Over 50% Data Breaches Are Due To Human Error

Cyber-fraud is sector agnostic. Any business in any industry is just as vulnerable, if not more, to data leaks and fraud, which is why curbing tech naivety should be high on the agenda for growing businesses. Considering how both of these issues can be debilitating for growing businesses, it is crucial to understand the difference between the two, their relationship to one another and the warning signs of each.

What's a data breach and why should I care?

A data breach is essentially when sensitive, protected or confidential information has been viewed, stolen or used by someone unauthorised to do so. Data breaches can be as broad as all of your employees' email addresses, or specific and more sensitive, such as personal health information or intellectual property.

The average cybersecurity breach in the UK costs upwards of £1.4 million, and according to new research, 52 per cent of data breaches last year were due to human error, mostly from a lack of awareness.

According to CompTIA, a global non-profit association for the technology industry, cybersecurity awareness is a vital first step for businesses across sectors to protect themselves against data breaches.

“Every business that uses IT needs to be aware of the consequences of bad cybersecurity practice,” according to Graham Hunter, CompTIA's VP certifications, Europe and Middle East.

“Time and time again, we hear of employees causing data breaches, whether that be through leaving a USB device with important data lying around, or clicking on unsolicited links in emails. Such actions are rarely malicious and more often the result of a lack of training, knowledge or general carelessness.”

In order to drum up awareness among the SME community, CompTIA has launched a training programme, CyberSecure, which will include all the fundamentals of cybersecurity in the workplace.

“It’s clear that cybersecurity is no longer exclusively the domain of the IT security department,” Hunter adds. “The responsibility lies upon all employees to be secure with their devices, and this only increases as more employees work remotely and on the move.”

What about cyber-fraud?

Overall, fraud could be costing the UK economy up to £193 billion a year, according to this year's Experian Annual Fraud Indicator. Phishing attacks rose by more than a fifth (21%) last year and were estimated to cost Britain more than £280 million, affecting the procurement and insurance industries the most.

In terms of legal support, Patrick Arben, a partner at Gowling WLG, explains that the onus to prevent cyber-fraud may lie entirely on businesses. "Where tackling cybercrime is concerned, it is important that business owners remember that the role of the police and other national crime agencies is not focused on detection, rather raising awareness of the risks and the need to self-protect against any attacks. Business owners should, therefore, be as pro-active as possible in backing up valuable data and realising how to spot suspicious communications requesting confidential information," he explains.

According to Experian's ID and fraud expert, Nick Mothershaw, businesses have a lot to gain by taking accountability for their IT security. "Resilience to fraud can only be tackled from the grass-roots up, so it’s up to each organisation to not only manage fraud as a loss factor, but to overcome it by treating fraud prevention as a growth opportunity," he says.

The two-for-one combo

Data breaches and cyber-fraud are essentially two sides of the same coin, so a two-pronged approach towards both may be in order to prevent attacks of any kind. Both tend to be financially motivated, and that could have an immediate impact on your business. Attackers may attempt to use stolen data to carry out fraud in a two-part crime.

"Fraud costs merchants money in a number of different ways. Lost goods and lost revenue through chargebacks both hit merchants in the pocket. There is also the possibility that merchants will become too risk averse and tighten up their rules to the extent that legitimate transactions are declined because merchants do not have the protocols, expertise, and systems in place to differentiate between fake and genuine consumers," Don Bush,VP at fraud solution firm, Kount explains.

Unfortunately, businesses will always have to stay vigilant against data breaches and fraud. However, basic understanding of the two, how they’re different, how they relate and how to watch for them is good place to start.

How can you protect your business against cyber-fraud?

Recent Barclaycard research revealed 48 per cent of small businesses have been hit by at least one cyberattack in the last year, and 10 per cent suffered repeated attacks, many of which have a direct impact on customers. Here's how to ramp up IT security, starting with the fundamentals.

1.       Cover the basics: Firstly, all businesses should complete a risk assessment to understand what potentially sensitive or valuable information is being held, and where it is. This informs what controls are needed to protect customer data. By identifying what data is attractive to criminals, businesses will be in a much better position to take the right precautions to keep it safe.

2.       Adhere to standards: All businesses must be compliant with the Payment Card Industry Data Security Standards (PCI DSS) which are designed to ensure they are processing and storing customer card data as securely as possible. Being compliant won’t stop businesses from being targeted by cybercrime, but it will make sure that they’re in the best position to prevent an attack, helping them avoid the financial and reputational losses.

3.       Enlist the help of a web developer: It is important for businesses to ask their web developer how they are protecting customer information, including personally identifiable data. Web developers should also frequently be conducting patch management, monitor the site for suspicious activity and regularly search for traces of malware.

4.       Keep the conversation going: Security is not a one-off cost, it’s an on-going – and essential – business investment. Maintaining a dialogue with the web developer and payment provider allows businesses to keep abreast of the latest cyber threats and solutions, which will ensure they stay protected even as the landscape changes.

5.       Stay alert: In the event that data is compromised, businesses must stay alert – this is because one merchant’s data breach may lead to fraud on the website of another. Fortunately, the payments industry has put in place a number of measures to help restrict the damage. Existing solutions include 3D Secure, Card Security Code and the Address Verification Service. These all require customers to enter additional information at the point of sale during card-not-present transactions to assess whether the transaction is genuine.

Additionally, the Industry Card Hot File – a subscription service which compares card details against a list of lost or stolen cards – can help to block attempted transactions made as a result of a data breach.

GrowTheBusiness: http://bit.ly/2a9wRg6

 

« London Police Chief Says Spy Agencies Face Terror Fight
Businesses Need To Protect Data, Not Just Devices »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

BMC Software

BMC Software

BMC provide solutions for IT service management, Cloud management, IT workload automation, IT operations, and mainframe system management.

InfoWatch

InfoWatch

InfoWatch solutions allow you to protect data and information assets that are critically important to your business.

SecuTech Solutions

SecuTech Solutions

SecuTech is a global leader in providing strong authentication and software licensing management solutions.

TruSTAR Technology

TruSTAR Technology

TruSTAR is a threat intelligence exchange platform built to protect and incentivize information sharing.

Evidence Talks Ltd

Evidence Talks Ltd

A leading forensic computing authority developing unique digital forensic technologies. Tools that detect potential terrorists & criminals & used by the military, enforcement & intelligence commmunity

Kingsley Napley

Kingsley Napley

Cyber crime is an area of growing legal complexity. Our team of cyber crime lawyers have vast experience of the law in this area.

ENAC

ENAC

ENAC is the national accreditation body for Spain. The directory of members provides details of organisations offering certification services for ISO 27001.

Norsk Akkreditering

Norsk Akkreditering

Norsk Akkreditering is the national accreditation body for Norway. The directory of members provides details of organisations offering certification services for ISO 27001.

Totaljobs

Totaljobs

Totaljobs is the UK’s largest hiring platform. We have over 280,000 live jobs adverts on our site, helping you to find any type of job in any industry, including cybersecurity.

National Cyber Security Center (NCSC) - Vietnam

National Cyber Security Center (NCSC) - Vietnam

National Cyber Security Center of Vietnam has a central monitoring function and is a technical focal point for monitoring and supporting information security for people, businesses and systems.

ProCheckUp

ProCheckUp

ProCheckUp is a London-based independent provider of cyber security services, including IT Security, Assurance, Compliance and Incident Response.

CornerStone

CornerStone

CornerStone is an award winning, independent risk, cyber and security consulting firm providing a range of Risk Management, Security Design and Implementation Management Services.

CCX Technologies

CCX Technologies

CCX Technologies design and develop a wide range of cybersecurity and testing solutions for the aviation, and military and government markets.

AmiViz

AmiViz

AmiViz is the first B2B enterprise marketplace focussed on Cybersecurity business in the Middle East and Africa, designed specially to serve the interests of enterprise resellers and vendors.

Airbus Protect

Airbus Protect

Airbus Protect is an Airbus subsidiary bringing together the Company’s expertise in cybersecurity, safety and sustainability-related services.

SignPath

SignPath

SignPath provides leading-edge software and SaaS services that ensure code integrity from development to distribution.