app

Cybersecurity

12 Password Best Practices

With the business world heavily reliant on digitalization in this day and age, the use of technology in your organization is unavoidable. Although technology can undeniably give your business an advantage in increasingly competitive markets, there are many troublesome areas to keep an eye on. This is why interest in cybersecurity has risen in recent years.

Password protection is the best place to start if you want to ramp up your cybersecurity. Setting a password to secure an entity’s data is called password protection. Only those with passwords can access information or accounts once data is password-protected. However, because of the frequent use of passwords, people tend to overlook their significance and make careless mistakes, which could lead to breaches in security. This makes it imperative for businesses to devise strategies to educate employees about best practices when using passwords.

6 Password “Don’ts”

Protect the confidentiality of your passwords by following these six password “don’ts”:

1. Don’t write passwords on sticky notes
Although you may feel that writing down passwords improves password protection and makes it more difficult for someone to steal your passwords online, it can make it easier for someone to steal your passwords locally.

2. Don’t save passwords to your browser
This is because web browsers are terrible at protecting passwords and other sensitive information like your name and credit card number. Web browsers can easily be compromised and a wide range of malware, browser extensions and software can extract sensitive data from them.

3. Don’t iterate your password (for example, PowerWalker1 to PowerWalker2)
Although this is a common practice among digital users, it is unlikely to protect against sophisticated cyberthreats. Hackers have become far too intelligent and can crack iterated passwords in the blink of an eye.

4. Don’t use the same password across multiple accounts
If you do so, you are handing cybercriminals a golden opportunity to exploit all your accounts.

5. Don’t capitalize the first letter of your password to meet the “one capitalized letter” requirement
Out of habit, most of us tend to capitalize the first letter of our passwords to conform with the “one capitalized letter” requirement. However, hackers are aware of this, making it easy for them to guess the capitalized letter’s position.

6. Don’t use “!” to conform with the symbol requirement
However, if you must use it, don’t place it at the end of your password. Placing it anywhere else in the sequence makes your password more secure.

6 Passwords “Do’s”

Protect the confidentiality of your passwords by following these six password “do’s”:

1. Create long, phrase-based passwords that exchange letters for numbers and symbols
For instance, if you choose “Honey, I shrunk the kids,” write it as “h0ney1$hrunkth3k!d$.” This makes your password harder for hackers to crack.

2. Change critical passwords every three months
Passwords protecting sensitive data must be handled with caution because there is a lot at stake if they are compromised. If you use a password for a long time, hackers may have enough time to crack it. Therefore, make sure you change your critical passwords every three months.

3. Change less critical passwords every six months
This necessitates determining which password is crucial and which is not. In any case, regardless of their criticality, changing your passwords every few months is a good practice.

4. Use multifactor authentication
It’s your responsibility to do everything in your power to keep nefarious cybercriminals at bay. One of the best approaches is to barricade them with multiple layers of authentication.

5. Always use passwords that are longer than eight characters and include numbers, letters and symbols
The more complicated things are for hackers, the better.

6. Use a password manager
A password manager can relieve the burden of remembering a long list of passwords, freeing up time for more productive tasks. Need a password manager? We can help. Call today for a complimentary consultation 904-559-1600 x 915

Adhering to password best practices requires constant vigilance and effort on your part. As a result, it is best to work with an expert managed service provider (MSP) like us who can help you boost your security and put your mind at ease. Contact us for a no-obligation consultation.

Balancing a Proactive and Reactive Approach to Cyber Incidents

A cyber incident is a type of security event that can harm a business like yours. Ranging from data breaches and system failures to malware attacks and phishing scams, these incidents can hinder productivity, revenue growth, and customer satisfaction.

In most cases, a cyber incident will result in data loss or downtime. This can include loss of confidential information, customer data or business records. In some cases, a cyber incident can also cause business interruption or financial loss. Download our Infographic on Cybersecurity and Business to learn more.

We can all agree that no one wants their business to be hacked. A single cyberattack can rob you of your time, money and peace of mind. In addition to getting systems operational and data restored, you have to let all affected parties know that their data may have been compromised. This can be a difficult situation to navigate for anyone, but it doesn’t have to be the end of the world.

In this blog, we’ll provide you with proactive and reactive approaches to tackle an attack, cope with the aftermath of a hack and prevent future incidents.

Balancing a Proactive and Reactive Approach to Cyber Incidents

Proactive Approach to Cyber Incidents

By taking these proactive steps, you can help protect your business from the devastating consequences of a cyberattack:

Routinely update your passwords

It’s critical to update your passwords regularly to help keep your accounts safe. By updating your passwords every six months, you can help protect your accounts from being hacked.

Here are a few tips on how to create a strong password:

  • Use a mix of upper and lowercase letters, numbers and symbols
  • Avoid using easily guessable words like your name or birthdate
  • Use a different password for each account
  • Don’t reuse passwords

Use a virtual private network (VPN)

A virtual private network encrypts your company’s data and gives you complete control over who has access to it. This can aid in the prevention of data breaches and the protection of your company’s information. However, make sure to select a reputable provider offering robust security features.

Conduct regular security awareness training

As a responsible business executive, you must ensure that your company’s security awareness training program is comprehensive, engaging and adaptable to new threats. In today’s digital age, this is critical to protect your business.

Run regular phishing tests

Phishing is a type of cyberattack that employs deceitful techniques to try and obtain sensitive information from users or cause them to download malicious software. Phishing attacks can be highly sophisticated and challenging to detect, which is why it is essential to periodically test your employees to assess their vulnerability to this type of attack.

Reset access controls regularly

It is crucial to regularly reset access controls to prevent unauthorized access to protected resources. This helps to ensure that only authorized individuals have access to sensitive information. Resetting access controls can be done manually or with automated tools.

Use multifactor authentication (MFA)

Multifactor authentication is a security measure that requires your employees to provide more than one form of identification when accessing data, reducing the likelihood of unauthorized data access. This can include something they know (like a password), something they have (like a security token) or something they are (like a fingerprint).

Before we move on, take note of the cybersecurity training topics recommended by the Small Business Administration (SBA) for all small businesses:

  • Spotting a phishing email
  • Using good browsing practices
  • Avoiding suspicious downloads
  • Creating strong passwords
  • Protecting sensitive customer and vendor information
  • Maintaining good cyber hygiene

Reactive Approach to Cyber Incidents

The National Institute of Standards and Technology’s (NIST) reactive incident response framework covers the following five phases:

Identify

To develop an effective incident response plan, security risks must be identified. This includes, among other things, threats to your technology systems, data and operations. Understanding these risks allows you to respond to incidents more effectively and reduce the impact of security breaches.

Protect

To protect your company, you need to develop and implement appropriate safeguards. Security measures to guard against threats and steps to ensure the continuity of essential services in the event of an incident are examples of safeguards.

Detect

Detecting anomalies, such as unusual network activity or unauthorized access to sensitive data, are needed to limit the damage and get your systems back up and running faster following an incident.

Respond

A plan to respond to detected cyber incidents is critical. This strategy should include breach containment, investigation and resolution strategies.

Recover

To minimize disruption, you must have a plan to resume normal business operations as soon as possible after an incident.

Balancing a Proactive and Reactive Approach to Cyber Incidents

Implementing the above proactive and reactive steps requires time, effort and skillsets that are possibly beyond what you can commit to at the moment. However, you can still accomplish this by collaborating with TruTechnology as your IT service provider. Our experience and expertise may be just what you need. Feel free to reach out to schedule a no obligation complimentary technology consultation here.

Also, to walk you through incident prevention best practices, we have created a checklist titled “Cyber Incident Prevention Best Practices for Small Businesses,” which you can download by clicking here.

What Is Cybersecurity?

Cybersecurity is a set of practices, processes, and technologies used to protect computer systems and networks from any sort of breach, damage, or theft of data, hardware, or software. 

In short, cybersecurity solutions ensure that no unauthorized users enter your system or interfere with it.

According to Security Intelligence, companies lost around $600 billion in 2017 alone due to the rampant increase in cybercrimes that affected businesses both large and small. So it is crucial, now more than ever, to have firewalls and security checks in place to protect not only important data, but also the software infrastructure of your business.

If you’re a small business and think you’re not at risk, think again. A recent report found that more than two-thirds of companies with fewer than 1,000 employees have experienced a cyberattack, and 58 percent have experienced a breach. That same report found that 60 percent of small businesses could go out of businesses due to financial and operational damages associated with a cyberattack. 

What Is Cybersecurity?

The Impacts of a Cyber Attack

In order to understand the importance of cybersecurity, you need to understand the short-term and long-term impact an attack can have on you and your business. 

Short-Term Impacts

Attacks like DoS (denial of service) or ransomware have the ability to completely shut down the operation and functionality of your business. It can even prevent your customers from accessing your services and divert traffic to unknown sources that could be harmful or malicious in nature, which doesn’t just disrupt your business, but also destroys your reputability. Similarly, with ransomware, you can lose customer, employee, or statistical data that can only be retrieved after paying a ransom amount to the attackers. Such attacks can leave you economically and operationally paralyzed.

Long-Term Impacts

Cyberattacks can destroy a business’s reputation. If a business keeps ignoring breaches of data or disruptions in services, then it’s more likely to lose new and existing customers, especially if their competition is taking steps to protect their customers and their data. If you’re trying to build a good rapport with your clients, you have to ensure their privacy and safety. Remember, cyber attacks don’t just impact your business — they often impact your clients as well. You don’t want to put your customers at risk of data breaches, and you don’t want to open yourself up to a potentially financially crippling lawsuit.

Protect Your Business Against Cyberattacks

In today’s world, cyber attacks are everywhere, and they can happen to any company, large or small.  If you want to protect your business, the key is to stay proactive. Plan ahead of time on how to best prevent potential cyber attacks. One way to do this is by hiring a trusted IT company that can help you:

  • Protect your business from security risks, like data breaches, data loss, and ransomware.
  • Plan for predictable and predetermined technology outcomes.
  • Increase your confidence and productivity with technology you know is going to work.
  • Receive protection and support from skilled IT professionals, 24/7/365.

Tired of searching for IT support companies in Jacksonville, FL? Schedule a call with our team to assess your current level of security and protection or sign up to receive a FREE dark web scan today. Experience business IT services done right.

Tony Haskew

Project Engineer

Tony Haskew has 15+ years of experience in the IT field. He started working as a web developer in the 90’s and over the years migrated into the administration of systems and infrastructures of companies. 

Tony enjoys working on new technology and finding new ways to address old issues in the management of IT systems.

Outside of work, Tony is a 3D printing enthusiast, commission painter, and enjoys spending time with his family.