MERCH!
Giant Bomb - a website about video games and the people that make them

Best Practices for Cybersecurity Hygiene

by itgametime

Cybersecurity is one of the most important considerations for any business, but many leaders mistakenly think that cybersecurity requires a massive investment or a large team of IP professionals. In reality, data can be effectively protected with simple, proactive steps on the part of the employee and the company. Cybersecurity expert and CEO of White Knight Labs , Greg Hatcher, works with his...

Cybersecurity is one of the most important considerations for any business, but many leaders mistakenly think that cybersecurity requires a massive investment or a large team of IP professionals. In reality, data can be effectively protected with simple, proactive steps on the part of the employee and the company. Cybersecurity expert and CEO of White Knight Labs, Greg Hatcher, works with his clients to inform them of these best cybersecurity hygiene practices that businesses can use to protect their data.

No Caption Provided

What are cybersecurity hygiene practices?

Cybersecurity hygiene” is the term encompassing the best practices that users and security practitioners of an organization can take to protect the integrity and security of the organization’s system and data. More often than not, these practices are relatively simple and straightforward — requiring little effort from the user — but can play a pivotal role in ensuring that the organization’s data is not compromised.

Best cybersecurity hygiene practices for employees

The first and most obvious cybersecurity hygiene practice that must be implemented is strong passwords. Though it is certainly tempting to use a simple password because of the ease by which they can be remembered, this also means they are easier for wrongdoers to uncover and use for malicious purposes.

“Create a strong password based on each system’s requirements: have it be on the longer side, use a mixture of letters (uppercase and lowercase), numbers, and symbols, and avoid common words and phrases (pet or child names, birthdays, and the word ‘password’),” Hatcher suggests. “Also, avoid reusing passwords for multiple systems because once a hacker gets access to one system, reused passwords allow access to all systems.”

When available, two-factor authentication should also be utilized. “Some employees might complain about this measure at first because it can seem like a nuisance,” explains Hatcher. “However, the purpose of two-factor authentication is to ensure that only authorized users access the system. By sending them an email, text message, or push notification to a 2FA app, it is an extra layer of protection to ensure hackers can’t access the account. And if someone cracks the password, an unprompted 2FA notification can be an alert to change the password.”

There are also even more simple steps that users can take to protect their data and the organization’s data. For example, something as simple as keeping software up to date can be a pivotal part of cybersecurity hygiene. “When software companies find security issues with their programs, they typically fix them through updates to the software,” says Hatcher. “If you don’t update your software, you leave your data vulnerable to known and exposed flaws.”

Employees must also simply remain vigilant with their actions, and strive to avoid any mistakes that could leave their or their organization’s data vulnerable. For example, phishing scams are becoming more common and complex. “Scammers will send emails impersonating a legitimate communication from a party, such as a boss, coworker, or vendor, and use this to trick employees into giving them access to data,” Hatcher explains. “Employees must do their due diligence and ensure that they only share their info with people who should actually have access.”

Best cybersecurity hygiene practices for business leaders

From the business side, it is important that company leaders make an investment in the cybersecurity hygiene of their organization and employees. “Take the time to educate your employees about best practices for cybersecurity,” Hatcher suggests. “Discuss cybersecurity in meetings, train employees on new softwares, and alert employees of known breaches and threats.”

Of course, companies should certainly invest in reputable cybersecurity software. “The needs of a company will vary based on several factors, including their size and the type of data they work with,” says Hatcher. “Businesses with only a handful of employees will need a less complex cybersecurity solution than those with large workforces or handling sensitive data — such as medical or personal identification.”

Hatcher also suggests companies back up data in case of ransomware or cyber incidents. “Once a ransomware attack hits, it’s often too late,” he asserts. “However, you can be better prepared for damage control if you have a backup of all your data, as this means you still have access despite the hackers’ attempts to lock you out.”

Indeed, Hatcher likes to remind business owners that cybersecurity is all about being proactive. “Businesses might go years without ever being targeted by a cyberattack, but if those cybersecurity measures are not in place, it will be too late to do anything once the attacker accesses your data,” he adds. “It is better to be proactive and not need cybersecurity services than to need them and not have them.”

White Knight Labs specializes in professional cybersecurity penetration testing services, which can expose vulnerabilities in an organization’s systems and allow business leaders to create a game plan to address any pressing cybersecurity issues. As part of a business's commitment to being proactive about their cybersecurity hygiene, this type of service can help identify areas of concern before wrongdoers even have the chance to exploit them.

The goal of implementing these best practices for cybersecurity hygiene is to prevent hackers, scammers, and other wrongdoers from ever gaining access to your organization’s data. “Once your organization has fallen prey to an attack, it is much more difficult to remedy than to protect your organization from the start,” Hatcher concludes. “An investment in cybersecurity now means avoiding costly tragedies in the future.”