Stay Safe: Key Cybersecurity strategies to protect your business
As independent retailers, ensuring the safety of your business and customers is paramount in today’s digital landscape. Understanding that cyber security can feel overwhelming, MGAIBA has partnered with the experts from GPK to offer practical tips that are easy to implement. From developing effective incident response plans to utilising multi-factor authentication, these strategies are designed to equip you and your team with the knowledge to safeguard your business. Together, we can enhance our cyber resilience and ensure that your retail operation remains secure. Read on for essential insights to help keep your business safe.
Plan for what to do when an incident occurs
What & Why: Having a well-defined action plan for when an incident occurs is crucial for minimising damage and preventing future incidents. This plan should include steps for identifying the breach, containing the damage, communicating with stakeholders, and conducting a post-incident review. It ensures that the organisation can respond quickly and effectively to security incidents, reducing downtime and mitigating risks.Who Should Do It: IT Security Teams and Incident Response Teams should develop, implement, and regularly update the incident response plan. All employees should be trained on their roles and responsibilities in the event of an incident.
MFA (Multi-Factor Authentication)
What & Why: Multi-Factor Authentication (MFA) adds an extra layer of security by requiring a second form of verification, such as a code sent to a mobile device, in addition to a password. This significantly reduces the risk of unauthorised access to accounts and sensitive information. This is critical to protecting against credential stuffing attacks, which use lists of compromised usernames and passwords to breach other systems. You can check if your business email address has been compromised at GPK Group or GPK Breached.
Who Should Do It: All employees should use MFA for their accounts. IT departments should enforce MFA policies and ensure that it is enabled across all systems and applications.
Harden Endpoint Devices
What & Why: Hardening endpoint devices involves implementing advanced security measures such as Next-Generation Antivirus (NGAV), Endpoint Detection and Response (EDR), attack surface reduction, and mobile device protection. These measures help detect, prevent, and respond to sophisticated cyber threats, ensuring that all devices connected to the network are secure.
Who Should Do It: IT Security Teams and Managed Security Service Providers (MSSPs) should work together to implement and manage these security solutions, with NGAV and EDR being your first line of endpoint defence.
Security Awareness Training
What & Why: Security Awareness Training educates employees about cybersecurity best practices, such as recognising phishing emails and avoiding suspicious links. Regular training helps prevent human errors that could lead to security breaches and ensures that employees are aware of the latest threats and how to respond to them.
Who Should Do It: IT Security Teams should develop and deliver regular security awareness training programmes. Many tools on the market can help automate this process. All employees should participate in these training sessions and stay informed about the latest cybersecurity threats; nobody is too important or too junior—everybody is a target for cyber criminals.
Keep OS and Apps up to date
What & Why: Regular updates to operating systems and applications are crucial for patching security vulnerabilities and improving system performance. These updates often include security patches that protect against newly discovered threats. Keeping systems up to date reduces the risk of exploitation by cyber criminals. It is strongly recommended that IT departments run vulnerability scanning tools over their assets regularly. The ACSC recommends, for Maturity Level One, that an asset scan should be run at least every fortnight, and a vulnerability scan should be run every 24 hours to identify fresh vulnerabilities.
Who Should Do It: IT departments should manage and schedule regular updates for all operating systems and applications. Even if an organisation is not attempting to align with an ACSC maturity level, patching and updates are a critical component of any security regime.
Minimise the number of admin users
What & Why: Minimising the number of admin users reduces the risk of unauthorised access and potential misuse of administrative privileges. By limiting admin access to only those who absolutely need it, organisations can better control and monitor the use of sensitive systems and data.
Who Should Do It: IT departments should regularly review and manage administrative privileges, ensuring that only necessary personnel have admin access. “Just-in-time access” should be implemented where possible, and even users with elevated access should have a day-to-day account with permissions reflective of their daily operations. Employees should be informed about the importance of this practice and adhere to the policies.
Email and Web Filtering
What & Why: Email and web filtering helps block spam, phishing attempts, and malicious websites, protecting the organisation from email and web-based threats. These filters ensure that harmful content is detected and blocked before it can cause any damage.
Who Should Do It: IT departments should implement and manage email and web filtering solutions. Employees should be trained to recognise phishing emails and report suspicious messages.
Perform regular backups and test restores
What & Why: Regular backups involve creating and storing copies of data to protect against data loss or corruption. The 3-2-1 rule is widely embraced as a reliable backup practice, referring to 3 copies of your data on 2 different media storage types, with 1 copy stored off-site. Immutable or indelible backups are also strongly recommended; these are read-only versions of the data that cannot be altered, deleted, or overwritten, preventing malicious actors from destroying backup data in the event of a major compromise. Testing restores ensures that backups are reliable and can be used to recover data in the event of a cyber attack, system failure, or accidental deletion, minimising downtime and data loss.
Who Should Do It: IT departments should establish and manage regular backup schedules, ensuring that backups are stored securely and tested periodically.
