At Bob’s Business, we’re at the very forefront of organisational cybersecurity training and simulated phishing training. Making training entertaining, engaging and effective is what we do.
In order to make training truly effective, however, we need to understand the cybersecurity habits, behaviours and assumptions that underpin behaviours across organisations.
It’s why we created the Human Vulnerability Assessment, our unique organisational benchmarking tool which we deploy to Bob’s Culture clients to help deliver truly tailored training and demonstrate organisational improvement.
Now, we’re ready to reveal some of the statistics we’ve gleaned from over six months of opening HVA deployments – statistics that reveal the good, the bad and the ugly of cybersecurity in 2021.
The Good
97% of recipients believe that everyone in their organisation had a role to play in cybersecurity.
77% did not feel that they could be complacent with regard to cybersecurity due to their organisation’s automated defences.
71% consider it possible for their organisation to fall victim to a cyberattack.
The Bad
24% of recipients answered that they occasionally download files and media without verifying their authenticity. That means that around one in four employees were at risk of accidentally downloading malware, which can have severe consequences for an organisation.
11% of recipients responded that they do with some level of frequency share work passwords with their colleagues. Sharing passwords like this leads to less secure accounts and may result in data breaches.
45% of those questioned did not claim to be at all suspicious of incoming emails.
The Ugly
65% of recipients admitted to reusing passwords on multiple sites. This means that a data breach on one external site may lead to multiple compromised accounts.
16% admit to clicking links in emails from unverified sources. Our tests show otherwise, as while any given phishing simulation typically achieves a ~16% click rate, the overall portion of recipients that click on at least one template throughout a campaign is higher.
Only 46% of recipients claimed always to follow their company’s cybersecurity policies. More troubling still was that 14% claimed not to know the policies at all.
The methodology
The HVA questionnaire was sent to users at 25 organisations. In total 4,937 users completed the test. As questions were added to the HVA or changed over time, the sample for specific questions varies. The results for all organisations were collated. Key demographic statistics were then drawn from questions of interest.
How can you give partner organisations and customers greater confidence in the way they interact with your business, and assure the reliability, security, and integrity of your systems and information? The answer: ISO 27001 certification.
ISO 27001 certification is an important standard for most organisations with an ISMS (Information Security Management System), but what is ISO 27001, and do you need it?
This article will discuss why your organisation should be ISO 27001 certified and answer all your questions.
What is ISO 27001?
ISO 27001 is the internationally recognised specification for implementing an ISMS (Information Security Management System). It delivers a framework to establish, operate, monitor, review and maintain an ISMS.
ISO 27001 is the most comprehensive and respected standard of its kind, published by the International Organisation for Standardisation (ISO), in partnership with the International Electrotechnical Commission (IEC). It is one part of a wider series of standards (the ISO/IEC 27000 series) that covers information security.
What are the requirements of ISO 27001 training?
You could jump straight into ISO 27001 training without any primer, but you’ll get much more from it if you familiarise yourself with the standard first.
As such, we recommend your team take our ISO 27001 course, where they will learn the principles of ISO 27001, why it’s important, how everyone can improve information security in your organisation, and how to react to noncompliance in your organisation.
Deploying cybersecurity awareness training to your team is the next step. Demonstrating that your team have completed cybersecurity awareness training is a required element to achieve the standard. Whether it’s Bob’s Culture or Bob’s Compliance, our products help you do just that.
You may be wondering where cybersecurity comes into all this, and the answer is simple – ISO 27001 is an information security framework and cybersecurity forms part of this. As the world becomes more dependent on technology, cyber will take an increasing role in how we establish, operate, monitor, review and maintain our ISMS.
In terms of specific requirements for ISO 27001 training, this depends on the type of course you take, and the needs of your organisation.
What are the benefits of ISO 27001 certification?
There are several benefits to ISO 27001 certification:
Increased partner and customer confidence in your organisation
Retain customers and win new business
Prevent loss of reputation over compliance concerns
Avoid hefty fines over non-compliance
Avoid wasted investment in the wrong security standards
Comply with other regulations, such as SOX
Plug gaps and loopholes in your information security
Improve risk management
Demonstrate a clear commitment to information security
Build a culture of security within your organisation
Establish, operate, monitor, review and maintain an ISMS to the highest standards
ue to this wide range of benefits, you should look beyond ISO 27001 as a compliance tool and more as a way to achieve several business benefits. It can deliver value in several ways, making it a worthwhile investment for many organisations.
What types of organisations benefit from ISO 27001 certification?
While many organisations have some form of information security standards in place, ISO 27001 is a comprehensive framework for information security, delivering compliance, and assurance, across all areas of an ISMS.
Because of this, ISO 27001 certification can benefit any organisations that are directly or indirectly involved in information security — and especially those that handle sensitive data.
Examples include:
Government agencies – including national and local government departments
IT companies – including software developers, cloud computing companies, IT support companies
Telecoms companies – including internet service providers, mobile networks, satellite companies
Technology companies – including software companies, hardware companies, biotech companies, renewable energy companies
Another important thing to remember is public and private organisations can define compliance with ISO 27001 as a legal requirement in their contracts.
This means you may need ISO 27001 certification to be a partner, customer or supplier to some organisations, a point that is most relevant to highly-regulated industries like finance, where ISO 27001 is considered an industry standard.
What next?
If you’ve made it this far, then there’s a good chance you believe your organisation would benefit from ISO 27001 certification.
The next step is to discuss this with ISO certification experts, who will help you figure it out once and for all if it’s right for your organisation.
In any case, it’s important to implement effective information security education and awareness across your organisation, and our cybersecurity awareness training is the perfect way to get started.
Let’s face it, GDPR legislation isn’t an easy read. Scrap that – it’s a slog. It’s so vast, in fact, that you can spend hours reading it and not understand very much at all.
The good news, however, is that it gets significantly easier once you understand what the jargon means and how it all links together.
To help out, we’ve put together this helpful GDPR jargon buster which you can use as a primer before undergoing GDPR training and diving into the intricacies of the legislation. It’s a 5-minute read that’ll save you hours of time.
Let’s get to it…
What is a Data Protection Officer?
A Data Protection Officer is an expert in data protection law. Their role is to ensure an organisation processes personal data in compliance with the GDPR.
It is a legally required appointment where the processing in question involves regular and systematic monitoring of data subjects on a large scale, or where the processing is of special categories of data on a large scale (the threshold is 5,000 persons).
What is a Subject Access Request?
A Subject Access Request (SAR) is a request for access to personal data. This is the correct legal mechanism under the GDPR for accessing and receiving a copy of personal data as well as other supplementary information held on file.
An individual can make a SAR themselves or have a legal representative do it in writing, verbally, or even on social media. As the ICO says, “a request is valid if it is clear that the individual is asking for their own personal data. An individual does not need to use specific words, refer to legislation or direct the request to a specific contact.”
What is a Data Subject?
A Data Subject is any person with a data file who can be identified directly or indirectly via an identifier from the data collected about them.
Examples of personal identifiers include name and passport number. Identifiers also include physical, physiological, genetic, mental, economic, cultural and social identifiers, such as religion and race.
What is a Data Controller?
A Data Controller is an entity (company, individual, or other body) that controls the means and purpose of processing data. They are the decision-makers with regards to processing. In other words, they instruct the processor.
What is a Data Processor?
A Data Processor is an entity (company, individual, or other body) that processes data on behalf of a Data Controller. They only work on the instructions of the Data Controller. They serve the controller’s interests rather than their own.
What is Profiling?
In the GDPR, Profiling is defined as “any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person.” Organisations use profiling to predict behaviour, discover user preferences, and make decisions (such as credit decisions).
What is Pseudonymisation?
Pseudonymisation is a data entry technique that replaces or removes certain identifiers from data sets with pseudonyms or values that cannot identify the individual. Controllers will often pseudonymise data so they can use the data beyond the purpose for which it was originally collected. This is allowed under Article 6(4)(e) of the GDPR.
The UK GDPR defines Pseudonymisation as “the processing of personal data in such a way that the data can no longer be attributed to a specific data subject without the use of additional information.”
What is the Data Protection Act?
The Data Protection Act 2018 is UK legislation that sets out the framework for the UK GDPR, a modified version of the EU GDPR with derogations and other provisions.
Put simply, the Data Protection Act 2018 is the UK’s implementation of the EU’s General Data Protection Regulation, which is why you will see the phrase “UK GDPR” used a lot in reference to legislation that applies in the United Kingdom.
Find out more
Our NCSC-certified GDPR training courses are the perfect way for everyone in your organisation to learn more about the GDPR. We can help you get to grips with the GDPR and ensure compliance across your organisation.
When you think of bribery, you might think of bent coppers (thanks, Line of Duty). Or, you might imagine shady political deals and cash-lined handshakes.
The reality for the vast majority of businesses and organisations, however, is much more prosaic – though no less insidious. Bribery is, in fact, extremely commonplace. Why? Simply because many employees don’t know a bribe when they see one.
As such, anti-bribery training is required to reduce the risk that someone who works for you or on your behalf might be exposed to bribery.
Oddly, despite bribery being a common cause of corruption, many organisations do not train staff to be aware of what situations and actions they should be avoiding. This leaves them exposed to non-compliance and regulatory or legal action.
The compliance aspect of bribery comes via The Bribery Act 2010, not only says that commercial organisations should adopt a “risk-based approach” to managing bribery risks, but also includes training as one of its six principles.
In this blog, we’ll reveal what you need to know about anti-bribery training so you can figure out if your organisation needs it and what to do next.
What is anti-bribery training?
Anti-bribery training educates staff about bribery so they can recognise it and make the correct decisions when they encounter it.
There are two core learning outcomes with anti-bribery training:
Being able to recognise the many forms of bribery
Being able to react/respond to bribery attempts correctly
It’s important for everyone in an organisation who might be exposed to bribery to receive anti-bribery training so there are no weak links.
The Bribery Act 2010 defines bribery in law and any good anti-bribery course should help people understand the intricacies of the legislation.
What are the six principles of the Bribery Act?
The Bribery Act 2010 has six principles. They are not prescriptive but are designed to guide and inform decisions regarding anti-bribery policy.
Principle 1
Proportionate procedures
Put in place procedures that are proportionate to the scale and complexity of your commercial organisation’s activities.
Principle 2
Top-level commitment
Foster a top-level culture within your organisation that takes bribery seriously and makes it clear that bribery is not acceptable.
Principle 3
Risk assessment
Assess and understand the risks of bribery posed to your organisation and the persons associated with it.
Principle 4
Due diligence
Take a proportionate and risk-based approach to bribery in respect of procedures and the persons who might be exposed to bribery.
Principle 5
Communication (including training)
Ensure that your bribery and prevention policies are understood within your organisation with training that is proportionate to the risks you face.
Principle 6
Monitoring and review
Keep on top of your bribery policy and procedures and make improvements where necessary to assure continued compliance.
You can find more detail about the six principles of the Bribery Act here.
Who needs an anti-bribery policy?
Every commercial organisation that is at risk of being exposed to bribery needs an anti-bribery policy to comply with legislation.
The Bribery Act 2010 creates offences of offering or receiving bribes and failing to prevent persons associated with your organisation from committing bribes on its behalf.
An anti-bribery policy is necessary to comply with the law and ensure that your organisation proportionately counters bribery and corruption.
What is classed as bribery?
Bribery is an unethical gesture intended to influence a person’s behaviour by offering a financial or other advantages.
Bribes are often business-motivated and come in many forms, but they always intend to achieve an advantage, whether it be financial or preferential treatment.
Unfortunately, bribes can be difficult to spot. Is offering a referral fee to an executive in another company to win a contract a bribe? Is offering a female employee a bonus in return for coming back to work early from maternity leave a bribe?
Because bribes can be difficult to spot, anti-bribery training is essential for commercial organisations. By knowing what a bribe looks like, everyone in your organisation will be able to avoid it, spot it and stop it before it escalates.
How can you reduce bribery in your organisation?
The most important thing is to understand the legislation surrounding bribery and create an anti-bribery policy around that legislation.
One of the most important aspects of your policy will be anti-bribery training so that everyone in your organisation can recognise bribery and react to bribery attempts correctly.
Like all procedures, training should be proportionate to risk, but some training will also help to establish an anti-bribery culture in your organisation.
We recommend mandatory general training for all employees that covers education and awareness raising about bribery. More intensive training may also be needed for people in higher-risk roles such as finance, purchasing and IT.
Our anti-bribery course is a great place to start. It’s accredited by the National Cyber Security Centre and simplifies the intricacies of bribery legislation, with engaging animations and simple, effective language.
Of course, not all phishing emails are created equal, ranging from broad attacks around phoney billionaires with trapped funds to specific, targeted campaigns which utilise your publicly available information.
At Bob’s Business, we’re at the forefront of the fight against phishing emails. Our award-winning Think Before you Click phishing simulation finds the vulnerabilities in your organisation and launches targeted training to reduce the likelihood of your workforce clicking on malicious links.
Our approach is deeply rooted in science, which is why, working in conjunction with the University of Huddersfield, we have created a statistical analysis of the results from over 67,000 phishing emails.
The results were stunning and revealed the factors that can lead to a phishing success rate of 94%. But what are those factors, and what can you do to reduce your organisation’s risk of falling victim to an attack? Join us as we share our findings.
What Makes an Effective Phishing Email?
Element #1: Internal vs. External emails
The key factor that determined if a phishing email was a success or not was whether it appeared to come from within the organisation (internal, e.g. an apparent IT security update) or outside the organisation (external, e.g. a discount offer from an online retailer).
Over one in three employees (37.2%) were phished when opening external emails. However, the phishing rate rose to 78% when the emails seemed to be from an internal source. This suggests that employees trust emails that appear to come from internal sources almost twice as much as those from an external source.
Element #2: Danger vs. Benefit
The other factor that determined whether a phishing email was a success or not was whether it employed a ‘danger’ or ‘benefit’ to encourage the recipient to engage with the embedded link.
A ‘danger’ in a phishing email is some sort of risk of loss to the recipient if they do not respond, such as the threat of losing access to an account or a large unexpected bill. A ‘benefit’ might be a voucher for a free product or a tax rebate that requires claiming.
Our research found that a phishing email featuring a ‘danger’ had a phishing success rate of 75%, whilst a phishing email with a ‘benefit’ had a phishing success rate of 39%, clearly indicating that we’re all more likely to act when under pressure.
Combining Factors
By combining elements, our analysis reveals the common blind spots in organisations.
As expected, phishing emails that posed as internal and included a ‘danger’ were by far the most effective.
The analysis shows that, if the email was from an external source, just over one in three employees (37.2%) clicked on the email and were phished. However, if the email was from an internal source, between 44.6% and 94.1% clicked, depending on whether there was a benefit or a danger that encouraged the user to do so.
If an email was from an internal source and contained a benefit, we saw a phishing rate of just under one in two (44.6%), while internal emails that contained a danger led to a high risk of phishing, with over nine out of ten people being phished (94.13%).
What Can We Learn From This Analysis?
With phishing rates on the rise globally and attacks growing more sophisticated by the day, it’s vital that each of us understands the risks that phishing attacks pose.
Technological solutions offer some protection from phishing attacks, but with analysis of big tech firms finding that only 36% of phishing emails with links were stopped by their systems, it’s clear that more needs to be done to tackle the issue.
It’s especially pressing when you consider that just one phishing email needs to be successful in order to potentially breach your systems.
As such, the only viable option for organisations is to train their staff to better understand how to identify and report phishing emails effectively. By combining a simulated phishing campaign with targeted training, we have found that phishing risk can be reduced by 74.83%.
We firmly believe that focusing on human behaviour and understanding why your employees’ click is the key to reducing risks as training can then be targeted towards changing behaviour.
Want to raise awareness of phishing within your organisation, or simply looking for a visual way to share our findings? Click on the infographic below to download your own sharable copy.
Methodology
Bob’s Business’ analysis includes 67,000 users and found that more than 18,000 (26.8%) individuals opened phishing emails. Of these 18,000 that were opened, over 10,000 (56.2%) were successfully phished. All statistics are pulled from the 18,000 individuals who opened the phishing emails.
Contact Us for Comment
Want to discuss our findings? Get in touch with our team at marketing@bobsbusiness.co.uk
Bob’s Business is proud to announce the launch of an all-new, SaaS solution aimed at bringing cybersecurity training to SME organisations. Available from just £1.39 per user, per month.
At Bob’s Business, we know that cybersecurity is crucial for organisations of all sizes, not just big businesses. In fact, according to the FSB, UK SME organisations see almost 10,000 attacks a day.
Historically, however, smaller organisations have shied away from training their team on cybersecurity and compliance topics. Why? Because the products available to them have been too expensive, demanded long-term contracts and had features that SME’s don’t need.
The good news? We’ve built a solution that’s tailor-made to give you everything you need, and nothing you don’t, at a price that’s affordable for all. It’s called Bob’s Compliance, but what makes it the ideal solution for you?
Affordable pricing, instant access
Times are tough, especially for SME organisations. That’s why we’ve driven down the price of our training to make it affordable for every organisation.
From the price of a cup of coffee a month, your team can start learning critical cybersecurity, compliance and social engineering topics. Better still, signing up and enrolling your users takes mere minutes, and is completed online.
Full access to our NCSC-accredited course catalogue
With Bob’s Compliance, every member of your team gets access to our full course catalogue on your own organisational LMS, complete with completion tracking.
That means access to our full GDPR catalogue and popular courses like Secure Printing, Social Media, Carefully Classified, Email Etiquette, Mobile Working, Perfect Passwords and Phishing Fears; ideal for demonstrating compliance with ISO 27001.
No long-term contract (unless you want one)
We’ve heard you loud and clear – committing to a one or three-year contract is a significant demand in trying times. That’s why with Bob’s Compliance we’re introducing rolling one-month contracts.
It’s the ideal solution for organisations looking to give our training a try, spread the cost of their annual training or simply cancel their subscription as and when they wish.
Want even better value? One and three-year contracts are available with huge savings on monthly subscriptions!
The General Data Protection Regulation (GDPR) sets out legislation that governs how data related to people in the EU and UK should be collected and processed. In the UK, the GDPR forms part of the Data Protection Act 2018.
One of the areas of focus for the GDPR is data breaches, which fall under the wider topic of data management. Under the GDPR, organisations that control and process data are accountable for that data and must take steps to manage and secure it.
When this data is compromised, a breach of GDPR occurs. With potential fines of up-to €20 million (about £17.5 million) or 4% of annual global turnover – whichever is greater – for infringements, data breaches can have serious consequences for you and your organisation.
In this blog, we’ll share with you what a constitutes a GDPR breach, the most common cause of breaches and what your organisation can do to avoid them.
What is a breach of GDPR?
In the GDPR text, a data breach is defined as a breach of security leading to the accidental, unlawful or deliberate destruction, loss, alteration, unauthorised disclosure of, or access to, personal data related to individuals living in the EU.
Based on this, data breaches can fall into three categories:
Confidentiality breach – unauthorised or accidental access to personal data
Availability breach – loss or destruction of personal data
Integrity breach – unauthorised or accidental alteration of personal data
The GDPR covers two types of data: ‘personal data’, such as name and surname, home address, email address, location data; and ‘sensitive personal data’: such as biometric data, healthcare records, union memberships and religious beliefs.
What are the common causes of breaches?
Data breaches come in various forms and sizes, ranging from breaches caused by hacking, malware and ransomware, to breaches facilitated by password guessing, phishing and Distributed Denial of Service (DDoS) attacks.
Other causes of data breaches include portable device loss, unintended disclosure, insider leaks and physical data loss (such as from a fire).
Not all incidents are the result of a cyberattack, however, many are. Here’s a breakdown of some of the most common breach types:
Hacking
Most large-scale data breaches are caused by hackers. A variety of techniques are used by these criminals, including SQL injection, Malware and DDoS attacks. Hacking is premeditated in most cases to compromise a specific data set.
Ransomware
Ransomware is a malicious program that demands payment while holding a computer for ransom. The program then threatens to destroy all data on the computer if the ransom isn’t paid, which would count as an availability breach.
Employee negligence
Employee negligence could be something as simple as emailing a spreadsheet containing personal data to the wrong person, or as sinister as emailing data to a criminal pretending to be the company CEO, which is exactly what happened with Snapchat in 2016.
Unauthorised access
Unauthorised access can be facilitated by weak passwords, one-step authentication and leaving devices logged in. Privileged users with access to sensitive information present the biggest risk to organisations.
Portable device loss
Portable device loss poses a significant data management risk and especially when devices are not encrypted and cannot be remotely wiped. This happened in 2007 when a disc containing the personal details of 25m British families got lost in the post.
Unintended disclosure
Unintended disclosure is when employees with access to sensitive information unintentionally or by mistake reveal confidential information. This is a leading cause of major data breaches under the GDPR.
What can your organisation do?
Invest in training
With the potential for serious fines, it’s vital that GDPR training is deployed to your employees, so that they understand their role in your organisation’s data protection policy.
Your existing training may be insufficient to cover the GDPR and implement necessary behavioural changes. Your employees will need the training to put into practice your privacy and security policies.
Make cybersecurity a top priority
Nothing poses a bigger risk to your organisation than data breaches. Making cybersecurity a top priority will ensure your organisation takes all necessary steps to establish protocols like assigning a data protection officer (DPO) and carrying out Data Protection Impact Assessments (DPIAs).
Stay up to date
Cybersecurity threats are evolving at a rapid rate. Industry trends come and go. Compliance requirements change over time. You need to be aware of the latest developments in cybersecurity and GDPR law so that you can be prepared for the latest threats, continue to comply with the GDPR and run a sound operation.
Partner with a cybersecurity expert
Bob’s Business offers NCSC certified cybersecurity courses that are designed to change company culture. We can put your organisation on a path to GDPR compliance. Request a free web demonstration to see how Bob’s Business can help keep your organisation secure, or click here to view our success stories.
We’re lucky enough to speak to hundreds of organisations every single month, and often hear the same question asked: ‘Is small business cybersecurity training worth it?’
Whilst cybersecurity attacks might seem like a big business problem, the reality for small organisations is stark.
19 seconds from now a small business in the UK will be hacked. Around 65,000 hacks are attempted on small businesses every day in the UK, with around 4,500 being successful. That’s around a 7% success rate.
So, is small business cybersecurity worth investing in? Of course it is. The way we see it, if your organisation depends on technology to operate, cybersecurity training is as vital to your operation as a shutter is to a newsagent.
Don’t believe us? Join us as we share the stats behind small business cyber attacks, the reasons small businesses are targeted, and how you can protect yourself.
What do the stats say about small business cyber attacks?
Small and medium-sized businesses are primary targets for cyber-attacks. Here are some recent statistics to paint a picture:
40% of small businesses in the UK experience a cyber-attack each year (Statista)
Every 19 seconds a small business is hacked (Hiscox)
Every 14 seconds an SMB is victim to a ransomware attack (Herjavec Group)
45% of employees receive no cybersecurity training (Kaspersky)
71% of customers would take their business elsewhere after a data breach (Allianz)
27% of malware incidents can be attributed to ransomware (Verizon)
60% of SMBs that suffer a cyber-attack go out of business within 6 months (com)
These numbers paint a stark picture: SMBs are primary targets for cybercriminals and the consequences for these businesses can be devastating.
The most shocking stat of all though? A stunning 45% of employees receive no cybersecurity training at all. This has to change. Without cybersecurity training, employees cannot be expected to protect themselves and the company against cyber-attacks.
Why are SMBs targeted?
SMBs are primary targets for cyber-attacks because they tend to have less security than larger enterprises, and in some cases, no security at all. Low security gives cybercriminals an easy payday. It’s easier to go after smaller fish than develop complex attacks to expose the big fish.
Another reason SMBs are targeted is that they often lack the ability to respond to attacks in real-time. SMBs are often slow to react to attacks, if they react at all, which gives hackers more time get in and out with whatever they are trying to steal.
SMBs are also guilty of not investing in cybersecurity training for employees. Over 90% of successful cybersecurity attacks can be traced back to human error. As such, training is important because it equips employees with the knowledge to recognise threats, prevent cyber-related incidents and respond to potential threats.
What impact could an attack have?
Cyber-attacks can result in financial losses from theft of information, financial losses from disruption to doing business, lost customers, costs from cleaning systems, costs from downtime, costs from fines if personal data is lost, damage to your reputation, damage to other companies and damage to your customers.
What is directly at risk?
When we talk about cybersecurity it can be difficult to imagine what is directly at risk and how it could affect your organisation.
Here’s what’s at risk:
Your money
Your money is at risk in several ways. Hackers could empty your bank account, steal cryptocurrency, intercept payments and raise false invoices. They could disrupt your service, interrupt subscriptions, and delete payment data.
Your IT-based services
In 2020, 43% of online security breaches were from attacks on web applications, more than double the results from last year (Verizon). The disruption caused by hackers to IT-based services can destroy a brand and business overnight.
Your data
Data takes many forms. It includes bank information, client lists, customer databases, emails, financial reports, deals you are making, pricing information, patents, manufacturing data, stock and inventory lists and much more.
What can your organisation do?
Invest in cybersecurity training
By taking steps to deploy cybersecurity training in your organisation, you can reduce your risk of breach by up-to 74%. Bob’s Business offers unique, jargon-free NCSC certified cybersecurity training solutions for organisations of all sizes.
Encrypt data
Use encryption on all devices that hold and receive data. This will ensure that sensitive data is useless without decoding.
Secure your computers
Your computers should have anti-malware software and two-factor authentication. You can also restrict access to certain websites and restrict downloads.
Secure your networks
Secure your network with a firewall, proxies, access control, antivirus software and a high-quality VPN. Enable two-factor authentication for admin access.
Monitor your systems
Collect activity logs and monitor your IT systems. You can use performance monitoring solutions and network monitoring software to identify unauthorised or malicious activity.
Implement identity and access management
Identity and access management facilitates a secure and effective remote workforce and ensures devices can only be accessed by authorised people.
With our award-winning range of small business cybersecurity courses, you can start taking cybersecurity seriously in a fun, pragmatic way. Get in touch with us to discover how we can help your organisation become much more secure.
When we think of theft, we tend to think of our belongings like wallets, purses, smartphones, tablets and laptops. But there’s nothing more precious that can be stolen than your identity.
It can’t be snatched out of a bag or swiped from a table whilst we aren’t looking, but careless behaviour can result in your identity falling into the hands of a cybercriminal.
Simple mistakes, such as throwing away a bank statement without shredding it, leaving your laptop unattended in a public place, or sending an email to the wrong address, can expose your personal information.
While those actions might seem innocuous, leaving personal information lying around or accessible to others can hold financial or reputational repercussions. Personal data holds substantial value, making it an important target for cybercriminals.
Once your personal information has been exposed, an identity thief is then able to impersonate you and act on your behalf. For example, signing you up for bank loans, applying for tax refunds, or even emptying your bank account!
What is the Scale of Identity Theft?
Identity theft might seem like an abstract threat, but it’s far from rare. In fact, 2019 saw the highest ever reported cases of identity theft, according to the Cifas National Fraud Database with over 223,000 cases reported, up a remarkable 18% on the previous year.
Identity theft poses a huge threat for individuals and organisations. Don’t believe us? Check out these statistics:
Identity theft is often framed as an issue for the individual. After all, it’s your identity being stolen. However, identity theft is being increasingly utilised to gain access to organisations’ vital data.
By focusing on human vulnerability, attackers can compromise a single email account and use the stolen data to form more advanced attacks against the business.
This can impact the financial position of a business, potentially resulting in large sums of money lost without any possibility of recovery.
A business’ reputation, built upon years of excellent service and trust, can likewise experience substantial damage. This can create a secondary financial loss, where customers leave due to fear and loss of confidence in a business.
Ultimately, the consequences of an attack can become too difficult to deal with, amidst recovery costs exceeding business capabilities, giving a business no option but to shut shop and close trading doors completely.
How to Protect Yourself (and Organisation) from Identity Theft
Identity theft can have serious implications on both your personal and professional life. However, becoming a victim can be relatively easy to avoid.
Take a look at our prevention tips to stop your personal information and data from being stolen:
Invest in a paper cross-shredder to destroy all personal and confidential information before discarding.
Check your credit card and bank statements regularly and look out for any unfamiliar activity.
Be wary of telephone calls, emails or letters that ask you to give or update security or personal information. Check the identity of removal staff and any unfamiliar faces.
Never share your pins, passwords or personal identification.
Install firewalls and protections on your electronic devices, in particular, your computer, phone and laptop.
Be careful when using public WiFi networks. Fraudsters can hack into a network, putting your personal data and information at risk.
Be conscious of the usernames you choose when online as they can give away your identity to those researching you, for example, ‘Firstname.Lastname84’.
Don’t be afraid to question someone asking for a copy of your driving license, passport or another form of primary identification.
What to Do If Your Identity Is Stolen
There is no worse feeling than the knowledge that a complete stranger has gained access to your personal information or belongings.
It’s a situation nobody wants to face, so here’s our quick 7 step guide to follow if your identity is stolen.
Act quickly. As soon as you become aware of a case of Identity fraud make sure you act upon it immediately. Contact Action Fraud on 0300 123 2040 or at the Action Fraud website.
Report any lost or stolen documents to the organisation that issued them. This includes items such as your passport, driving licence and credit card.
Inform your bank, building society and credit card company. Get in touch and let them know that you have become victim to a fraud attack and make them aware of any unusual transactions on your statement.
Contact the police and inform them about the theft/loss of your personal information, and any suspicious applications and transitions that you have encountered. Make sure you ask for a crime reference number.
Contact the Post office. Your identity thief may have changed your home address, so contact the post office to prevent mail being sent to the wrong address.
Request copies of your credit file and check for any suspicious credit requests.
Contact CIFAS (the UK’s Fraud Prevention Service) to apply for protective registration.
Feel like you have more passwords than you’ve had hot dinners? You’re not alone. With studies showing that the average person has 100 passwords, we’re all managing an ever-growing arsenal of passwords.
Choosing the perfect password, however, can feel like an arduous task, and often leads us into creating the; quickest, easiest, most memorable passwords we can.
The problem? They’re rarely the most secure ones.
The result is a pandemic of poor password choices that fatally weaken our defence against cybercriminals. They’re traps which can compromise your data, finances and even your organisation’s cybersecurity.
With the Coronavirus pandemic and the rise in home working in 2020, cybercriminals and the software they utilise has not only grown more sophisticated, but more effective. As such, there’s never been a better time to brush up on how to write a secure password.
So, join us below as we share with you 2020’s most common passwords and explain why you shouldn’t reuse your password alongside much, much more.
What were the most common passwords of 2020?
The top five most commonly used passwords in 2020 were:
123456
123456789
picture1
password
12345678
Just as in 2019, what unites each of these passwords is the very same thing: simplicity.
The appeal of simplistic passwords is clear. They don’t take long to think up; they’re easy to remember and – most of all – you get to spend less time dreaming up passwords and more time doing something fun, like watching your new Netflix subscription.
Unfortunately, simple passwords come with a simple downside; they’re just as simple to crack. In fact, password cracking software can break through 4 of 5 of these passwords in less than a second.
What does the password list tell us?
Several themes recur time and time again in the NordPass password list.
As always, numerical patterns are a prevalent theme, with repeated digit passwords like ‘1111111’, ‘555555’ or ‘999999’ appearing alongside ‘12345’ and ‘123654’ in the top 100.
In fact, out of the top twenty passwords, numerical patterns appear eleven times, highlighting just how common they are.
Another theme that appears time and time again in the list is football teams and fictional characters. Forbes research found that football teams ‘liverpool’, ‘chelsea’, ‘arsenal’, ‘manutd’, and ‘everton’ were the five most commonly used. Meanwhile, ‘superman’, ‘naruto’, ‘tigger’, ‘pokemon’ and ‘batman’ were the most commonly used fictional characters.
Other popular common passwords are names and musicians, which appear throughout the top 100.
So, what do all these patterns tell us?
When building passwords, most of us fall back into behaviours which favour choosing something simple, easy to remember and in some cases, close to our hearts. Whether it’s our football club, favourite band, an easy to recall set of numbers or even our name – many of us are choosing passwords that don’t require us to memorise anything complicated.
All of which brings us to:
How to create a stronger password
There are countless ways to create good, secure passwords, but many popular methods ignore the fact that though ‘C7sf3LU!6w’ is a strong password, it’s virtually impossible to remember. Especially when you compare it to something like ‘leedsutd’, or ‘ashley’.
That’s why at Bob’s Business, we recommend the ‘three words’ method of password creation. Pick three random, unconnected words and put them together. Passwords like ‘frogcapitalglass’ are easy to remember and, crucially, unique.
For an even more secure password, combine those three words with capital letters and numbers, like “Frog6Capital0glass” want to check how secure your new password is? Try How Secure is my Password and discover just how quickly cybercriminals could crack your password.
How often should you change your password?
When it comes to how often you should change your password, you might have heard some conflicting reports. Some schools of thought suggest every month, others once every quarter.
The problem with a mandatory password change is that they tend to encourage rushed superficial changes – an extra capitalised letter here or a few new numbers there. For hackers, these slight changes are easy to guess.
For that reason, it’s recommended that you create unique passwords for each service you use.
Of course, if any service you use is breached, you should immediately change your password to stop criminals from accessing your private information. Finding out whether an account you use has been exposed is simple, just use a website like Have I Been Pwned?
How to remember your passwords
Strong passwords are crucial, but unique passwords are perhaps the most critical element of password security. After all, should your login credentials for one service become exposed, unique passwords ensure that your other accounts remain secure.
That can mean dozens – if not hundreds – of unique passwords required. So, how exactly do you remember all those passwords?
You don’t.
Instead, we recommend you make use of a password manager.
Password managers come in many shapes and sizes, from software managers like Passbolt to password managers that are built directly into your browser. In fact, there’s a good chance you’re already using a password manager in your browser.
So, instead of trying to recall your passwords, make use of a password manager and never worry about forgotten passwords again.
Bob’s top password tips
Creating a secure and memorable password doesn’t need to be complicated. Just follow our top password tips below, and you’ll never need to worry about your password security again.
Choose three random, memorable words to make your password. Try to choose words that aren’t related to your life, hobbies or passions, so that no automated hacking system or individual can figure out your password.
Create unique different passwords for every website or service you use. The temptation to use the same password everywhere is strong, but doing so means that a single breach on any service could compromise all of your accounts.
Check to see if any of your accounts have been breached. By checking Have I Been Pwned? you can see whether any of your details have been breached and released. It should go without saying, these passwords should be changed as soon as possible.
Make use of a password manager. Password managers ensure that no matter how unique your passwords get, you never forget about them. Most modern web browsers have password managers built-in, but there are free solutions available also, which are compatible with most devices.
How can organisations educate their employees?
Password security is no joke, especially when insecure passwords can create unnecessary risk for businesses.
At Bob’s Business, we understand that your employees are at the core of your organisational cybersecurity health. They’re the front line of your battle against cybercrime and, without proper training, can be manipulated to grant access to confidential and valuable information.
Our online cybersecurity courses cover everything from making the perfect password to GDPR compliance, phishing detection and data protection. They’re designed to help your team understand cybercrime threats and empower them to protect your organisation further.