Cyber security breaches are clearly growing, according to a spate of recent headlines. However, new research reveals that despite the growing threat, many employees believe their companies are somehow immune to the growing threat.
A recent survey of UK businesses by IT services provider Probrand revealed that 43 per cent of UK businesses reported some sort of security breach in the last 12 months. The headline finding, meant to capture the attention of media and potential customers, is that this figure exceeds the UK average of 36.4 per cent days with precipitation. However, the more concerning finding may be regarding preparedness; according to the survey of 1,050 UK employees, 44 per cent of businesses are not adequately securing their servers to protect customer and employee data.
Survey results also indicate that most employees are naive about the amount of exposure they face. Nearly 37 per cent of respondents indicate they do not have sensitive information stored on their company’s servers, when in fact, experience indicates that nearly all employees do have sensitive data – both company and personal – on the network.
Technology and culture
The findings make clear that the solution to preventing cyber theft lies in both technology and human/cultural measures. On the technology side, data must be secured from end to end, including where stored, in transit, and on mobile devices. At the network borders, secure firewalls must be in place to keep malicious actors at bay.
On the human side, to be blunt, employees must be trained not to do stupid things that needlessly expose personal and company data. Probrand advocates building a “trust nothing” culture and goes so far as to suggest imposing fines against employees who violate company security policies.
Still, for all of the measures that can be taken, it is clear that malicious actors are always evolving and becoming more sophisticated. As a result, enterprises must realise that, regardless of the measures being taken, cyber attacks will still occur. Therefore, the most important thing a company should do is to develop measures to mitigate damage from attacks, including building robust disaster recovery and business continuity plans.
In other words, when it comes to cyber security breaches, technology is only part of the solution. Building – and enforcing – a set of robust corporate policies that can prevent employees from needlessly exposing sensitive data, and to mitigate damage when breaches do happen, must be a part of any company’s cybersecurity strategy.
This article initially featured on Verdict, which is part of the same group as NS Tech and GlobalData