ESET: Digital technology is becoming increasingly important in our lives, making a user's personal data as important as their material possessions. At the same time, it makes them equally vulnerable to attacks, with criminals flooding not only the real world, but also cyberspace.
According to a study by the Pew Research Center, even though users are more aware of the magnitude of this threat, they continue to make the same mistakes regarding cybersecurity.
ESET has compiled seven of the most common mistakes and presents them, offering practical advice on how to avoid them.
1. Email. Phishing tactics via email have become very common and cybercriminals are constantly improving them. To protect themselves, users should not neglect to carefully check each email regarding the recipient and subject, using common sense. In case of doubt, a Google search can be very helpful regarding validity. Also, be careful with attachments, checking file extensions and only opening files that are considered safe and from trusted sources.
2. Social Media. Social media has become the new favorite medium for cybercriminals, while many users still appear careless with their accounts – for example, a 2016 survey showed that 58% of users do not know how to update their privacy settings. As with emails, the user should always check the authenticity of the sender, the message and the link. Particular attention is also required with popular hashtags, as many scammers use them to trick unsuspecting Twitter and Facebook who are trying to stay up to date with the latest news.
3. “It won’t happen to me.” Culture is arguably the biggest issue with security right now. From everyday users to CEOs, everyone thinks the same thing, that nothing bad will happen to them. This complacency is misguided, as we are all targets and potential victims. However, by implementing a few basic, simple steps, we can stay safe: using good passwords, regularly updating software, using anti-virus, password managers, VPNs, and encryption apps.
4. Passwords. Weak passwords, such as 123456, password, 12345678, qwerty, etc., remain common and are very easy to crack. According to Forrester, 80% of all attacks involve a weak or stolen password. Fortunately, some services now force users to create random or complex passwords. A password manager app, as well as using a “complex” password with letters, numbers, and characters, are also very good solutions.
5. Lack of software updates: Desktops, laptops and mobile devices regularly need to install software updates for applications, the operating system or the security solution. Many users are annoyed by pop-up notifications reminding them of updates, but in reality they are extremely important. Without updates, software and devices are vulnerable to attacks, as cybercriminals try to exploit vulnerabilities that have not been patched. Choosing to do them automatically when we trust the software or application manufacturer can prove to be a lifesaver in this case.
6. Suspicious Links. URLs, in addition to interesting electronic destinations, can also lead to password and data theft, and even malware attacks. Before clicking on this shortened link, we ask ourselves if we trust the sender who sent it to us or the platform we found it on, as well as the destination it is supposed to lead us to. We should be particularly cautious when this Link coincides with important events (natural disasters, major sporting events) as cybercriminals usually exploit them to achieve their goals. Especially in shortened URLs, we can use LongURL and CheckShortURL and see the original address.
7. Antivirus. Many users believe that if they only visit secure pages on the Internet, they are not at risk, but the truth is that the device can also be infected by visiting trusted sites that have been compromised, or fall victim to a “zero-day” attack from a browser vulnerability. Using a reliable security solution can prove to be a valuable ally, as thousands of experts work daily to identify malware and eliminate them, keeping users safe.
