Bianca, what cyber attack points are there in a company?
Bianca Sum: First of all, any device that is connected to the Internet or internal networks is basically vulnerable. This starts in the office with computers, laptops, printers and ends with networked production equipment in a factory. An important aspect is now also IoT devices, i.e. devices from the Internet of Things. This can be a light bulb, a camera or even a robotic arm. Each of these points of attack is ideally protected with specific IT measures.
Is hardware also vulnerable?
Bianca Sum: Yes, the classic is a USB stick infected with malware that is placed in the company parking lot by someone with bad intentions. In the worst case, it says "important project" or "pay slips" on the stick to increase the incentive for someone to actually plug it into a device. Of course, it can also happen that someone accidentally plugs a malware-infected USB stick into their device during external appointments or events. In addition, there are real hacking tools, some of which can be easily ordered on the Internet. This can be, for example, a small adapter that you plug between the keyboard and PC to record all keystrokes. Caution is advised everywhere!
What are the first steps to protect his company?
Bianca Sum: A first step would be to assign secure and, above all, different passwords for access to devices and programs. The rule of thumb here is: the longer, the better. I like to recommend password sets, e.g. "Maria Müller has an ultra-secure password for her company laptop". You should also always keep all the programs you use up to date and install updates. Another tip is to be prepared for an emergency. So make sure that someone can help you - for example, specialists in your own IT department or external experts.
By Covid19 are currently many employees in the home office. What is there to consider here?
Bianca Sum: It is more difficult to take precautions with uniform IT security standards when employees use their private devices instead of company laptops. Binding rules should be communicated in both cases:
- All programs used must be kept up to date.
- It is mandatory to use strong passwords.
- The preset router password must be renewed.
- Access to company data may only be made via extra-secured connections (e.g. VPN client).
- The laptop should always be locked when leaving the workplace.
- The company must regularly inform its employees about dangerous phishing emails.
In addition, employees make sure at best that their home office can be locked and conversations cannot be overheard through open windows.