25.01.2022

5 cyber security mistakes made by businesses and how to correct them

RoundWorks IT Technology & Software

5 cyber security mistakes made by businesses and…

twitter icon

The single, biggest cybersecurity mistake businesses can make is to fail to appreciate the importance of robust cybersecurity. All other common mistakes stem from this initial error. Here are five of the main ones and what they can mean for your business.

Failing to appoint someone to manage cybersecurity

Cybersecurity is far too important to be left for when (if) somebody has some free time from their “proper” job. It needs to be at least part of somebody’s official job role. That somebody then needs to be given appropriate resources (and authority) to fulfil their designated responsibilities.

It’s absolutely fine if your cybersecurity manager delegates everything to do with cybersecurity. In fact, that’s likely to be standard practice in SMEs, particularly smaller ones. Their role is to make sure that the work is done rather than necessarily to do it themselves.

Failing to review and refresh your IT policies

This failure often ties back to a failure to appoint someone to be in charge of cybersecurity. Technology is one of the fastest-moving industries the world has ever known. Cybersecurity is probably the fastest-moving part of the technology sector. 

Even though the basic principles of cybersecurity have been around for thousands of years, their implementation needs to be constantly reviewed and refreshed as technology develops.

For example, in the early days of IT, “data theft” meant printing out data or copying it onto a floppy disk. Now, it’s more likely to mean phishing or even spear-phishing.

If you fail to stay on top of these changes (or to hire someone to do it for you), you leave yourself very exposed to attack. Remember, no business is “too small to be a target”. If you make yourself a soft target then you can expect to be attacked no matter how small you are.

Failing to set a realistic budget for cybersecurity

Effective cybersecurity effectively boils down to a combination of skills, tools and training. All of these come at a cost, even if the cost is only the time of the people involved. You, therefore, need to be prepared to invest in hiring skilled cybersecurity professionals and providing them with the tools they need.

The good news is that this can be a lot more affordable than you might think. For most companies, especially, SMEs managed IT services are the way to go.

Depending on your needs, wants and budget, you could hire a managed cybersecurity specialist or have cybersecurity included as part of a broader managed IT services package.

Your managed cybersecurity partner may be able to arrange training for your staff. Even if they can’t, they can generally suggest training options for you. It is, however, down to you to set aside a budget for this.

Similarly, you will need to set aside a budget for regular hardware upgrades. Different items of IT equipment will have different life-cycles. As a rule of thumb, however, desktops/laptops, tablets and mobile devices should be replaced every three years.

Failure to manage your assets effectively

You need to know every last item of hardware or software that could touch anything in your company. This includes hardware and software that is designed to be used offline (e.g. physical storage media).

You should know what it is, what it does/holds, where it is and who is responsible for it. You should also have a plan for ensuring that it is looked after for as long as it is needed and then archived if appropriate before being destroyed/deleted.

Failure to implement robust access controls

The most basic way to protect your security is to make sure that people only access sensitive resources if they actually need to do so. This concept is simple in theory but generally takes some effort to implement in practice, especially as companies grow larger.

Luke Watts is the director of RoundWorks IT, which are specialists in managed IT services, including, backup and disaster recovery, cyber security and more for businesses across East Midlands.

Follow us for more articles and posts direct from professionals on      
IT, Disaster Recovery

Disaster Recovery Plans Explained: Is Your Business IT...

No one in business wants to face a disaster, and yet all of us are at risk of it. We have already seen what a global…
Security, Business, Cyber Security

How Cyber Security Awareness Training Can Benefit Your...

Whatever your business offers, there are many types of security that you might need to consider, but aside from burglar…
IT Support, IT Security, Business Support

5 reasons why your business can't afford to not invest in...

Since IT is fundamental to the operation of modern businesses, it follows that businesses need absolutely reliable IT…

More Articles

Business, Cyber Security, Business security

Common cyber attacks & how to avoid them

While cybercriminals are always developing new methods of attack, they often follow similar themes. In fact, they are…
Data Backup, Data Security, Cybersecurity

6 tips for securing your business data

Your business data is hugely valuable. It doesn’t matter what size of business you are or what sector you’re in. Your…
IT, Business, Cyber Security, Managed IT Support

The benefits of switching to a managed IT service provider

The main benefit of switching to a managed IT service provider is that it helps you to deliver optimum service to your…

Would you like to promote an article ?

Post articles and opinions on Professionals UK to attract new clients and referrals. Feature in newsletters.
Join for free today and upload your articles for new contacts to read and enquire further.