The Best Cybersecurity Practices for Small to Medium-Sized Businesses
19th December 2024
Cybersecurity can sound like an intimidating prospect, especially for smaller businesses. However, it doesn’t have to be – this guide has lots of easily implementable tips for SMEs that can save time and money as well as protect your business from data breaches and other cyber threats. For more guidance, see the small business guide on the NCSC website here.
Train all employees in basic security practices
Good security practices are the responsibility of all employees, and the best way to ensure everyone plays their part is to train employees in the basic principles of good cybersecurity and data protection. You can give different levels of training depending on job role and levels of responsibility, but all staff training should include the basics, such as good password security, guidelines on appropriate internet use, rules for handling and storing customer information, and general workplace security. See the Griffin House Data Protection Academy for courses, training and eLearning modules that can help.
Keep all software and systems up to date
Thanks to outdated software, both small and large organisations alike have been the victims of cyberattacks. As well as using firewalls and antivirus software, all systems and programs used on devices at work should be kept patched and up to date, as whilst all programs have security measures built in that help protect them from cyber attacks, hackers are always innovating. Earlier this year, the ICO reprimanded the Electoral Commission for allowing voter information to be accessed by failing to update their software. Hackers were able to bypass authentication on Microsoft Exchange Server and access files stored on the server using a ProxyShell attack which had been patched months previously by Microsoft.
Back up your data
Keeping all important data backed up helps to make sure your business can continue in the event of data loss due to any reason, from flood, fire, theft and other possibilities. Having up-to-date backups of your data that are easily recovered means you are at less risk of ransomware attacks. Always keep data backed up on a device that is separate from your main computer or use secure cloud storage. Setting up an automated backup is a good way of saving time and reducing manual tasks.
Just remember that backups and archives must be adequately protected, for example, using 256-bit encryption as a minimum, and bear in mind your organisation’s retention schedules. If you say that you delete information after 2 years, but have backups going back for 10 years, this is a problem. The information within the backup may also fall within the scope of a subject access request.
Keep control of all workplace devices
Providing company laptops, tablets and smartphones helps increase productivity and gives employees the chance to work from any location, but they can also present a security risk in the event of loss or theft. Make sure all devices are password protected, set up tools so they can be remotely found or wiped, and keep all programs and operating systems up to date. Only allow the installation of pre-approved apps and programs and avoid connecting any device to public Wi-fi hotspots. Where possible, your policy should prohibit individuals from using private devices to access corporate systems as this will introduce a whole world of unnecessary security vulnerabilities, not to mention potential data protection breaches.
Take steps to avoid phishing attacks
Phishing is when a threat actor contacts someone to ask for sensitive information or encourages them to open a file or click a link; often the hacker pretends to be a trusted contact. Most people consider themselves able to spot a phishing attack, but if a colleague or work contact email is spoofed (sent from a forged sender address that looks like a pre-existing contact or trustworthy source), it can be difficult to tell the difference between phishing and a legitimate email.
Avoid phishing attacks by implementing DMARC which checks the credentials of incoming emails. Employ the principle of ‘least privilege’ which means giving employees the lowest level of user rights required to do their job, reducing the risk of sensitive data being leaked. Train employees on how to spot phishing attempts – this can include carefully examining the sender details of an email as well as any unusual requests, such as demands to share sensitive data like passwords or bank details ‘urgently’ or warn against some detrimental consequence of not sharing said data. If in doubt, ask your IT team to check the email before opening.
Use passwords effectively
Using passwords is a simple and effective way of protecting stored data. However, having the most complex passwords in the world will not be effective if people write them down on notepads and post-its around the office or store them in browsers or spreadsheets. So make it clear to employees that this kind of behaviour is putting your company at unnecessary risk.
If there are a lot of passwords for employees to remember, consider using a password manager or password vault like 1Password, NordPass or Dashlane. Password managers also assist with disaster recovery and business continuity allowing authorised senior managers to access password directories. You should provide employee training and guidance on what kinds of passwords are suitable, e.g. avoiding obvious passwords like names of their spouses, children or pets or easily guessable passwords like ‘admin’, ‘qwerty’ or ‘123456’. For systems and files that need to be extra secure, e.g., those containing bank details or special category data, consider using multifactor authentication to protect them. This means that access requires not just a password, but a code sent to someone’s email or smartphone. So if a password does get compromised, the data is still protected.
If you have any questions or thoughts on your organisation’s security practices, get in touch with us here at Griffin House Consultancy by emailing [email protected] or calling us on 01673 885533. We are here to share our knowledge and skills to help keep your company safe and protected against all cyber threats.
Author: Mike Martin LLM
Mike is an information governance specialist and one of the founder Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.