CyberSecurity – Are you playing a game of Russian Roulette with your livelihood?

Cybersecurity – The world today is dishing out surreal challenges, the likes of which are rarely seen in a lifetime and yet we are being subjected to two traumatic disasters in really close succession. Having just managed to fight our way through a gruelling two years plus of the Coronavirus pandemic, we are now plunged into the horrors of the Russian invasion of Ukraine.

Right now, the National Cyber Security Centre for the UK and Cybersecurity and Infrastructure Security Agency in the USA, have issued strong recommendations for businesses to ensure their cybersecurity is increased to protect against the very real threat from the Ukraine situation.

We have a duty to keep you, our loyal customers, as safe as possible. So, the following gives you the information, so you can make an informed decision on what you want to do.

But how can Russia’s attack on Ukraine impact my business?

Obviously, the fallout from war always brings its financial burden, but there comes an ever more direct risk that your business is facing. Geographically you may be many thousands of miles from the direct warzone, but as Lindy Cameron, National Cyber Security Centre’s CEO pointed out recently:

“The UK is closer to Ukraine than you might think. While 2,000-odd miles separate us physically … that distance is much shorter in cyberspace – and attacks targeting Ukraine’s digital infrastructure could be felt here in Britain.”

Cameron is urging organizations “to accelerate plans to raise their cyber-resilience in the longer term … to build greater resilience.”

What was good enough yesterday, really is not good enough anymore.

Make sure you know what is going on – 24/7/365

Cybercrime is increasing rapidly. It’s no longer kids in bedrooms, but highly intelligent cyber experts, who are specialists in getting into systems.

They are relentless in their attacks and their favourite time to strike is your downtime: holidays, night-time, weekends…

You need to make sure your guard-dogs are in place 24/7/365. You can’t afford to turn a blind eye.

But how will they get into my systems?

There are many ways that cybercriminals can gain access, but as Cloud solutions, and specifically Microsoft, are the main business systems across the world, it’s obvious we need to make sure any weak areas are covered.

Microsoft 365 is an excellent business solution, but the most sophisticated software is only ever as good as its users. This will always be your weak spot. You can’t be on top of your staff 24//7/365, making sure that they don’t click any rogue links, turn off multi-factor authentication, inadvertently ‘give away’ their usernames and passwords… The list goes on.

You know users shouldn’t use their business accounts for personal use, but are you sure they adhere to this 100% of the time?

What about when they’re out and about and want to catch up with their jobs/emails, etc. That local coffee shop is just the place to do this, but are you sure the wi-fi connection they are using is safe?

Once cybercriminals have gained access, unless you are consistently monitoring for it, you won’t know. They’ll sit hidden in systems, watching and waiting for the ideal time to strike – usually when they can reap the most financial reward, or cause you the most distress!

Do you use apps that link with your Microsoft 365?

I know this sounds confusing and you’re probably thinking, ‘I have absolutely no idea.’

Nor, do you need to know, but the fact is that you probably are. They exist in basic every day business programs like Calendly, Docusign, Microsoft 365 remote backup software …

Whilst these are perfectly legitimate and do not offer a threat, the problem arises when cybercriminals decide to reference these common programs to attempt to gain access. They send utterly convincing, albeit totally fraudulent, emails with messages requesting users to take action to upgrade/secure/enhance the purported software. All the user has to do is follow the simple link and it’s all done.

Your staff will never know they’ve done anything wrong and neither will you, but what they’ve just unknowingly done is granted cybercriminals access to all of your systems.

This is a very popular means of gaining access to systems right now as it gives rapid access without any hacking: the user lets them in themself!

In the paraphrased words of Kevin Mitnick, ex-cybercriminal turned good guy, if he wanted to break into a system, he wouldn’t waste time hacking firewalls, etc, but he’d go the most direct and easiest route – through socially engineering users.

But I educate my staff, so they’d never fall for this!

Isn’t that what we all think?!

However, our experience as experts in this field shows that this is not the case.

Members of staff from all sectors: accountants, solicitors, retailers, teachers … have all fallen prey, clicking on and ultimately inadvertently giving away security details without even knowing.

It doesn’t matter how clever you think you are or how much you educate your staff not to click, we are all vulnerable to our emotions and cybercriminals will use this to their advantage.

So, what can I do to protect my business?

America’s Cybersecurity and Infrastructure Security Agency recommends that if you are using Microsoft 365, you:

“Assign a few (one to three) trusted users as electronic discovery (or eDiscovery) managers to conduct forensic content searches across the entire M365 environment (Mailboxes, Teams, SharePoint, and OneDrive) for evidence of malicious activity.”

I think we all know the sheer extent of having staff doing this, even if you knew how to, would be exhaustive and totally prevent you from getting on with your fundamental business operations.

Be in control – know what’s going on 24/7

However, we have invested in brilliant security monitoring software for Microsoft 365. It will do all of this for you 24/7. Yes, even when you’re sleeping soundly in your bed or enjoying quality time out with your loved ones.

You will be rapidly alerted if anything suspicious is spotted so it can be dealt with before any damage can be done.

It’s like a sophisticated CCTV and alarm system for your cyberworld.

What’s more alongside the alerts, you can see everything that is going on in your Microsoft 365 systems, with clear, detailed reports, showing key security information: what is shared with who, who has access to what mailbox, etc, etc.

You will be in control, leaving nothing to chance!

Is it going to cost a fortune?

With prices starting from only £50 the question is how can you afford to be without it?

What’s the next step?

If you want to make sure your systems are protected as soon as possible, just call and we can schedule a conversation

Government Information

You can follow the NCSC and their commentary on Russia cyberthreats here:

UK government assess Russian involvement in DDoS attacks… – NCSC.GOV.UK

Back to Blog