It is rarely economically viable for small-to-medium sized businesses to employ an in-house IT security team. Often only one person is in charge of an entire organisations cyber security, and sometimes this person isn’t even a permanent or full-time employee.
It is true that a single good IT employee can help, but even the best will inevitably miss something when working on their own, particularly if they have to resolve multiple issues and all of them are urgent.
With this in mind, it’s a good idea to establish a few essential security checks:
Renew your website’s security certificate
Any website that requests or processes user data must have an SSL (Secure Sockets Layer) certificate. This is a digital certificate that authenticates the identity of a website and encrypts all information collected by it.
SSL certificates are an essential aspect of a business’ website. Without one, almost all modern browsers will warn their users that the website is unsafe, scaring away potential customers.
Your current website most likely has an SSL certificate, but their validity period is limited. Depending on the certification authority, SSLs will need to be reissued every three, six, or twelve months. We strongly recommend researching the last time your SSL was renewed, the length of its validity period, and then setting a reminder when the certificate is due for renewal.
Update essential software & router firmware
Older, end-of-life software is likely to have more vulnerabilities, and is likely to be exploited by cyber criminals. This makes it critical to keep all software up-to-date.
But it is not just the everyday devices that need regular updates. Routers also have built-in software, know as firmware, which will contain vulnerabilities. Unlike software on workstations, routers do not send notifications when their firmware is out of date, so updates have to be performed manually.
As a result, it’s important to inventory all business network equipment, and every few months check your administration console to see if a new version of your existing router firmware has appeared. If you are unable to check for updates through the router itself, check the manufacturer’s website regularly.
If you are notified that your router is end-of-life and no longer supported with regular updates, you should consider replacing the device, as without regular updates, the router will always represent a vulnerability in your organisation’s network.
Workstation operating systems have procedures in place to notify users when new updates become available to install. However, users commonly ignore or put off essential updates, leaving them vulnerable to cyber attacks.
Ensuring that all software on all devices within a business are regularly updated, whilst also managing other tasks, is an impossible goal for a single IT technician. If you have concerns about regular patch management within your organisation, contact a professional and reliable Managed Security Service Provider (MSSP), such as TecSec.
Revoke admin privileges from unnecessary users
A recently dismissed employee can severely disrupt a business if allowed to retain access to their accounts, data, and the business network. To avoid this, ensure that your organisation has strict access procedures in place when a member of staff leaves.
A critical procedure is to revoke all access rights immediately after dismissal. This includes changing passwords on user accounts, and on locked entry points into your organisation’s building.
But it’s also important that security action is taken regularly, and not just when an employee leaves. Regularly audit all accounts and user permissions. The same security risks apply when a member of staff moves to a different role or department as when they leave the company. When moving internally, employees often retain access rights that they no longer need. Any unnecessary privileges held by staff can dramatically increase the damage a cybercriminal can cause if they gain access to your network.
Regularly back up your data
Backing up your data has always been a good idea. It helps protect your organisation’s daily operations from cyber attacks, careless employees, natural disasters, and other hazards. It is possible to manually backup all of your data, but it’s much safer and convenient to schedule regular, automatic backups with an third-party supplier.
Even if you are currently backing up your data automatically, you should carry out a number of checks with your provider. How often are they being carried out? Are the backups always successful? What security measures are in place to prevent malware being backed up alongside your data?
Due to the importance of your backups being reliable and secure, make sure to only entrust your data to a Managed Security Service Provider (MSSP). Not only will they ensure that your backups are protected by additional layers of cyber security, their internal network will be protected by the latest and most effective cyber security software, such as AI-driven threat intelligence and XDR platforms. To find out more, contact an industry-leading MSSP here.
Carry out regular staff cyber security training
85% of all data breaches involve a human element, typically a member of staff being tricked by a cybercriminal into gaining access to their network.
An organisation’s defence against cyber attacks always begins with their staff, and yet only 11% provided cyber security training or a security awareness program to their employees in 2020. That’s one of the many reasons that cyber attacks have grown exponentially over the last five years, with at least 40% of UK businesses experiencing a major cyber attack in 2022 alone (GOV.UK, 2022).
However, like all of the checks on this list, ensuring that your staff are up-to-date on the latest tricks and scams used by cybercriminals is too much to ask of a single IT technician.
MSSPs (Such as TecSec) understand the cyber security risks that untrained staff present to organisations. That’s why we’re offering a free anti-phishing training session for organisations across the UK. The session will involve all staff receiving a realistic phishing email with a fake scam link. At the end of the session, your organisation will receive a detailed report stating which employees were fooled by the fake scam, and offer advice on how to mitigate the risk presented by future attacks.
To take part, just fill out the contact form below, and we’ll be in touch shortly:







