Combatting cyber threats: how to protect your business

Karl Hoods, Chief Digital & Information Officer at the Department for Business, Energy and Industrial Strategy, talks to Reed about how you can protect your business from cyber security threats.

8 mins read
I Stock 1322205588 (2)

almost 2 years ago

As companies continue to utilise workplace technologies to allow their business to grow and develop, the risk of cyber security attacks increases tenfold.

According to PwC, Swiss companies suffer ransomware attacks around every 11 seconds. Medium-sized Swiss companies suffer average damage of about CHF 6 million per cyberattack.

Now more than ever, companies across the world try and prevent cyber attacks. Because of this, the role of information technology in the workplace becomes even more critical for businesses to not only protect their assets, but to also lead towards a sustainable future.

We interviewed Karl Hoods, Chief Digital & Information Officer (CDIO) at the Department for Business, Energy and Industrial Strategy (BEIS) - UK, to find out what companies can do to protect their business from cyber security threats.

Watch the full interview with Karl, where he goes into detail on the importance of IT within business and how it has changed, alongside how companies can protect themselves from cyber attacks and the ‘must haves’ that can help ensure protection and sustainability for your business, here:

The role of IT in business

Information technology and the IT department now play a crucial role within any business, as the emphasis on monitoring and managing technology and communication systems grows.

There are very few companies now that don’t have an IT department or a professional who looks after the digital elements of the organisation. From being able to send an email, to changing and verifying a password, accessing and maintaining databases and troubleshooting, information technology allows businesses to become more efficient and productive.

While the role of the IT department still encompasses day-to-day operations, the responsibilities and strategic direction has changed exponentially, according to the CDIO at BEIS, Karl Hoods.

He said: “I think the role of the IT department, or the digital department, is incredibly important.

“There aren't many industries that don't have any reliance on technology at all. It's really a relationship that needs to continue to develop and evolve because there's so much value that technology can bring to everyday activities, from productivity if you're working in the office, through to manufacturing and what that can actually mean for output.

“IT has definitely progressed over the years, from being a supporting function to being something which should be integral to the operation of the organisation you’re in.”

Protecting your business

The need to protect your business from cyber-attacks has never been greater, and global governments continue to urge businesses to strengthen their cybersecurity practices. According to PwC, in 2020, 20,544 cases of cybercrime were reported in Switzerland, and 16,395 of these were classified as cyber fraud.

Conducting business through digital means can bring a host of opportunities and benefits to the fore, including the ability to email safely, store data, work remotely, and manage everyday operations. On the other hand, having a digital workstream can enhance the risk of a cyber attack.

While cyber-attacks can be hard to predict, Karl believes it’s imperative that companies look into potential risks to ensure that the business can remain functional, operational and secure.

He said: “There's definitely a conversation to be had about understanding what the threats are and really getting your head around that."

"From a cyber perspective, we've recently seen the exponential growth in cyber activity and cyber threats. It hits every part of every organisation and it can be incredibly disruptive. You need to look at your own risk as an organisation and where your threat vectors are, where you might have some weaknesses, where you might be exposed and then look to plug those."

Karl Hoods, Chief Information & Digital Officer, BEIS

In most cases, today’s technology tools come equipped with the necessary protection that allows businesses to safely go about their day-to-day operations. But making sure you understand how to use the tools is paramount.

Karl adds: “If you're using things like Office 365 or Google Workspace, they all come with tools which can help you. If you don't know how to use them, get some advice on what to do with that – an independent view is beneficial.

“Once you've got that base level of technology protection, then you can look to see how you can evolve that over time. There's also scope to put into place a technology recovery process, as well as a wider business recovery that needs to be done as well.

“Really understanding the key recovery processes, the key people and how long you can survive without having access to the technology is incredibly important.”

The technology ‘must haves’

Protecting your business in a digital world will allow your business to be both sustainable and progressive – but to do so, employers need to make sure that they’re doing everything possible from an IT standpoint.

There are certain processes and tools that can be put in place that will protect a business in both the short and long term. Because IT departments have gone from being purely ‘reactive’ to ‘proactive’, there are multiple ways that companies can firewall their digital assets, believes Karl.

He said: “So the ‘must haves’ are an awareness of the threats. Then there are basic principles that you need to employ which all come down to people a lot of the time. That includes the need for strong passwords, two-factor authentication, all those kinds of things that you need to put in place.

“If you look at the history of some of the compromises that happen, they are around compromised accounts, around credentials that are not being rotated often enough for admin accounts, etc. There's a similar pattern emerging over and over again – usually down to a flaw in the process.

“Focus on understanding your threats, understand where your weaknesses are, and plug those where you can. Also having a really strong user training and awareness programme is incredibly key because people are the weak spot in many of these things.”

Focusing on the employee

Companies need to take the time to invest in their employees to ensure security breaches, no matter the size, can be prevented.

Researchers from Stanford University suggest that approximately 88% of all data breaches are caused by an employee mistake. Human error is still very much the driving force behind an overwhelming majority of cyber security problems, which makes upskilling your employees more important.

Karl believes that “no matter what technology you've got in place, there’s always a weak point which can be individuals, whether that's malicious or just a genuine mistake.

“Investing in the technology, the processes and the people in terms of upskilling has got to be key for any organisation of any size to recover.

“We all get phishing attacks and malware attacks at home. Just because you've come into the office doesn't mean to say that everything's taken care of by the security or technology team.

“It's just about keeping abreast of that, keeping up to date, making people aware of the consequences and understanding what the outcomes could be.”

According to software company Symantec, in the UK, one in every 3,722 emails is a phishing attempt, further reinforcing the need to make employees aware of any potential threats that can occur both within the office and while working from home.

Karl adds: “If there is a breach, it’s about knowing who to notify when something happens, even if you're unsure whether it's a breach or not.

“It's better to put your hand up and say, ‘can you look at it for me?’ rather than just say ‘I'm not quite sure’ and let it go so even more damage can be done.

“There are lots of software and courses that are available. It can be very much bitesize and consumable on the move, just short little snippets of information that can really help to protect your business.”

Growing awareness business wide

As the IT department’s roles and responsibilities evolve, so too does their ability to influence and inform senior leaders, which is crucial when it comes to the prevention and awareness of cyber security measures.

Growing awareness around cyber security isn’t just for entry-level employees, it must encompass all departments from graduates all the way up to c-suite executives and the board.

"There’s this concept of the ‘human firewall’ that is what we really need inside organisations."

Karl Hoods, Chief Information & Digital Officer, BEIS

Karl said: “Awareness should start in general terms so that people know how to protect themselves, know not to click on links that they don't expect to receive- for all employees at all levels.

“It isn't just focused on the most junior person in the organisation. This needs to be right up to board level and down, everyone needs to understand the role that they play in protecting the organisation.”

Are you looking for a talented IT professional to drive your business’ growth? Get in touch with our specialist recruiter now.

You may also be interested in...

How to fight economic inactivity
1 mins read

How to fight economic inactivity

​It was recently my turn to pick up the pen and contribute to City AM’s ‘The Note Book’.

I chose to write about the issue of economic inactivity and to focus on ways to encourage younger people into the workforce and ways to incentivise older workers to work for longer.

My thinking is that this will encourage the highly paid and highly skilled to work up until retirement age rather than choosing, as many do, to retire early.

And my estimation is that this would result in more, not less, tax being collected and collected sooner because these individuals are frequently higher rate taxpayers who will typically find ways to avoid inheritance tax in the extra spare time they have after they’ve taken early retirement.

Instead, these highly capable higher rate tax payers will be incentivised to continue to contribute to the growth of their organisations and the wider economy and consequently to the exchequer as well.

One for the Office of Budget Responsibility (OBR) to grapple with perhaps… but I’ve no idea how you’d model such an idea. Sometimes it’s just better to give things a go!

And if you do get a chance to see the play ‘A View from The Bridge’, you should go. It’s a precious thing - a brilliant play, brilliantly acted!

Click here to read the article.

Sales CV template: for Sales Executives and other sales professionals
2 mins read

Sales CV template: for Sales Executives and other sales professionals

​​Whether you are a sales executive, supplier relationship manager or field sales consultant, use our free template to build your perfect sales CV today.

[Full Name]
[Home address]
[Contact Number] • [Email Address]

Personal Statement

Use this section of your CV to highlight the skills that would be transferable in a sales environment e.g. questioning and listening, tenacity, resilience and the ability to think on your feet. It’s also a good idea to include a link to your LinkedIn profile.

Sales professionals are target driven and financially motivated, so don't forget to highlight and "sell" yourself.

Try to avoid statements such as "I work well as part of a team and on my own initiative" or "I can communicate at all levels" - the majority of CVs contain these statements. CVs that show creativity stand out in sales.

Education

A relevant degree, for example Business Studies will give you a great start, but many degrees have a sales element, e.g. Psychology - understanding people, Engineering - problem solving, Law - negotiation skills etc.

It is important to present your education in a way that identifies you as a sales person.

In some sales positions experience trumps education, so if you don’t have a glittering academic record, make sure you elaborate on your experience.

[College/School Name]
[Date M/Y– Date M/Y]

A-levels:

  • [Subject] – [Grade]

  • [Subject] – [Grade]

  • [Subject] – [Grade]

GCSEs:

  • [Number] GCSEs, grades [range], including Maths and English

Work Experience

This should be brief and, as a general rule of thumb, focus on the last five years of your career, or last three roles, in chronological order with the most recent at the top. Highlight your key achievements, and aim to use bullet points rather than lengthy descriptions.

[Job Title], [Company Name] [Location]
[Date M/Y- Date M/Y]

Achievements and responsibilities:

  • Brief role overview

  • Worked alongside [team] to produce [project]

  • Implemented [change] which resulted in [benefit]

  • Received an [award name] for [reason]

Hobbies and Interests

This section is not essential, but can be a good opportunity to reinforce your application, and show a future employer what motivates you outside of work.

Don’t just say that you ‘like to socialise’ be specific, and don’t be afraid to share your successes. If you can put a sales slant on this part of your CV too, even better.

I’ve completed a marathon for [charity]

I negotiated my away across [country] on a budget, working as I went

References

References are available upon request.

Download our full sales CV template.

Accountant CV template
2 mins read

Accountant CV template

Are you an accountant looking to build the perfect curriculum vitae? Use our template today for a free example CV

[Full Name]
[Home address]
[Contact Number] • [Email Address]

Personal statement

This section is your chance to summarise the rest of the CV, and convince the recruiter to get in touch. It is important to keep it brief, between 50-200 words, and outline who you are, the technical skills you have to offer and your career aim. Achievements are better listed under each job, rather than in your profile.

I have developed strong technical experience within the accounting profession over recent years, specifically covering [analysis/month-end reporting/reconciliations]. I have worked with and am highly skilled in the use of [technologies/systems].

I am able to clearly articulate my thoughts, and have proven the ability to interact with both finance and non-finance staff in order to facilitate efficient reporting procedures. I now seek an opportunity within an [business type/industry] organisation, where I can bring significant value, and continue to develop my skills further whilst I finalise my studies.

Education

Given the importance of education – both accounting specific and general – in advancing through the early stages of your professional career, it is important to highlight your academic strengths early in your CV. Recruiters and employers looking for a PQ will want to see evidence without having to hunt for it. Be clear with your grading, and emphasis any specific topics studied.

[Examining body – ACA, ACCA, CIMA, AAT, ICM, IPP]
[Date M/Y– Date M/Y]

  • [list examinations passed]

[University Name]
[Date M/Y– Date M/Y]

  • [Degree subject] – [Grade]

[College/School Name]
[Date M/Y– Date M/Y]

  • [A Level Subject] – [Grade]

  • [A Level Subject] – [Grade]

  • [A Level Subject] – [Grade]

[College/School Name]
[Date M/Y– Date M/Y]

  • [Number] GCSEs, grades [range], including Maths and English

Work Experience

This should be a detailed outline of the work you have conducted throughout your career, listing your technical responsibilities gained through practical experience. Employers will not assume your knowledge – you must illustrate this clearly.

Do not be fooled by the suggestion that CVs should be limited to two pages – this is wholly irrelevant to professions which require evidence of responsibilities undertaken.

[Job Title], [Company Name] [Location]
[Date M/Y- Date M/Y]

Responsibilities:

  • Preparation of month-end management accounts to strict deadlines inclusive of P&L statement, fully reconciled balance sheet and debtor/creditor analysis

  • Production of variance analysis commentaries focusing upon [gross profit/sales/cost of sales/actuals vs budget]

  • Reconciliation of [number of] bank accounts in [GBP/EUR/USD/CADZAR/AUD] currencies

  • Preparation and submission of [VAT/CIS/PAYE/Intrastat/EC Sales] returns

  • Preparation and posting of [accrual/prepayment/payroll/depreciation/adjustment] journals

  • Maintenance of fixed asset register to include additions, disposals and depreciation

Achievements:

  • Implemented [change] which resulted in [benefit] – list as many as is suitable to benefit your application

  • Received an [award name] for [reason]

Hobbies and Interests

This section is not essential to include, but you may wish to depending on the role you are applying for. It can be a useful chance to show a little more of your personality. However, be warned this can be very subjective, so ensure anything listed here reinforces your application, and the idea that you’ll be the right fit for the role. If you don’t have any real relatable hobbies, it is best to omit this section.
I organise a weekly [sport] game, managing bookings, transport and help to coach the team
Undertook a [course] in order to improve my [skill]

References

References are available upon request.

Download our full accountancy CV template.