It’s also important to practice cybersecurity awareness. The biggest cyber threat to an organization is its employees, as employees often lack cybersecurity awareness and training and fall victim to phishing schemes (increasingly the most common form of cyber attack). Phishing is when the cybercriminal sends out an email that includes a malicious file or link that, when downloaded, begins installing malware on the computer and can spread throughout the system.
Spearphishing is a more sophisticated form where the hacker may spoof or use a similar email to someone the victim knows and trusts to either install malware or make requests for information or money.
Phishing attacks are extremely effective on organizations that lack cybersecurity awareness. It is most likely that the Montana school district fell prey to a phishing attack that allowed hackers to access their servers and steal the personal information.
To increase cybersecurity awareness in your organization, consider the following:
- Educate employees on phishing schemes
- Report all suspicious emails
- Be wary of overly generic emails
- Be conscious of spoofed email addresses
- Be aware of spearphishing, very sophisticated and highly-tailored attacks
- Ignore and report any emails requesting sensitive information or money
- Do not click on any links or files from an unverified source
- Conduct a cybersecurity training seminar, refresh every semester
- Cover topics such as passwords, two-factor authentication, and phishing schemes
- Keep cybersecurity top of mind by inciting discussions about recent breaches
- Send a quick email out for pertinent breaches found in the news
Through cyber hygiene and awareness, an organization can severely decrease their chance of becoming the victims of a cyber attack. Don’t let your organization be an easy target.
Secure Information, Not Perimeters
Despite the best cyber hygiene and awareness, it is still possible that an intelligent and persistent cybercriminal may find their way into an organization. Organizations need to encrypt and back-up all of their data, so when a cybercriminal gains access they will not be able to steal anything of value.
Given the propensity of phishing attacks and email hacking, organizations should also consider encrypting their emails. This will further protect for sensitive information that is being exchanged through email and not protected by the organization’s network encryption. Encrypted data is useless to cybercriminals because they can’t sell it or use it as leverage to get the organization to pay a ransom. When organizations have their data backed up it also negates the need for them to pay cybercriminals a ransom to restore the stolen information.
When profit is removed from the equation, the cybercriminals lose motivation.
