If you knew that almost a quarter (22%) of all UK companies were hit by a cyber attack in the past year, what would you do to tighten up your own security? This shocking figure features in a 2024 report from the government Department for Science, Innovation and Technology, but is likely to be only the tip of the iceberg. It’s why we wanted to spotlight 3 cyber security concerns and workarounds for SMEs – especially as many don’t have the budget, resource, time or expertise to run a full-time IT department. Read on to find out more about these common concerns and how you can both fix and prevent them in Leicester.
1. Phishing
First on our list of 3 cyber security concerns and workarounds for SMEs is phishing. You’ve probably heard of it before, and may even know what it is (essentially: an attempt to trick someone into clicking on a malicious link in an email, to access sensitive information or transfer money). But, it comes in many different guises and can be difficult to spot. Here are a few:
- Smishing: The text equivalent of phishing.
- Spear-phishing: An attempt to target a particular group or individual. (If the individual is particularly senior, such as a company CEO, it’s referred to as ‘whaling’).
- Vishing: Where phishing is attempted over the phone (‘voice’ phishing).
The National Cyber Security Centre (NCSC) has some great advice on defending against phishing attacks. They recommend a layered approach, so attackers can find it harder to target your employees or access their accounts, and employees themselves can identify and report phishing emails. Some things you could try include multi-factor authentication for accounts and devices, and using filters to automatically sift incoming emails and block any that look suspicious.
But what do suspicious emails look like? The sender’s address may not match the organisation it’s purported to be from (such as including extra characters, words or punctuation marks). The email might sound odd or contain typos. And there is often a time element that pressures you to act quickly – for instance: ‘Your account has been hacked! Click here to unlock it’.
While your organisation must adhere to legal and regulatory responsibilities, it’s often a good idea to change account passwords, run scans on company devices, inform employees and continue to monitor things afterwards.Â
2. Malware
Next on our list of 3 cyber security concerns and workarounds is malware, which stands for ‘malicious software’. It’s designed to infect anything from individual devices to entire networks. And while it’s often used to steal data or funds, some kinds are designed to take over, or even inflict damage. Malware can include:
- Viruses: Malicious code that can corrupt or destroy data, and requires a user to physically send it to another user (for example, in an email attachment)
- Worms: Similar to viruses, but able to spread autonomously.
- Spyware: Programs that track or monitor activity on your device (such as browser history).
- Trojans: Applications that seem harmless or legitimate, but hide malware.Â
It might not be immediately obvious that malware has been installed, but there are some common tells – like slower speeds, unwanted redirects and even add-ons appearing on your browser.
While antivirus can go a long way in protecting your employees from malware, there are other steps you can follow:
- Keep systems and software up-to-date.
- Check links before clicking them (for example, by hovering over them first to see the full address).
- Avoid downloading software from the internet or clicking on pop-ups.
- Limit any file-sharing in your business.
Removing malware can be a little more complicated. Some can be removed through antivirus software, while more dangerous or widespread cases might require using a system restore point. Again, if data has been compromised, you must follow legal procedures. You can start with the ICO website, which has some essential information about reporting and managing breaches.
3. Vulnerabilities
Finally, general vulnerabilities – the last on our list of 3 cyber security concerns and workarounds. We wanted to particularly emphasise how to prevent vulnerabilities, as company systems, networks and devices are vulnerable by default. Any one of them could be a doorway to your data or finances. So, here are a few things we’d recommend:
- MFA: Not only do employees need to use screen locks on their devices and strong passwords for their accounts, but as a business, you need to enable additional measures for logging in, in general. MFA uses a separate piece of information (typically across more than one device) for an extra layer of security (think account password entered on a laptop, and a one-time passcode sent to your phone).
- Antivirus software: Defending against malware is essential for all businesses – even more so for those where employees may work in other locations besides the office, or use their own devices alongside company ones.Â
- Data management: Who really holds keys to your data? Not all your employees will need the same level of access to company files (and that’s without GDPR concerns – such as around sensitive HR and personal data), and old data needs to be properly disposed of. As for storing data, back-ups are essential.
- Secure WiFi: Again, remote and hybrid working can pose a threat to networks where public WiFi is being used. A secure connection helps mitigate risk, or you could use a Virtual Private Network (VPN).Â
Call in the professionalsÂ
While there’s a lot in our article of 3 cyber security concerns and workarounds that you can roll-out yourself, sometimes, it pays to speak to a professional. Our Leicester cyber security experts can help with all this and more, so you have complete peace of mind that your business is as secure as possible.
Get in touch with our team in Leicester by calling 03450 099 099, or visit our LinkedIn profile, website blogs or service page for more information about our IT support in Leicestershire.