Caithness Map :: Links to Site Map Great value Unlimited Broadband from an award winning provider SAT 26TH JUL 2025    7:07:14 AM BST
This site uses cookies, by continuing to use this site you accept the terms of our privacy policy
Back To Top
Caithness.Org Quick Links
Home
Construction
Leisure
Manufacturing
Misc.
Primary
Professional
Public
Retail
Tourism
Transport
Site Map
 
 
 
 
 
 
 
 
 
 
 
 
 

Feed 2.0 Loading...

Is Cyber Security Part Of Your Business Plan?

10th January 2018

Photograph of Is Cyber Security Part Of Your Business Plan?

The increasing use of digital services in a connected world brings an increasing threat of cyberattack. The Internet that connects systems doesn't discriminate between the type of traffic it allows on the network, it is our responsibility to manage this when we connect to and use the Internet by recognising and reducing the risk as appropriate. Attackers are constantly improving their ability to penetrate systems through social engineering and the opportunity of our increased online presence. The first step for an organisation to counter the threat from cyberattack is to understand their risks and to deal with the question of not "if" it will happen, but "when".

The consequence of a successful attack depends heavily on the nature and scale of the attack and the ability of the organisation to respond to it. Some attacks may result in complete failure of an organisation's systems; some may take money from bank accounts or credit cards; some may compromise data; and some may impact on an organisation's reputation. It is important to remember that not all attacks come through the computer systems, successful telephone based vishing attacks are being seen in ever increasing quantities to demonstrate that our ability to detect them does not depend on computer based security systems.

The majority of cyberattacks are not targeted at specific individuals or organisations but are opportunistic and look to exploit known vulnerabilities in computer systems that can be exploited. Cyber attackers, hackers and writers of malware use programs that are able to automatically exploit known weaknesses, poorly configured systems and weak passwords without consideration of the impact that it will have on the target.

Organisations should not look on the cyber security threat as being a technology problem, it is an organisational risk as it is the organisation that will be disrupted and it should be addressed at this level. Whilst technology is a natural part of the process to secure the organisation, most of the changes that are required in the attitude of employees to the risk and the management of the risk. Security needs to be an integral part of the business process, technology can assist in the implementation and management of the process but it can't fully protect it.

There are some practical and basic steps that individuals and organisations should take in order to better protect themselves:

Do not share passwords between employees or on different services/applications, preventing multiple systems being compromised if one username and password is obtained.

Robust passwords provide one of the first lines of defence against attack and we should think about pass-phrases rather than passwords when choosing our passwords. Policies on password management vary from one organisation to another with some demanding passwords have a minimum length, a mixture of numbers, letters and special characters and that needing to be changed frequently. Consider using passwords that are 12 or more characters long that are based on three or four unrelated words that are punctuated by numbers and characters, e.g. Blue1Fish.Moon.

An organisational password policy indicates that the issue is taken seriously and provide guidelines to employees and users on password selection and management. Consider using one of the many available password managers to make the management of passwords within the organisation easier and secure for everyone as user should be using more than the typical five to six unique passwords.

Regularly educate users on the various attacks vectors that are used, this should include email, social media and the use of social profiling. Deliver regular training sessions to ensure that users are aware of the current techniques being used and consider carryout tests on the systems and users through carryout ethical penetration tests to see how effective this training is.

Restrict access to data to only those that require it

The security threat is not static and neither should the system resilience, to assist in maintaining resilience within the business systems:

Ensure that all systems are properly configured so that only authorised and restricted users have management/administrative rights and that they are only used when needed.

Ensure that system updates and patches are applied promptly after being released.

Install commercial grade anti-virus software and keep it up to date.

Review systems to ensure that they are compliant and manage change to ensure that the system resilience is maintained.

Take regular system and data backups and ensure that the organisation can recover with acceptable data loss.

Implement a recovery plan to ensure that the organisation can get back to the required operational level within an acceptable timeframe.

To assist with this, the National Cyber Security Centre has produced a 10 Steps to Cyber Security resource at https://www.ncsc.gov.uk/guidance/10-steps-cyber-security.

The Cyber Essentials scheme has been developed by Government and industry to fulfil two functions. It provides a clear statement of the basic controls all organisations should implement to mitigate the risk from common internet based threats, within the context of the Government’s 10 Steps to Cyber Security. And through the Assurance Framework it offers a mechanism for organisations to demonstrate to customers, investors, insurers and others that they have taken these essential precautions.

Cyber Essentials offers a sound foundation of basic hygiene measures that all types of organisations can implement and potentially build upon. Government believes that implementing these measures can significantly reduce an organisation's vulnerability. However, it does not offer a silver bullet to remove all cyber security risk; for example, it is not designed to address more advanced, targeted attacks and hence organisations facing these threats will need to implement additional measures as part of their security strategy. What Cyber Essentials does do is define a focused set of controls which will provide cost effective, basic cyber security for organisations of all sizes.

The Assurance Framework, leading to the awarding of Cyber Essentials and Cyber Essentials Plus certificates for organisations, has been designed in consultation with SMEs to be light-touch and achievable at low cost. The two options give organisations a choice over the level of assurance they wish to gain and the cost of doing so. It is important to recognise that certification only provides a snapshot of the cyber security practices of the organisation at the time of assessment, while maintaining a robust cyber security stance requires additional measures such as a sound risk management approach, as well as on-going updates to the Cyber Essentials control themes, such as patching. But we believe this scheme offers the right balance between providing additional assurance of an organisation’s commitment to implementing cyber security to third parties, while retaining a simple and low cost mechanism for doing so. The Scottish Business Resilience Centre maintains a list of organisation that can assist organisations to achieve Cyber Essentials at: https://www.sbrcentre.co.uk/services/cyber-services/cisp-and-cyber-essentials/approved-practitioners/

https://www.sbrcentre.co.uk/services/cyber-services/cisp-and-cyber-essentials/trusted-partners/

HIE is currently working with a range of its clients across the region who are working towards their Cyber Essentials accreditation. This has been running since September and included a one day intensive workshop and 1-2-1 support from a digital adviser to develop a Cyber Resilience plan. Any account managed organisations or businesses interested in this programme should contact their account manager or can email hidigital@hient.co.uk

Computer Security is a vast topic and more information can be read at https://en.wikipedia.org/wiki/Computer_security

 

Related Businesses

 

Related Articles

HIE holding drop-ins for Wick Business Park expansion plansThumbnail for article : HIE holding drop-ins for Wick Business Park expansion plans
People in the Wick area of Caithness are being invited to share their views on proposals to expand Wick Business Park.   Following the successful development of phase one, Highlands and Islands Enterprise (HIE) is planning a second phase of development on land next to the existing business park.  
Salmon farm company to convert waste to useable product
A project to recycle waste at an aquaculture hatchery in Wester Ross has secured up to £630,290 from Highlands and Islands Enterprise (HIE).   Bakkafrost Scotland limited is leading the project, which has a total investment value of more than £2.5m.  
Renewable energy firm ENERCON welcomed to Wick Business Park
Wick Business Park has welcomed wind energy technology company ENERCON as the first occupant of one of four new units completed last year.   ENERCON specialises in designing, producing, installing and servicing onshore wind turbines and has been operating in the Caithness area since 2013.  
New recruits at HIE Caithness and Sutherland teamThumbnail for article : New recruits at HIE Caithness and Sutherland team
Highlands and Islands Enterprise (HIE) has appointed new members to its Caithness and Sutherland team as the agency settles into its new premises and works to expand its client portfolio.   Claire Wilson has joined as head of business growth and investment.  
Applications open for the 2025/26 Scottish Rural Leadership Programme
Businesses in the Highlands and Islands are invited to apply to the 2025/26 Scottish Rural Leadership Programme.   The initiative is designed to empower rural business owners and senior leaders across Scotland with the skills, confidence and strategic insight needed to drive innovation and growth in their communities.  
Recruitment under way for next Chair of Highlands and Islands EnterpriseThumbnail for article : Recruitment under way for next Chair of Highlands and Islands Enterprise
The Scottish Government has begun recruitment to appoint a new Chair for the Board of development agency Highlands and Islands Enterprise (HIE).   Applications are currently being invited through the government's public appointments website with a closing date of 7 July 2025.  
Renewable energy training centre officially opened in InvernessThumbnail for article : Renewable energy training centre officially opened in Inverness
Deputy First Minister, Kate Forbes, has officially opened Aurora's pioneering Renewable Energy Training Centre in Inverness - the only facility of its kind serving the Highlands.   The £1.2m training centre has already demonstrated its importance to Scotland's net-zero ambitions, training to more than 1,000 people in its first year and gearing up to train more than 2,000 workers annually who will be central to the country's renewable energy future.  
Highlands and Islands Enterprise (HIE) will invest up to £24 million at Kishorn Port
A multi-million pound investment is being made in one of Scotland's most strategically important ports.   Highlands and Islands Enterprise (HIE) will invest up to £24 million at Kishorn Port in the west Highlands to enhance its capacity and capabilities, with an expanded dry dock and land reclamation enabling the manufacture of floating offshore wind foundations.  
Commercial diver training company in Argyll to scope expansionThumbnail for article : Commercial diver training company in Argyll to scope expansion
A commercial diver training company in Argyll is exploring the potential to expand the business to include closed bell diver training.   Dunoon based Professional Diving Academy (PDA) has secured £5,000 from Highlands and Islands Enterprise (HIE) to help cover associated market assessment consultancy costs.  
New green training skills facilities open in Stornoway - Fosgladh Goireasan Trèanaidh Sgilean Uaine ann an SteòrnabhaghThumbnail for article : New green training skills facilities open in Stornoway - Fosgladh Goireasan Trèanaidh Sgilean Uaine ann an Steòrnabhagh
The new, state-of-the-art Technology and Innovation Centre at UHI North, West and Hebrides' Stornoway campus officially opened following a £2.3m investment.   It is the first capital project to be delivered under the Islands Growth Deal, a ten-year package that seeks to drive economic growth and the creation of sustainable jobs across Shetland, Orkney and the Outer Hebrides.