Whether for work or personal use, our reliance on technology has never been higher. As this reliance grows, so do the associated cyber risks. And when more people are working or studying from home, the potential for a cyber incident increases in different ways.
Cyber criminals know that when more people are communicating online, they’re interacting with technology in different ways – even sometimes using networks or software for the first time. Bad actors often attempt to take advantage of such situations, using deception to gain access to protected information. At the same time, corporate IT and operations teams are working overtime to keep networks running without interruption – potentially impacting their ability to detect malicious activity quickly.
This makes protecting confidential information more challenging than ever. At Chubb, we look for ways to do more for our clients, like suggesting ways to possible help you prevent issues from happening in the first place. Following these ten tips may help your business and your employees stay cyber-safe, even in periods of uncertainty.
- Prepare for IT resourcing issues from both a people and a technology perspective. When more people are connecting remotely, technology call centers may face a higher call volume than normal, and more resources may be needed outside of standard business hours. Simultaneously, network bandwidth, data storage capabilities, and computing power are put to the test. Despite this increase in traffic, attention to detail cannot falter. Businesses are encouraged to keep a close eye on these needs, prepare a plan to reallocate resources as necessary, and recognize that this dependency may increase over time.
- Ensure your network, software, and applications are up-to-date. Remote access technologies have known vulnerabilities – and are all too often the weak link that bad actors use to gain access to protected information. Make sure all software and applications are updated, and patch any weaknesses that are identified.
- Make sure your resources are aligned – before an incident occurs. Organizations should make sure their business continuity plans, disaster recovery teams, and cyber incident response plans are in alignment. Bad actors know that dependency on your network and its availability is never higher than when more people are accessing it remotely, and will attempt to take advantage of the situation.
- Review your existing policies, and closely monitor any necessary security exceptions. When IT resources are stretched, organizations may need to make some exceptions to published security policies, standards, or practices. Implement a thorough review process to ensure such exceptions are closely monitored and solved. Also, most work-from-home policies weren’t originally drafted to address a global conversion to remote work; organizations should carefully review those as well.
- Only connect to the Internet through a secure network. When connected to a public network, any information you share online or via a mobile app could be accessed by someone else. Always use a Virtual Private Network (VPN) to encrypt your activity. Most organizations provide a VPN to their employees to ensure secure, remote access for work use, and personal VPN accounts are available from various service providers.
- Use strong passwords. Many people use the same or similar version of a password for everything, even between work and home. Unfortunately, this means a single stolen password can be reused on multiple sites to unlock dozens of accounts for hackers. Remembering secure and complex passwords for every account can be difficult, if not impossible. Use password management software to ensure you have strong, unique passwords for everything, because passwords are the foundation of sound online security practices.
- Use multifactor authentication – now is the time to implement if you haven’t already. Traditional user login and password accounts are easy for bad actors to penetrate. Whenever possible, set up multifactor authentication on your accounts. This requires you to provide at least two authenticating factors, or proofs of identity, before you can access protected data, giving you a second line of defense against criminal activity. This additional level of protection is particularly critical when more people are accessing networks remotely, giving bad actors more entry points to access private networks.
- Only click on links, open attachments, and download software from trusted resources. Most people want to stay informed with the latest information, especially during periods of uncertainty. Bad actors know this, and will attempt to take advantage by masking malicious links as something informative. Once clicked, that malicious link can be used to gain access to an individual’s or organization’s private information and/or freeze their computers or networks. If you’re unsure of the source, go to the organization’s website. If it’s important, the information will be posted there as well.
- Verify website URLs before sharing confidential information. Bad actors can create fake websites where both the URL and homepage look remarkably similar to a site you trust – such as your healthcare provider, bank, or email provider. Instead of following a link in an email, type the URL in by hand. Also, make sure the site you visit has HTTPS in the URL; these sites are more secure than those with HTTP.
- Don’t respond to requests for information from unknown sources – especially if the request is for personally identifiable information or passwords. Bad actors will attempt to con people into sharing confidential information by pretending to be someone you know or work with. Take extra care in identifying who you’re sharing information with – even if you think the request came from a trusted resource or organization. Don’t feel rushed; take the time to research the request and whether it’s appropriate before responding.
If you want to learn more about cyber coverage for your home or your business, contact our team today.
This checklist contains general information only. Chubb does not have any obligation to oversee or monitor any insured’s adherence to any guidance or practices set out in this document, or to any other risk control practices. The content of this document is presented for informational purposes only, and is not intended as a substitute for consultation with your insurance broker, or for legal or other professional advice. No liabilities or warranties are assumed or provided by the information contained in this document. Chubb is the marketing name used to refer to subsidiaries of Chubb Limited providing insurance and related services. For a list of these subsidiaries, please visit www.chubb.com. Product highlight are summaries only. Please see the actual policy for terms and conditions. Products may not be available in all locations, and remain subject to Chubb’s underwriting criteria. Surplus lines insurance is sold only through licensed surplus lines producers. © 2020. Form 17-01-0269 (Ed. 03/20)