Maybe you’ve seen the above IBM commercial recently. It paints a picture of a world where there are no security breaches and the only news to share is good news. While IBM aspires to that kind of Internet utopia, it’s not the reality most businesses live in. Most recently the social site, Ashley Madison, had a very public data leak. Closer to home in the Twin Cities, Target’s 2013 security breach affected tens of millions of retail shoppers. Lockheed Martin, trusted with some of the world’s most confidential information, was breached in 2011. Each of these companies is an example of a large and established company being exploited online. But, businesses of every size face the daily threat stemming from cyber security failures.
What can go wrong?
‘It won’t happen to us’ is a common sentiment when it comes to cyber security failures. We like to think that our vulnerabilities are few and our risks are low. But, 43% of businesses encountered a data breach in 2013. Protecting your site and your business should be a priority and not an afterthought.
If your cyber security efforts fail like with Ashley Madison or Target, you could face a substantial financial loss and loss of consumer confidence among other things. Attacks aren’t always about stealing data like in those two examples. The presence of malware in your network can slow things down and cause a loss of production. A denial of service attack will shut down your site and prevent any potential leads from converting. A stolen password could lead to entire teams being locked out of crucial day-to-day software. We don’t want any of that to happen to you, and I’m sure you wouldn’t enjoy it either.
What does taking cyber security seriously look like?
Effective cyber security is much more than just purchasing some software and setting up a firewall. There are a lot of moving pieces beyond just protecting and optimizing your website’s code. It extends into how your users interact with your site, how you store data, and how invested your employees are in the process.
Get technical.
Have your developers institute best practices to secure your company and user data. If you ask your users to login and share personal information, make sure to have an SSL certificate installed and ready to go on the server. Create a secure environment for your site’s admin pages with your robots.txt file—to make sure search engines aren’t indexing them. Firewalls, regular site scans, and dozens more pieces are essential parts of the process to keep your site safe. If you’re not the technical type, make sure to get help from talented web developers who won’t cut corners.
Form a culture of data protection.
One sloppy employee or weak password can still bring all of the technical safeguards in the world down. Your company needs to have a culture of cyber security awareness and execution. It starts with the site admins creating requirements for strong passwords, and then employees protecting those passwords. It does no good to have the perfect password if you’re going to leave your computer open when you step away to get more coffee at Starbucks. Or, if you’re in a collaborative environment like ours at Spyder Trap, discourage sharing passwords over Skype and unsecure email. Make software updates mandatory, but limit the average user’s control over downloading new programs and plug-ins to the network. It only takes a very small window for someone with malicious intent to make a big impact on your network.
Stay up to date.
Everyone knows the Internet evolves quickly. Everything happens even quicker with cyber security. Attackers find new ways to exploit vulnerabilities all the time. The IT security industry does its part by coming up with new defenses just as regularly. The most important thing to remember for staying secure online is to never have a ‘set it and forget it’ attitude. Protecting your website and business will keep becoming more and more sophisticated and complex. That complexity makes it imperative to stay on top of things; having a reliable technology partner is one effective way to do that.