Published 31/07/2023 – est. 5 minutes to read.
Fortify your Business without Breaking the Bank.
Cybersecurity can often seem like a daunting subject, with countless areas of an organisation to consider, alongside significant upfront and ongoing investment. We aim to provide clear, pragmatic advice at the lowest possible price to any audience.
This article will explore low-cost yet powerful measures your organisation can implement to bolster your Cyber Security posture. From authentication best practices to security solutions, we’ve got you covered. Let’s dive in and discover how you can achieve big protection on a small budget!
Strong Passwords
When creating passwords, it is crucial that users can identify an insecure password. A login page telling you that your password, Pa$$w0rd123, is strong doesn’t mean it is secure!
The following should be considered when users are creating a password:
- Use unique passwords for all applications/services.
- All passwords should be at least 12 characters in length.
- When creating passwords, combine three or more random words.
- When recording passwords, use trusted Password Managers like KeePass 2.
- Do not use common passwords (e.g. 123456, Blink182, qwerty, a football team).
- Do not use passwords containing personal information (e.g., date of Birth or Name).
Multi-Factor Authentication (MFA)
Multi-Factor Authentication (including 2FA) adds additional authentication steps and is essential for securing your accounts. For instance, if an account password is compromised, MFA will serve as an additional barrier against bad actors! This can be easily enabled for most day-to-day accounts and usually involves a one-time code sent via a mobile authenticator app or text message.
Software Updates
Software updates (as much of a nuisance as they can be!) should be installed as soon as possible. This is to ensure that any security fixes are applied promptly, thereby reducing the risk to your organisation. It is recommended to enable automatic updates on all applications where possible and to schedule one day a week for users to open their applications and check for updates.
Network Configuration
Upon receiving network equipment (e.g., a router), the default passwords should be changed to strong passwords. This is to ensure that default credentials such as ‘admin’ cannot be used by an attacker to gain access to your network. Additionally, strong wireless encryption protocols such as WPA3 should be used. As a side note, always make sure you are connecting to a trusted network (especially not an open network!).
Security Training
Security training is imperative for all users within an organisation. You may have the strongest password and MFA enabled; however, it is ultimately your users who define how effective these measures are. This is not only to ensure that users follow protocols, such as using strong passwords, but also to ensure they are aware of key threats, such as phishing emails that can lead to sensitive credentials being provided to attackers. Phishing Emails specifically have been defined as ‘The most significant threat facing citizens and small businesses’, as cited by the National Cyber Security Centre.
Security training can be difficult to develop and deploy effectively, which is why we offer a low-cost CS Security Training service, which includes:
- Security Awareness Training: Users are assigned a 15-minute monthly course featuring an informative video, followed by questions.
- Simulated Phishing Exercises: Users receive monthly bespoke Phishing Simulations to build resilience to Phishing Emails.
- Security Policy Management: We provide automated, centralised policy distribution to all users, with policies also available for review after signing.
- Email Address Breach Alerting: We constantly monitor the Dark Web for any organisational email/IP breaches and notify those affected.
- Monthly Reporting: We provide monthly reports covering all modules, highlighting significant areas (e.g., areas for improvement).
- Support: Our friendly team of Cyber Security Specialists is available by phone and email.
To evaluate your Cyber Security, conduct a Cloud Security audit, or discuss our services, connect directly with our technical team:
Telephone: 0161 706 0244
Email: info@cybersecurityspecialists.co.uk
