The threat of human error you cannot afford to risk human error compromising your cyber security.
In spite of the ongoing evolution of cyber security processes and technology, human error is still responsible for 95% of data breaches1. Phishing attacks alone represent a particularly insidious risk, with 91% of organisations experiencing a successful attack in 2021 alone2.
We've talked several times on this blog about the need for ongoing cyber security education within organisations at all levels, across all sectors. While this should be an ongoing part of any robust cyber security policy, in light of recent events, where highly-effective new breeds of malware have been unleashed against both private and government organisations abroad, and the National Cyber Security Centre (NCSC) has identified a number of bad actors responsible for both the recent attacks, and a number of past attacks on organisations around the world, it is imperative that you conduct a thorough review of your training processes.
All staff must be made aware of the latest threats and - equally importantly - understand their part in preventing serious breaches. While an effective email filtering service will certainly help here, you cannot afford to assume that fraudulent emails will never get through and that no member of staff will respond to it in a moment of poor judgement. Consider the following, and ensure all staff have been trained and tested on them:
In spite of the growing sophistication of cyber criminals' strategies, there are still a few typical warning signs to look out for when establishing whether a communication can be trusted or not. These include (but are not limited to):
Staff must have multiple channels through which they can report any suspicious communications or potential security risks, with processes in place to ensure these are forwarded to the right person and resolved at the earliest opportunity. Once an incident has been resolved, the outcome should be immediately communicated to all members of staff, so they can spot similar attacks in the future. Crucially, all staff must be made aware that they will not be punished for reporting any concerns, even if this involves alerting cyber security teams after they have inadvertently responded to a phishing email. This will only serve to make staff reluctant to report any incidents and compound the risk of a successful breach.
We share more information online than at any other time in history, which makes it imperative that staff understand the wider impact of what they share online, particularly on social media, particularly details of where they work.
At the very minimum MFA should be in placed for staff at all levels, with all users given the minimum number of access privileges they need to undertake their duties. This will help minimise the reach of any successful attacks.
If you are looking to optimise your existing cyber security training or develop a new programme to accommodate the very latest best practice and current threat intelligence, do not hesitate to contact Exponential-e's Cyber Security team.