Four cybersecurity misconceptions placing your business at risk

Common cyber misconceptions may be preventing your organisation from maintaining a safe online environment, says UNSW Canberra Cyber Director Nigel Phair

Cybercrime is on the rise. In 2019, cyberattacks occurred every 14 seconds, up from every 40 seconds in 2017. Accenture’s 2019 Cost of Cybercrime Study calculated that the organisational costs of these attacks have increased from US$11.7 million (A$16.02 million) in 2017 to a new high of US$13.0 million (A$17.8 million) – a rise of 12 per cent. This can impact organisations from start-ups to multinationals, and even governments.

Despite this, many professionals remain in the dark about what cybersecurity is and how to implement it. According to a survey by antivirus software provider McAfee, 57 per cent of Australian cybersecurity managers have trouble finding staff to join their cybersecurity teams.

“Business [today] is intrinsically linked to the internet, so it’s crucial for businesses to understand threats in the online environment," says Nigel Phair, Director of UNSW Canberra Cyber, a global leader in cybersecurity research and education. Alongside his work in Canberra, Mr Phair provides thought leadership and policy advice on the impact of cybercrime on multinational organisations and governments globally.

Businessman clicks on sign in page appears on screen reflecting a hooded hacker  (1).jpg
All businesses have at least one digital component making them vulnerable to a cyberattack. Image: Shutterstock

According to Mr Phair, there are four main cybersecurity misconceptions that hinder business leaders in maintaining a safe online environment.

1. Not all businesses are at risk of a cyberattack

Since virtually all businesses have at least one digital component – whether a website, email system or computerised database – they are all vulnerable to cyberattacks. “Since all businesses have an online aspect, it seemed appropriate that people learn this integral part of a successful business,” Mr Phair explains.

For Mr Phair and his colleagues, one fundamental aspect is helping business leaders identify risks to their businesses.

“First, we talk about protecting the business value and ensuring the survivability and ongoing measure of the business,” he says. “We also use a risk management framework to make decisions about their cybersecurity protocol and how to implement it,” he says.

2. Viruses are the biggest cyber threat

Although ransomware and spyware attacks tend to attract the most media attention, they are not the most common cyber threats – in fact, according to a study by cybersecurity solutions provider FireEye, 86 per cent of email attacks are free of malicious software, or malware, as it is commonly known.

The two biggest cyber threats are currently phishing attacks and compromised emails.

“Protecting against these ubiquitous threats requires company leaders to quickly recognise them and relay this information to their team"

NIGEL PHAIR

In a phishing attack, cybercriminals attempt to collect confidential data using deceptive emails and websites. An email compromise is a similar but more targeted form of email attack, in which criminals impersonate a prominent company member to convince an employee to provide money or information.

These attacks are incredibly common. One 2019 survey found that 88 per cent of organisations experienced a phishing attack that year, while 86 per cent dealt with an email compromise attack.

“Protecting against these ubiquitous threats requires company leaders to quickly recognise them and relay this information to their team,” says Mr Phair. “The business’ ability to pass on knowledge is crucial.”

3. Antivirus software and firewalls are the only lines of cyber defence

Software plays an important role in keeping digital assets secure, but people – not programs – are a company’s first line of cyber defence.

Email attacks depend on human fallibility, so well-informed employees are a key component of cybersecurity strategy.

Man installing firewall antivirus  on laptop (1).jpg
Antivirus software and firewalls are useless unless employees are well-informed and trained in their organisation's cyber strategy. Image: Shutterstock

“Cyberattacks are not so much a technical problem as a people problem,” Mr Phair reflects. “Everyone in an organisation could be susceptible to a cyberattack, and it’s everyone’s responsibility to protect the digital assets of their organisation. Regular training is a crucial element of any organisation’s cybersecurity strategy.”

Incidents like Uber’s 2018 data leak also highlight the human error aspect of cybersecurity. The breach occurred when two hackers accessed data stored in a third-party cloud service and could have been prevented through access monitoring using readily available software. It was a blind spot in Uber’s cybersecurity strategy that allowed the incident to happen. 

To avoid such oversights, Mr Phair recommends a careful assessment of the data an organisation holds. “You then need to use risk management concepts to work out what data needs to be protected, understand where it is housed, who has access, and the login regime,” he explains. For this approach to be effective, trained individuals must constantly monitor and maintain online security and communicate any potential leads to business leaders.

4. Cyber threats do not vary much

Although phishing and other email threats are the most common forms of cybercrime, it's important to bear in mind that the risks an organisation faces can vary significantly depending on its industry, size, structure, and the kind of data it holds. These threats are constantly evolving.

Twitter office building hq (1).jpg
A recent cyberattack on Twitter allowed hackers to access 130 high-profile accounts including Kim Kardashian, Barack Obama, and Jeff Bezos. Image: Shutterstock

“[Besides phishing,] other risks include attacks on unpatched software, payment systems, and supply chains,” Mr Phair notes. “Leaders need a clear understanding of all these factors as they predict threats and employ a cybersecurity strategy. Elements of this strategy might include staff training, firewalls, or antivirus software,” he adds. “There’s no blanket route to overcoming cyber threats.”

Social media accounts have also recently emerged as a point of vulnerability. A recent cyberattack on Twitter allowed hackers to access the accounts of 130 celebrities, politicians, and businesspeople – including Kim Kardashian, Barack Obama, and Jeff Bezos.

7 recommendations for industry professionals

  1. Treat cyber risk as part of business continuity rather than as a task for an IT team alone.
  2. Map data holdings, storage, access and login processes before allocating controls.
  3. Train employees to recognise phishing and email compromise and establish a process for reporting concerns.
  4. Review payment systems, software, supply chains and social media accounts when mapping points of exposure.
  5. Match cybersecurity controls with the organisation's industry, size, structure and data holdings.
  6. Repeat risk assessment as threats and business systems change.
  7. Give leaders access to cyber risk information so they can make decisions about controls, training and investment.

Republish

You are free to republish this article both online and in print. We ask that you follow some simple guidelines.

Please do not edit the piece, ensure that you attribute the author, their institute, and mention that the article was originally published on Business Think.

By copying the HTML below, you will be adhering to all our guidelines.

Press Ctrl-C to copy