Share this article
To everyone who used the Covid lockdowns to learn a new language, redecorate their home or train for a marathon, we salute you. But the reality is that many more of us didn’t develop new skills or shape up. In fact, a BBC survey found that 48 per cent of people say they have put on weight through the pandemic. It’s a similar story with cyber security.
This is mainly because remote-working brought about a seismic shift in the way businesses operate but many cyber security policies were not adequately adapted to accommodate the vastly increased number of threats presented by the global pandemic. As a result, those who did not adapt their cyber security policies to the new threat landscape now find themselves halfway through 2021 in worse shape than ever.
The similarities do not end there. Because, as we grapple with new variants of Covid, we have also seen an evolution of the tactics employed by cybercriminals. For example, before the pandemic 20 per cent of attacks used malware that had not been seen before. Over the last year this figure has risen to 35 per cent as hackers used ingenuity to exploit the crisis.
Covid has been classified as the largest ever cyber security threat, with reported cyberattacks running globally to 445 million, doubling up on the previous year. Meanwhile Government statistics report that in 2021 just 83 per cent of organisations currently employ malware protection and only 33 per cent have conducted a cyber risk assessment. A Deloitte survey found that only 59 per cent of employees had received cyber security training in response to the rise in remote working.
However, rather than focusing on these rather terrifying statistics, here are some words of comparative comfort from the National Cyber Security Centre: “Cyber attacks come in many shapes and sizes, but the vast majority are very basic in nature, carried out by relatively unskilled individuals.”
This means that some vigorous shaping up of essential cyber security measures will improve organisational resilience during these difficult times.
Cyber Essentials
Cyber Essentials is a Government-backed scheme aimed at providing protection against a range of the most common cyber attacks, including malware, ransomware and phishing attacks. It is a mandatory requirement for any organisation which is engaged as government supplier or those tendering for public service contracts. But is equally relevant to any company that wishes to improve its security.
There are five technical controls which, if implemented properly, will provide a base-level of security for company networks.
Cyber Essentials certification also provides value in the form of reputational benefits, demonstrating to business partners, regulators, suppliers and customers that you take cyber security seriously.
As with so much in life, however, the devil is in the detail and taking your business through the certification process can put a heavy burden on resource. Those unfamiliar with the process may struggle to be both time and cost-efficient.
The SRM team is experienced in all aspects of Cyber Essentials certification, ensuring that you get it right first time, without spending on unnecessary tools or services. We can do as much or as little as is required: from scoping and assisting with activities that need to be undertaken to providing guidance and practical support all the way up to a pre-audit assessment.
During the process, our clients are sent the cyber essentials question set to allow them to prepare their answers and receive help from SRM’s consultants. The client then enters the responses into the SRM portal. There is also a document Cyber Essentials: Requirements for IT Infrastructure from National Cyber Security Centre (NCSC) that is required reading for all Cyber Essential Clients.
Our team provides all the guidance necessary to ensure that Cyber Essentials certification is achieved and maintained, providing ongoing support where required. A full range of cyber security services is also available, including ISO 27001 certification, PCI DSS compliance and business continuity planning. For those wishing for complete peace of mind, we also offer a fully Managed Security Service.