Our recommendations for new staff data security training
It’s often said that people are the weakest link in cyber security, but – like a muscle – cyber security can be strengthened with training and practice. We find that the best way to ensure a chain that’s free of weak links is to train staff on data and cyber security from day one, and keep that training going.
Recently, we’ve proudly been expanding our team here at Beaming and for all new members of staff, cyber and data security training are given the highest priority during induction. In week one of their training (before they’re allowed access to our network) we ensure that everyone is put through our new staff data security training.
As our new recruits discover, data security is about ensuring customer and staff confidentiality, as well as keeping your own business information safe from competitors or those with malicious intent, so sharing too much company information is a big no-no. However we can briefly outline the main topics covered in our training.
Follow our 6 point plan to make your employees more cyber security confident.
- Data security is about the CIA. It is everyone’s responsibility to ensure that we maintain the Confidentiality, Integrity and Availability of the data we hold. Make sure that staff members understand what each of these means in relation to data security.
- Password practice: Do not use the same passwords at home and at work. Follow our guidelines for choosing a strong, memorable password.
- Avoid removing any work documents from the business’s secure network in order to work from home.
- Be conscious of what’s happening around you. Don’t discuss confidential company information on a crowded train or work on documents in a public cafe (especially using free wifi!) where people may be able to “shoulder surf”.
- Phyiscal security is also important, when you enter and leave the building you work in, make sure you’re not followed in. Don’t be afraid to challenge anyone you would not expect to be entering the premises.
- Always report anything suspicious, even if you’re worried you may have done something wrong. It’s important to create a culture where people are not afraid to report a possible breach, especially now since the GDPR stipulates that a breach must be reported within 72 hours of discovery.
Of course, each business will have its own unique quirks based on its industry, internal structure and physical surroundings. We find that the above points are a great place to start. In addition to delivering training, make sure that it is documented and that participants sign off to agree that they have received it.
We’re aware that no one will ever remember every single thing from one training session, but as time goes on we make sure to reinforce our security messages with on-going training and creating a culture where everyone supports each other to prevent the business being a victim of cyber threats.
A cyber attack could cost you your business
More news from Beaming
Q1 2021 Cyber Threat Report
Commercial cyberattacks are up 11 per cent year-on-year, with businesses hit every 45 seconds.
Bouncing Back Better Post Lockdown
Here, partners at Purple Beach, Annemie Ress and Olivia Gribaudo explain how businesses can use the changes we’ve seen to bounce back better than ever.
How to secure network access for remote working teams
As thoughts turn to more permanent home working set ups post-pandemic, IT teams need to find a way to make it easy for teams to access remote networks in a way that doesn’t jeopardise the security of the network.
Hybrid working: Getting the technical side right
It is now time to take stock of decisions made during the pandemic & ensure that technology is resilient, secure and fit for the future.
Supporting employees in uncertainty
Being clear about plans and what’s expected, building a sense of team, driving perceptions of fair play and developing a growth mindset all feature in this guidance from Andrea Derler, Director of Industry Research at the NeuroLeadership Institute.