Human Firewalls and How to Build Them

When it comes to protecting your organization from cyberattacks, keeping your technology up to date and equipped with the latest security measures goes a long way. But if you really want to keep your data safe, you need to address the biggest vulnerability: people.

More and more, cybercriminals are exploiting our weaknesses as human beings because it’s easier to get the overworked and stressed-out Joe in accounting to hand over the verification code than it is to hack into his account with brute-force computing. 

Your staff is not an afterthought. They are the first line of defense, and you should treat them as such.

 

What are we talking about here

Ever get a frantic call or text from someone you know saying they urgently need money because something went wrong and they can’t handle the payment themselves? In today’s world of AI spoofing and deepfakes, that call or text can sound indistinguishable from the real person you know.

Cybercriminals create a sense of urgency and panic to short-circuit our critical thinking skills. They don’t want you to stop and think about why this person is asking you for help, or why they’re asking for that specific thing. They just want you to react, because we’re hard-wired to want to help, which makes us easy targets for these types of scams.

 

Lesson Plan for New Age Cybersecurity

People are social creatures. We want to share and trust. In order to protect ourselves, our loved ones, our clients, and our business, we must teach our staff to trust their gut instincts first, and that begins with a few basic lessons:

Practice vigilance and protect your privacy

It’s tempting to share all the good things in our lives on social media, but it’s never a good idea to share sensitive information publicly. If you can, keep your profile private or restricted to people you know and trust. Never share your location in real-time. Post vacation photos a week or two after you come back home. Don’t post your children’s names, location, or any information that could identify where they live or go to school. And, of course, never share sensitive business or client information, either.

Use a good, reliable password keeper, and always enable MFA

You should never save your login information in browser. It’s not secure. These passwords are kept in a non-encrypted file on your computer and if hackers get a hold of it or if your computer gets lost or stolen, your accounts will be compromised.

Instead, use a reputable password keeper like LastPass or NordPass. These tools not only help you preserve your passwords, they can also create highly secure ones and alert you when your password is insecure or used on multiple sites.

MFA (Multi-Factor Authentication) can be annoying, but it should be enabled where possible to protect your account access. It’s good practice in your personal life and should be a requirement for all business-related accounts in your organization. At minimum, all of your staff, including leadership, should set up MFA for anything accessing sensitive cloud data (e.g. financial, patient EHR, student data, etc.) and email.

Set up and educate staff on standard company protocols

Are you familiar with the Green Dot bank payroll scam? It’s a common scam in which criminals spoof an employee’s email and send a request to HR or Accounting to update their direct deposit information, thereby stealing the employee’s salary.  Without proper procedures and safeguards, this type of scam is very easy to perpetrate.

Your cybersecurity protocols should set standards and expectations for how your company handles certain processes so that your staff members recognize when something is wrong. To make it clear that this is not just about bureaucracy and paper pushing, educate your staff on why these procedures are in place and underscore the importance of protecting themselves as well as the organization.

Train staff on how to respond to cyberattacks and refresh regularly

Your employees, interns, and volunteers don’t need to be experts in cybersecurity. They just need to be able to recognize when something looks or sounds wrong, and respond appropriately:

  1. Pause and take a breath. Don’t panic and don’t act rashly. Take a second to breathe through the initial shock so you can think clearly.
  2. Don’t engage with hackers. If you receive a message or phone call that you suspect is a scam, don’t engage. Take notes, screenshots, or photos of the initial interaction, and then end the conversation and contact your supervisor or IT team immediately.
  3. Don’t try to fix it yourself. If something goes wrong, don’t try to fix it. You might make the problem worse.
  4. Report immediately. It’s not about guilt or shame. Stuff happens, we’re all just human. The important thing is to contain the damage as quickly as possible. Don’t wait, don’t beat yourself up. Just report it ASAP and wait for further instructions.
  5. Share, learn, adapt. Once the security breach is contained and corrected, sharing what happened with your staff can help them avoid similar incidents in the future. Use what you learned to adjust your training and procedures to improve security going forward.

 

Need a little help?

If you need help drafting a cybersecurity policy or training guide for your organization, we can help. Contact us to schedule a free IT consultation to help identify the vulnerabilities in your IT infrastructure.