Business Daily Media

Men's Weekly

.

Why businesses should invest more in their people and not cybersecurity technology

  • Written by Josh Lemon, author and certified instructor at SANS Institute, managing director DFIR APAC at Ankura

Continuity is essential in the business world. Yet, the pandemic stunted the traditional business model. Employees that were going into the office five days a week immediately transitioned to working in a remote work environment, causing a shock to the system – or should I say our IT systems.

Employees began working on unmanaged and unmonitored home networks in the name of 'getting the job done', thereby creating a broader attack surface for cybercriminals to infiltrate systems. As a result, organisations turned their efforts to investing in more cybersecurity technology to secure their networks while ensuring remote access.

The benefits of cybersecurity technology are evident, but implementing and applying it to already established systems can be expensive and time-consuming. As cybercriminals continue to evolve their social engineering tactics, technology can't be the only solution to secure an organisation.

Now, as hybrid work becomes our working normal, businesses must address their cybersecurity more than ever. To save time and money spent on cybersecurity technology, organisations should be taking an educational approach to their cybersecurity strategy. By educating employees on the cyber risks associated with working in various locations and methods to use when faced with a potential cyber breach, businesses can further build a mature cybersecurity model that mitigates the chance of cyberattacks and provides an early notification when they do occur.

Where to start?

The social engineering tactics of cybercriminals today have made something clear – business systems can no longer be protected just by technology, people play a significant part in protecting an organisation. Employees work within an organisation's network five days a week or more. They understand the intricacies of the business's data and the information that passes through various systems.

Yet, in today's hybrid work landscape, organisations need to empower employees to reduce a business' attack surface for cybercriminals by implementing a cyber awareness program. Implementing a cyber awareness program into your business can provide a structured approach to managing human risk.

The first step to developing a mature cyber awareness program is to evaluate human risks and employee behaviour on how they are using an organisation's systems. Once organisations understand their employees' cybersecurity behaviours, business leaders can better assess what systems or employees' are more attractive targets for cybercriminals.

The second phase is to start maturing the cyber awareness of your employees to invoke change. Organisations can gamify phishing simulations but tracking the employees that successfully reported/identified a phishing email. As employees correctly identify phishing emails, they can progressively receive harder to determine phishing emails in future simulations. This not only educates employees, and hopefully makes phishing simulations more entertaining for staff, but it also ensures staff are always thinking "have I levelled up and is this a phishing email" – especially with a real threat actor sends them one.

While there's no one-stop-shop to achieve an educated workforce, it is good to start with some basics, including the need for strong passwords, implementing multifactor authentication, and regular software updates on remotely used devices and internet-facing systems.

Prevention is at the centre of cyber awareness programs. Maturing a business's cyber security awareness program gives time, money, and energy back into the business, whereas it could be ill-spent in reacting to a cyber breach.

The pandemic's impact on business continuity has been felt across Australia, from small-medium businesses to large enterprises, but ensuring an entire dimensional cyber strategy is in place can take the pressure off in our new working landscape.

Workplace DMs, Reinvented: Deputy Messaging, Purpose-Built For Shift-Based Teams

Deputy, the global people platform for shift-based businesses, has launched Deputy Messaging, a fully integrated, real-time communication tool designe...

Revolutionizing Fulfillment: How Virtual Warehousing is Changing the Game?

The e-commerce landscape is evolving more rapidly than ever, and the way businesses are managing their fulfillment is also revolutionizing. At the...

SME lender Dynamoney welcomes new CEO, Brett Thomas

Strengthens growth ambitions and signals expanded offering Dynamoney, a leading commercial finance provider for Australian SMEs,  has today appoint...

The cost of ignoring AI governance in business

Artificial intelligence (AI) is no longer the promise of a distant future: it's active, embedded, and already shaping decisions across industries. H...

Quickli launches new SMSF product as free beta for limited time only

The leading technology provider for Australian mortgage brokers, Quickli, has answered the prayers of brokers yet again with the launch of a stand...

Portable Monitors for Coding and Programming Students

Today, coding and programming require more focus and efficiency. But, the most essential thing it demands is ample screen space. Students can stru...

Sell by LayBy