International Computer Security Day 2022

International Computer Security Day was first introduced to the global calendar in 1988 when PCs were originally starting to appear in homes – and it’s been successfully rebooted every year since. Whether we’re talking about National Computer Security Day or National Cybersecurity Awareness Month which was in October, the goals are essentially the same. Individuals and organisations must be proactive in protecting their online security.

Its aim has always been to encourage computer users to stay safe online due to the need to heed this message which is now more pressing than ever. This is because there is a growing threat of cyber-attacks and cyber-crime, which has cost the UK economy a staggering £87 billion since 2015, according to internet service provider Beaming.

November 30th was the day chosen for computer security day, so that attention on computer security would remain high during the holiday season period approaching. Mainly because this is when people are typically more focused on the busy shopping season than thwarting security threats.

This year, amid hybrid working, and the lingering effects of covid19, the importance of protecting digital assets is vital to any person or business. The Cyber Security Breaches Survey 2022 results show that in the last 12 months, 39% of UK businesses identified a cyber-attack.

So, what can we do to help out during this time?

 

Our 5 top tips to staying safe during the holidays:

 

1. Use a password manager

A password manager can generate complex passwords, which are unique for each of your online accounts. These can store the passwords for you, where you have to use your password for your user login credentials to access the password. This removes the task of users needing to remember all the different passwords they use. This can also be used with biometrics for facial recognition which you may already do with mobile phones.

2. Use complex passwords

A recent article by NordPass reported that ‘password’ and variations of ‘123456789’ still rank among the most commonly used passwords. The password advice from NCSC and the Cyber Essentials scheme shares a common theme: simplify passwords and put the burden on the authentication system. 3 random words are a good way to help protect users, by limiting anything which would link back to the user and lower the chances of social engineering from being effective.

3. Keep all devices up to date

This one seems straight forward but is one of the most vital. Most devices will be on auto updates by default, but it doesn’t hurt to check everything. This includes checking any internet browsers, checking the systems updates and any applications that you use. If you use antivirus or endpoint security apps, you’ll need to ensure these are updated regularly. Like other software, antivirus updates include bug fixes and new features, but also include new signatures, which can be used to detect new malware that’s recently been detected by the AV companies.

4. Device support

Encrypt and back up all your files either using Google drive, cloud storage, or an external storage device. Whether it’s on a USB stick, on a separate drive or a separate computer, access to data backups should be restricted so that they are:

  • Not accessible by staff.
  • Not permanently connected (either physically or over a local network) to the device holding the original copy.

Ransomware can often attach to storage files automatically, which means any such backup could also be infected, leaving you with no backup to recover from. For more resilience, you should consider storing your backups in a different location

5. Use Multi-Factor authentication for all profiles

Two-factor authentication (2FA) is an identity and access management security method, that requires two forms of identification to access resources and data. 2FA gives businesses the ability to monitor and help safeguard their most vulnerable information and networks. This can be something you know like a password and something you have like a phone for a push notification to be sent to, or a fingerprint. All of these when layered together can provide the protection needed for accounts. All accounts have the ability to activate 2FA, and these should be used to protect all accounts, not just the important ones.

 

This time of year, can be one of the most proactive and successful times for hackers to invade both personal and company devices. Keeping up to date with the latest software and hardware releases is vital to keeping secure. As always, it is important to stay vigilant, you can always find useful resources from the National Cyber Security Centre (NSCS), including places to report any suspicious links from texts, emails and websites if you are ever unsure. For more help and information contact the CSP Team here.

Leave a Reply

Your email address will not be published. Required fields are marked *