HomeSecurityThree in ten companies vulnerable to cyberattacks

Three in ten companies vulnerable to cyberattacks

Three in 10 companies vulnerable to cyberattacks
Three in ten companies vulnerable to cyberattacks

The recent disclosure of the activities of a cyber gang, whose loot reached $1 billion, has once again brought to the fore the issue of the security of the information systems of large organizations. And in the case of this particular "cyber gang", which Kaspersky Lab, the company that investigated the issue, has given the name Carbanak, what has become - once again - obvious is that the real "back door" of businesses is their own employees.

In order to gain access to the corporate network of the banks they "hit", the members of Car-banak used employee computers on which they managed to install a malicious program (malware).

Lenovo
Continuous information and training of employees on cybersecurity issues is essential, in order to limit the chances of successful "attacks" by cybercriminals

More generally, in recent years it has become increasingly obvious that the weak link in cybersecurity issues is none other than employees, who most often do not have sufficient knowledge of how to protect the devices they use to connect to the corporate network from "attacks" by cybercriminals.

It is noteworthy that according to a recent survey by Kaspersky Lab and B2B International, 21% of all European businesses have lost sensitive business data due to "insider threats" in the last twelve months.

According to the survey, the most common insider threat remains software vulnerabilities, reported by 32% of businesses in Europe. Accidental data leaks by staff (reported by 26% of businesses) and loss/theft of mobile devices by staff (reported by 29% of respondents) follow in second and third place respectively.

 

Tips

But what should businesses do to train their employees so that they don't fall victim to cyberattacks?

According to experts, in principle, companies should talk to employees about cybersecurity issues at regular intervals, explaining what the consequences will be if an incident occurs. Mobile devices (smartphones, tablets) require particular attention, while information should not be limited to simply asking employees to read a text and accept it.

Top executives of companies should also be fully and thoroughly informed, as they are the most likely targets, given that they have access to much more critical data. It is worth noting that there have been incidents where cybercriminals have “infected” the computers of high-ranking executives when they used the free WiFi of the hotel they were staying at during a business trip!

What companies need to explain to employees is that no matter how advanced security systems are in place, the network is only as vulnerable as its weakest link. And that's why they shouldn't just comply with the instructions of those in charge, but should collaborate with everyone responsible to limit the chances of an incident.

It would be good if the updates were occasionally focused on a security issue, as well as if there were some incentives, such as, for example, the update including protection tips for the computers and smartphones that an employee has at home.

One point that managers should draw employees' attention to is the use of social media. In many cases, the "door" for cybercriminals is video links that appear on social media and are selected by unsuspecting employees, resulting in the computer being "infected".

It is also important that employees are trained so that they can understand when they are being "attacked". Also, managers should never mock or make bad comments about an employee who raises an "alarm" even if it turns out to be wrong. Furthermore, when an incident occurs, it is necessary to fully inform employees about it. Transparency will have better results than trying to keep what has really happened hidden.

Finally, it is a good idea for a company to regularly check its employees' knowledge of security issues, as well as ask them for their opinion on how they should deal with potential cyberattacks.

Source: imerisia.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS