Cybersecurity threats are on the rise and one misstep could cost you your business. We spoke with High Point Networks Senior Security Engineer Jamie Maguire to learn about how to prevent and recover from cybersecurity disaster.
Q: What are the most common cybersecurity threats businesses are facing today?
A: Business email compromise is the biggest one we see and we see it almost weekly. The second one we see is ransomware.
Q: How should companies protect themselves from those two threats?
A: The best way to prevent email compromise is multifactor authentication. We recommend people install an authenticator app on their phone so they get a push notification when they try to log in. That can cut down the risk of email compromise a lot.
Another good thing to have is a strong password policy. We like to tell people that longer passwords are almost always stronger. 16 characters for a password or passphrase is a good place to start.
Another thing that should be done is security awareness training. Businesses should educate staff on common types of phishing emails and what common types of scams look like so they can recognize them and not fall victim to them.
Ransomware is more complex. It’s a bit more involved. Ransomware often starts with phishing. So those three methods of prevention I just mentioned apply to ransomware as well.
To prevent ransomware from making a significant impact on your business you should be doing a lot of backups because when someone deploys a ransomware attack, they lock up all of your data.
It’s also important to understand what your business has exposed to the internet. A lot of ransomware groups are starting to attack the perimeter of networks in addition to phishing. They like to go after services, applications, and servers that are exposed directly to the internet. So, understanding where your exposure is can help a lot as well.
Q: Are there any formal pieces of training or external pieces of information that you’re aware of that i should point readers to?
A: There are a lot of good resources out there. The National Cybersecurity Alliance has some great resources and articles at staysafeonline.org. They also have a good video series on YouTube (@StaySafeOnlineNCA).




