Latest News

  • Home /
  • Latest News

Mitigo - 6 cybersecurity resolutions for your firm

1 February 2021
David Fleming, Chief Technology Officer at Mitigo gives his 6 top cybersecurity resolutions for 2021.

Never in our working lives should it be clearer that you need to allocate budgets and resources to mitigate known risks. Cybercrime is now one of the most significant of those risks and the start of a new year is always a good time to start planning. So, in that context here are my suggested 2021 cybersecurity resolutions for firms:

2021 cyber resolutions.
  • Invest time to understand your risk from cyberattacks.
Cyber attacks are indiscriminate, they hit any vulnerability they can find. I suggest you get the right group of experts together to assess your risks, and then consider the controls you have in place to reduce that risk e.g., policy, training, software, support, etc. Consider paying for a vulnerability risk assessment that can guide you on where to start.

  • Get your remote connections FIT for purpose.
From March last year, cyber criminals have had a field day compromising poorly set up remote connections. In the rush to connect remotely, speed was prioritised over security. Please carry out the exercise to make sure your connections are fit for purpose in 2021. This includes logins to cloud platforms, VPN connections to the office and all versions of remote desktop control. And pay extra attention if you have allowed staff to use their own computers.

  • Stop assuming that your IT support have this covered.
The firms that got hit last year still assumed this. In our experience IT do not look after this because they are not risk or cyber experts and you are frankly not paying them to shoulder this responsibility. This assumption can be a blocker to firms acting.

  • Change employee habits through training, testing and simulation.
All the incidents we investigated last year had an element of human error. Good resolutions change bad habits. This includes link-clicking, alert-ignoring, update-delaying, data-syncing… I could go on. Best practice is to follow up training with simulated attacks on staff, e.g., a pretend email phishing campaign, to strengthen a defensive culture.

  • Write and communicate a mobile phone policy.
Do not forget mobile phones. Personal and work mobile use can be necessary for business. But have you got a policy on it, with the necessary controls in place? Cyber criminals increasingly rely on mobile phones as an entry point into company systems. Once you have agreed what your policies are you will need to configure your technology to support your approach.

  • Prove to yourself that your back-up actually works.
Most back-ups that we check will not survive a ransomware attack because they are poorly configured. Have you ever had this checked? And is it still operating correctly in this remote working world? Staff may have started storing files locally for convenience or even started using third-party storage. Have you still got control of your data footprint?

Obviously, this is not an exhaustive list, but I am hoping it will get you thinking about this subject because it isn’t going away. Indeed, the cyber criminals are more organised than ever, and their attacks are increasingly sophisticated. It is a lucrative business for them, so they invest money and resources into constantly improving their game. I suggest you do the same.

Paradigm has partnered with Mitigo to offer technical and cyber security services to our members. 

Take a look at Mitigo’s full service offer at https://www.consultparadigm.co.uk/strategic-partners/mitigo 

For more information contact Mitigo on 0161 8833 626 or email [email protected] 


 

16 December 2021

Invesco - Investment Intelligence Seminars 2021 - On demand


14 December 2021

Invesco - 2022 investment outlooks


10 December 2021

Prudential: Case study 3 - Funding for decumulation


8 December 2021

intelliflo - Uncovering the advice gap; the Advice Map of Britain


29 November 2021

Just WIN, WIN, WIN... Thank you


26 November 2021

Blackfinch Energy acquires largest solar farm to date


26 November 2021

ESG at Invesco


26 November 2021

Prudential - International Portfolio Bond – helping your clients help the planet


16 November 2021

Octopus On Film - Diversity and inclusion


3 November 2021

What investors want: Our research on client perceptions of ESG investing


3 November 2021

Mitigo - Why cyber risk management is not the same as IT support


28 October 2021

intelliflo - Why you shouldn’t discount technology for older clients


28 October 2021

Prudential - The year of 2.5 budgets


25 October 2021

Invesco - Small steps to a better future


15 October 2021

Prudential - ISA Case study 1 – Managing volatility with cash


14 October 2021

Prudential On Film - ESG


12 October 2021

intelliflo - How technology will impact the future of paraplanning and advice


11 October 2021

Just: Winners of Just Group vulnerable customer awards announced


11 October 2021

Prudential: ESG Policy for the Risk Managed Passive and Risk Managed Active fund ranges


7 October 2021

Aegon - Thinking ahead: Social care funding and intergenerational advice


13 September 2021

Invesco - Investment Intelligence Seminars 2021 – register now


8 September 2021

Blackfinch Renewable European Income Trust September 2021


7 September 2021

intelliflo - Five benefits of a client portal


7 September 2021

Prudential - Our 'Future-proofing Fridays' seminars are coming to you virtually


6 September 2021

Prudential - New PruFund Support


26 August 2021

PruFund range of funds - EGR and UPR announcement


26 August 2021

intelliflo - The power of deep integrations


25 August 2021

PruFund Planet - Support for your ESG client conversations


23 August 2021

Prudential - PruFund Planet - How are the funds managed?


20 August 2021

Prudential - Download the app for automatic daily valuations through intelliflo


12 August 2021

Prudential - The Great Reset: Why it's time to invest for a sustainable recovery


11 August 2021

Prudential - Planning for education?


6 August 2021

Invesco - It's more about growth than inflation


6 August 2021

Prudential - Sir Isaac Newton’s first law of motion and ESG


3 August 2021

Prudential - PruFund Planet - The power to create the world your clients want


2 August 2021

Prudential - Our 'PruFund Planet - a world of good' seminar is coming to you virtually


21 July 2021

Just on Film - Vulnerable Clients


19 July 2021

Prudential - Pep up your ISA planning webinar


7 July 2021

intelliflo - Future-proofing your technology


2 July 2021

Prudential - Our 'Onshore... Offshore - you decide' seminar is coming to you virtually


1 July 2021

Prudential - New AKG financial strength report and due diligence support