Are you confident your practice is immune to computer threats? Sandip Parekh explains the steps you need to take to protect your data.
In this modern world, the pace within which we are becoming absorbed, surrounded and reliant on technology is increasing at an alarming rate. The degree of computerisation, automation and, in the not too distant future, machine learning, artificial intelligence and quantum computing brings about a whole new level of socioeconomic impact. The benefits are almost immeasurable now, but can we ignore the threats that come with such a technically driven environment?
Absolutely not! When it comes to implementing technology, the first question any individual or a business should ask themselves is: how do we protect the business, its operations, sales and finances? How do we protect its technical infrastructure? How do we protect the data we hold? How do we provide the people that work for us, or our clients the trust and confidence to share with us their critical, confidential, financial or medical data?
These questions have been simmering away across the broad spectrum of society, growing with fervour and momentum for many years. The result being the introduction of the General Data Protection Regulations, coming into effect in May this year.
GDPR seeks to redress the balance of power in favour of the person whose data is being obtained, retained, processed and perhaps shared with others, which isn’t a bad thing. We wouldn’t be happy if someone took a tangible item from you and did what they wanted with it without your permission or even knowledge, like your car or bike, but your personal data has never been seen in quite the same light, but with GDPR, the balance will shift.
A raft of legal obligations is cascading down on businesses who process data and there is a need to be able to provide evidence that reasonable measures have been put in place to protect personal data of clients, suppliers, and employees and prevent unauthorised use, access, loss or corruption.
Reducing your risk
With this in mind, let’s touch upon some of the security tools and applications to reduce the risk as much as possible, which you should be considering as essential and no longer an option.
- Security patch – software is constantly being tested for vulnerabilities, by both the software developers and bad guys. When a vulnerability is identified, the developer will release patches to fix the security leak
- Anti-virus and firewall – implement a trusted anti-virus/firewall application. This area is very much a ‘you get what you pay for’ environment. You will be hard pushed to justify a breach if you have relied on a free tool or break licensing laws by using a non-commercial tool. Enterprise-grade applications are the only way to go
- Passwords – use a combination of letters, numbers, and special characters. Do not share and change it regularly. You must start to consider a different way of working; no longer will it be acceptable to have ‘Surgery 1’ and everyone know the login password
- Limit user access – do not leave the computer unattended, lock the user profile when away, configure mass storage restrictions. Make sure that users are disabled when they leave the organisation and other codes and door entries are also changed
- Back ups – Backing up data is a life-saving practice; make sure you have an encrypted local backup but invest in offsite secure encrypted online backup. Be careful, there are a lot of products out there with amazing headline prices but you have to make sure they conform to the GDPR regulations and encryption rules (and don’t have hidden costs when you need your data back in a disaster scenario!)
- Internet and emails – browse and access trusted links/sites and attachments. Avoid free downloads from unknown sources. Most ransomware attacks don’t come through browsing the internet, most come from fake emails with links that encourage a user to turn off the network security enabling an attack from within
- Remote connections – use secure and encrypted connections to connect to your workplace or remote resources – again, free or non-commercial products are likely not to have such secure connections and place your entire network at risk
- Knowledge – stay up to date with the latest information on technology and security of your data – look out for e-shots from Microminder – if in doubt, ask!
Stand up against the serious threats to your business and personal data. Protect your data to protect your business.