Cyber Security

The big three

The big three

I guess it’s an occupational hazard! But I have read a lot of articles about data security.  Admittedly it can be overwhelming at times, so what I do like is short bursts of information. I have picked 3 security threats and some practical advice and kept it high level, hope it helps!

1.     Mobile Devices

Data loss is always a high risk when employees are using mobile devices, that increases when it is their own device that they are using to share data, access company information or neglect to change mobile passwords!

“According to a BT study, mobile security breaches have affected more than two-thirds (68%) of global organizations in the last 12 months.”

It’s important to have a clear BYOD (bring your own device) policy in place, employees are better educated on device expectations and companies can better monitor email and documents that are being downloaded to company or employee owned devices.

However, one of the devices that’s overlooked is the USB drive! It’s too late to change culture and start putting unenforceable controls on such devices. Thankfully there are technology vendors such as www.ClearCrypt.eu out there who provide secure USB storage devices that offer robust, affordable, high performing solutions which not only secures the data but offers the user a truly enhanced experience over the cheap memory stick!

2.     Your Staff!

It’s well documented that staff either through ignorance or apathy can be a real risk to data security, whether that’s mishandling data, sharing passwords or accessing information they are not authorised to provides the corporate world with real nightmares (add in a rogue user or a colleague with a grudge and the ramifications could be considerable). But who polices the police? One of the areas that’s often overlooked is the IT team itself, even junior staff can have access to the most sensitive data because IT operates at a level behind the firewall – it’s important to keep IT access and control is transparent and auditable.

Something as simple as an unlocked phones can pose as much of a risk as a disgruntled employee who maliciously leaks information. Training is key to enforce security best practices such as weak passwords, visiting unauthorised websites, clicking on links in suspicious emails and so on.

3.      Unpatched Devices

Network devices such as routers, servers and printers that employ software or firmware need to be regularly patched to be protected from vulnerabilities. Hackers are always on the lookout for a back door into your network, unpatched devices leave exploits in your network.

Sometimes organisations can be exposed when major vendors stop supporting their products, e.g…

“On July 14, 2015, Microsoft will no longer provided support for Windows Server 2003 – meaning organisations will no longer receive patches or security updates for this software,”

With 10+ million Windows 2003 servers estimated to still be in use, and millions more in virtual use, (according to Forrester), then you can see how big the challenge can be!

A patch management program is critical to ensure that devices, and software, are kept up to date at all times!

If you have any questions, please don’t hesitate to get in touch

Follow Renaissance on LinkedIn / Twitter for daily cyber security news and updates