Business Daily Media

The Times Real Estate

.

Why businesses should invest more in their people and not cybersecurity technology

  • Written by Josh Lemon, author and certified instructor at SANS Institute, managing director DFIR APAC at Ankura

Continuity is essential in the business world. Yet, the pandemic stunted the traditional business model. Employees that were going into the office five days a week immediately transitioned to working in a remote work environment, causing a shock to the system – or should I say our IT systems.

Employees began working on unmanaged and unmonitored home networks in the name of 'getting the job done', thereby creating a broader attack surface for cybercriminals to infiltrate systems. As a result, organisations turned their efforts to investing in more cybersecurity technology to secure their networks while ensuring remote access.

The benefits of cybersecurity technology are evident, but implementing and applying it to already established systems can be expensive and time-consuming. As cybercriminals continue to evolve their social engineering tactics, technology can't be the only solution to secure an organisation.

Now, as hybrid work becomes our working normal, businesses must address their cybersecurity more than ever. To save time and money spent on cybersecurity technology, organisations should be taking an educational approach to their cybersecurity strategy. By educating employees on the cyber risks associated with working in various locations and methods to use when faced with a potential cyber breach, businesses can further build a mature cybersecurity model that mitigates the chance of cyberattacks and provides an early notification when they do occur.

Where to start?

The social engineering tactics of cybercriminals today have made something clear – business systems can no longer be protected just by technology, people play a significant part in protecting an organisation. Employees work within an organisation's network five days a week or more. They understand the intricacies of the business's data and the information that passes through various systems.

Yet, in today's hybrid work landscape, organisations need to empower employees to reduce a business' attack surface for cybercriminals by implementing a cyber awareness program. Implementing a cyber awareness program into your business can provide a structured approach to managing human risk.

The first step to developing a mature cyber awareness program is to evaluate human risks and employee behaviour on how they are using an organisation's systems. Once organisations understand their employees' cybersecurity behaviours, business leaders can better assess what systems or employees' are more attractive targets for cybercriminals.

The second phase is to start maturing the cyber awareness of your employees to invoke change. Organisations can gamify phishing simulations but tracking the employees that successfully reported/identified a phishing email. As employees correctly identify phishing emails, they can progressively receive harder to determine phishing emails in future simulations. This not only educates employees, and hopefully makes phishing simulations more entertaining for staff, but it also ensures staff are always thinking "have I levelled up and is this a phishing email" – especially with a real threat actor sends them one.

While there's no one-stop-shop to achieve an educated workforce, it is good to start with some basics, including the need for strong passwords, implementing multifactor authentication, and regular software updates on remotely used devices and internet-facing systems.

Prevention is at the centre of cyber awareness programs. Maturing a business's cyber security awareness program gives time, money, and energy back into the business, whereas it could be ill-spent in reacting to a cyber breach.

The pandemic's impact on business continuity has been felt across Australia, from small-medium businesses to large enterprises, but ensuring an entire dimensional cyber strategy is in place can take the pressure off in our new working landscape.

Five signs that AI is growing faster than the internet did

What do Aussie businesses need to do to keep up? There has been mounting chatter that AI is growing even faster than the rapid acceleration we sa...

Protecting Your Small Business from Cyber Threats This Holiday Season

The holiday season brings a surge of online activity for small and medium businesses (SMBs), with increased sales and customer inquiries offering ...

Essential SEO Strategies: Boosting Your Real Estate Business

In recent years, it is said that more and more people are searching for properties online than those who visit real estate companies in person. For ...

Every Business Needs to Apply a Concrete Strategy

Do you want your website to rank higher in the top results of the Google search engine? Then hire the excellent SEO Services in Australia for your n...

Navigating Cyber Fraud After a Natural Disaster

As Australia enters another long, hot and potentially destructive summer, businesses and residents are preparing for the natural disasters synonym...

8seats messaging startup aims to transform business communication

The new platform brings an innovative approach to unite office-based and desk-less teams 8seats, a next-generation messaging platform for busine...

Sell by LayBy