Top Five Most Common Gaps In Businesses’ Cyber Security

The finding that two in five UK companies have faced cybersecurity attacks in the last twelve months, coupled with the growing availability of tools to simplify hacking, is making business leaders nervous. Operational cybersecurity vulnerabilities are common across the board. There is no escaping the threat, whether you’re in the financial, industrial, education, or power sectors, every industry is at risk.

Knowing where your systems are vulnerable is the first step to protecting them. To gain these insights, a comprehensive assessment and analysis is needed to reveal cybersecurity gaps. From our own analysis, we have found there are some gaps that crop up in almost every business.

Understanding The Enemy

Firstly, and possibly most obviously, cybersecurity starts with understanding the risks. Communicating current security risks to the entire workforce is a primary step in securing a business, and often the simplest gap to fill in a company’s protection.

For example, an increase in remote monitoring and third-party access has also led to a rise in cyber vulnerabilities. The IoT connected devices that have enabled so many businesses to quickly transition to homeworking bring challenges along with their benefits. These tools have essentially increased the ‘attack surface’ for hackers and, in many cases, have acted as an organisation’s Achilles heel.

In most cases, cybersecurity professionals have less than a week to ensure that remote systems were secured before making the shift to remote working, it’s fair to say that the preparation for remote-access related security threats is far from mature in most cases. However, companies must now be taking stock of the new technology they have implemented. Building an awareness of the current risks is the first step in mitigating them.

Holistic Protection

In many cases, people are the first and last lines of protection. So collaboration between teams, including higher management, is essential. However, a common gap in a business’ security is caused by a disconnect between teams, particularly between management and operations.

Embedding cybersecurity into your operations takes the whole enterprise – everyone, everywhere – to understand and accept their own responsibility for cybersecurity. In particular, this means bringing IT and OT together so they can help the entire organisation – not just an area, a function or individual team – be as secure as possible.

Establishing this “we” culture helps to connect the dots across the enterprise, fill gaps and maintain always-on vigilance. This change starts from the top. Employees and vendors, at any level of seniority, need to be aware of and compliant with security policies. This ‘all-in’ approach is what will garner more thorough and consistent commitment to the cybersecurity initiative throughout the organisation.

Understanding Your Assets

Many cyberattacks are successful because employees have caused unintended errors. It is important that staff are aware of, and vigilant against, cyberthreats. This doesn’t just mean blanket, company-wide training on how to spot a phishing email, but also establishing the specific threats associated with the assets under an employee’s care. These could include specific protocols around the use of passwords, policies around WiFi access or regular auditing of user accounts and permissions.

This gap has been especially prominent over the past year. During periods of heightened activity or business restructuring, as personnel move into a new work environment, businesses are even more vulnerable to threats and attacks. 

Before attempting any reorganisation, companies need to consider the types of data and technology they require the reallocated workforce to use. Assigning new or inexperienced workers to different roles requiring the use of unfamiliar technology is always a risk, which is amplified when malicious activity is on the rise. During a crisis, it’s a dangerous combination that could open the door to attacks. 

Preparation Is Key

When it comes to cyberattacks, you can never be too prepared. Implementing proactive, tested incident response and risk mitigation plans which are documented and tested, are an essential step in minimising risk and strengthening customer assurance. A security-aware environment should audit and enforce cybersecurity best practices on a consistent and effective basis, utilising available supervision and detection tools, so that exposure to threats is as limited as possible.

However, in terms of risk mitigation, companies tend to deal with what they perceive to be high-probability, disruptive events that are most likely to occur and can be planned for. However, this is only one part of the bigger picture.

Business Continuity Plans need to also consider events that can disrupt entire industries or, in extreme cases, the global market, such as natural disasters or financial crises and pandemics. While these events are low probability, when they do occur, they can change the assumptions made in all other risk planning – causing gaps in protection capabilities if not properly mitigated.

Limited Capabilities

When it comes to cybersecurity, many companies are very conservative – sometimes for good reason – but that needs to change. A collaborative approach that draws on the expertise, capabilities and visibility of all parties is the key to closing these gaps and achieving fully mature cybersecurity for a business.

Most business leaders do not, unsurprisingly, have the knowledge and experience to enact a cybersecure business strategy. That is why collaborating with skilled and certified professionals, who can provide vendor-agnostic services to help assess an individual business’ risk, implement cyber-specific solutions, and maintain those defences over time, is vital to ensuring no gaps in your armour are left unattended to.

Fully mature cybersecurity is not a destination, it’s a journey, and one that effects the entire organisation. Therefore, there is no quick fix that can be completed over night. It is an ongoing and accumulative process, but, if conducted correctly, it can be of significant benefit to a business, and not a burden.

About The Author: Victor Lough is Cyber Security & Advanced Digital Services Business Lead at Schneider Electric.

You Might Also Read: 

Managing Cyber Security As Office Work Resumes:

 

« Your Organisation Needs A Cyber Audit
Why You Should Never Use A Free Proxy »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 7,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

DigiCert

DigiCert

DigiCert is the only provider of enterprise-grade SSL, IoT and PKI solutions. Our certificates are trusted everywhere, millions of times every day, by companies across the globe.

Qualys

Qualys

Qualys is a pioneer and leading provider of cloud security and compliance solutions.

iLand

iLand

iland is a global cloud service provider of secure and compliant hosting for infrastructure (IaaS), disaster recovery (DRaaS), and backup as a service (BaaS).

Odix

Odix

Odix security software neutralizes file embedded targeted cyber attacks before they enter your organization’s network.

Asoftnet

Asoftnet

Asoftnet are specialists in IT security, IT forensics, IT service, websites, applications and mobile solutions.

Information and Communication Technology Authority (ICT Authority) - Kenya

Information and Communication Technology Authority (ICT Authority) - Kenya

The ICT Authority is responsible for enforcing ICT standards in Government and ensuring information security.

Tier1Asset (T1A)

Tier1Asset (T1A)

T1A is Europe’s leading IT refurbisher. We offer certified data erasure using blancco on site and at our facilities, providing environmentally sound disposal of your used equipment.

Invest Ottawa

Invest Ottawa

The IO Accelerator Program is designed to rapidly and systematically accelerate the development and commercial success of high growth technology firms.

IntaPeople

IntaPeople

IntaPeople are IT and engineering recruitment specialists. We have specialist teams for job sectors including Cybersecurity, IT infrastructure and DevOps.

Hyperwise Ventures

Hyperwise Ventures

Hyperwise Ventures lead seed investments in startups in the cyber security and enterprise software spaces.

Kalima Systems

Kalima Systems

Kalima’s mission is to securely collect, transport, store and share Industrial IoT (IIoT) trusted data in real time with devices, services and mobile workers.

Ward Solutions

Ward Solutions

Ward Solutions are an information security consultancy and managed services company. We help organisations protect their brand, people, assets, intellectual property and profits.

LogicGate

LogicGate

The LogicGate Risk Cloud™ is an agile GRC cloud solution that combines powerful functionality with intuitive design to enhance enterprise GRC programs.

Epoch Concepts

Epoch Concepts

Offering a full line of IT services, solutions, and integration capabilities, Epoch Concepts is the trusted partner of the US military, federal agencies, private enterprises, and systems integrators.

Techtron Business IT Services

Techtron Business IT Services

TECHTRON has been providing business IT services since 2004. Our focus is on SMBs and we are good at it. Our customers trust us, they love our high levels of service, and they love what we stand for.

e-Safer

e-Safer

e-Safer's mission is to provide solutions and services that ensure a safer digital environment.