1. Patching, Patching, Patching
Security Patching and updates to your operating system, is the best place to start. Keeping your machine up to date and running all the latest security patches is key to staying safe and keeping your data safe. It is also important that you are running the latest version of Windows / MacOS, where possible i.e., Windows 10/11 and not Windows 7.
2. Not just windows, update everything!
Just remember, it’s not just Windows that needs to be updated – it’s everything! If you’re running the Adobe Suite for example or Microsoft Office, that software also needs to be kept up to date. Having the operating system up to date is all well, but if someone sends you an email and you read it using an outdated version of Microsoft Outlook, you could be putting yourself at risk from attack that way.
All software manufacturers will run and support the latest version of their software, as well as one or two of the previous versions as well. Once they declare a product as being “End of Life” they will stop providing support for it. More importantly stop providing security updates for it. As most software upgrades are built upon refinements to the previous version many parts of the code will be the same. Hence, if a flaw or coding error is found in the latest version, it may well apply to ALL the previous versions too. Including all the ones that have gone “End of Life”. These ones will continue to have that hole, a security hole that any hacker will be very happy to try and exploit!
2. Anti-virus software
Assuming you’ve done the first two, you may ask why you should worry about running anti-virus software or malware detections.
Just because your software is up to date, doesn’t mean you aren’t vulnerable! Quite often it’s the hackers and virus coders who will find the security flaws in the software. Often well before the manufactures find it themselves. They will then craft their software to take advantage of these flaws and get access to your systems and your data before you or the manufactures becomes aware of the issues.
Running anti-virus software should therefore be a vital step in keeping your business safe from cyber-attacks etc. There are several free anti-virus software solutions are available. But I would always recommend paying for Anti-virus cover, as you will get a better service and faster updates when new viruses are discovered. This is after-all how they make the free software “free” by not providing support for it or deploying the virus signatures as quickly as they would if you were paying for the software. Ultimately you get what you pay for!
4. Firewalls
Assuming you’ve done all the above, you now want to lock down the network environment too and that means deploying firewalls. You can think of a firewall as being a security cage or brick wall that you build in front of either you PC or your internet connection. This will prevent people from trying to get into your systems from outside. Again like most things you get what you pay for – so don’t always assume that the flashy routers you got from your service provider is up to the job. They have after all probably provided it to you “free of charge”. So it won’t be the very best tool you can get to do the job right.
If you purchase a firewall/router from an IT Security specialist, then it may come with other “extra features” to provide even more protection. Some systems will even scan your web traffic for viruses, as it passes into and out of your environment.
Just remember, if you do purchase a router from another supplier. You need to keep the software on this up to date as well. Yes it’s that word again – even routers need patching!!
5. Website Security – update it too!
Ok, so you’ve done all the above and your local environment and network are now safe from being attacked (or as safe as they can be!).
But what about your website?
The chances are that is sitting on a web server that is provided by some other supplier, one that you may not have that much control over. In most cases your website will be sitting in a shared environment too – with lots of other websites too. So, it is very important that you keep the software running your website (WordPress, Jomla etc) up to date too. Just like your computer, this is running on a computer too and could be vulnerable to attack. If not more so as it’s a in a public location and quite often shouting for attention.
6. Be Aware/Diligent – Emails
Sadly, all the software and virus scanners etc cannot every provide you with 100% cover. So, it is also vitally important that you stay alert to attacks in the form of an email. If it doesn’t look safe don’t read and certainly don’t click on the links in the email. Even if it appears to come from a trusted source.
All too often, human error can result in serious issues for a business.
Reading emails that claim to be coming from the Boss, asking you to transfer money to unknown locations, once it’s gone, it’s gone! I have sadly known this happen to a couple of clients who weren’t quite vigilant enough. So if you get an odd request, and you’re not sure if it’s genuine – check another way. Pick up the phone and give the client a ring “Did you send me this invoice”. If they didn’t, they might need to know about it as someone could have gained access to their systems and be exploiting this access to get money out of the innocent.
7. Passwords & 2 Factor Authentication
Whether you’re working locally and accessing emails or logging into Twitter to do some social media work, you’re bound to be using a password. Everything we use today needs to have a password… sadly this also means that hackers and everywhere and trying to get into your accounts. Once they’ve worked out what your email address is, they’ll be off to all the favourite locations – LinkedIn, Facebook, Twitter etc and they’ll be trying to break into your accounts.
For this reason, it is vitally important that you use long and secure passwords. Not just words and especially not words associated with your business! Try and choose something obscure, put in a change of case (i.e. make a letter in the middle of the word a capitalised one). Add a few numbers and non-alphanumeric characters (i.e. !@£$%^) and you’ve got a better password. Another good rule is to make it a LONG password – 12 characters or more.
If the provider you are using gives you the option to use 2 Factor Authentication, I would strongly recommend doing that as well. This just adds an extra roadblock to prevent that would be hacker from getting into your system.
We recently wrote this article on password security.
8. Update your Hardware
This might seem like an odd one but keeping your hardware up to date is also key to remaining safe and secure. As the versions of Windows or MacOS are produced the older versions of the hardware will stop being supported. This isn’t as fast as the software changes and goes end of life. But it will happen and running your business on a 5-year-old machine will also decrease your risks. Having new hardware quite often means you can run the newest software and therefore keep everything running securely. Newer hardware may have extra security features too, like hard disk encryption hardware and facial recognition systems etc.
9. Have a Security Policy and apply it!
If you’ve ever worked for a larger business, then you’ll remember doing the regular password changes. Or how you sometimes had to request access to get to certain resources etc. This should be no different for a smaller business. You should have a policy in place that says how often you change your passwords and what your staff should do to ensure your data is kept secure.
This policy can be enhanced with software technologies to restrict access to USB drives or file permissions when emailing documents etc. If you can think of a restriction there’s probably a setting to allow us to do that. So it is a very good idea to have a Security/IT policy in place.
10. Backups
Finally, and by no means least, Backups! It doesn’t matter how vigilant you think you are being or how careful there are always other things that could come along and cause you a serious issue i.e., Floods, Theft of IT equipment, Fires etc.
The backup service is your insurance against this from causing you a catastrophic problem for your business, but is quite often the last one that anyone will think of. So many times, have I heard the phrase “Oh I do a backup when I remember”. I’ve also discovered that it’s not until someone suddenly losses that spreadsheet or the proposal they’ve spent the last month building, that consider having a backup. Sadly this can also be the case when they’ve lost everything and it’s too late. So, if you take nothing else from this article, go away now and backup those files!
Conclusion
If you need help with implementing our business cyber security top 10 tips, get in touch to see how we can help.

