As the name suggests, this is a Blog about security and risk for small organisations where we aim to provide information on Digital Safety Skills for SMO's and raise their skill levels. We want to demystify risks and security for people with little or no security backgrounds.
Cyber Essentials Certification - Secure Configuration
All your operating systems, apps, software and services you use must be configured correctly to protect you from attacks. Secure Configuration of user and system devices and servers must enable you to protect these assets and know when there has been a compromise.
Cyber Essentials Certification - Gateways & Firewalls
An Organisation’s Internet Gateways (mainly routers and firewalls) are usually packaged in with modems as single devices and enable access to the Internet. Firewalls help control the flow of data coming into and out of an Organisation. Together these devices play a big role in the security of a Small Organisation’s network.
Cyber Essentials Certification - Introduction
Previously, in many episodes, we’ve mentioned Cyber Essentials Certification as a way to demonstrate a level of cyber security controls. But what is it and how does an SMO get it, can they get it working on their own or do they need an expert? This is the first of our seven-part series on How to Certify in Cyber Essentials Basics, without paying someone else to do the work for you.
Monitoring Employees in SMOs
Small and Medium-sized Organisations sometimes have issues which result in a thinking that they should monitor what employees are doing. These issues may be well founded in many cases, but the fact remains that there is often a need to monitor what is happening on the network. In this Blog we look at the right approach to employee monitoring for SMOs
Social Media and Cyber Security in SMO
Social media has grown over the last fifteen years from being something you used occasionally to being something that some people rely on to do just about everything on. Social media sites and apps have included services and functionality to enable users to interact with brands and personalities in ways that were never possible.
Website Security for Small Organisations
People read or hear about breaches in the press on a regular basis, and website breaches are one of the largest categories of breaches that take place. These don't just affect large corporates, they affect Small Organisations as well, especially since they don't not have the expertise to secure their websites. Here we look at what Small Organisations can do to secure their websites.
Safe & Secure Internet Browsing
As web development has matured so to have the applications and interfaces of websites and the browsers used to view and access them. The fact that we can do so much more on the web now than ever before comes with greater opportunities for criminals. Here, we go though some of the things people can do to ensure that they are browsing more safely.
Ensuring Secure Supply Chains for Small Organisations
For small organisations to keep large enterprise customers they must make sure that their supply chain is secure, consistent and not affected negatively easily. To do this successfully they have to invest in processes similar to those used by their enterprise customers. Here we explore some of those considerations for small organisations, so that you are not comparing apples to pears.
Getting and Keeping Enterprise Customers with Security
Today's enterprise customers are more attuned with risk and security and because of that they want to work with suppliers which take security seriously. This is especially so as there have been many high-profile breaches which originated from a third-party supplier. So, the best way that Small Organisations can get and keep enterprise customers is to demonstrate that they understand risk and security.
Getting Started with Security in a Small Organisation
Get started with your Organisation's Security Programme! The hardest part of anything is often getting started, whether it is a personal fitness habit or getting started with our organisation's cyber security protection.
Security and Risk topics we cover
Managing Security Risks
Identifying threats and risks to organisations
- Identifying assets specific to small and medium-sized organisations
- Tools, services and controls small and medium-sized organisations can use:
- Email security issues for organisations
- Ransomware risks to organisations
- Network security for small organisations
- Risks and strategic and tactical approaches to security from a 10 to 50 to 250 employee company and beyond.
Security and Risk Questions we cover
- How to get started in managing security risks?
- What are the quick wins for protection?
- Which assets are attackers after?
- Which assets details should we keep records of?
- How can we get through our Cyber Essentials Certification without having to pay an external consultant?
- What is the best way to share data with our customers and partners?
- What should we be doing about data protection to comply in our country?
- What are the best back-up tools for a small organisation?
- How do we choose a managed security service provider?
- How to choose authentication tools for your organisation?
- At what point do we need to employ security staff?
- How to use best security practices for a competitive edge?
- How to decide which options provide better benefits?
Free security and risk resources we are providing
- Complete Cyber Essentials Asset Register spreadsheet with:
- Computer details
- Server details
- Mobile devices
- Network devices
- Printers and scanners
- Other devices
- Special bonus includes other Intellectual assets tab not for Cyber Essentials Certification
- Template policies
- Action lists.
This Blog is aims to help small and medium-sized organisations to raise the bar and reduce attacks to their organisations by taking effective actions to protect them. We want to help make being secure an easier option to take than the insecurity resulting from not taking any action. We endeavour to make as much security and risk information as freely accessible as possible for all SMO's. If you have any pressing issues that you would like us to cover for other organisations which may be experiencing similar challenges to you, please get in touch with us through our contact us page, or if you are a Registered or Subscribing User please use the messaging tool provided.