Cyber Essentials is no longer a tick-box exercise – businesses need to act now
When was the last time you reviewed your cyber security standards? Let’s be clear: keeping a company secure is a constant task.
Cyber breaches are on the rise; according to the latest UK Government Cyber Security Breaches Survey, 4 in 10 businesses were compromised in the last 12 months.
It’s important to remember businesses of all types and sizes are at risk – where there are gaps in security, attackers will take advantage.
Against this backdrop, plus high-profile cyber-attacks on companies including M&S and JLR, the government has reviewed its Cyber Essentials framework.
Its latest overhaul is raising the bar for organizations of all sizes.
Designed to provide the basic controls to protect businesses and their staff, if taken seriously, Cyber Essentials can make all the difference.
Yet many businesses are still struggling to meet even baseline security standards.
Common issues such as a lack of budget, limited resources and a focus on other priorities are all factors holding organizations back – and they all make a major IT breach more likely.
Historically treated as a once-a-year compliance exercise, the latest ‘Denzel’ Cyber Essentials framework signals a clear and overdue shift towards implementing continuous cyber resilience.
This means tougher standards which could catch businesses out.
Here are the key changes and how to approach them, to reduce the risk of a breach.
Implement a robust patching regime Under the new framework, expectations have been tightened around patch management – the process of fixing a security risk or software error by installing updates – and vulnerability management.
Previously businesses could demonstrate compliance with patching requirements though documented processes and periodic updates.
In reality, teams find it hard to build in regular patching routines which work without affecting live services, due to downtime and continual testing.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.