Protect Your Business During Cybersecurity Awareness Month
October is Cybersecurity Awareness Month, creating a timely opportunity to look at cybersecurity from a financial perspective, particularly for growing businesses that may be adding employees, vendors, payment platforms and access to company accounts faster than they are adding internal controls. Additionally, new and evolving technology, such as artificial intelligence, is accelerating the rate at which hackers can find and take advantage of weak spots in computer software and systems, according to the Cybersecurity and Infrastructure Security Agency (CISA).
Cybercriminals look for easy targets. Businesses and organizations without basic precautions are an easier target for cyber-attacks. CISA recommended that organizations start with four essential steps to safeguard their data and enable their employees to stop attacks before they happen:
- Teach employees to avoid phishing scams: Phishing tricks employees into opening malicious attachments or sharing sensitive information. Train staff to recognize and report suspicious activity.
- Require strong passwords: Strong passwords are a simple but powerful way to block criminals from accessing your accounts through guessing or automated attacks. Make them mandatory for all users.
- Require multifactor authentication (MFA): MFA adds an extra layer of security beyond passwords. Require it to make accounts significantly safer. Use phishing-resistant MFA where available.
- Update business software: Outdated software can contain exploitable flaws. Promptly install security updates and patches to keep your systems protected.
CISA offered additional steps to help businesses of all sizes protect themselves from cyber threats:
- Require a log-on process to access systems.
- Back up data.
- Encrypt data.
- Get a .gov domain if eligible.
- Report cyber incidents to CISA.
- Have an incident response plan and use it.
- Be prepared for system disruptions.