Cybersecurity Awareness: Simple Actions To Dial Up Digital Defences

The traditional 9-5 working day at the office now seems like a hazy memory from a very distant past. In its place, we find ourselves in an ‘always on’ digital world with hybrid or work-from-anywhere practices now a cemented fixture in day-to-day life. 

Our lives have shifted at enormous speed and against those shifting sands, hackers have revealed their many faces.  

Today, hackers have ramped up operations, with an increasingly targeted and complex bag of tricks. The figures alone highlight the scale of the challenge. Every day 450,000 new pieces of malware are detected, and 3.4 billion phishing emails hit inboxes across the globe. 

If there’s one key takeaway from this new state of play, it’s that awareness, vigilance, and education are vital weapons and our most critical first line of cyber defence. To get ahead of the challenges, each of us, whether at work or play, has a n important role in our collective safety online. The ball now lies firmly in our court, so what are the core threats we need to tackle, and what simple actions can dial up digital defences? 

Ransomware 

Ransomware is a type of malware. Like other types of malware, it commonly infects your computer when you open an infected email attachment or click on a malicious link. It takes over the data on your computer, usually encrypting it. You receive a notice that you can no longer access your data until you pay a ransom. Cyber criminals may also threaten to publicly release your data if you don’t pay the ransom.

What are the best ways to protect yourself?

  • Be suspicious of any urgent messages pressuring you into clicking a link, installing software, or opening an email attachment.
  • Make sure you are running the latest version of anti-virus software.
  • Make sure the operating systems, programmes, and apps you use are always updated and current.

Phishing Indicators 

Email phishing attacks attempt to infect your computer, steal your passwords, fool you into sharing sensitive data, and more. After clicking on a link or opening an email attachment, you are asked to enable various permissions to access your account or system. While phishing attacks often have different goals, they share many of the same tell-tale signs.

What should you look for to keep yourself off the phishing line?

  • Always beware of an email using an enormous sense of urgency, often using fear or demanding “immediate action.” These emails are attempting to rush you into making a mistake.
  • Someone pressuring you to bypass or ignore our security policies and procedures. Requests for highly sensitive information, such as your credit card details, banking information, or passwords.
  • An email that appears to be from a person you know, but their tone of voice or email signature seems odd or strangely worded.
  • An email that creates a strong sense of curiosity or enticement, perhaps even an offer for something that is too good to be true.
  • An email with a generic greeting such as “Dear Customer,” or has numerous spelling or grammar mistakes.

Passwords

We all want to protect information, and that often starts with a secure password. 

What are the best ways to keep your passwords safe?

  • Make each password long and strong. The more characters in your password, the stronger it is.
  • Use multiple words to create a passphrase, such as “Don’t forget to stand” or “stopping- woods-snowy-evening”.
  • Create a unique password for each account. If you can’t remember them all, ask if you can use a password manager.
  • Keep passwords a secret. Never share them with anyone, including a supervisor.
  • Never use public computers to log in to your online accounts.
  • Use two-step verification whenever possible

What Does This All Mean?

People are at the heart of the cybersecurity solution. Whether at work, rest, or play, all of us are more likely than ever to be attached to one or more digital devices.

While these devices bring convenience and opportunity, they also bring considerable risk. Securing our digital lives with a few key tips helps reduce the risk so we can enjoy the benefits of our digital age. Now, more than ever, we need to be prepared for anything and everything, so let’s not wait until there’s an emergency to take action. 

Contributed by SANS Institute:

You Might Also Read:

The Do’s and Don’ts Of Security Risk Management:

 

« The Role of Zero Trust Architecture In Minimising Cyber Risks
The Hidden Costs Behind Black Friday Bargains »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Thales

Thales

Thales provides solutions, services and products that help its customers in the defence, aeronautics, space, transportation and digital identity and security markets to fulfil their critical missions.

Cofense

Cofense

Cofense (formerly PhishMe) is a leading provider of human-driven phishing defense solutions.

International Telecommunication Union (ITU)

International Telecommunication Union (ITU)

ITU is the United Nations specialized agency for information and communication technologies – ICTs. Areas of activity include cybersecurity.

Tubitak

Tubitak

Tubitak is the scientific and technological research council of Turkey. Areas of research include information technology and security.

IoT European Research Cluster (IERC)

IoT European Research Cluster (IERC)

IERC brings together EU-funded projects with the aim of defining a common vision for IoT technology and development research challenges.

CERT Tonga

CERT Tonga

CERT Tonga is the national Computer Emergency Response Team for Tonga.

Ten Eleven Ventures

Ten Eleven Ventures

Ten Eleven is a specialized venture capital firm exclusively dedicated to helping cybersecurity companies thrive.

Infinidat

Infinidat

Infinidat delivers enterprise-proven solutions for data storage, data protection, business continuity, and sovereign cloud storage.

ENSCO

ENSCO

The ENSCO group of companies provides engineering, science and advanced technology solutions that guarantee mission success, safety and security to governments and private industries worldwide.

Infostream

Infostream

Infostream is a leading integrator of Digital Transformations Solutions (DTS); Public, Private, and Hybrid Cloud; Cybersecurity; Data Integrity; DevOps, DevSecOps, and Infrastructures.

HEROIC Cybersecurity

HEROIC Cybersecurity

HEROIC’s enterprise cybersecurity services help improve overall organizational security with industry best practices and advanced technology solutions.

U2opia Technology

U2opia Technology

U2opia is a consortium with a proven track record of delivering groundbreaking technology, cybersecurity, and innovative business solutions.

Exium

Exium

At Exium we’ve integrated networking and security in a cloud-delivered Zero Trust platform powered by 5G and open source.

Siren

Siren

Siren provides the leading Investigative Intelligence Platform to some of the world’s leading Law Enforcement, National Security and Cyber threat investigators.

BioID

BioID

BioID are a German company offering deepfake detection, liveness detection, facial authentication & identity verification as a Service. 

SafeLiShare

SafeLiShare

SafeLiShare’s data security platform unifies encryption strategies for organizations with hybrid and multi-cloud infrastructures, ensuring data is secure regardless of its location.