“No-body can log in, this is a DISASTER!” the CISO's cracking voice blares in your ear. Not exactly the call you were hoping for.
No more invoices, no more schedules sent out, everything down. Every director's nightmare. It may sound far removed from your world, but it is not. We have even seen employees go unpaid because payment was a manual task that only one employee could perform.
The costly truth is that your data and systems are particularly at risk of attack by cybercriminals during the summer holidays.
Why are the summer holidays such a good time for hackers? What can you do as a director, director-major shareholder or owner to protect your business?
In this article, you will read about the easiest and most effective way to keep hackers and other undesirables out.
Logging in on holiday has become quite normal
Many sectors breathed a sigh of relief that, post-COVID, in “the new normal”, we are happily continuing with hybrid working. We have been used to it for over 2.5 years now, and it works well. But the disappearing boundary between private and business life creates a new cybersecurity challenge: your employees simply take access to your data and systems with them.
On their work phone. On their laptop. On their tablet. And we consider it perfectly normal. Cybercriminals gratefully take advantage of that.
Before discussing how to keep the undesirables out, here is the single most important tip we want to give you.
The number one tip for everything cybersecurity-related: check your emergency plan
The most important tip, which should really be at the very top of every company's list all year round, but especially before the holidays:
Check that the emergency plan you have ready is still up to date and clear.
We also call this incident management: how you manage incidents. Although prevention is best, cybercriminals are clever and fast, and their approach changes constantly.
That is why no cybersecurity company can give you a 100% guarantee: it is simply impossible. It is also why a reputable cybersecurity company will push for measures for when things go wrong. Through incident management, meaning a ready-to-use, up-to-date, complete and comprehensive emergency plan 😉, you can influence how much damage can actually be done.
Back to the approaching summer holidays. Let's dive in.
Four risks that have become normal, and measures to make them safe
1. Taking a phone, tablet and/or laptop on your travels
It makes sense to give your employees good gear. And it makes sense that it travels with them; you cannot always prevent that, especially if employees also use the device privately.
Whether on holiday abroad or in the Netherlands, your employees often depend on public places such as coffee shops and hotel lobbies. Not only for the coffee, but because they offer power sockets and a “stable” Wi-Fi connection for free. We have never actually experienced that on holiday ourselves, have you? 😉
What you can do:
- Fit screens with privacy filters. “Shoulder surfers” still play a role in the murky world of hacking, online fraud and so on. Give them no chance!
- Make sure security updates are installed on all laptops and phones and keep track of this, including during your holiday, so the equipment does not become an easy target for hackers.
- Establish a policy for charging phones and laptops: always use your own cables or a USB data blocker that protects your data. Do not use public or borrowed cables. You never know whether your data is being read while you think you are simply charging the battery at the airport or shopping centre.
- Take measures against the use of public Wi-Fi, especially abroad. Using your own 4G or 5G mobile data is safer. Make sure your employees know exactly how much data their allowance includes and in which countries they can use it. Assess together whether the allowance is sufficient and usable in the destination country.
- Check with your IT department whether there is a company-wide policy on automatically synchronising your IT to the cloud. Have this switched off, especially for the holiday period.
2. Logging in to systems from abroad
Your employee will naturally go online, if only to visit Tripadvisor or find a route. Work phones and devices used for business are sometimes also used to log in to systems. In the worst case, this happens automatically, for example at start-up. This means the device provides direct access to systems, which hackers also find convenient.
Without logging in, you cannot prepare customer invoices, pay suppliers, test or process assessment results for patients or exam candidates. Even to pay employees and temporary workers, your employees open applications or programs using their login details.
Usernames and passwords are often stored in the browser's autofill function. Nine out of ten employees often use the same passwords for multiple logins because they are easier to remember. But that also lets hackers into everything at once.
What you can do:
- MFA MFA MFA: ALWAYS use multifactor authentication.
- If work must be done abroad, work with your IT department to establish a sound, workable policy for working securely from abroad, aligned with your emergency plan.
- Remember not to give temporary, holiday or cover staff more permissions than they need for their work, and remove those permissions when the work ends. This prevents misuse of the account by them or by outsiders.
3. Phishing emails
Ha! Surely nobody falls for phishing emails any more? No, not those scams involving an 87-million-dollar inheritance a wealthy philanthropist without descendants wants to leave you, although even those apparently still work 😊. But the “real” fake emails look increasingly like those from genuine, familiar providers of cheap flights or other holiday deals.
What you can do:
Remind your employees in good time and periodically about scams and phishing emails, using themes such as “cheap flights”, “unique summer deals”, “Albert Heijn summer discount” or “all-inclusive fly-and-drive offers”. In spring and summer, people are simply more ready for a holiday, a little less alert and therefore more likely to click, even accidentally. Have employees check the sender's address and domain name and double-check whether the email address matches the domain name. Do not let them open attachments or links in unexpected emails.
Pro tip: did you know phishing is one of the most effective forms of cybercrime for gaining access to your business data or placing malware such as ransomware on your network? If you want to know how aware your employees are of phishing and how they respond, schedule a phishing assessment. You will know where you stand, summer or winter. 😉
4. An empty office, everyone away
Especially since COVID, leaving nobody on board has become quite normal. Everything can be done remotely, right? It can, provided you take the right measures. Cybercriminals understand that an IT problem is not easily solved when everyone is away. They also understand the urgency if they then start making demands, for example because ransomware has been installed.
What you can do:
- Always ensure enough people are in the office during holiday periods. Do not send everyone on holiday at once, especially those responsible for cybersecurity in your business.
- Keep automatic out-of-office replies superficial. Cybercriminals can exploit them if they reveal too much information.
- Do not share holiday photos on social media while you are away, and ask employees not to do so either. Wait until you are home. It increases not only the risk of burglary at your home address, but also the risk of hackers using this information to break into your work accounts.
The summer gift box is the new Christmas hamper
How can you make employees aware of cybersecurity in a fun way without making it feel imposed on them? Try something playful, such as a “summer holiday gift box”, like the familiar Christmas hamper but with a cybersecurity theme.
Instead of frisbees, beach volleyball sets or beach balls, include RFID card holders for safely storing credit and debit cards.
Instead of a sun visor, an NFC protector for paying contactlessly for ice creams and dinners safely, even abroad.
Instead of factor 55 sunblock, a USB data blocker so your data cannot simply be read.
Back from holiday? Consider a penetration test
During such a penetration test, a cybersecurity company examines the security of your ICT environment. You learn how easy or difficult it is to access sensitive data from outside. Because an ethical hacker thinks in the same way as a malicious hacker, a penetration test reveals exactly how difficult or easy it is to break into your system, your IT infrastructure, your own internal digital highway. This lets you guard your pot of gold even better afterwards. And… a penetration test is not only extremely valuable after the summer holidays, but in any case once or twice a year.
Want to know more? Download our free Cybersecurity Checklist. You will also be added to the Cyber No Shitshow mailing list. At irregular intervals, we will send you the clearest signal in cybersecurity.
