Intelligent SME.tech Issue 08 | Page 21

intelligent

// EDITOR ’ S QUESTION ?

JOHN MCLOUGHLIN , CEO OF J2 SOFTWARE

S mall businesses need to change their security policies and educate their remote workers on cybersecurity . Cybercriminals have shifted their focus to vulnerable employees who now work from home and use personal Internet connections .

In a recent study by Microsoft , more than 25 % of remote workers had personally experienced a cyberattack . This is largely as a result of employers being forced to quickly implement a remote work strategy and still not having the necessary security , privacy and workplace procedures in place to secure this new environment more than a year after hard lockdowns and work from home orders started around the world .
SMEs just cannot afford to neglect userbased activity monitoring and cybersecurity awareness training , it could be catastrophic . Education is key to ensuring that they are protected from cyberattacks . To be effective , the training must be consistent , engaging and provide real examples of what to look out for to make any difference . Engaging training and an easy-to-use platform will get staff talking about cybersecurity issues and discussion provides greater understanding .
SMEs need to hold everyone to the same standard for adopting cybersecurity protocols . Nobody should get a ‘ free pass ’ when it comes to cybersecurity awareness training because of their designation . Management is ultimately responsible for the secure use of company assets and must ensure that nobody is allowed to break security protocols .
Cybersecurity practices are sometimes seen as a burden and this could entice remote workers to find workarounds because they believe it might increase productivity . Open communication and practical security controls , with increased visibility , will drive good cybersecurity practices into the DNA of one ’ s remote workforce .
Ensuring total visibility will prevent mistakes , allow one to respond immediately to threats and ensure patches , training and other items are properly managed . Visibility allows one to control compliance and cybersecurity issues and will give a view on anybody who may install unverified apps on their work devices , be sending sensitive or confidential work documents to personal email addresses or even sharing passwords .
Work devices have now also become personal devices , remote workers also often let family members use their work computer for non-work-related activities . Allowing family members to use work devices could expose the entire corporate network to significant risk and every business needs to assess their policies and measure their risk exposure when personal activity is conducted on work devices . In certain instances , this might not be allowed at all and clearly explaining this to the users is critical . However , until one has visibility , there is no way of knowing what is really happening at the endpoint , it will just be a guess . Guesswork is not a recommended method to ensure data security .
SMEs should make sure that they have visibility of what is really taking place with their data and on their systems to reduce their risk exposure . This is bolstered by educating their remote workers on what to look out for and how to identify potential breaches .
While it ’ s near impossible to stay entirely secure , there are basic rules that remote workers can follow to reduce the risks in this new working environment and total visibility and monitoring gives you the capacity to respond to changes before damage is done .

NOBODY SHOULD GET A ‘ FREE PASS ’ WHEN IT COMES TO CYBERSECURITY AWARENESS TRAINING BECAUSE OF THEIR DESIGNATION .
Intelligent SME . tech
. tech
21