Preloader Close

Cyber Attacks

7 Ways Your Employees Make Your Business Vulnerable to Cyber Attacks

Companies collect and store enormous amounts of data. From billing invoices to customers' credit card information, so much of your business focuses on private data.

To succeed, you have to trust employees with this data. But, sometimes, even the most well-intentioned employee can make mistakes that leave your company vulnerable to cyberattacks.

Here's a list of the seven most common employee mistakes and what you can do to fix them.


icon Opening Emails from Unknown People

Email is the preferred form of business communication. The average person receives 235 emails every single day, according to The Radicati Group. With that many emails, it stands to reason that some are scams. Opening an unknown email, or an attachment inside an email, can release a virus that gives cybercriminals a backdoor into your company's digital home.

Solutions
  • Advise employees not to open emails from people they don't know.
  • Advise employees to never open unknown attachments or links.
icon Having Weak Login Credentials

Mashable reported that 81% of adults use the same password for everything. Repetitive passwords that use personal information, such as a nickname or street address, are a problem. Cybercriminals have programs that mine public profiles for potential password combinations and plug in possibilities until one hits. They also use dictionary attacks that automatically try different words until they find a match.

Solutions
  • Require Employees To Use Unique Passwords
  • Add Numbers And Symbols To A Password For Increased Security. For Example, Change "Creative" To "Cre8ive."
  • Create Rules That Require Employees To Create Unique, Complex Passwords Of At Least 12 Characters; And Change Them If They Ever Have Reason To Believe That They Have Been Compromised.
  • Take The Headache Out Of This By Using A Password Manager Software To Automatically Generate Strong Individual Passwords For Multiple Apps, Websites And Devices.
icon Leaving Passwords on Sticky Notes

Have you ever wandered through the office and spotted a sticky note on a screen with passwords written on it? It happens more often than you think. While you want a certain level of trust inside your organization, leaving passwords visible is too trusting.

Solutions
  • If Employees Must Write Down Passwords, Ask That The Paper Copies Are Kept Inside Locked Drawers.
icon Having Access to Everything

In some cases, companies don't compartmentalize data. In other words, everyone from interns to board members can access the same company files. Giving everyone the same access to data increases the number of people who can leak, lose or mishandle information.

Solutions
  • Set Up Tiered Levels Of Access, Giving Permission Only To Those Who Need It On Each Level.
  • Limit The Number Of People Who Can Change System Configurations.
  • Don’t Provide Employees With Admin Privileges To Their Devices Unless They Really Require Such Set Up. Even Employees With The Admin Rights Should Only Use Them As Needed, Not Routinely.
  • Enforce Dual Sign-Off Before Payments Over A Certain Amount Can Be Processed To Combat CEO Fraud.
icon Lacking Effective Employee Training

Research shows the majority of companies do offer cybersecurity training. However, only 25% of business executives believe the training is effective.

Solutions

Provide annual cybersecurity awareness training. Topics could include:

  • Reasons For And Importance Of Cybersecurity Training
  • Phishing And Online Scams
  • Locking Computers
  • Password Management
  • How To Manage Mobile Devices
  • Relevant Examples Of Situations
icon Not Updating Antivirus Software

Your company should deploy antivirus software as a protective measure, but it shouldn't be up to employees to update it. At some companies, employees are prompted to make updates and can decide whether or not the updates take place. Employees likely say no to updates when they're in the middle of a project, since many updates force them to close programs or restart computers.

Antivirus updates are important, should be handled promptly and shouldn't be left to employees.

Solutions
  • Set Up All System Updates To Take Place After Work Hours Automatically.
  • Don't Let Any Employee, No Matter What Their Title, Opt Out Of This Company Policy.
icon Using Unsecured Mobile Devices

Do your employees have company cell phones, tablets or laptops? If so, do you have protocol in place to keep these devices secure? Many companies have a lax attitude toward mobile devices, but they present an easy target for cybercriminals.

Solutions
  • Every Device Should Be Password Protected.
  • If A Device Is Lost Or Stolen, Have A Point Of Contact To Report This To And Steps Taken To Deactivate The Device Remotely.
  • Use Endpoint Security Solutions To Manage Mobile Devices Remotely.
  • Don’t Conduct Confidential Transactions Using Untrusted Public Wi-Fi.
 

Employees are human, and digital accidents can happen. However, if you take certain steps to safeguard devices and train employees, you can prevent cyberthreats.

Of course, managing your company's cybersecurity goes beyond employee education. Protecting a company's digital footprint and managing threats requires the help of a reputable cybersecurity company.

Disclaimer: The information is provided solely for general informational and educational purposes and is not intended to be a substitute for professional advice. As a result, before acting on such information, we recommend that you consult with the appropriate professionals.