The National Cyber Security Centre (NCSC) has called for increased cyber security vigilance among firms in response to the Russian invasion of Ukraine.
To help small and medium sized businesses protect themselves, the NCSC advises that they should take regular backups of their important data and make sure that backups are recent and can be restored.
Whether it’s on a USB stick, separate drive or a separate computer, access to data backups should be restricted so that they are not accessible by staff and not permanently connected to the device holding the original copy and use cloud storage where possible.
In its security guide, the NCSC says: “Using cloud storage means your data is physically separate from your location. You’ll also benefit from a high level of availability. Service providers can supply your organisation with data storage and web services without you needing to invest in expensive hardware up front.”
Firms should also install and switch on antivirus software to prevent malware from damaging the organisation and prevent staff from downloading third party apps from unknown vendors/ sources.
According to the government agency: “Staff accounts should only have enough access required to perform their role with extra permissions only given to those who need it. When administrative accounts are created, they should only be used for that specific task with standard user accounts for general work.”
In addition, the NSCS says that with mobile technology now an essential part of modern business, they require even more protection than ‘desktop’ equipment. Firms using mobile phones for business should make sure lost or stolen devices can be tracked, locked or wiped and staff should ensure that their phones and tables are kept up to date at all time, using critical security updates to keep the device protected.
It also recommends not to connect to unknown wi-fi hotspots and instead use mobile 3G or 4G mobile networks which will have built-in security.
The NCSC also says firms should ensure that password protection is always switched on and staff should consider using long passwords that are difficult to guess. Staff should also consider using two-factor authentication.
It says: “If you’re in charge of how passwords are used in your organisation, there’s a number of things you can do that will improve security. Most importantly, your staff will have dozens of non-work related passwords to remember as well so only enforce password access to a service if you really need to.”
Finally, the NCSC has devised steps to help firms identify the most common phishing attacks.
It said: “Phishing emails are getting harder to spot and some will still get past even the most observant users. Whatever your business, however big or small it is, you will receive phishing attacks at some point.
“You should configure your staff accounts in advance using the principle of least privilege. This means giving staff the lowest level of user rights required to perform their jobs so if they are the victim of a phishing attack, the potential damage is reduced.
“To further reduce the damage that can be done by malware or loss of login details ensure that your staff don’t browse the web or check emails from an account with administrator privileges.”
Anthony Rafferty, CEO Origo, commented: “While the National Cyber Security Centre says it is not aware of any current specific cyber threats to the UK following events in Ukraine, it is highlighting a need for increased cyber security vigilance amongst all firms.
“A core element of cyber security for providers, platforms and financial advice firms has to be securing their email communications.
“Email is vulnerable to hacking and attack, yet personal and confidential information is still being sent within open emails, which if obtained by malicious or criminal organisations can be used against individuals and companies.
“If we think about the personal detail that may be contained in communications between client and advice firm, provider or platform, it’s easy to see that if intercepted the consequences could be devastating both for the individual as well as for the company which could face fines and reputational damage, including lack of client trust.
“Using a military-grade encryption service secures the email in transit and ensures that only the intended recipient can access the email, and that the recipient knows it comes from a trusted source.
“Securing our emails has to be base-level security, and not just because of the current situation in Ukraine, but as good business sense.”






























