News, info & events

22 Apr
COVID-19: Keep your team operating securely while working remotely

Welcome to the latest ER blog – keeping you up to date on cybersecurity.

COVID-19 is having a major impact on everyone’s life, including changing the way we work resulting in the huge number of us now doing so from home.

Cybercriminals are taking advantage of reduced IT team sizes due to self isolation and lockdown who are having to manage a remote workforce which leads to significant pressure on the IT infrastructure.

The online trade publication and social community for IT professionals, Techrepublic, yesterday reported that the COVID-19 lockdowns are causing a huge spike in data breaches – much worse than anticipated – according to the International Association of IT Asset Managers who said “Too many organisations have left themselves wide open for attack”. 

In the report, they cite four areas causing breach risks: 

Assets are being purposely left with reduced security – eg removing admin permissions so that employees can complete the task without administrator oversight and working remotely may mean computers are not being kept up to date with the latest security patches. 

The rapid addition of new hardware leaves reduced time for security. The need to quickly purchase and deploy laptops has removed focus on cybersecurity and user training.      

Computers on home networks may be less secure. Connection should be via a properly configured VPN rather than just over the internet.

Due to the rush to equip people to work from home securely after lockdown, unprepared/untrained users are more prone to making mistakes and falling victim to   phishing attempts such as appeals for money, disinformation campaigns or new information about COVID-19.  This gives cybercriminals the opportunity to gain login credentials and install malicious software. 

This increased risk of breach is dangerous for businesses who leave themselves wide open to loss of data, reputation, income and potentially huge fines.

There are things business leaders can do to help them protect themselves and reduce the risks significantly:

Turn your employees from being a potential vulnerability to a cybersecurity asset: provide online training to help them understand their responsibilities under GDPR, how they can spot and avoid the risks and turn them into a human firewall.

Set up a VPN or other secure means to ensure employee access to the company network is done safely.

Ensure advanced cybersecurity solutions are in place to help protect and secure each computer.        

Data security is a joint effort between IT teams and users. User training and good computer security is the only way to ensure businesses get through COVID-19 intact and stop them from becoming yet another security statistic. 

Contact us today to find out how EnterpriseRed can help your company stay safe and secure during the COVID-19 pandemic  – for no cost, no contract and no commitment, for up to 6 months. Click here for more information.  

Tel: 0203 371 9178 or 07711 783907

Email: support@enterprisered.com

Read more here

 

06 Aug
Data Privacy: Time to take it seriously?

From our social media photos to our spending habits to our route to work – data about us is everywhere. It helps to make services more convenient but it also has huge implications for privacy and surveillance. Do we need to take it more seriously?

EnterpriseRed’s CEO, Ian Kennedy-Compston, joined TRT World’s Roundtable panel show to talk about protecting our data. Watch the show here.

If you have any questions please get in touch.

23 Jul
Cybersecurity risks of the supply chain
pexels-photo-1437866
Most businesses rely on an extensive supply chain to deliver for their customers – you probably have a number of suppliers yourself. Supply chains can be long and complex, with suppliers who are visible, and some that aren’t. Since the introduction of GDPR, businesses are more aware of the importance of a rigorous cybersecurity approach within their own IT systems, however business owners need to stop and think about whether they are doing the same thing with their suppliers, and can they be sure of the rigour those suppliers take with theirs?

A number of high-profile attacks has demonstrated that attackers can, and will, exploit the weakest link of the supply chain.  Last year, Npower admitted a data breach in which the names, addresses, payment amounts and FIT reference numbers of around 5,000 of its customers were received through the post by the wrong people, leaving customers considerably concerned about identity fraud. Npower had used a fulfilment partner to send the postal mailing on their behalf. Ticketmaster were also the subject of a data breach in 2018 when malware was found in a third-party customer support service, underlining the importance of supply chain security.  

Read More “Cybersecurity risks of the supply chain”

Sidebar: