Understanding the Risks
Client data breaches make headline news, but potential damage to an organisation by the release of sensitive employee data (salaries, home addresses, appraisal content) is also potentially cataclysmic.
If your HR or Talent team are processing large volumes of resumes it’s all too easy to open an infected attachment or malicious link (e.g. a LinkedIn profile or external portfolio) which can be a vector for injecting malware into your corporate network.
What are the types of impact your business faces?
Direct financial impact - e.g. fines, actual theft of funds
Damage to reputation
Loss of data - industrial espionage
Malicious damage to data, ransomware

People and Culture
Talk about being a ‘Security First’ business. Foster an environment where everyone in the organisation is talking about security issues and acting on them is a priority.
Instil your security culture immediately with your new starters - ask the senior management team to get personally involved in discussing the importance of cyber awareness.

Processes
Undertake independent security audits, identify high risk and priority data - who can access it and how do you protect it.
Set-up an email address for reporting security breaches - available to employees, customers & other third parties.
Have processes in place to fix issues quickly.
Regularly update security processes.
For instance, law firm Mishcon de Reya recently instructed employees to mute or disable devices in their home such as Amazon Echo and Google Home, in the wake of reports that such devices have been found to eavesdrop on sensitive conversations.

Solutions
Train your employees to ensure they treat sensitive information responsibly and guard against social engineering vulnerabilities such as phishing attacks.
Create a culture of listening - if someone points out a vulnerability, don’t ignore them - make sure they have a clear channel for communicating their concerns - and reward this activity.
Invest in experienced Cyber Security personnel.
Make security experience one of the key criteria when assessing the suitability of new hires.

What next?
We've devised a number of workshops aimed at people across a variety of roles and technical backgrounds to assist them in fortifying their organisation's systems and processes.
In-depth Cyber Awareness training for your whole organisation
Infosec Overview for senior management and decision makers
Secure Web Application Development training for your IT developers
DevSecOps training for your DevOps, Developers and SREs
Get in touch to find out how we can help you strengthen your defenses.