In almost all serious hacking cases, human error leads to the issue by providing access or control over systems. Hence, it is becoming increasingly important that all businesses find ways to educate their team on CySec – as cyber crime becomes more sophisticated and more common, often the best base defence that we have is ensuring team members are informed the types of scams and how they operate.
Of course, there are many different scams and types of attack depending on your industry, but generally speaking the two most common include:
- Phishing – one of the most common forms of cybercrime, phishing emails are disguised to look as though they come from legitimate sources. They attempt to trick users into clicking a link, which takes them to the copy of a website that they regularly use. Here they enter their log-in credentials, which can then be stolen by criminals.
- Ransomware – a form of malware that locks users out of their system and then demands a ‘ransom’ be paid or all of the data on the system will be deleted.
It might seem logical that the IT department is the only one that needs to think about digital security issues, but the entire business needs to be informed and educated, it only takes one person to click a bad link or download the wrong program to breach your businesses network, this is where a cyber incursion begins.
Ransomware
One of the ways that phishing is often deployed by cyber criminals is in the use of ransomware. This is a type of malicious software that effectively locks a company out of their system and data and then demands a ‘ransom’ in order to get the data and information returned to them.
“Phishing is one of the most commonly used ransomware attack vectors, whether this is through links, attachments or both,” says George Glass, Head of Threat Intelligence at digital security specialists Redscan, “attackers create emails purporting to be from a trusted source and attach a malicious file, such as a Word or Excel document”.
It has been suggested that paying a ransom is not a good move. There is no guarantee that you will get your data back, and even if you do, cyber criminals will be aware of your compromised system which could lead to you being targeted again. Once again, this can be very negative for your business. Your goal is to attract prospective buyers and to retain as many paying customers as possible. However, paying a ransom will show customers that you were not properly protected against cyber crime and will certainly cost you dearly!
Phishing
One of the most common forms of cyber crime is phishing. This involves sending fraudulent emails that appear to come from a genuine company email address. Unfortunately, this can have a big impact on the marketing department from two perspectives.
First, if email scammers can find a way to get access to your company inbox, they can send out nefarious emails to your customers. It may be the case that you have a mailing list with thousands of names, and they could all be a target of cyber crime. This is clearly a huge problem, as it can ruin your business’ reputation.
It is also worth considering the impact that phishing can have when your marketing department is the victim. It is natural that marketing departments use a very wide range of apps and software, which all require login credentials. One of the most common phishing scams attempts to trick users into clicking a link and signing into an identical login page created by the scammer. This reveals your login details to them.
It is important, then, to not only ensure that you provide training to staff to allow them to spot scams and phishing attempts but also put a policy in place to make sure that passwords and login credentials are not re-used.
There is so much more at stake for a business that suffers a crime against its digital security than simply the money that they could lose. As well as financial hit from direct theft or downing tools, the overall threat is the damage a cyber attack can cause to the reputation of your entire business operations – something that can take a long time to recover from.


