[{"data":1,"prerenderedAt":82},["ShallowReactive",2],{"story-cybersec-guide":3},{"articles":4},[5],{"documentId":6,"title":7,"slug":8,"createdAt":9,"publishingDate":10,"description":10,"content":11,"quote":12,"postAuthor":10,"thumbnail":16,"relatedProducts":10,"industry":66,"relatedPosts":71,"metaData":72},"lth5u0zjeot3dkadtwgv2buh","A practical cybersecurity guide for any company","cybersec-guide","2023-04-21T09:34:35.000Z",null,"The primary tools of office jobs are computers and other smart devices. Instead of working with piles of papers and setting up all meetings in person, a somewhat time-consuming matter, we have the convenience of arranging all of that online. Furthermore, the remote and flexible working arrangements allow people to work from anywhere in the world. \nIt is safe to say we spend more and more time online – after all, a large part of today’s society’s social life is online, too. Alas, the conveniences of our digitalised lives may come at a cost.\nRecently, our Head of Cybersecurity Department Sander Valvas discussed threat management systems in a [blog article](https:\u002F\u002Fcyber.ee\u002Fresources\u002Fstories\u002Fincremental-and-iterative-improvement-of-cybersecurity\u002F). “The problem is not the cost of information security management, but lack of skills to implement suitable risk\u002Fthreat\u002Fvulnerability management system(s) and procedures,” he said. To reiterate and discuss the importance of cybersecurity in a firm of any size, we collaborated with out good client [Directo](https:\u002F\u002Fdirecto.ee) in a recent webinar. Rewatch the webinar in Estonian [here](https:\u002F\u002Fcyber.ee\u002Fresources\u002Fwebinars\u002Fdirecto2023\u002F).\n\nWe started off the webinar with some questions and we instantly met with a telling fact – over 50% of respondents said there had been records of cyber incidents at their company. On the other hand, about 30% of respondents did not know if there were any incidents recorded. “It is quite common to not be aware of the incidents, since cyberattackers act covertly and unnoticeably,” commented Directo’s CISO Toomas Oper. When asked what the respondents see as the biggest threats, a noteworthy amount of mentions for human error and ignorance came in. It is great to see that people are acknowledging the most common threats, and that the lack of knowledge is seen as threat, too. \n\nWhen talking about the most common threats, Toomas Oper noted that phishing schemes are developing rapidly and becoming more and more believable. The most common scheme is someone impersonating a CEO or other management member asking you to click on links, pay invoices or transfer money urgently. More often than not, the emails are written with a sense of urgency. Of course, the best practice is to ignore these emails and simply delete them. Always make sure to double check the sender’s email letter by letter. Living in a country with a complicated language, like us here in Estonia, is also a great giveaway for such phishing emails since they almost always sound unnaturally written. \n\nThe centre point of our webinar was a rather simple message – invest into prevention since aftermath of a cyberattack is always more expensive. “For example, if a company happens to fall prey to a cyberattacker and sensitive data is leaked, the company may be facing repercussions of the GDPR, and they may turn out to be costly,” said Oper. In addition to the initial devastating financial consequence, the company may lose its credibility and trustworthiness, which again send the business into a downward spiral. This is of course the worst-case scenario, but not an unlikely one. \n\nSo, how should a company begin to navigate towards the right cybersecurity solution? “Firstly, a company should assess its value and choose a solution that is financially optimal and in line with its assets’ worth,” said Sander Valvas, Head of Cybersecurity at Cybernetica. “A good starting point is evaluating the core processes of your company. Say, your company operates with direct sales and relies on ERP software. Imagine you are not able to access it for some period of time, what would happen then?” Valvas continued. Should the company’s work be restricted or it is impossible to operate without the software, it outlines a clear business priority that has to be protected.\n\nHere are some questions a company should think about that help with the asset evaluation:\n-\tCan we operate without our assets?\n-\tWhat happens if we lose access to the assets?\n-\tHow long can we operate without the assets?\n-\tWhat happens if a stranger gains access to my assets?\n-\tWhat happens if a stranger is able to modify my assets?\n\n“It is important to initiate a routine process for cybersecurity and not just casually,” said Valvas. As a basic starter, conducting a cyber hygiene training for all employees is a must, as well as being responsible for keeping passwords strong, safe and using multi-factor authentication.\nWhile figuring out the evaluation, it is a good idea to map the threats and possible perpertators.\nThe threats include:\n-\tForce majeure, such as environmental disasters, technical problems, human errors\n-\tTargeted attacks, such as phishing, DDoS attacks, ransomware, malware, social engineering, threats agains data, internet threats, disinformation, misinformation, supply chain attacks etc\n\nThe possible perpetrators include:\n-\tAn internal perpetrator, such as an employee or an ex-employee\n-\tA state-level attacker\n-\tAn attacker looking for materialistic gains\n-\tHackers\n-\tA competitor\n-\tAn attacker looking for revenge\n-\tSimply casual attackers\n\nAnd lastly, Valvas suggests to evaluate possible losses:\n-\tBreaking regulations, laws or contracts\n-\tHarm to personal health or wellbeing\n-\tHarm to business operations\n-\tHarm to public image\n-\tFinancial losses\n\nNowadays it is very common to outsource various IT or cybersecurity services in order to save costs and resources, but the risks have to be assessed here, too. \nValvas lists some of the risks that come with subcontractors:\n-\tLack of control\n-\tCommunication errors\n-\tPoor quality of services and software\n-\tLack of industry knowledge\n-\tUnforeseen expenses\n-\tLack of experience with distributed teams\n-\tSecurity breaches and lack of IP protection\n\nOn the other hand, there are many notable benefits of subcontractors, such as:\n-\tCost effectiveness\n-\tEffectivity increase within business operations\n-\tAbility to focus on main priorities\n-\tAccess to knowledge and skills\n-\tIncreased flexibility to cope with variable business conditions\n-\tAccelerated business launch on the market\n\n“A common misconception with outsourcing is that the subcontractor is responsible for everything. In reality, both the client and the subcontractor hold a divided responsibility over processes,” said Valvas. [Microsoft](https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fsecurity\u002Ffundamentals\u002Fshared-responsibility) has illustrated this issue well in a following graphic: \n\n![shared-responsibility.jpg](\u002Fuploads\u002Fshared_responsibility_71a61bc454.jpg)\n \n“In conclusion, the most important is to raise employees’ awareness about utilising company’s assets in a correct and a mindful matter. Refrain from using social media on your work computer and be mindful of where you click. Don’t store important assets in cloud drives or on personal accounts,” Valvas concluded.\nWhile on this topic, we suggest reading further about [dealing with a cyberattack](https:\u002F\u002Fcyber.ee\u002Fresources\u002Fstories\u002Fso-a-cyberattacker-broke-into-my-systems-what-comes-next\u002F) and how to correctly [back up your data](https:\u002F\u002Fcyber.ee\u002Fresources\u002Fstories\u002Fthe-value-of-backups-how-much-do-you-trust-yours\u002F) to avoid catastrophic losses.\n\nShould you be interested in cybersecurity solutions offered by Cybernetica, learn more [here](https:\u002F\u002Fcyber.ee\u002Fsolutions\u002Fcybersecurity\u002F) and don’t hesitate to [get in touch](https:\u002F\u002Fcyber.ee\u002Fsolutions\u002Fcybersecurity\u002F#contact-person) via the contact form.",{"content":13,"author":14,"jobTitle":15,"profileImage":10},"It is important to initiate a routine process for cybersecurity and not just casually.","Sander Valvas","Head of Cybersecurity Department",{"featuredImage":17},{"documentId":18,"url":19,"alternativeText":20,"width":21,"height":22,"formats":23,"mime":28},"lwhr2c57qgz766c51gsphzbu","\u002Fuploads\u002Fsander_crombach_On_ay_Ju_Jtg_E_unsplash_3f13139e6c.jpg","A pixellated image of an aerial veiw of a city",2000,1000,{"large":24,"small":32,"medium":38,"xlarge":45,"xsmall":52,"thumbnail":59},{"ext":25,"url":26,"hash":27,"mime":28,"name":29,"path":10,"size":30,"width":22,"height":31},".jpg","\u002Fuploads\u002Flarge_sander_crombach_On_ay_Ju_Jtg_E_unsplash_3f13139e6c.jpg","large_sander_crombach_On_ay_Ju_Jtg_E_unsplash_3f13139e6c","image\u002Fjpeg","large_sander-crombach-On_ayJuJtgE-unsplash.jpg",139.12,500,{"ext":25,"url":33,"hash":34,"mime":28,"name":35,"path":10,"size":36,"width":31,"height":37},"\u002Fuploads\u002Fsmall_sander_crombach_On_ay_Ju_Jtg_E_unsplash_3f13139e6c.jpg","small_sander_crombach_On_ay_Ju_Jtg_E_unsplash_3f13139e6c","small_sander-crombach-On_ayJuJtgE-unsplash.jpg",35.86,250,{"ext":25,"url":39,"hash":40,"mime":28,"name":41,"path":10,"size":42,"width":43,"height":44},"\u002Fuploads\u002Fmedium_sander_crombach_On_ay_Ju_Jtg_E_unsplash_3f13139e6c.jpg","medium_sander_crombach_On_ay_Ju_Jtg_E_unsplash_3f13139e6c","medium_sander-crombach-On_ayJuJtgE-unsplash.jpg",76.55,750,375,{"ext":25,"url":46,"hash":47,"mime":28,"name":48,"path":10,"size":49,"width":50,"height":51},"\u002Fuploads\u002Fxlarge_sander_crombach_On_ay_Ju_Jtg_E_unsplash_3f13139e6c.jpg","xlarge_sander_crombach_On_ay_Ju_Jtg_E_unsplash_3f13139e6c","xlarge_sander-crombach-On_ayJuJtgE-unsplash.jpg",489.9,1920,960,{"ext":25,"url":53,"hash":54,"mime":28,"name":55,"path":10,"size":56,"width":57,"height":58},"\u002Fuploads\u002Fxsmall_sander_crombach_On_ay_Ju_Jtg_E_unsplash_3f13139e6c.jpg","xsmall_sander_crombach_On_ay_Ju_Jtg_E_unsplash_3f13139e6c","xsmall_sander-crombach-On_ayJuJtgE-unsplash.jpg",1.32,64,32,{"ext":25,"url":60,"hash":61,"mime":28,"name":62,"path":10,"size":63,"width":64,"height":65},"\u002Fuploads\u002Fthumbnail_sander_crombach_On_ay_Ju_Jtg_E_unsplash_3f13139e6c.jpg","thumbnail_sander_crombach_On_ay_Ju_Jtg_E_unsplash_3f13139e6c","thumbnail_sander-crombach-On_ayJuJtgE-unsplash.jpg",10.64,245,123,{"title":67,"slug":68,"icon":69},"Enterprise","enterprise",{"icon":70},"finance",[],{"metaTitle":7,"metaDescription":73,"shareImage":74},"Navigate the complex landscape of cybersecurity with our comprehensive guide. Explore essential tips, best practices, and the latest insights.",{"formats":75},{"large":76,"small":77,"medium":78,"xlarge":79,"xsmall":80,"thumbnail":81},{"ext":25,"url":26,"hash":27,"mime":28,"name":29,"path":10,"size":30,"width":22,"height":31},{"ext":25,"url":33,"hash":34,"mime":28,"name":35,"path":10,"size":36,"width":31,"height":37},{"ext":25,"url":39,"hash":40,"mime":28,"name":41,"path":10,"size":42,"width":43,"height":44},{"ext":25,"url":46,"hash":47,"mime":28,"name":48,"path":10,"size":49,"width":50,"height":51},{"ext":25,"url":53,"hash":54,"mime":28,"name":55,"path":10,"size":56,"width":57,"height":58},{"ext":25,"url":60,"hash":61,"mime":28,"name":62,"path":10,"size":63,"width":64,"height":65},1788355399086]