With the many pressures facing smaller businesses, trying to reduce expenditure is always at the forefront of the company mind, but sometimes this leads to taking a shortcut that can have drastic consequences. I typically see this when companies start to think that information security begins and ends with IT and believe that their third-party IT support company who looks after the purchasing of devices, setting up email addresses and installing anti-virus, can equally well assist with preventing, investigating and recovering from a data breach.
While some support companies can do this, there is a reason most cybersecurity companies do not offer IT support as a service. If a breach occurred, they would be marking their own homework, and would they really hold their hands up and say ‘that was our fault’? Of course not! It would be easier to blame someone else and get more money thrown at it. In most cases, this will be done incorrectly, with bad advice and poor, expensive outcomes due to not having suitably qualified professionals engaged.
Add to that the fact that an IT company doesn’t have the experience in dealing with the complex legal, regulatory, and contractual issues that information security often has to navigate, and it’s clear that depending on IT support to perform this vital function is the wrong way to go.
A couple of accounts of breaches I have heard over the past few weeks cement my opinion that having a dedicated information security function or partner is becoming more integral to mitigating, investigating and responding to a data breach.
One business suffered a data breach where the attacker gained full control of the company’s email accounts, trying to get multiple fake invoices paid after sending a successful phishing email. It was only caught when the person in accounts wanted to check they were paying with the correct card. The IT support company who assisted with this suggested the breached company change their email passwords, utilise multi-factor authentication on all email accounts, let the staff know what had happened and inform the ICO. To be fair, all is this is technically correct, but just the tip of the breach response iceberg.
I asked if the breached account used the same username and password combination anywhere else; surprise-surprise, they did! I asked if their customers and suppliers had been notified since full access to all emails and contacts was gained by the attacker; the answer was no. The final question I asked was: apart from what their IT support did, were there any other updates or amendments to policies, procedures, solutions, or training by IT support? A long silence followed by a slightly worried no!
IT support is NOT information security!!
If you are unable to afford a dedicated internal resource, I would suggest utilising the skills and expertise of a security professional in the role of virtual CISO / CIO / ISO. This service could be as little as annual meetings with senior managers, alongside quarterly reviews and phone assistance when required. Having this resource means a company should be able to have an up to date and understood incident response plan, improve the level of security, both with regards to systems and personnel and have a trusted expert they can call upon with confidence.
For small businesses, this is the most efficient and cost-effective way to increase security maturity.
If you want to discuss anything from this article, or on the topic of IT security, in more detail, get in touch.
IT Support is NOT CyberSecurity!
By Lee Gilbank
Lee has a real passion in the arena of Cybersecurity. After working for companies such as Smoothwall, the NCC Group PLC and Commissum, Lee founded YorCyberSec as the world of cyber security was getting more popular with each reported breach, and in turn, the costs for security spiraled. This is not fair for businesses, especially SME’s and startups. Team that with bad information and poor advice it was time to do something about it. Offering advice that is simplistic and achievable, Lee hopes to make a difference. Reach out for more information.
W:www.yorcybersec.co.uk – E:firstname.lastname@example.org – T:07552 634475