With cyber-attack regularly in the news, the Information Commissioner’s Office (ICO) is reminding businesses to check they have appropriate security measures in place to protect personal information.
Businesses experienced an estimated 7.7 million cyber-crimes over the past year, according to government figures. Most small businesses hold personal information and conduct business digitally, so cybersecurity must be a priority.
“Cyber-attacks have been hitting the headlines again recently, serving as a timely reminder for all businesses to check their own security measures. When people share their personal information with your company, they need to feel confident you’ll do as much as possible to keep that information secure,” Ian Hulme, Executive Director for Regulatory Supervision at the ICO, said.
“While cyber-attacks can be very sophisticated, we find that many organisations are still neglecting the very foundations of cybersecurity. As the data protection regulator, we want to support organisations to get this right and these simple steps will help to protect both your customers and your business.”
The ICO has provided some practical advice for businesses and staff to take heed to improve data security and resilience:
Back up your data
Regularly back up your data; encrypting data, keeping external storage away from the workplace, and locking data storage units away is vital. Checking that back-ups worked is also critical.
Strong Passwords and Multi-Factor Authentication
Using strong and unique passwords should be a must across all accounts and devices.
Where possible, multi-factor authentication should also be employed.
Vigilance
Vigilance is critical – this means being aware of ones surroundings when it comes to discussing private information or accessing private documents, but also being wary of suspicious emails amid the rise in sophisticated phishing and social engineering tactics.
Protecting your device when unattended is also important – this can be achieved as simply as using a lock screen.
Anti-virus and Malware Protection
Keep these up-to-date, the ICO warns. These should be installed on all devices, even those used at employees’ homes.
Securing Wi-Fi
Using public or insecure connections can but data at risk. Always use secure connections, and consider using a Virtual Private Network (VPN) if a public network is your only option.
Recommended
- ICO Warns of Increasing Cyber Threats of Students
- Why Are Young People Becoming Cyber-criminals?
- Four Arrested in Investigation Into UK Retail Cyber-attacks
Limit Access
While data silos should be avoided, putting access controls to information is vital to data security. Suspending access to systems for those who have left your firm or those on long leaves of absence is recommended.
Take Care When Sharing
Sharing a screen in a virtual meeting should be done with care to avoid sharing documents that need to remain private. Checking to ensure emails are also not shared is important using various email tools.
Don’t Keep Data Longer Than Needed
Disposing of data after it is no longer of use is important to free up storage space and also puts less data at risk of being stolen in a cyber-attack or breach.
Secure Disposal
Personal data should be wiped from all devices when they are being disposed of in order to keep this data secure.





