Review Your Cybersecurity Awareness

In 2018, a person couldn’t listen to the news without hearing of the latest company breach, which included many well-known companies such as Adidas, Timehop, Saks Fifth Avenue, Panera, T-Mobile and Facebook. 

Several of these breaches affected subscribed users or patrons by exposing their personally identifiable information which they entrusted to these companies.

Some breaches were caused by insider threats, some by social engineering and others by unpatched vulnerabilities. Yet, with all of these breaches this year and years past, phishing still remained one of the top attack vectors in 2018, and will continue to play a major role in the threat landscape of 2019 and beyond. 

Phishing, along with other social engineering attack vectors, preys on the human element. If 2018 taught us anything, it’s that companies need to use a more proactive approach in order to try to prevent these attacks from happening in the first place. 

This can be made possible by holding the human aspect of security in high regard and ensuring that training and education continue to play a large part in a multi-layered approach to security. 

While social engineering continued to stay on the security radar in 2018, automation and Artificial Intelligence were two topics that truly became popular buzzwords in the industry, and we can expect to see more of these being implemented into security programs going forward.

Although these are both massive technological advancements for the industry, still the human factor remains thus they will need to be used in conjunction with training to help prevent incidents. 

From a security awareness perspective, another growing trend that needs to be addressed going forward is connected devices. We are in an “always-on” culture, surrounded by technology that we enable to make our lives move faster and more efficiently.

However, with this connectedness comes more risks, and these risks are the ones people sometimes don’t even realise exist. If we can educate users on best practices regarding IoT, we can make everyday occurrences that are as simple as their drive to work, their time spent watching television or listening to music via their digital assistants, or even adjusting the temperature in their home ecosystem more safe and secure.  

Just like in 2018, the need for security awareness programs at companies of all sizes will continue to grow in 2019, and the demand to fill these roles will grow as well.

As more attacks continue to happen, additional training around prevention, as well as response, is imperative. Likewise, as the need for training increases, more and more vendors are popping up each day to help fill this security awareness void.

Many of these third-party training and awareness materials can be wonderful supplemental material to a robust and mature security awareness program, but it’s essential that those in the field do diligent research to choose a vendor that is reputable and best meets their company’s needs. 

Security also finally has the ear of the board, and security awareness is a question that is top of mind to most executives. With an extensive amount of cybercrime occurring, more companies are making headlines in a negative light, forcing boards to acknowledge the undesirable recognition a breach can lead to including being front and center in the media which can be damaging to their brand and reputation.

Many of the breaches that occurred during and prior to 2018 could have quite possibly been prevented had a user been given the proper training and tools they needed to be more vigilant. 

There are also additional regulations coming out globally as well as in the US on a state by state basis: these regulations are mandating more restrictions around data privacy and protection of information, thus making the old checkbox approach to security awareness a practice of the past.

All these factors drive the need for security awareness professionals to develop programs that include frequent training and education to keep their companies and their assets secure. 

As an industry, we are continuing to make great strides when it comes to security awareness and education but, unfortunately, the threat actors continue to remain one step ahead. Every aspect of the business needs to be security aware because anyone from the top down, to the bottom up, can become a victim.

In 2019, security teams should empower people to take more control of their own security, not only at work, but at home and not only with themselves, but with their families as well. It is imperative in the coming years that people remain adaptive to the changing events, technologies and threats, and continue to view security awareness and the human factor as a necessary part of any security program.

With this in mind, we as an industry also need to continue to create innovative approaches to engage employees and ensure they are equipped with the knowledge that they need to play an effective role in preventing these attacks in the first place. 

Because after all, you can put all the technology in place but the people will remain a major factor when it comes to securing your company and its assets.

For Cyber staff training please contact us at Cyber Security Intelligence. 

Infosecurity:

You Might Also Read:

Cybersecurity 2019: Predictions You Can’t Ignore!

« US Marines Turn To Artificial Intelligence To Better Deploy Troops
Germany Develops Offensive Cyber Capabilities Without A Coherent Strategy »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Security Magazine

Security Magazine

Security, the business magazine for security executives, focuses on management issues facing top security professionals and effective solutions being employed, both physical and cyber.

Joe Security

Joe Security

Joe Security specializes in the development of automated malware analysis systems for malware detection and forensics.

Openminded (OPMD)

Openminded (OPMD)

Openminded is a French security and network services company.

France Cybersecurity

France Cybersecurity

France Cybersecurity represents the French cybersecurity industry to raise international awareness of French cybersecurity capabilities and solutions.

EIT Digital

EIT Digital

EIT Digital is a leading digital innovation and entrepreneurial education organisation driving Europe’s digital transformation. Areas of focus include digital infrastructure and cyber security.

Silent Breach

Silent Breach

Silent Breach specializes in network security and digital asset protection. Services include Pentesting, Security Assessments, Incident Detection & Response, Governance Risk & Compliance.

Xage Security

Xage Security

Xage is the world’s first blockchain-protected security platform for Industrial IoT.

Perimeter 81

Perimeter 81

Perimeter 81 is a Zero Trust Network as a Service designed to simplify secure network, cloud and application access for the modern and distributed workforce.

Cybersecurity Innovation Hub

Cybersecurity Innovation Hub

Cybersecurity Innovation Hub is a non-profit network organization focused on cooperation, information sharing, research and implementation of cutting-edge technologies in cybersecurity.

Cyber Lockout

Cyber Lockout

Comprehensive ransomware insurance and preventative cybersecurity technology solution, working together to help protect businesses 24/7/365.

Varutra Consulting

Varutra Consulting

Varutra Consulting is an Cyber Security Consulting, Solutions and Training services firm, providing specialized security services for software, mobile and network.

Prescott

Prescott

Prescott acts as your guiding light in the preparation for your CMMC assessment and long after by governing your cybersecurity practice.

Autobahn Security

Autobahn Security

Autobahn Security is a growing team of 80+ experts from 25+ nationalities, established in 5 countries. We’re working hard to make Autobahn Security the No. 1 solution for improved hacking-resilience.

SureCloud Cyber Services

SureCloud Cyber Services

Our Cyber Testing capability has been honed since we were founded in 2006 as a disrupter in the penetration testing market.

Precision Cybertechnologies & Digital Solutions (Precision-Cyber)

Precision Cybertechnologies & Digital Solutions (Precision-Cyber)

Precision-Cyber was founded on the philosophy of state-of-the-art cybersecurity and digital solutions. Our guiding principle is simply that we will provide and secure all your digital needs.

NetSfere

NetSfere

NetSfere provides next-generation messaging and mobility solutions to carriers and enterprises globally including its enterprise-grade, secure mobile messaging platform NetSfere Enterprise.