Easy Mode | Get it Done | The Journey |
---|
| | |
AI? This is a whole other topic. If you are using any of these new Generative AI tools in any way, stop and think what data you are feeding it. If you would not put that data on your public website, don’t give it to an AI engine.
| | AI is used where appropriate and only where approved by the business. AI usage is monitored and the business responds to the rapidly changing technology by continuing to evaluate if the usage fits within their risk profile.
|
| | |
| Have a visitor register so you know who comes into your premises and when. Do you want a “clean desk policy” so nothing is visible when the cleaners come through at night? Are visitors (eg trades, repairs) escorted within your premises at all times?
| |
All of the tech things! Yes, the things that you don’t want to know about or think are too hard. If that is the case, find someone who can explain it until you understand it, and why it is important for your business. Challenge your Technical Advisor and ask good questions. But that does need to be balanced with knowing when to take advice from them. What are the technical things in your business that you don’t understand? Here are a few examples: Multi Factor Authentication - MFA Encryption including Encryption at Rest and End to End Encryption Transport Layer Security - TLS Secure Sockets Layer - SSL (the s in https:) Antivirus Firewall etc
| | |
| Understand all the terms and conditions of your Cyber Insurance Have a good dialogue with your Insurance Advisor so they really understand your business and the cyber risks your business faces. Ensure your insurance gives you access to a team that will help your business manage a significant incident. A lawyer specialising in cybersecurity recommended that I talk to a lawyers on their panel, to understand what they do in case of an incident, and that is something she regularly does with the insurance companies she works for.
| |