Author name: admin

Blog

What is MFA? Why is it important?

What is MFA? Why is it important? What is MFA? MFA is an acronym for Multi-Factor Authentication. It is the term people in the IT world use to describe the process of a computer checking your identity in more than one way before it lets you into your account. The terms are however important to understand, as they help you to better understand how MFA works and why it’s important. A deeper look at what MFA means You might be sitting there thinking that you know exactly what ‘multi-factor’ means. You could well be right, so let’s skip defining what ‘multi’ means. Just to be thorough, and because we are going to talk about factors in a bit more detail, let’s take a look at what ‘factor’ means in IT semantics. A ‘factor’, in the context of authentication, is a way of defining your identity. The password you type into an account to log-in is one factor through which a computer confirms you are you. It is the most common factor used. Confirmation of the password grants you access into your account. The computer has authenticated your identity through the combination of your username and password matching. This is the ‘authentication’ process. With MFA, you use more than one factor to confirm your identity alongside your username. MFA uses a combination of three factors to confirm your identity, all of which are interlinked and about you, so you will know them. Three factors By using all or a combination of options from these three different key factors, MFA provides a more robust protection system for your data. 1: Know This is the password, pin, security question or other form of identification that you are most likely already familiar with and using to access your online accounts. If you want to manage this and save some brain space, we recommend using a password manager to keep your passwords safe. 2: Have This is something that is in your possession and that you directly link to your online account. It will most likely be the device that you log-in on or something that you are given by a business to use as part of a multi-factor authentication process. 3: Are This is you, something that physically defines who you are. This includes a fingerprint, retinal scan or facial recognition, all of which are intrinsic to you. You don’t have anything to remember and many of us are already using this form of authentication every day as part of our internal phone security. That sounds unnecessary You may now be wondering why on earth you would put yourself through the stress of trying to remember more. For every account you have using more than just a password to log-in may feel daunting. The prospect of taking more time to log-in and taking-up more brain space to remember extra steps which you worry you might forget is perhaps the reason you don’t think MFA is the best-fit for your business. If you’re thinking it isn’t for you right now, you need to read on. It is for you. MFA is necessary. It’s also really easy to do. 3 Statistics about the impact MFA 1: MFA has been found to block 99.9% of automated cyber-attacks in 2023 according to statistics. 2: Weak or stolen passwords account for 80% of cyber breaches. MFA adds layers of security to your password so one weak or stolen password will not give access to accounts. 3: 67% of  customers in the UK believe that companies who use MFA care about the protection of personal data according to recent statistics. Why is MFA important? MFA plays an important role in the fight against cyber-crime for both individuals and businesses. It is an easy step you can take to protect your accounts from being easily hacked by cyber-criminals. If they have your username, which let’s be honest is often just your name or your email address, they only need to guess your password to gain access. Once in they have access to your personal data. Do you have faith that your passwords are strong enough to defend against a hacker? If the answer is maybe, read on. Did you know that cyber security experts across the world have found that in every second there are an average of 530 signs of a potential cyber-attack? That’s a whopping 46 million indicators of potential cyber-attacks in just one day. Protecting yourself and your business from the ticking clock with MFA is usually free. It is normally something you can turn-on in the settings of your online accounts. No extra cost to you or your business. It’s just a choice you need to make. Then an action you need to implement. Take a look at the following statistics which demonstrate an interesting parallel between businesses and cyber-attacks. 2 statistics you should not ignore: 1: Over 68% of people surveyed did not use MFA where it is available. 2: Half of business surveyed by the UK government in 2024 have experienced some form of cyber-attack in the last year. It is interesting to look at these statistics and consider what impact there may be on the second statistic of people began using MFA as part of their cyber security policy. How does MFA work? To describe how MFA works and why you should use it, let’s use an analogy. Your password is the lock you use on your door to gain entry to your house – the place you keep all the information that belongs to you and that you are responsible for looking after. Using one password is like having one lock. If your password isn’t very strong, it’s like using a padlock on the front door to your house and hoping you won’t get robbed. The weaker the password; the flimsier the padlock. If you’re using the word password for your password, you’ve forgot the lock entirely. The chances of a thief gaining access to your home and robbing you is high.

Blog

What is MFA? Why is it important?

What is MFA? Why is it important? What is MFA? MFA is an acronym for Multi-Factor Authentication. It is the term people in the IT world use to describe the process of a computer checking your identity in more than one way before it lets you into your account. The terms are however important to understand, as they help you to better understand how MFA works and why it’s important. A deeper look at what MFA means You might be sitting there thinking that you know exactly what ‘multi-factor’ means. You could well be right, so let’s skip defining what ‘multi’ means. Just to be thorough, and because we are going to talk about factors in a bit more detail, let’s take a look at what ‘factor’ means in IT semantics. A ‘factor’, in the context of authentication, is a way of defining your identity. The password you type into an account to log-in is one factor through which a computer confirms you are you. It is the most common factor used. Confirmation of the password grants you access into your account. The computer has authenticated your identity through the combination of your username and password matching. This is the ‘authentication’ process. With MFA, you use more than one factor to confirm your identity alongside your username. MFA uses a combination of three factors to confirm your identity, all of which are interlinked and about you, so you will know them. Three factors By using all or a combination of options from these three different key factors, MFA provides a more robust protection system for your data. 1: Know This is the password, pin, security question or other form of identification that you are most likely already familiar with and using to access your online accounts. If you want to manage this and save some brain space, we recommend using a password manager to keep your passwords safe. 2: Have This is something that is in your possession and that you directly link to your online account. It will most likely be the device that you log-in on or something that you are given by a business to use as part of a multi-factor authentication process. 3: Are This is you, something that physically defines who you are. This includes a fingerprint, retinal scan or facial recognition, all of which are intrinsic to you. You don’t have anything to remember and many of us are already using this form of authentication every day as part of our internal phone security. That sounds unnecessary You may now be wondering why on earth you would put yourself through the stress of trying to remember more. For every account you have using more than just a password to log-in may feel daunting. The prospect of taking more time to log-in and taking-up more brain space to remember extra steps which you worry you might forget is perhaps the reason you don’t think MFA is the best-fit for your business. If you’re thinking it isn’t for you right now, you need to read on. It is for you. MFA is necessary. It’s also really easy to do. 3 Statistics about the impact MFA 1: MFA has been found to block 99.9% of automated cyber-attacks in 2023 according to statistics. 2: Weak or stolen passwords account for 80% of cyber breaches. MFA adds layers of security to your password so one weak or stolen password will not give access to accounts. 3: 67% of  customers in the UK believe that companies who use MFA care about the protection of personal data according to recent statistics. Why is MFA important? MFA plays an important role in the fight against cyber-crime for both individuals and businesses. It is an easy step you can take to protect your accounts from being easily hacked by cyber-criminals. If they have your username, which let’s be honest is often just your name or your email address, they only need to guess your password to gain access. Once in they have access to your personal data. Do you have faith that your passwords are strong enough to defend against a hacker? If the answer is maybe, read on. Did you know that cyber security experts across the world have found that in every second there are an average of 530 signs of a potential cyber-attack? That’s a whopping 46 million indicators of potential cyber-attacks in just one day. Protecting yourself and your business from the ticking clock with MFA is usually free. It is normally something you can turn-on in the settings of your online accounts. No extra cost to you or your business. It’s just a choice you need to make. Then an action you need to implement. Take a look at the following statistics which demonstrate an interesting parallel between businesses and cyber-attacks. 2 statistics you should not ignore: 1: Over 68% of people surveyed did not use MFA where it is available. 2: Half of business surveyed by the UK government in 2024 have experienced some form of cyber-attack in the last year. It is interesting to look at these statistics and consider what impact there may be on the second statistic of people began using MFA as part of their cyber security policy. How does MFA work? To describe how MFA works and why you should use it, let’s use an analogy. Your password is the lock you use on your door to gain entry to your house – the place you keep all the information that belongs to you and that you are responsible for looking after. Using one password is like having one lock. If your password isn’t very strong, it’s like using a padlock on the front door to your house and hoping you won’t get robbed. The weaker the password; the flimsier the padlock. If you’re using the word password for your password, you’ve forgot the lock entirely. The chances of a thief gaining access to your home and robbing you is high.

Blog

Social engineering: 11 tips to avoid the risk

Social Engineering: 11 tips to avoid the risk By Helen C Imagine your business has had a cyber leak and you have lost the data of nearly 70,000 customers exposing them to the risk of social engineering. The cause of this is most likely human error and the hole in your security system has been ominously lurking, unchecked, in cyber space waiting for the moment when an opportunistic cyber criminal will attack. Case Study: Welsh Rugby Union That is exactly what happened to the Welsh Rugby Union (WRU) this week, who allegedly had a hole in their security system which was exposed by cyber criminals. The hole was a publicly accessible Amazon Web Services (AWS) Simple Storage Service (S3) bucket. This is by default locked and private, but it can also be made publicly accessible without much prompting from the source that this change was being made and the potential impact this change could have. Misconfiguring the settings on an account, often a human error which is the result of an absent-minded click or uncertainty in what to click, leads to the creation of holes in cyber security which can then be exploited. Data suggests that 95% of all data breaches result from human error, but investigations are still currently underway to investigate what the cause was for this hole in the WRU’s security. Reports suggested that the exposed information held 1419 text files holding the personal details of 69,317 of WRU’s members. These are the fans who have subscribed to the WRU, who support and maintain the Union by purchasing memberships which provide perks such as exclusive content and priority tickets for matches. Inconvenient timing In a discussion two weeks ago with BBC Wales Scrum V discussing the state of the sport this season, former Wales centre Tom Shanklin, stated: “We have to be careful at the moment otherwise we are going to have fans turning away from watching rugby and they are going to be finding another sport.” With a string of defeats under their belt, the timing of the WRU cyber attack could not be worse. That’s the problem with a cyber attack though, you never know when it will happen and the impact it can have on a business can be catastrophic. What can happen to a business? The loss of sensitive information to cyber criminals can impact a business in the following ways: Loss of sales Loss of customer faith Loss of customers Long and short-term damage to reputation Negative feedback across social media and media channels which can be difficult to manage ICO fines Business closure Although business closure is an extreme response, it is possible if fines are imposed, and consumers loose compete faith in the business. The average cost of a cyber-attack in the last year to a small business is estimated to be £1,100 and £4,960 to a medium or large business. Imagine having to release a statement to your customers to reassure them that their data is safe now to mitigate the damage of a cyber-attack. The WRU statement said: “No other vulnerabilities or suspicious activities have been found in WRU systems after a thorough review of all systems and processes.” As a business, it is better to follow procedures and keep data secure through regular reviews and by having good cyber security protocols and tools in place to protect the confidential data you hold. The importance of good cyber hygiene cannot be emphasised enough. Offering reassurance to customers that their data is now safe is positive, but for the customers who have had their data stolen they could now be facing cyber security threats of their own. Although there are many different types of cyber-attack which could occur following a data breach, in this situation members of the WRU are most likely to be facing the threat of social engineering. What is social engineering? Social engineering is a manipulative tactic used by cyber-criminals to exploit people in a non-technical way. Attackers often exploit people into performing tasks, such as transferring money from their bank account, by conning them into believing they are talking to someone they can trust such as a bank manager or even friend. People are duped into breaking their own security practices during this kind of attack which plays on psychology and human emotion. The types of data leaked in the WRU attack included email addresses, phone numbers, names and dates of birth; personal information which could be used by cyber criminals to convince unsuspecting victims that they are legitimate. Effectively modern-day con artists, attackers armed with confidential personal information can successfully dupe people into opening emails containing malware, con them into sending money, or even get them to divulge confidential business information. The key danger with social engineering is that it enables an attacker to gain legitimate and authorised access to confidential information by employing tactics which play on human emotion. To click or not to click; would these emails fool you? Social engineering attacks are designed to be compelling and draw you in. Let’s look at a few examples of what may be used to emotionally grab your attention and call you to action. An email from the boss You could receive an email from your boss asking for information which you know should not be shared and seems uncharacteristic but looks legitimate. You may be asked to not follow protocol and chances are if you think it is from the boss you will feel emotionally compelled to do what is asked in order to retain job security. An urgent call for help An old friend needs money for a treatment which is not provided on the NHS, you were once close but have lost touch and you did know this person. Out of kindness you act and provide bank details to an account you are directed to, but in reality this is not a friend, but a criminal. A trusted business who email you often You often interact with this business and

a hook phishing
Blog

Phishing: a dive into the world of cyber-attacks

Phishing: a dive into the world of cyber-attacks By Helen C & David Bloxberg Whether you are a person fishing for the animal as a hobby or a criminal phishing to steal data from your next victim, these two very different activities share one common tool – a hook. A literal hook catches the fish, but an emotional hook is usually what entices a person to respond to a phishing cyber-attack. Here, we take a detailed look into phishing to provide your business with the information it needs to defend itself. Introduction Phishing is a cyber-crime where individuals are approached through email, websites, phone calls, or text messages by hackers claiming to represent legitimate organizations. The aim is to deceive individuals into divulging private information, including personally identifiable information (PII), protected health information (PHI), banking and credit card details, passwords, and other confidential data. The term itself, a homophone of “fishing,” hinting at the tactic of baiting individuals into exposing their private data, mirroring the act of waiting for a fish to bite when bait is placed on a hook. This deceptive practice is a significant threat in the digital world, as it is a type of cyber-crime which uses the vast reach of the internet to exploit human vulnerabilities across the world. History Phishing has been around since the early 1990s, coinciding with the rise of the internet. Initially, attackers targeted AOL users in a famous phishing attack from 1995, tricking them into divulging their login credentials. These early attempts were relatively straightforward, often involving direct messages requesting users to verify their accounts or confirm their passwords. As phishing techniques advanced, the sophistication of these attacks significantly increased. A notable example of this evolution is the 2020 Colonial Pipeline attack. Here, attackers used a compromised password to access the network, leading to massive disruptions in fuel supply across the Eastern United States. This incident illustrates the shift from simple deceptive messages to complex, multi-layered cyberattacks that exploit both technological vulnerabilities and human error. This progression from the primitive phishing scams of the 1990s to today’s highly elaborate schemes highlights the adaptability and persistence of cyber criminals in exploiting new technologies and human psychology. In today’s digital age, understanding phishing is crucial for two key reasons. Firstly, the internet has become part of nearly every aspect of day-today life. The inescapable nature of the internet combined with the proliferation of digital transactions make individuals and organizations perpetually vulnerable to these attacks. Secondly, a successful phishing attack’s financial and reputational damage to a business can be devastating. Understanding How Phishing Works Phishing is a digital deception technique cyber criminals use to fool people into divulging sensitive information. It’s effective because the lies are carefully crafted believable requests or alerts that appear to come from trusted sources. Personal data can be used for identity theft, unauthorized transactions, or even sold on the dark web. For organizations, the stakes are equally high, with potential losses running into millions and severe damage to customer trust. Therefore, awareness and education on the nature of phishing attacks, their indicators, and prevention strategies are vital components in safeguarding both personal and organisational assets in the digital landscape. Who Are the Targets? Initially, phishing scams cast a wide net, targeting the general internet population. But in England and Wales, data provided by the National Office of Statistics shows that those between the ages of 25 to 44 are most likely to be affected. However, as techniques have evolved, so has the specificity of targeting. Today, anyone can be a target—from individual internet users to employees at any business. Specific campaigns, known as spear phishing, target high-value individuals or employees with access to sensitive corporate data. Larger-scale campaigns may aim to collect data from as many individuals as possible or install malware for various malicious purposes. The New Future of Work Report published by Microsoft stated that security professionals had found a 62% rise in phishing campaigns over any other type of attack. Why Are Attacks Successful? Phishing scams leverage social engineering to exploit human psychology, in other words they appeal to our human nature to get a response. They often create a sense of urgency, fear, or curiosity to prompt immediate action. Official logos, familiar layouts, and language mimicking legitimate organizations add to their believability. This psychological manipulation makes it challenging for individuals to distinguish phishing attempts from genuine communications, leading to high success rates for attackers. For cybercriminals, phishing is a low-risk and high-reward activity. Compared to other cyber-crimes, it requires minimal investment but has the potential for significant financial gain or access to valuable information. Phishing can also serve as a stepping stone for more complex attacks, including those on corporate networks or government agencies, by enabling the installation of malicious software or the theft of credentials. The Evolution of Phishing with AI The integration of Artificial Intelligence (AI) into phishing schemes marks a significant evolution in cybercrime. AI algorithms can automate the creation of phishing emails, phone calls or messages, making them more personalized and more challenging to detect. These algorithms sift through extensive data sets to pinpoint the most efficient phishing tactics to provoke a response. Furthermore, AI can help create more convincing fake websites and mimic human behaviour in chatbots or emails, increasing the sophistication of attacks. This evolution underscores the need for advanced detection systems and heightened awareness among businesses and individuals. Understanding the dynamics of phishing scams is crucial in developing effective countermeasures. As these scams become more sophisticated with AI, the importance of staying informed and vigilant cannot be overstated. Different Types of Phishing Attack Email Phishing Email phishing is the quintessential model of phishing attacks, notorious for its wide net and simplicity of execution. This method involves sending out large quantities of fraudulent emails, targeting a broad audience without discrimination. The success of email phishing hinges on a numbers game; even a tiny fraction of recipients succumbing to the scam can lead to substantial data breaches or financial benefits for the attackers. Example of a phishing email   Email

Ransomware on computer
Blog

What is a ransomware attack?

What is a Ransomware Attack? By David Bloxberg and Helen C. There are many types of cyber-attack, but ransomware attacks make-up 10% of all security breaches in 2024.  A ransomware attack can be devastating to a business with the consequences reverberating through businesses for months, even years. In 2023, organisations around the world detected a staggering 317.59 million ransomware attack attempts and the UK had the second highest number of targeted ransomware attacks at over 71 million. With figures like that, it is an important topic to understand and discuss. What is a ransomware attack? Ransomware is a type of malware that is used by cyber criminals which prevents the rightful user from being able to access their own data. Kicking the user out by encrypting data, the criminal holds the rightful owner of the data to ransom  to gain access to their data again. Often, the ransom comes with a deadline and the sums of money asked for can be crippling to individuals and businesses alike. This type of attack poses a daunting prospect, and is a threat that should be taken seriously.  Is this a cyber-threat my business should worry about? Ransomware, now exacerbated by the advancement of technology using Artificial Intelligence, (AI), stands as a critical threat in the modern digital environment. It impacts individuals, corporations, and governmental bodies globally. This sophisticated malware is engineered to breach computer networks and encrypt files, databases, and even entire systems by denying access to legitimate users. The involvement of AI in ransomware attacks serves to escalate the complexity and efficiency of recovering from this type of breach. How serious is a ransomware attack? Some ransomware has become increasingly sophisticated, making them increasingly difficult to prevent and counteract. Using a diverse range of infective malwares including phishing emails and malicious attachments and through the exploitation of security vulnerabilities, ransomware attacks are a brutal breach of your cyber security. The aftermath of a ransomware attack can be catastrophic, leading to critical data breach, substantial financial losses, and severe reputational damage. As ransomware evolves, it becomes imperative for organizations and individuals to prioritize preventive measures, such as regular data backups, software updates, and comprehensive security training to mitigate the risks of these harmful cyberattacks. Being aware of the process of a ransomware attack is crucial to understanding why prevention is the best option for your business. Stages of a Ransomware Attack: From Infiltration to Recovery Understanding the various stages of a ransomware attack is crucial for prevention and effective response. 1: Initial Infiltration Stage: Before encryption, the ransomware must first access the system. This often occurs through phishing emails, by exploiting software vulnerabilities, or malicious downloads. Understanding the initial infiltration stage is crucial as this is the point where you can still stop the attack. 2: Installation Stage: After infiltration, the ransomware installs itself on the system. During this phase, it may also attempt to spread to other connected systems or networks, increasing its impact. 3: Data Harvesting Stage: Some advanced ransomware variants may extract sensitive data from the infected system before encrypting it. This stage adds a layer of complexity as attackers can threaten data leaks and encryption. 4: Lockdown Stage: Post-encryption, some ransomware variants display a ransom note or lock the user’s screen, making it evident that an attack has occurred and providing instructions for payment. 5: Communication Stage: If the victim engages, this stage involves communication between the attacker and victim, usually anonymously, about payment and decryption. This stage is emotionally draining for the victim and leads to a serious dilemma – pay and communicate or don’t. 6: Disclaimer and decision stage: Choosing to pay the ransom offers no data recovery guarantee. In the UK, the National Cyber Security Centre (NCSC) note that law enforcement services do not endorse this choice as it can lead to further attacks, means you are funding cyber-crime and data recovery is not guaranteed. It might encourage further criminal activities, and refusing to pay can lead to permanent data loss or public exposure of sensitive information. 7: Decryption Stage (Conditional): If the ransom is paid and the attacker is willing to provide a decryption key, this stage involves decrypting the locked files. This task alone can be technically challenging, and your computer is likely to still be infected with the malware. 8: Post-Attack Analysis and Recovery Stage: This stage consists of assessing the damage, removing the ransomware, restoring data from backups if available, and implementing measures to prevent future attacks. This stage occurs whether you choose to pay the ransom or not. 9: Reporting and Legal Follow-Up Stage: In cases where people are put at high risk there is a regulatory requirement to report the attack to the Information Commissioners Office (ICO).  The NCSC should also be informed as they will be able to provide support and incident response to help mitigate the impacts, while also learning cyber security lessons to help other businesses in the future. The Financial Impact of Ransomware The financial repercussions of ransomware in 2023 were profound and widespread, significantly impacting businesses and economies. With 59% of businesses affected by ransomware globally and the cost of a ransomware attack increasing by 500%  from $400,000 to $2 million this year alone, a ransomware attack can financially cripple a business. This substantial increase in incidents signifies a growing boldness and sophistication amongst the cybercriminals orchestrating these attacks. Cyber security has never been so important. The need for adequate ransomware protection is critical for all businesses, not just large organizations. Ransomware poses a significant threat to small and medium-sized enterprises (SMEs). Specific industries have been disproportionately affected by ransomware, with the healthcare sector being a notable example. This critical industry has suffered losses exceeding $7.8 billion due to operational downtime caused by ransomware attacks. Such figures underscore the sector’s vulnerability and the severe consequences that ransomware can have on essential services and patient care. Case Study: The impact of ransomware on the NHS In May 2017, WannaCry ransomware, a type of ransomware known as cryptoworm, infected computers running the Microsoft Windows Operating System. Spreading autonomously between computers, encrypting data and demanding Bitcoin ransoms, this attack

hacking laptop contents
Blog

Easy to hack passwords banned in the UK

Easy to hack passwords banned in the UK by Helen C.                                                                                                                                                                                                                               May 2024 Passwords are the frontline of defence for most people when protecting their data online and there is now a new law in the UK which bans people from having certain easy to hack passwords. New laws came into effect this week in a significant step to protect consumers from the soaring number of cyber-attacks that are affecting both businesses and individuals. It is now mandated that internet connected smart devices must meet minimum-security requirements which are set out in the new laws. What do passwords do?   Passwords can be thought of as house keys. The password being the key and the information being our house. The key lets you in and is unique to your house – it won’t let you in next door’s house, just like a password does. If you give your key to someone or you lose it, then your house is not secure and other people can gain access. Passwords are the gatekeepers to our information, and it is vital that they are strong. All a hacker needs to get in is your account name and a password. Now your account name is usually an email address or your name, so it is vital that your password is secure enough to protect your data. When a data breach happens in a business, often what’s stolen is a huge list of email addresses, which means that cyber criminals are one step closer to your information and that is one of the reasons the government have changed the legislation. The 5 most common passwords used by businesses in the UK   NordPass have been keeping track of the password habits of business executives across several levels of management, revealing that the top 5 passwords are: 1: 123456 2: password 3: 12345 4: 123456789 5: qwerty Alarmingly, these passwords can often take hackers less than a minute to crack. Is your password on the list? The need for this legislation is clear, and the government has pledged £2.6 billion as part of the wider National Cyber Strategy, which aims to protect and promote UK national interests in cyberspace and online. In today’s world where Smart devices are owned by nearly 99% of UK adults and the average UK home has 9 connected smart devices this legislation is a crucial step forward in cyber security. Speaking about the impact of the new law, Minister for Cyber, Viscount Camrose said: “From today, consumers will have greater peace of mind that their smart devices are protected from cyber criminals, as we introduce world first laws that will make sure their personal privacy, data and finances are safe.” A world-first   The UK is the first country in the world to these laws which mean that all internet enabled devices, including phones, games consoles and even fridges, must meet legally required standards to protect consumers from hacking and cyber-attacks. Data and Digital Infrastructure Minister Julia Lopez said: “Our pledge to establish the UK as the global standard for online safety takes a big step forward with these regulations, moving us closer to our goal of a digitally secure future.” In a recent Which? investigation they found that a home filled with smart devices could be facing over 12,000 hacking attacks in just one week. They also discovered that across just five devices in 1 week, 2,684 attempts were made to guess weak and default passwords. This means that the average UK home faces 4,697 password hacking attempts to guess weak and default passwords a week. That is 20,409 attempts in a year. Strong passwords should form an integral part of any cyber security strategy and the changes made on Monday not only recognise this but have brought into law the need for strong passwords. Hopefully this will highlight the importance of strong passwords across all devices, whether mandated in law or not. It is essential that strong passwords are always used to keep your data secure. What makes a strong password?   Lots is written on this and there is a lot of guidance floating around the web about what makes a strong password, so let’s keep it simple: Your password should be unguessable and random, with no identifiable information used that could be found easily on the web or guessed after a quick glance at a social media page. We recommend a minimum of 20 characters, using upper and lower case letters, symbols and numbers, but the longer and more random the more secure it will be. Aim to have something that does not read like standard English and that you wouldn’t find in a dictionary. Good password example: P9*joo&Ghj^rdf£40slE3JH Bad password example: Panda Always create a new password for each site you use. Lots of random unique passwords, like the example of a good password above, are essential. Never re-use the same password across multiple sites. Change your password frequently, more frequently when you are using a site which contains more sensitive or personal data, such as a bank. Never keep your password on a piece of paper or somewhere where it can be easily accessed by others and don’t share it. These steps will help you to create a strong password, but we recommend a multi-faceted approach to using passwords to keep your data safe and

Fundamentals of Security
Blog

Fundamentals of Security

Fundamentals of Security   This article is about the Fundamentals of Security for SME’s.  Small Business Owners often downplay or ignore  threats to their business with a common belief they would not be targeted and too small.  In 2023 38% of Small Business suffered a Cyber Attack of some kind. Cyber Guidance for SME We don’t want to scare you into action.  But most of the steps to help protection your business are simple, some of them free and mostly inexpensive.  Below are a few common steps you can take to protection your business from threats.  This isn’t exhaustive, you don’t necessarily need all of the steps, but if you take some you will be going in the right direction. So what are these Fundamentals of Security?   So before we dip into the specifics lets talk about a couple of overriding principles worth bearing in mind. Security is created through a number of layered solutions.  It’s not just about (for example) having Antivirus (AV). AV is important but it needs to be thought of as a component and one of a number of solutions Policy based application of the tools you use to.  There is no point having AV if you are going to allow users to disable or uninstall it.  A policy based solution will ensure these changes cannot take place OR that you are at the very least notified to take action. Access Control Passwords, Single Sign On (SSO), Password Managers & Multi-Factor Authentication (MFA) and Bio-metrics. As a simple place to start you should always have 2 of these as a minimum.  Password + MFA or Bio metrics + MFA are good examples.  Depending on your environment, the applications you use, how they are accessed, by whom and from where might lend weight to some of the other options.  At Cirrus we use ALL of these for different systems, different reasons and situations.   We mandate strong passwords + MFA, these are selections we insist our team subscribe to.  In addition to this we use SSO in all situations where an application allows us. SSO for Starters & Leavers The attached article from Gartner Advantages vs Disadvantages talks about client experience in deploying SSO.  Like everything else on the topic, SSO is not a silver bullet but a useful and practical approach to Access and Security.  SSO also simplifies administration for starters & leavers as you will have less to setup and less to remove.  The fact users have to remember, manage and set fewer passwords also improves the experience and removes the more hard to ignore prompts for passwords. Password Managers In situations where passwords are less avoidable, password managers provide a great way to store and generate SECURE passwords.  Password Managers coupled with MFA provide really robust access and decrease the need to have regular password changes.  If the password for a system is secure and the password it self is 20 Characters, has upper and lower case letters, contains numbers and special characters breaching the password itself requires a very different act Disk Encryption If you are running Windows 10 or 11 in your business environment Disk Encryption is built and FREE to use.  Depending on settings it may need to be enabled but it’s a no-brainier of a step to take.  If you are running MacOS, all versions support Encryption too.  Disk Encryption protects in the event of the equipment being stolen Patch Management Most high profile data breaches of the last few years;  BA, NHS & Talk Talk are largely attributed to exploiting a vulnerability that had been previously addressed but not deployed to devices .  Patching applications, Operating Systems & Hardware all need to form part your defense strategy.  A policy based solution can ensure updates happen outside of core working hours and  do not interrupt productivity. AntiVirus An Antivirus solution should certainly be part of your strategy.  The subject of Antivirus is a commonly understood aspect of security so we won’t dig too deep into the merits of this.   Having a solution that is policy based, that does not allow users to disable it and , importantly, report/ alert when malicious content has been detected should be a must and be something you look for.  All vendors have this management capability Mail Scanning Mail is a huge part of any business and as a result e-mail is the number one vehicle for transmitting threats and attempting to exploit your organisation. ViPRE Security Report highlights the volume and scale of this issue with criminals evolving fast in terms of the volume of messages but also the types of threats.  Mail threats often appear genuine or familiar.  Increasingly they contains links to external sites, attach documents or ask you to call a number.   Considerations Our Fundamentals of Security are not the only aspects for consideration.  Backing  up your data is also important as are network policies and having a robust firewall.  Clients also look toward Cyber Essentials certifications or full Information Security as part of their strategies to bolster security but also raise awareness with employees.  All of these are valid and as as a minimum should be discussed Conclusion It’s a big topic.  We understand.  But broken into a number of workable action items everyone can take some basic steps to protect their business from on-line threats.  Cyber criminals are not targeting your SME, they are targeting everyone’s SME. For more information contact us : hello@thinkcirrus.co.uk T: 03303 130966 #cybersecurity #manageditservices #cheshirebusiness

Fundamentals of Security
Blog

Fundamentals of Security

Fundamentals of Security   This article is about the Fundamentals of Security for SME’s.  Small Business Owners often downplay or ignore  threats to their business with a common belief they would not be targeted and too small.  In 2023 38% of Small Business suffered a Cyber Attack of some kind. Cyber Guidance for SME We don’t want to scare you into action.  But most of the steps to help protection your business are simple, some of them free and mostly inexpensive.  Below are a few common steps you can take to protection your business from threats.  This isn’t exhaustive, you don’t necessarily need all of the steps, but if you take some you will be going in the right direction. So what are these Fundamentals of Security?   So before we dip into the specifics lets talk about a couple of overriding principles worth bearing in mind. Security is created through a number of layered solutions.  It’s not just about (for example) having Antivirus (AV). AV is important but it needs to be thought of as a component and one of a number of solutions Policy based application of the tools you use to.  There is no point having AV if you are going to allow users to disable or uninstall it.  A policy based solution will ensure these changes cannot take place OR that you are at the very least notified to take action. Access Control Passwords, Single Sign On (SSO), Password Managers & Multi-Factor Authentication (MFA) and Bio-metrics. As a simple place to start you should always have 2 of these as a minimum.  Password + MFA or Bio metrics + MFA are good examples.  Depending on your environment, the applications you use, how they are accessed, by whom and from where might lend weight to some of the other options.  At Cirrus we use ALL of these for different systems, different reasons and situations.   We mandate strong passwords + MFA, these are selections we insist our team subscribe to.  In addition to this we use SSO in all situations where an application allows us. SSO for Starters & Leavers The attached article from Gartner Advantages vs Disadvantages talks about client experience in deploying SSO.  Like everything else on the topic, SSO is not a silver bullet but a useful and practical approach to Access and Security.  SSO also simplifies administration for starters & leavers as you will have less to setup and less to remove.  The fact users have to remember, manage and set fewer passwords also improves the experience and removes the more hard to ignore prompts for passwords. Password Managers In situations where passwords are less avoidable, password managers provide a great way to store and generate SECURE passwords.  Password Managers coupled with MFA provide really robust access and decrease the need to have regular password changes.  If the password for a system is secure and the password it self is 20 Characters, has upper and lower case letters, contains numbers and special characters breaching the password itself requires a very different act Disk Encryption If you are running Windows 10 or 11 in your business environment Disk Encryption is built and FREE to use.  Depending on settings it may need to be enabled but it’s a no-brainier of a step to take.  If you are running MacOS, all versions support Encryption too.  Disk Encryption protects in the event of the equipment being stolen Patch Management Most high profile data breaches of the last few years;  BA, NHS & Talk Talk are largely attributed to exploiting a vulnerability that had been previously addressed but not deployed to devices .  Patching applications, Operating Systems & Hardware all need to form part your defense strategy.  A policy based solution can ensure updates happen outside of core working hours and  do not interrupt productivity. AntiVirus An Antivirus solution should certainly be part of your strategy.  The subject of Antivirus is a commonly understood aspect of security so we won’t dig too deep into the merits of this.   Having a solution that is policy based, that does not allow users to disable it and , importantly, report/ alert when malicious content has been detected should be a must and be something you look for.  All vendors have this management capability Mail Scanning Mail is a huge part of any business and as a result e-mail is the number one vehicle for transmitting threats and attempting to exploit your organisation. ViPRE Security Report highlights the volume and scale of this issue with criminals evolving fast in terms of the volume of messages but also the types of threats.  Mail threats often appear genuine or familiar.  Increasingly they contains links to external sites, attach documents or ask you to call a number.   Considerations Our Fundamentals of Security are not the only aspects for consideration.  Backing  up your data is also important as are network policies and having a robust firewall.  Clients also look toward Cyber Essentials certifications or full Information Security as part of their strategies to bolster security but also raise awareness with employees.  All of these are valid and as as a minimum should be discussed Conclusion It’s a big topic.  We understand.  But broken into a number of workable action items everyone can take some basic steps to protect their business from on-line threats.  Cyber criminals are not targeting your SME, they are targeting everyone’s SME. For more information contact us : hello@thinkcirrus.co.uk T: 03303 130966 #cybersecurity #manageditservices #cheshirebusiness

Technology Partner
Blog

Why You Might Need a Technology Partner?

Why You Might Need a Technology Partner?   As a business owner, director or head of a department, you probably want to focus on your core duties and for technology to just work.  Like any business the word technology has come to mean a lot of things.  From internet connections or WiFi to applications working or just the phone on your desk allowing you to make or receive calls.  Whose job it is to make these systems work? You probably have neither the time nor inclination to manage either.  If this is you, maybe it’s time to think about a technology partner. Our Business   Our business is to look after your business, specifically the technology you use or maybe need.  We have a framework to take all of the daily pains away, centralise and organise them into your IT function.  A single home, a single point of accountability.  You let us know the the problem and we’ll manage it and when done report back.  No tearing your hair out, frustration or hours on the phone being passed from pillar to post. It’s worth at this juncture talking a little about our capabilities and breadth of services.  Lets explain briefly about what we do and how we operate. We operate a service desk from our offices in Ellesmere Port near Chester 7 days a week.  From here we take calls and resolve client issues.  We also have our monitoring systems that are checking the health of YOUR systems 24×7 7 days per week.  This allows us to take proactive steps to ensure you stay working while we head off issues before they affect you.  In addition all of YOUR systems are patched with updates and have maintenance routines run on a regular basis.  Our services are backed by service levels and a reporting system to ensure expectations are managed and you are up to date on both routine activities but also more high severity incidents.  We understand that how we manage key issues is every bit as important as the solution itself. To support this we also have 60 field engineers who cover the UK that can be with you quickly where the need arises. It’s not just about fixing the issues either   As a technology partner we also design and install systems.  Whether it’s hardware or software we can design and deliver services which then go under management and business as usual.  Internet Connectivity, Wi-Fi, Structured Cabling, Network Equipment, Security, Hosting, Door Entry, CCTV, Software Licensing & Application Development are some of the many things we can provide. Consult, Design, Deploy & Manage.  Way more than IT Support.  A true partner. Want someone to look after the mundane?  ThinkCirrus Looking for strategic advice? ThinkCirrus Need help with expansion? ThinkCirrus Keen to ensure your technology is keeping pace with the business? ThinkCirrus If this resonates and you would like to know more you can arrange an intro meeting here On-line Meeting with Cirrus if you’d prefer face to face drop us an e-mail to hello@thinkcirrus.co.uk or call 03303 130966, we’d be more than happy meet you in person  

Technology Partner
Blog

Why You Might Need a Technology Partner?

Why You Might Need a Technology Partner?   As a business owner, director or head of a department, you probably want to focus on your core duties and for technology to just work.  Like any business the word technology has come to mean a lot of things.  From internet connections or WiFi to applications working or just the phone on your desk allowing you to make or receive calls.  Whose job it is to make these systems work? You probably have neither the time nor inclination to manage either.  If this is you, maybe it’s time to think about a technology partner. Our Business   Our business is to look after your business, specifically the technology you use or maybe need.  We have a framework to take all of the daily pains away, centralise and organise them into your IT function.  A single home, a single point of accountability.  You let us know the the problem and we’ll manage it and when done report back.  No tearing your hair out, frustration or hours on the phone being passed from pillar to post. It’s worth at this juncture talking a little about our capabilities and breadth of services.  Lets explain briefly about what we do and how we operate. We operate a service desk from our offices in Ellesmere Port near Chester 7 days a week.  From here we take calls and resolve client issues.  We also have our monitoring systems that are checking the health of YOUR systems 24×7 7 days per week.  This allows us to take proactive steps to ensure you stay working while we head off issues before they affect you.  In addition all of YOUR systems are patched with updates and have maintenance routines run on a regular basis.  Our services are backed by service levels and a reporting system to ensure expectations are managed and you are up to date on both routine activities but also more high severity incidents.  We understand that how we manage key issues is every bit as important as the solution itself. To support this we also have 60 field engineers who cover the UK that can be with you quickly where the need arises. It’s not just about fixing the issues either   As a technology partner we also design and install systems.  Whether it’s hardware or software we can design and deliver services which then go under management and business as usual.  Internet Connectivity, Wi-Fi, Structured Cabling, Network Equipment, Security, Hosting, Door Entry, CCTV, Software Licensing & Application Development are some of the many things we can provide. Consult, Design, Deploy & Manage.  Way more than IT Support.  A true partner. Want someone to look after the mundane?  ThinkCirrus Looking for strategic advice? ThinkCirrus Need help with expansion? ThinkCirrus Keen to ensure your technology is keeping pace with the business? ThinkCirrus If this resonates and you would like to know more you can arrange an intro meeting here On-line Meeting with Cirrus if you’d prefer face to face drop us an e-mail to hello@thinkcirrus.co.uk or call 03303 130966, we’d be more than happy meet you in person  

Scroll to Top