Why cybersecurity is about culture as much as technology
Blog by Rhys Madoc CEO, UHY International
In the post pandemic world of work, robust cybersecurity defences are more crucial than ever.
That is not saying anything that most of us don’t know, but it is worth repeating. The pandemic has accelerated digital transformation, making us all much more reliant on online tools and services than we were just two years ago.
In our profession, we have seen a significant shift to using cloud-based bookkeeping software; and our clients expect to be able to contact us over Zoom, Teams or chat, as well as in person. We store more critical data in digital strongrooms, either in the cloud or on in-house servers.
Across the corporate world, reputations, revenue and even the futures of businesses rely on being able to keep that information safe. That is not an easy task. Cybercriminals are a determined foe.
Doing the simple things – every time
However, as determined as the criminals are, the reputation of cybercrime can sometimes exceed its reality. Cybercrime is rarely rocket science. The things you need to do to foil most attackers are actually quite simple – you just need to do them again, and again, and again.
That means not just investing in an enterprise grade firewall, but making sure it is always updated to the latest version. It means backing up data on a daily basis. It means buying and applying Virtual Private Network (VPN) licences for employees connecting to your network remotely and making sure they use them.
And perhaps most of all, it means making caution routine. Deleting an email that contains a link you don’t recognise once is not enough. You have to avoid clicking suspicious links every time you encounter them, from now until forever.
That is a tough ask, because it requires constant vigilance. Drop your guard on just one occasion and the hackers might be in.
The holistic approach to cybersecurity
That stark truth is confirmed by statistics. A recent report found that 85% of data breaches have a human aspect (source: Verizon, Data Breach Investigations Report 2022). The average cost of a data breach, meanwhile, is an eye watering USD 4.24 million according to IBM (source: IBM.com/security).
How do you avoid the calamity of a major cybersecurity incident? It takes a holistic approach, which certainly includes technology, and might require third party support.
Many UHY member firms around the world now offer cybersecurity as a professional service. Our US firm, for example, operates a rapid response unit, which has a formidable reputation for forensically investigating security breaches and containing threats before significant damage can be done.
Education is your first line of defence
But whatever else you do, your cybersecurity strategy absolutely must include employee education. In one telling study, 61% of employees failed a cybersecurity quiz, and 60% of those that failed said they felt safe from online threats. (source: talentlms.com cybersecurity survey).
In my opinion, that sort of misplaced confidence is as big a threat to your organisation as an unpatched server. Cybersecurity training should now be compulsory for all employees, as part of a process of continuing learning. Annual refresher courses should cover at least the basics, from recognising phishing attacks and securing mobile devices to connecting securely to your network from outside the office.
Or to put it another way, cybersecurity needs to become a habit. Your resilience to cyber attacks depends on the continuous vigilance of every member of your organisation.
So put the tools in place, from firewalls and antivirus software to intrusion detection and prevention systems. But remember that cyber resilience is as much about instilling a culture of caution as it is investing in the latest technology. As an organisation, you are only as strong as your weakest link.
You may also be interested in
/ News / Cyber Resilience
Cyber Resilience
Why cybersecurity is about culture as much as technology
Blog by Rhys Madoc CEO, UHY International
In the post pandemic world of work, robust cybersecurity defences are more crucial than ever.
That is not saying anything that most of us don’t know, but it is worth repeating. The pandemic has accelerated digital transformation, making us all much more reliant on online tools and services than we were just two years ago.
In our profession, we have seen a significant shift to using cloud-based bookkeeping software; and our clients expect to be able to contact us over Zoom, Teams or chat, as well as in person. We store more critical data in digital strongrooms, either in the cloud or on in-house servers.
Across the corporate world, reputations, revenue and even the futures of businesses rely on being able to keep that information safe. That is not an easy task. Cybercriminals are a determined foe.
Doing the simple things – every time
However, as determined as the criminals are, the reputation of cybercrime can sometimes exceed its reality. Cybercrime is rarely rocket science. The things you need to do to foil most attackers are actually quite simple – you just need to do them again, and again, and again.
That means not just investing in an enterprise grade firewall, but making sure it is always updated to the latest version. It means backing up data on a daily basis. It means buying and applying Virtual Private Network (VPN) licences for employees connecting to your network remotely and making sure they use them.
And perhaps most of all, it means making caution routine. Deleting an email that contains a link you don’t recognise once is not enough. You have to avoid clicking suspicious links every time you encounter them, from now until forever.
That is a tough ask, because it requires constant vigilance. Drop your guard on just one occasion and the hackers might be in.
The holistic approach to cybersecurity
That stark truth is confirmed by statistics. A recent report found that 85% of data breaches have a human aspect (source: Verizon, Data Breach Investigations Report 2022). The average cost of a data breach, meanwhile, is an eye watering USD 4.24 million according to IBM (source: IBM.com/security).
How do you avoid the calamity of a major cybersecurity incident? It takes a holistic approach, which certainly includes technology, and might require third party support.
Many UHY member firms around the world now offer cybersecurity as a professional service. Our US firm, for example, operates a rapid response unit, which has a formidable reputation for forensically investigating security breaches and containing threats before significant damage can be done.
Education is your first line of defence
But whatever else you do, your cybersecurity strategy absolutely must include employee education. In one telling study, 61% of employees failed a cybersecurity quiz, and 60% of those that failed said they felt safe from online threats. (source: talentlms.com cybersecurity survey).
In my opinion, that sort of misplaced confidence is as big a threat to your organisation as an unpatched server. Cybersecurity training should now be compulsory for all employees, as part of a process of continuing learning. Annual refresher courses should cover at least the basics, from recognising phishing attacks and securing mobile devices to connecting securely to your network from outside the office.
Or to put it another way, cybersecurity needs to become a habit. Your resilience to cyber attacks depends on the continuous vigilance of every member of your organisation.
So put the tools in place, from firewalls and antivirus software to intrusion detection and prevention systems. But remember that cyber resilience is as much about instilling a culture of caution as it is investing in the latest technology. As an organisation, you are only as strong as your weakest link.
You may also be interested in
Share This Post
Related insights
Early careers – St Barts Newbury careers fair
Could Inheritance Tax be Abolished in the 2024 Budget?
Tax Relief for Expenditure on Plant and Machinery
Tech insights: What should you be aware of ahead of filing an R&D claim?
Autumn Statement Summary 2023
Be the disrupter
Do you have a side income?
Spooky goings-on in Newbury
FAQ on the Let Property Campaign for Landlords
Why Changing Your Auditors Could Be the Best Move for Your Business
Frighteningly Good Tax Tips to Scare Your Financial Worries Away
Act now to reduce your 23/24 tax liability
How the Xero ecosystem can revolutionise your small business
What is the Let Property Campaign for Landlords?
Why haven’t you outsourced your payroll yet?
Common Mistakes in Cryptotax Filings and How to Avoid Them
Swindon accountants raise £506 for Wiltshire charities
Purposeful Business
Advanced Cryptotax Planning in the UK
Merger of R&D Tax Relief Schemes to go ahead
HMRC “dawn raids” surge 36%
How can you improve your employee financial wellbeing?
Tell Me More – HMRC to require more information from taxpayers
5 ways to avoid penalties on your Self-Assessment Tax Return
The importance of budgeting for charity trustees
Don’t Get Caught in the Child Benefit Tax Trap
How AI is Revolutionising Fundraising, Donor Management, and Financial Forecasting for UK Charities
Beware the SDLT sharks
Thought Leadership
Working from home and the £6 per week allowance
Do you need a further incentive to get an electric company car?
Effective Risk Management for Academy Trustees
Common cryptotax scenarios IRL
Should you buy or lease a company car?
Are you a business superwoman?
UHY Prosper magazine issue 7
Hungerford accountants go crazy
Embracing Technology for Business Growth
7 simple steps to reduce your company’s tax liability
Additional information required for R&D claims from 1st August 2023
Farage fiasco forces Government to act on banks
A day at the races
Grants – are you eligible?
How to set up a successful business in the UK
Working Capital Finance – can it help with cash flow?
Innovation Loans Future Economy competition – round 10
Here, there and everywhere
R&D tax credit claims – where are we now?
8 Tips for Effective Financial Management in Academies
What if I get my taxes wrong?
Is your charity paying too much tax?
Senior leadership team meet UHY colleagues
Looking Into the Patent Box: A Game-Changer for Businesses
4 Advantages of Filing Your Tax Return Early
Building life skills with work experience
The Importance of Choosing the Right Accounting Software for Your UK Business
Innovate UK Smart Grants
Keeping pace with inflation
Can you rely on HMRC guidance?
Charities gain new powers as more legislative changes come into force
Talk to us
Newbury: 01635 555666
Abingdon: 01235 251252
Swindon: 01793 610008
Hungerford: 01488 682546