Our ultimate 10 step guide to understanding how cyber security can work for your business.

Your premises, technology and your valuables are usually protected by some sort of lock and key system. You do this to protect them from unauthorised access, theft, and damage. Cyber security is just a term that brings together tools and strategies to protect your digital information from unauthorised access, theft and damage. Though ‘damage’ can have several implications including reputational damage.
The Importance of Cyber Safety Culture
A cyber security culture helps an organisation focus and strengthen its defence against digital threats. In other words, creating a culture where safe online security practices are second nature.
Assessing your current cyber safety posture is something you can do regularly, we have listed our steps here to give you insight and a place to start your assessment:
- Audit: Check all Applications are up to date (latest version). Are Firewalls enabled e.g. Windows Firewall and your WiFi router? Are antivirus programs installed, running regularly and up to date?
- Phishing simulation: A phishing simulation can be any many forms. There are several phishing simulators online that allow you to run a phishing test, and both free and paid for one’s available.
- Access controls: When was the last time you reviewed who has access to what? Has everyone that has left the organisation had their access revoked? Timetable regular reviews to ensure everyone only has access to information and systems necessary for the role.
- Password policy: What is your password policy? Does everyone use long complex passwords? Consider using a password manager like LastPass or KeePass. It’s worth noting that the latest guidance on password rotation has changed i.e. stop changing passwords every few months and only change them if there is evidence of a security breach or compromise. This is designed to tackle ‘password fatigue’. Alongside ensuring MFA (multi-factor authentication) is switched on.
- Incidence Response: Do you have a plan of what to do when a security incident occurs. This can be as simple as running through various scenarios and conducting table-top exercises. To reiterate, do you have a plan to deal with a security breach or comprise, like change all passwords?
- Physical Security: Is everything locked away that should be? For instance, it’s good practice to lock network devices inside a lockable network cabinet. What happens when something is discovered to be lost or stolen? Lockable wall mounted network cabinet for Routers, Switches, etc.
- Inventory: Do you have an inventory of all your Software applications and Hardware devices? An easy way to do this, is record everything in a spreadsheet – one tab for software and another for equipment: Some also have a third tab for intellectual property. Remember to cross reference your inventory with your audit.
- Training & Awareness: Do you have a cyber security training or awareness program? This could be as simple as an email newsletter discussing the latest security breaches and security trends.
- Compliance: Do you know your compliance obligations e.g., GDPR, PCI-DSS etc? For example, do you hold information on customers, clients, members and do you know your obligations? Do you know the financial implications if you get it wrong?
- External Assessment: Whenever you assess your security internally, you effectively, ‘marking your own homework’. One easy way to do this, is engage with us Digital Safety and we can carry out a full assessment and help your company stay secure.
Need help on where to start, we have curated design and delivery of Cybersecurity training for organisations, to view our products visit our corporate page here:
Corporate – Digital Safety CIC, Professional Practitioners, Training UK (ds-cic.com)

