Your Biggest Cybersecurity Threat is Poor Communication

Your Biggest Cybersecurity Threat is Poor Communication

The importance of communication in preventing and remediating cyberattacks

When it comes to cybersecurity, it’s all too easy to focus only on prevention.  Don’t get me wrong, securing critical systems and data is one of the top priorities for any Chief Security Officer (CSO) or Chief Information Security Officer (CISO). That means deploying everything from firewalls to intrusion detection systems to end-point security – and monitoring it continuously and effectively.

But the hard truth of conventional IT security is that enterprises play defense while hackers are playing offense. To win, the hackers only need to get an attack right once while corporate security strategies must be impregnable at all times. With technology like automated botnets that can launch thousands of attacks a second – not to mention users who click on malware-filled emails – the odds are that an attack will get through at some point.

Lost in the various technology discussions surrounding cybersecurity is the importance of effective internal communications before, during and after an attack. An organization’s ability to quickly muster counter measures when they are targeted for a cyberattack could be the difference between a data breach that costs millions and a slight blip in operations.

All Hands on Deck

Creating a culture of security helps prevent breaches and requires input from a variety of departments including IT, HR, marketing, facilities, and anyone else regularly involved in managing critical systems. In the event of a breach, CSOs and CISOs need to give every job function a clearly defined role based on their skills, location and availability. A simple call sheet is not sufficient.

Preparation is a Must

All the technology in the world won’t prevent an attack if employees are not fully trained on security awareness. Workers are an organization’s first line of defense so it is the security team’s responsibility to train and publish best practices around spear phishing (the use of fraudulent emails aimed at specific users to launch an attack) so employees know how to recognize suspicious emails, links and attachments. Those split-second decisions to quarantine or open an email can expose critical systems to attack no matter what security technology you’ve deployed. Cybercriminals are always refining their “phishing” techniques to trick users so enterprises must commit to continuous education so workers are up to date on the latest threats. While it isn’t a complete cure, keeping users from making damaging mistakes is a big win.

CISOs need buy-in from the C-suite to ensure management understands the risks to the business, the importance of developing a proactive strategy and implementing education programs not just with funding, but with their own personal example of practicing safe computing.

Response Team, Assemble!

Trust is such a vital part of how customers and business partners think about your business, which is why data breaches are particularly damaging to a company’s brand.

A coordinated, effective response can make the difference between a breach being a minor speed bump or a major hit to your brand or market value. For example, lack of adequate, proactive and prescriptive notification to all employees can drastically increase the damage from an attack by enabling criminals to compromise IT equipment rapidly as employees link their infected laptops to the company network.

Organizations may also need to establish alternate communications platforms, disconnected from the company’s infrastructure, for use during an attack if their regular telecommunications network and email systems are compromised. While quick and targeted communications with the relevant IT experts will be key, don’t forget you may also need frequent updates with management, legal, marketing, key stakeholders and partners to comply with regulations governing data privacy and security reporting.

Organizations that handled communications well after a breach typically suffer only small fluctuations in stock price and customer confidence. Those that couldn’t get the message out, or bungled the message, suffer longer-term effects.

Post-Attack Analysis

A successful post-attack communications plan provides an honest account of what went wrong, what went right and how processes can be improved to avoid a recurrence. Now is not the time to pull any punches. If a particular technology – or member of the team – didn’t perform up to expectations, new measures must be put in place to improve the outcome. 

Including an in-depth post-mortem into the enterprise cybersecurity strategy is vital as it is impossible to think about things critically during a crisis. Having a time-tested response plan in place, and a communications system to alert all the players, gives businesses a vital head start when the next cyberattack occurs.

You can’t control how hackers will try to defeat your technology and fool your users, but businesses can tilt the playing field in their favor with fast, effective, coordinated communications plans.

Featured

  • Human Risk Management: A Silver Bullet for Effective Security Awareness Training

    You would think in a world where cybersecurity breaches are frequently in the news, that it wouldn’t require much to convince CEOs and C-suite leaders of the value and importance of security awareness training (SAT). Unfortunately, that’s not always the case. Read Now

  • Windsor Port Authority Strengthens U.S.-Canada Border Waterway Safety, Security

    Windsor Port Authority, one of just 17 national ports created by the 1999 Canada Marine Act, has enhanced waterway safety and security across its jurisdiction on the U.S.-Canada border with state-of-the-art cameras from Axis Communications. These cameras, combined with radar solutions from Accipiter Radar Technologies Inc., provide the port with the visibility needed to prevent collisions, better detect illegal activity, and save lives along the river. Read Now

  • Survey: 84 Percent of Healthcare Organizations Spotted Cyberattack in Last 12 Months

    Netwrix, a vendor specializing in cybersecurity solutions focused on data and identity threats, surveyed 1,309 IT and security professionals globally and recently released findings for the healthcare sector based on the data collected. It reveals that 84% of organizations in the healthcare sector spotted a cyberattack on their infrastructure within the last 12 months. Phishing was the most common type of incident experienced on premises, similar to other industries. Read Now

  • Keynote Speakers Announced for ISC West 2025

    ISC West, hosted in collaboration with premier sponsor the Security Industry Association (SIA), unveiled its 2025 Keynote Series. Featuring a powerhouse lineup of experts in cybersecurity, retail security, and leadership, each keynote will offer invaluable insights into the challenges and opportunities transforming the field of security. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame. 3

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation. 3

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file. 3