Business Daily Media

Men's Weekly

.

Why businesses should invest more in their people and not cybersecurity technology

  • Written by Josh Lemon, author and certified instructor at SANS Institute, managing director DFIR APAC at Ankura

Continuity is essential in the business world. Yet, the pandemic stunted the traditional business model. Employees that were going into the office five days a week immediately transitioned to working in a remote work environment, causing a shock to the system – or should I say our IT systems.

Employees began working on unmanaged and unmonitored home networks in the name of 'getting the job done', thereby creating a broader attack surface for cybercriminals to infiltrate systems. As a result, organisations turned their efforts to investing in more cybersecurity technology to secure their networks while ensuring remote access.

The benefits of cybersecurity technology are evident, but implementing and applying it to already established systems can be expensive and time-consuming. As cybercriminals continue to evolve their social engineering tactics, technology can't be the only solution to secure an organisation.

Now, as hybrid work becomes our working normal, businesses must address their cybersecurity more than ever. To save time and money spent on cybersecurity technology, organisations should be taking an educational approach to their cybersecurity strategy. By educating employees on the cyber risks associated with working in various locations and methods to use when faced with a potential cyber breach, businesses can further build a mature cybersecurity model that mitigates the chance of cyberattacks and provides an early notification when they do occur.

Where to start?

The social engineering tactics of cybercriminals today have made something clear – business systems can no longer be protected just by technology, people play a significant part in protecting an organisation. Employees work within an organisation's network five days a week or more. They understand the intricacies of the business's data and the information that passes through various systems.

Yet, in today's hybrid work landscape, organisations need to empower employees to reduce a business' attack surface for cybercriminals by implementing a cyber awareness program. Implementing a cyber awareness program into your business can provide a structured approach to managing human risk.

The first step to developing a mature cyber awareness program is to evaluate human risks and employee behaviour on how they are using an organisation's systems. Once organisations understand their employees' cybersecurity behaviours, business leaders can better assess what systems or employees' are more attractive targets for cybercriminals.

The second phase is to start maturing the cyber awareness of your employees to invoke change. Organisations can gamify phishing simulations but tracking the employees that successfully reported/identified a phishing email. As employees correctly identify phishing emails, they can progressively receive harder to determine phishing emails in future simulations. This not only educates employees, and hopefully makes phishing simulations more entertaining for staff, but it also ensures staff are always thinking "have I levelled up and is this a phishing email" – especially with a real threat actor sends them one.

While there's no one-stop-shop to achieve an educated workforce, it is good to start with some basics, including the need for strong passwords, implementing multifactor authentication, and regular software updates on remotely used devices and internet-facing systems.

Prevention is at the centre of cyber awareness programs. Maturing a business's cyber security awareness program gives time, money, and energy back into the business, whereas it could be ill-spent in reacting to a cyber breach.

The pandemic's impact on business continuity has been felt across Australia, from small-medium businesses to large enterprises, but ensuring an entire dimensional cyber strategy is in place can take the pressure off in our new working landscape.

Deputy Launches Payroll in Australia: Purpose Built for Shift-Based Businesses

Deputy, the global people platform purpose-built for shift work, officially launched Deputy Payroll in Australia today — a seamless experience desig...

How Notion is Addressing Australia's Tech Bloat and Productivity Challenges

In Australia's rapidly evolving digital landscape, businesses are facing an unexpected challenge : tech bloat. This phenomenon is causing a signific...

Konica Minolta Australia partners with Box to drive Intelligent Content Management

Konica Minolta Australia has announced a strategic partnership with Box, the leader in Intelligent Content Management, to deliver a transformative...

TP Leverages AI for Accent-Translation to Improve Customer Engagement

Global digital business services provider Teleperformance (TP) is leveraging AI voice technology to improve communication between customers and se...

The quiet majority: why marketers need to cater to low intent shoppers

When shoppers are browsing online, whether for a new phone, holiday, or pair of shoes, they usually know exactly where they stand. Sometimes they’...

Lack of Salary Transparency is Costing Businesses Top Talent, Says Recruiters

As end-of-financial-year reviews approach, new research reveals a growing disconnect between Australian employers and employees on the issue of sa...

Sell by LayBy