{"id":56777,"date":"2023-06-20T16:19:42","date_gmt":"2023-06-20T08:19:42","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=56777"},"modified":"2023-06-20T16:19:45","modified_gmt":"2023-06-20T08:19:45","slug":"small-and-medium-businesses-remember-your-own-employees-might-cause-cyber-compromise","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2023\/06\/20\/small-and-medium-businesses-remember-your-own-employees-might-cause-cyber-compromise\/","title":{"rendered":"Small and medium businesses \u2013 remember: your own employees might cause cyber compromise"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><em>By Adrian Hia<\/em><br><em>Managing Director for Asia Pacific, Kaspersky<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Many small or medium businesses think they can do without a cybersecurity solution since they believe they cannot fall prey to cybercriminals. However,<a rel=\"noreferrer noopener\" href=\"https:\/\/www.strongdm.com\/blog\/small-business-cyber-security-statistics\" target=\"_blank\">\u00a0the recent study<\/a>\u00a0reports that nearly 46% of all cyberattacks are targeted at SMBs. And, according to the data from the World Economic Forum,\u00a0<a rel=\"noreferrer noopener\" href=\"https:\/\/www.weforum.org\/agenda\/2020\/12\/cyber-risk-cyber-security-education\" target=\"_blank\">\u00a095% of cybersecurity breaches<\/a>\u00a0are attributed to human error.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These figures claim that small and medium-sized businesses may be unaware that their employees could unintentionally \u2013 or even deliberately \u2013 cause harm to their company\u2019s \u201cwell-being\u201d. Some improper behavior might lead to financial losses, reputational damage or decreased productivity of the whole business.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s explore how employees, their negligence, or vindictive feelings may affect cybersecurity or SMBs. In this article, Kaspersky experts shed light on these questions, and none of them will remain unanswered.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Negligence isn\u2019t bliss<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to the<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/kas.pr\/itsecurityreport2022\">&nbsp;Kaspersky 2022 IT Security Economics survey<\/a>, involving interviews with more than 3,000 IT security managers in 26 countries, about 22 percent of data leakages in the SMB sector were caused by employees. Almost the same proportion was due to cyberattacks, which, at some point, makes employees almost as dangerous as hackers. Of course, in most cases, this happens because of employee negligence or lack of awareness.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There are various ways that employees\u2019 actions can unintentionally lead to serious security breaches and harm the cybersecurity of small and medium businesses. The main ones are:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. Weak Passwords:<\/strong>&nbsp;Employees might use simple or easily guessed passwords, which could be effortlessly cracked by cybercriminals, ultimately resulting in unauthorized access to sensitive data. There\u2019s even a list of<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.cnbc.com\/2022\/11\/23\/most-common-passwords-of-2022-make-sure-yours-isnt-on-the-list.html\">&nbsp;the most hacked passwords<\/a>&nbsp;&#8211; check to be sure yours is not among them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2. Phishing Scams:&nbsp;<\/strong>Employees might accidentally or unknowingly click on phishing links in emails, leading to malware infections and unauthorized access to the network. Most scammers can mimic an email address supposedly belonging to a legitimate company, and when sending an email with an attached document or archive, it turns out to be a malware sample. A recent example is the<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/securelist.com\/agent-tesla-malicious-spam-campaign\/107478\/\">&nbsp;Agent Tesla attack<\/a>&nbsp;that affected users around the world.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/ecp.yusercontent.com\/mail?url=https%3A%2F%2Flh4.googleusercontent.com%2FD_cEHLokH83GL87HO63kCuKhGiIuuiF-hMcuN_JubczfasP_bSg0p0uQ9zxvAYlnTSXJLaTvUN7fh0PcczaWO2cEvJovw-dYKz7y1Z3p4vIQoy1xXRg1c8Lp3vaZc05_G5Wgb7-ic_E9Um6HQGtTsEg&amp;t=1687237840&amp;ymreqid=27f3344f-c727-c29c-1cb4-600493012c00&amp;sig=NMj.TMdDwhxtIofe3X.T2A--~D\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Example of a mass malicious mailing message<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. Bring Your Own Device (BYOD) Policy:<\/strong>&nbsp;BYOD gained greater impetus as a result of the successive lockdowns during the height of the COVID-19 pandemic. At this time, staff in non-essential sectors were forced to work from home and business continuity, rather than security, was foremost in the minds of company managers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Employees frequently use personal devices to connect to corporate networks, which can pose a serious security threat if these devices do not have adequate protection against cyber threats. Given the fact that there are over&nbsp;<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/about\/press-releases\/2022_cybercriminals-attack-users-with-400000-new-malicious-files-daily---that-is-5-more-than-in-2021\">400,000 new malicious programs<\/a>&nbsp;appearing every day, and the number of targeted attacks against companies is growing, businesses find themselves in a very dangerous situation. At the same time, the majority of companies<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/about\/news\/business\/2012\/For_72_of_companies_BYOD_is_the_future\">&nbsp;are not planning<\/a>&nbsp;(or find it impossible) to completely block personal devices from accessing corporate data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unprotected business data stored on a personal laptop that gets lost in the airport or a taxi<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/typical-byod-threats\/14872\/\">&nbsp;is a typical nightmare of an unprepared IT department<\/a>. A number of companies solve this by allowing employees to work only in the office on approved PCs with highly limited abilities to send data and a ban on using USB flash drives. This approach, in fact, will not work in a BYOD-driven company. First, employees use their own computers for greater flexibility; but this should not mean that security is compromised. The ideal solution to the problem of losing devices is full or partial encryption of corporate data, enforced by a policy. This way, even if a laptop or a USB Drive has been stolen, the data on it would not be accessible data without a password.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>4. Lack of Patching:<\/strong>&nbsp;If employees use personal devices, IT staff may not be able to monitor the security of those devices or troubleshoot any security issues. Furthermore, the employees might not apply patches or updates to their systems and software regularly, leaving vulnerabilities that can be exploited by cybercriminals.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;<strong>5. Ransomware:&nbsp;<\/strong>In case of ransomware attacks, it is important to back up your data \u2013 to have access to the encrypted information even if cybercriminals have managed to take over the company\u2019s system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>6. Social Engineering:<\/strong>&nbsp;Employees might unintentionally provide sensitive information such as login details, passwords, or other confidential data in response to social engineering tactics or phishing scams. Those more likely to be easily tricked are new employees who are unaware of the company\u2019s \u201crituals\u201d. For example, a scammer may pretend to be the \u201cboss\u201d to a newcomer, and then try to steal some important information about the company or extort money.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One example of the way scammers operate is by sending<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/new-employee-scam\/47520\/\">&nbsp;an email posing as the boss or someone senior<\/a>&nbsp;(using an unofficial address) asking the employee to do a task \u201cright away\u201d. The newbie will be happy to oblige. The task might be, say, to transfer funds to a contractor or purchase gift certificates of a certain value. And the message makes clear that \u201cspeed is of the essence\u201d and \u201cyou\u2019ll be paid back by the end of the day\u201d. Scammers highlight the urgency so as not to give the employee time to think or check with someone else.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These are mistakes that employees can make out of negligence. But what can happen when an employee deliberately seeks to undermine a company\u2019s security while employed or right after leaving their job? More troubles may arise then.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Desire for revenge<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s begin with some statistics obtained by Kaspersky. Although innocent mistakes or ignoring cybersecurity policy were behind most leakages, security managers reported that&nbsp;<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/about\/press-releases\/2023_smbs-and-enterprise-plan-to-increase-it-security-budgets-equally-up-to-14-in-the-next-three-years\">around a third (36 percent) of employee-triggered leakages<\/a>&nbsp;were deliberate acts of sabotage or espionage.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kaspersky reported several issues relating to deliberate sabotage. One example occurred when a former<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/fired-insider\/38381\/\">&nbsp;medical device supplier sabotaged deliveries to customers<\/a>: after being fired from their entity, a healthcare exec used a secret account to delay the shipping process. Since the healthcare company was unable to deliver supplies on time, it was forced to shut down all business processes temporarily, and interruptions persisted even months later. In the end, the company resorted to contacting law-enforcement agencies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Another case of this type was when&nbsp;<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/ex-employees-cyberrevenge\/25393\/\">an IT ex-employee filed a racial discrimination complaint&nbsp;<\/a>against an organization. Once offered a relocation package, he refused; working remotely was one of his key conditions. As a result, he was dismissed \u2013 and decided to take revenge on his employer. He<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.inc.com\/gene-marks\/a-fired-it-worker-changes-a-password-and-demands-200k-for-it.html\">&nbsp;changed the company&#8217;s Google account password<\/a>, denying former colleagues email access, and blocking more than 2,000 students from receiving study materials.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These examples show how former employees, in the seek of revenge, might cause real harm to their once employer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>SMB needs some action \u2013 what should be done?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The high number of cyber incidents stemming from employee action shows all organizations need thorough<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/enterprise-security\/security-awareness\">&nbsp;cybersecurity awareness training<\/a>&nbsp;to teach staff how to avoid common security<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/security-tips-small-business\/15156\/\">&nbsp;mistakes.<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Businesses should use endpoint protection with capabilities for threat detection and reaction to reduce the risk of attacks and data breaches. Managed protection services will also assist organizations with attack investigation and professional reaction. To lessen the possibility of incidents brought on by employees, thorough cybersecurity awareness training that teaches how to prevent common security threats is also necessary.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To be truly assured that everything is fine with your firm\u2019s cybersecurity, Kaspersky prepared a list of advice:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use a protection solution for endpoints and mail servers with anti-phishing capabilities, to decrease the chance of infection through a phishing email.<\/li>\n\n\n\n<li>Take key data protection measures. Always safeguard corporate data and devices, including switching on password protection, encrypting work devices, and ensuring data is backed up.&nbsp;<\/li>\n\n\n\n<li>It is important to keep working devices physically safe &#8211; do not leave them unattended in public, always lock them, and use strong passwords and encryption software.<\/li>\n\n\n\n<li>Even small companies should protect themselves from cyberthreats, regardless of whether employees work on corporate or personal devices. Kaspersky Small Office Security can be installed remotely and managed from the cloud; it doesn\u2019t require much time, resources or specific knowledge for deployment and management.<\/li>\n\n\n\n<li>Finding a dedicated solution for small and medium businesses with simple management and proven protection features; such as Kaspersky Endpoint Security Cloud. Alternatively, delegate cybersecurity maintenance to a service provider that can offer tailored protection.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Let\u2019s explore how employees, their negligence, or vindictive feelings may affect cybersecurity or SMBs. In this article, Kaspersky experts shed light on these questions, and none of them will remain unanswered.<\/p>\n","protected":false},"author":7,"featured_media":54024,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[286,101,54,2103],"class_list":["post-56777","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-it-security","tag-kaspersky","tag-security","tag-security-breach"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/56777","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=56777"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/56777\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/54024"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=56777"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=56777"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=56777"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}