses with multiple IT checklists from risk assessment to AI guidance, walking through the questions every modern day business owner should be able to answer. You can download the free resource here.
As you're going through, you may find a few things you'd want a closer look at. AdvanTech is offering a Road Mapping Session, designed to evaluate your current infrastructure, and build out a personal roadmap for your business to get your tech where you want it to be, on your schedule, and for your unique needs. Submit the form below, and a member of our team will be in contact with you: