All articles

12 common cybersecurity mistakes

Tablet displaying a cyber threat warning symbol

Although it may not immediately spell the end of your business, you must never neglect an incident that could lead to data theft, reduced customer trust, reputational damage, fines for failing to meet obligations or legal costs.

Research last autumn found that the average data breach costs companies $15.4 million, with that figure rising by 19% each year. Nobody acting in good faith wants to cost their business money through a foolish mistake, including the chief executive. Of course, everyone makes mistakes. That is all right, but it is important to learn from them and not let them become a habit. One apt definition of stupidity is doing the same thing repeatedly while expecting a different result.

Below is a list, in no particular order, of twelve cybersecurity mistakes you cannot afford to make in today's age of modern cybercrime. If you think we have missed something, leave a comment.

  1. Failing to map your information flows
    I cannot say it often enough: data is the lifeblood of your business. Knowing and mapping where that data goes, particularly when it leaves your organisation, who it is shared with and where it resides is essential to understanding what you need to protect. You need this information available at all times; your attackers only need to know it once. That is why you need a clear picture.
  2. Skipping security tests
    Vulnerabilities occur everywhere: in databases, networks and applications, and now also in mobile devices and the Internet of Things. These need regular testing through automated vulnerability scans and thorough penetration tests. An important rule of thumb: you cannot know without measuring.
  3. Focusing too much on the perimeter
    Prevention still matters, but given how sophisticated attacks have become, you know intruders will find their way in. Once inside, they will seek privileges that let them pose as legitimate users. They can deceive you for a long time unless you have effective ways to detect attacks and know how to act when there are signs of intrusion.
  4. Forgetting the basics
    The simplest things are often overlooked. To avoid a 'well, obviously' moment later, make sure every employee has a strong password, or better still a passphrase. Ensure all parts of your network are properly segmented to minimise access to confidential data, configured to prevent unwanted changes and updated with the latest patches.
  5. Failing to provide security awareness training
    In the United States, the 'If you see something, say something' campaign encouraged people to report suspicious situations to the police. In cybercrime too, it matters that people inform security professionals when they experience an attack, or even an attempted one. Train your staff to secure their laptops and recognise social engineering attacks. Send them on refresher courses too, because attackers are becoming increasingly sophisticated.
  6. Failing to manage security
    Like most businesses, you probably do not have the budget to establish your own security centre. That means, however, that you must remain alert to security attacks around the clock and ensure you have enough expertise to investigate alerts, hunt threats, stop serious incidents early and minimise attacks.
  7. Ignoring supplier risk assessments
    Attackers now plan their cyberattacks so cleverly that they first infiltrate their victims' suppliers. Discuss security issues with the third parties you work with to ensure they place the same importance on strong security and minimal risk as you do.
  8. 'Shadow IT'
    The connections within your business are like ivy: they keep growing until you completely lose track. The days when you only had to worry about desktop and laptop computers are gone. Your employees now use so-called shadow applications and devices no longer supported by IT. You cannot stop it, but you can monitor it. First understand the risks, then work out how to control them.
  9. Thinking: it is only malware
    Malware remains an important tool for attackers trying to establish a foothold in your business. Once inside, they often use other strategies to take over your entire network. This frequently means staying under the radar by using the tools of legitimate administrators or ethical hackers, gathering sensitive information and finding vulnerabilities.
  10. Thinking: it will not happen to me
    You may still hope cybercriminals will leave you alone and skip your business, but the reality is that any company can become a victim, large or small. Prepare yourself so you can respond quickly and limit the damage if, or rather when, your turn comes.
  11. Leaving your boss and the board out of it
    A mature approach to security is the ultimate goal of every information security professional. In businesses that take this approach, security is embedded in the culture throughout the hierarchy, from top to bottom. Make sure your boss and the board support you. That may not always be easy, but in the current climate it is unavoidable.
  12. Trying to do everything yourself
    The cybersecurity skills shortage is severe. The global shortfall is estimated at one million people and continues to grow. Whether you are a small business with no security staff or a larger company needing help to expand penetration testing, security management or incident response, you will never manage to do more with fewer people. Working with a security provider such as SECWATCH is a good option. This need not mean fewer people are needed. It means you and your team can focus fully on IT projects relating to your business, while leaving security responsibilities to organisations with the expertise and people to handle them. This can improve job security for your IT staff and reduce concerns about losing an experienced security professional to another company in an industry with high staff turnover.

Original blog by Dan Kaplan, online content manager at Trustwave and former IT security reporter and editor.

 


Back to all articles