A "sizable proportion" of businesses have still not put in place basic protection and policies to protect themselves from attack.
That’s one of the conclusions of a newly-published UK government survey which uncovered that 46% of all UK businesses had “identified at least one cybersecurity breach or attack in the last 12 months.”
Before you feel smug that your business is doing everything it should to thwart online criminals, ask yourself honestly if you can count your company in the following categories:
Statistics suggest that – more likely than not - the company you work for is failing to reach at least some of these standards.
The Cyber Security Breaches Survey 2017, based upon a three month study of 1,523 UK businesses, found that the larger your organisation the more attacks you experience.
The most commonly reported breaches involved staff receiving fraudulent emails (72%), malware attacks (33%), impersonation of the organisation via email or online (27%), and ransomware (17%).
And even though attacks can frequently have a financial impact on business, external reporting of incidents remains uncommon.
According to the report, only a quarter of business victims reported their disruptive breach to anyone other than their security vendor.
“The findings suggest that some businesses lack awareness of who to report to, why to report breaches, and what reporting achieves.”
That statistic disturbs me, because if we fail to report computer security breaches appropriately, how can we hope to measure if businesses are doing a better or worse job of protecting our personal information?
Furthermore, how are the authorities supposed to determine if more money needs to be invested in educating industry in how to better defend against attacks, and providing more resources to law enforcement agencies to catch those responsible.
Although this particular survey focuses on UK businesses, there is no doubt that the problem is a global one – affecting organisations of all sizes and sectors.
More firms are waking up to the importance of effective computer security, and have seen the financial and reputational damage that can occur when a hacker manages to breach their systems.
It feels to me that the rise in prominence of ransomware in the last couple of years has particularly raised helped to raise awareness inside businesses of the threat, and made network security a more urgent issue in the boardroom.
And yet too many companies are still failing to take the most simple steps to reduce the chances of a successful breach.
IT security isn’t just a technical problem. It’s actually primarily a human problem. Some of the most commonly encountered attacks can be countered by having a skilled workforce who have been trained in what to look out for, and to contact their IT helpdesk if they think they’ve spotted something suspicious.
By raising awareness of threats, by educating staff as to what to look out for, by preparing for an incident before it occurs, and putting sensible defences in place to reduce their impact, you can dramatically reduce your company being the next statistic.
Graham Cluley is an award-winning security blogger, researcher and public speaker. He has been working in the computer security industry since the early 1990s, having been employed by companies such as Sophos, McAfee and Dr Solomon's. He has given talks about computer security for some of the world's largest companies, worked with law enforcement agencies on investigations into hacking groups, and regularly appears on TV and radio explaining computer security threats. Graham Cluley was inducted into the InfoSecurity Europe Hall of Fame in 2011, and was given an honorary mention in the "10 Greatest Britons in IT History" for his contribution as a leading authority in internet security.View all posts
Don’t miss out on exclusive content and exciting announcements!