08
Dec
By: Phil Gladwell
News, info & events
A data breach can have a severe impact on the health of an organization, not only can they be devastating financially but they can also erode customer confidence and trust. With the rapid shift to remote working due to the Covid pandemic, teams are now more distributed than ever and the organsation’s network perimiter has all but disappeared. It is no longer a matter of if but when a data breach will occur.
Data breaches are a killer of productivity. According to a 2021 Norton cyber safety insights report, victims of cybercrime spent nearly 7 hours resolving each breach, resulting in a total loss of some 2.7 billion working hours globally.
With the rapid rise of distributed working, use of Software as a Service and the prevalence of IoT devices, organisations risk having security vulnerabilities everywhere. An organisation’s security is only as good as that of its weakest link, whether that is a third-party vendor that they work with or a login on a personal computer.
Enterprise organisations ideally need 24/7 cybersecurity monitoring. A 24/7 security operations center (SOC) has long been considered an essential part of an effective cybersecurity strategy. However, SOC implementations tend to be complex and expensive, putting a modern SOC out of reach for many organisations. A recent Ponemon Report found that of those that did invest, despite the best efforts and money spent, only 42% rate their SOC as highly effective.
One option is to invest in SOC-as-a-service (SOCaaS) to add that extra layer of security. SOCaaS delivers all of the benefits of a dedicated 24/7 SOC, but without the high costs and complexity that come with building, staffing, and managing one in-house. With a managed SOC service, organisations can outsource the people, processes, and technology needed, the SOC is operated and managed offsite and delivered as a cloud-based service.
Most organisations rely on third-party suppliers in order to operate their business and because close collaboration is often required between organisations, their suppliers and resellers, computer networks may become intertwined and sensitive data may be shared. In this situation third-party security vulnerability and digital supply chain resilience become an important aspect of the organisation’s cybersecurity. Instead of attacking the target directly, a cybercriminal may attack a weaker organization in the target’s supply chain and use that to gain access to the target’s systems.
Supply chain security focuses on managing the risks of using external suppliers, vendors, logistics and transportation. Its goal is to identify, analyse and mitigate the risks inherent in working with other organisations as part of a supply chain. It can involve both physical security relating to products and cybersecurity for software and services. By applying the mitigations best suited to its business sector, an organisation can greatly improve its supply chain security.
Consumers are becoming increasingly wary of how their data is used. A large percentage of adults don’t like it when social media sites, search engines, mobile apps, etc. take their personal, online, and mobile location data and allow advertisers to use it to send targeted advertising. You can build customer trust by clearly communicating how you use their data and by offering opt-in or double opt-in options for the appropriate online customer interactions.
Internally, focus on building a cybersecurity-centric culture and stress the importance of attention to cybersecurity across all parts of the organisation. Weave cybersecurity into all your processes. Adopt a zero-trust security model. Even for SMBs, thinking about cybersecurity is critical. In 2019, a study from the National Cyber Security Alliance found that of small businesses with less than 500 employees, 10% were forced to close after suffering a cyber-attack. Small businesses often don’t have the resources to completely revamp their security protection but business leaders should look at all of the areas where the business is vulnerable, consider which one is the most pressing and address that first.