Getting your teeth into cyber security

teeth_into_cyber_security

There’s not much I love more than a good analogy, and I was struck with one that really tickled me the other day, as I read Tony’s desperate Whatsapp messages about the toothache that had been keeping him up all night.

I wasn’t insensitive enough to point this out at the time (okay, that’s a lie – I absolutely was), but there was something in those messages that made me think of a CEO or Director who’s just found out they’ve been hit by a cyber breach.

Maybe it was the urgency. The level of pain. The uncertainty of what to do next, or how to make it better. And the unspoken knowledge that the worst may still be to come…

Whatever it was, I thought about the analogy some more, and I reckon it’s a really simple way of explaining cyber security – typically misperceived as confusing and hard to understand.

In its simplest form…

For instance, if we look at the core principles behind how both a cyber breach and toothache develop:

  1. You have a weakness
  2. Something bad gets in
  3. Now, you’ve got a problem

And that problem needs to be sorted out. Which might hurt a bit. And probably won’t be cheap. But the longer you wait, the worse it’s going to get and the more you stand to lose.

To me, this just makes it obvious that it’s nuts waiting until then. Especially seeing as there are some really easy steps you can take to protect yourself in the first place – it just takes a bit of proactivity:

1) Start with some basic hygiene

This is all about preventing weaknesses; trying to stop them from developing in the first place. When we’re talking teeth, this is brushing, flossing, gargling with mouthwash or whatever else your jam is.

Similarly, in cyber security there are some basic things that should form part of your daily routine. Just like brushing your teeth, these things should be second nature for everyone in your business, causing minimal disruption and requiring minimal effort, providing a disproportionately huge positive impact.

  1. Make sure you have up to date anti-virus (and that it’s running regular scans)
  2. Make sure your in-built firewall is enabled
  3. Make sure your passwords are strong – and different. A reputable password manager makes this much easier
  4. Always update your software as soon as new fixes are released – and remove software and applications if you no longer use them
  5. Have robust policies and processes in place – and ensure everyone follows them

2) Reduce exposure to things that could cause damage

So our basic hygiene is on point – we’ve got the brushing thing nailed. Happy days! What’s next?

Well for our mouths, we might limit the amount of sugar we consume, to reduce the risk of a weakness (cavity) forming, which could lead to significant pain and problems.

And the same is possible in the cyber security world, too. We can limit our exposure to things that can cause damage or let ‘bad things’ in – some easy ways of doing this are:

  1. Avoid public wifi
  2. Only use secure websites
  3. Restrict the use of removable media
  4. Only download software from legitimate sources
  5. Be alert to phishing attacks

3) Ensure you have visibility

Whether it’s visibility of weaknesses or threats, the quicker you spot a (potential) problem, the more easily – and hopefully painlessly – you can get it sorted. That’s why we have regular checkups at the dentist… And yep – you guessed it – there is an equivalent in the world of cyber security.

The range of choices is slightly more sophisticated in the cyber security world, though. It starts with a snapshot of a single point in time, and ranges right through to continuous monitoring of your network and systems.

  1. Penetration testing
  2. Vulnerability scanning
  3. Cyber security audit
  4. Phishing simulators
  5. SIEM or SOC solutions

4) Fix weaknesses as they appear

For your mouth, this might mean a filling or two. For your business, it could be fixing some code on your website or investing in staff training. Whatever it is, you will have to endure far less pain, expense and heart-ache if you sort it now, before it becomes a bigger problem.

Final thoughts

I’ve bundled quite a lot of potential activities into this analogy but don’t think that means you have to them all of it for it to be effective.

With our teeth, few if any of us actually brush, mouthwash, floss etc every day, even though that would be ideal. However, most of us do at least one of them daily and the others from time to time, and that routine helps us avoid the most likely problems.

And the same goes with cyber security: it’s not an all or nothing thing and you can’t just fix it once and it’s sorted for good. You need to keep working on it and perfection isn’t the point: progress is the key and regular small steps are better than big occasional interventions that are quickly forgotten.