{"id":987655,"date":"2025-10-11T14:22:45","date_gmt":"2025-10-11T14:22:45","guid":{"rendered":"https:\/\/petrasoftsolutions.com\/ps\/?p=987655"},"modified":"2025-10-22T09:19:15","modified_gmt":"2025-10-22T09:19:15","slug":"what-you-shouldnt-be-doing-with-your-cybersecurity","status":"publish","type":"post","link":"https:\/\/petrasoftsolutions.com\/ps\/what-you-shouldnt-be-doing-with-your-cybersecurity\/","title":{"rendered":"What you shouldn\u2019t be doing with your cybersecurity"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"987655\" class=\"elementor elementor-987655\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-c79f30f e-flex e-con-boxed e-con e-parent\" data-id=\"c79f30f\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-3805ce3 elementor-widget elementor-widget-text-editor\" data-id=\"3805ce3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>Cyber threats<\/strong> are all around and increasing every day. But there\u2019s no need to let fear overwhelm you. Staying ahead of the would-be attackers doesn\u2019t have to be a constant game of whack-a-mole or something that keeps you up at night. You can protect your company\u2019s assets and enjoy some peace of mind.<\/p>\n<p>Being aware of the problems, or potential problems, is step one. You\u2019re reading this, so you\u2019ve got that covered. Vigilance is required, but you can take simple steps everyday to cover the basics, which you may already be doing. Standard corporate cyber hygiene \u2013 maintaining accurate hardware and software inventory, running updated endpoint protection, using firewalls, employing intrusion prevention and detection, conducting regular patching and maintenance \u2013 lays the foundation.<\/p>\n<p>Depending on your industry and the type of data you handle, there may be specific security measures you need to implement. But is there anything you shouldn\u2019t be doing? In fact, there are plenty cybersecurity mistakes companies often make. Hopefully, you won\u2019t recognize your company here. If you do, it\u2019s time to take action. More on that later. For now, here are 10 cybersecurity mistakes to avoid.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-7a14fae e-flex e-con-boxed e-con e-parent\" data-id=\"7a14fae\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-5f3ebc9 elementor-widget elementor-widget-text-editor\" data-id=\"5f3ebc9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>Step 1: Lack of Executive Support <\/strong><\/p>\n<p>At this point, most executives realize the importance of data security. No one wants to be the next CEO who has to explain why it took so long to identify a breach or address a known weakness. But top leadership may not understand what, or how much investment, is required to stay ahead of the bad guys. It\u2019s up to the chief security officer or chief information security officer to make the case for modern, flexible data security and infrastructure protection.<\/p>\n<p>Lack of executive support challenges many IT teams when they try to gain budget approval for proactive and ongoing security initiatives. Unfortunately, these same budgets are often approved after a breach has occurred. One way around the budget impasse is to include the cost of a breach in the budget package. Contrasting the cost of prevention with the devastating consequences of a very real threat can help loosen the purse strings and deliver the executive support crucial to an effective security program.<\/p>\n<p><strong>Step 2: Infrequent Testing <\/strong><\/p>\n<p>Gone are the days of once-a-year testing to check off that box on the IT to-do list. Testing at intervals required for compliance may not be enough either. The dynamic nature of most corporate environments calls for much more frequent testing. Not keeping up with best practices for your organization may put you in jeopardy of a breach.<\/p>\n<p>Just as early detection is important to the health of our bodies, it is as important to the well-being of an organization\u2019s network security. Similar to developing healthy habits such as exercise, sound nutrition, and regular check-ups, managing a corporate information network requires the same diligence. To improve security, it is imperative that regular assessments be conducted throughout the year to address any new vulnerabilities. Cybercriminals work all year round and security professionals must as well.<\/p>\n<p>Scanning and testing frequency will depend on the amount of change introduced into your particular network since your last check. You may be able to gain executive support by demonstrating how assets can be compromised by the types of changes that happen regularly in today\u2019s systems. You might also point out that having a regularly tested incident response (IR) plan reduced the cost of a breach by an average of $2.7 million or 58%, according to Ponemon.<\/p>\n<p><strong>Step 3: Being Strictly Defensive<\/strong><\/p>\n<p>The best defense is a good offense, and wouldn\u2019t it feel good to know your security had already been tested and weathered the storm? By all means, use all the defensive measures available. But you can\u2019t just sit back and wonder if you\u2019ve plugged all the holes.<\/p>\n<p>Regular, proactive penetration (pen) testing and red teaming can find unaddressed weaknesses and give you the peace of mind of knowing your defenses are solid. Pen tests can show whether your security measures will hold up in the real world and a red team of smart, determined pseudo-adversaries may find weaknesses your plan didn\u2019t account for.<\/p>\n<p>Develop and implement the strongest plan your team can conceive. Then look for weaknesses. Plug those holes and test again. An ongoing, iterative approach is your best bet for staying ahead of cyber thugs.<\/p>\n<p>If your company is relying solely on firewalls and external network scanning, you may have a false sense of security and be caught unaware. Pen testing and red teaming can help you more fully understand the security posture of your networks so you know where to invest to shore up your defenses.<\/p>\n<p><strong>Step 4: Overlooking The Human Element <\/strong><\/p>\n<p>Businesses often spend thousands of dollars on network security only to have crucial access data accidentally given away by an employee. Today\u2019s data protection technology has advanced, making it more difficult for hackers to \u2018get in\u2019, but human nature and a person\u2019s willingness to be helpful have not changed. Social engineers are always working smarter by exploiting basic human trust to get at the information they seek.<\/p>\n<p>The top attack vector last year was stolen or compromised employee credentials, according to the Ponemon report. It even outpaced phishing, the previous top threat.<\/p>\n<p>Employees are often the first place attackers go when trying to breach your systems, making them the first line of defense. To protect your data, train all employees to recognize an attempted attack and fight back. Make sure they know what to do at the moment and where to report any attempts. Don\u2019t neglect this crucial asset by leaving them unprepared.<\/p>\n<p><strong>Step 5: Investing In the Wrong Tools <\/strong><\/p>\n<p>Using technology to secure your systems makes sense. So does trying to save money by purchasing sophisticated tools that promise plug-and-play functionality. But all too often, IT teams wind up needing more personnel, weeks of training, or both to operate a system that was supposed to save time and money.<\/p>\n<p>When looking for a way to secure your network without adding hard-to-find IT pros, focus on user-friendly tools and responsive vendors who will provide excellent customer service or professional services to get you up and running and answer all your questions. Read the fine print and make sure a human will be available to help when you need it. And don\u2019t forget to conduct a risk\/reward analysis before committing to a new tool.<\/p>\n<p>Cybersecurity pros are in short supply these days but you can find powerful tools that are simple to operate and vendors that understand how to provide the support you need.<\/p>\n<p>Cornerstone security practices, like vulnerability management, can be high maintenance if the wrong tools are in place. You need enterprise-grade features in a user-friendly format that empower your team to identify and prioritize vulnerabilities accurately and efficiently, without weeding through mountainous reports that offer no context or prioritization.<\/p>\n<p><strong>Step 6: Assuming Compliance Equals Security <\/strong><\/p>\n<p>Many companies faced with a breach often have difficulty fully understanding the incident, wondering, \u201cHow could this happen? We passed our compliance requirements\/audits.\u201d<\/p>\n<p>It is important to appreciate the benefits of compliance based reviews such as SOX, HIPAA, HITECH, PCI DSS, and others, while also understanding that compliance does not equate to security. Some compliance requirements are broad in nature and can be left open to interpretation by the organization, auditor or compliance officer performing the review.<\/p>\n<p>There\u2019s a difference between what regulators require as compliance minimum and best practices to keep your networks secure. Even if your budget doesn\u2019t allow for all the bells and whistles, it\u2019s still important to identify your company\u2019s highest risk targets and do everything you can to protect them.<\/p>\n<p><strong>Step 7: Apathy and Indifference <\/strong><\/p>\n<p>A common mistake made by understaffed and overwhelmed organizations is security apathy and indifference. The leadership at these organizations makes the case that, if the bad guys want in, they will find a way and there is nothing that can be done to stop them.<\/p>\n<p>This type of apathy provides a prime target for a cybercriminal looking to gain access. Although there is no silver-bullet solution when it comes to security, there are very cost- and labor effective security solutions that can be implemented. With adequate resources and a proactive approach, the chance of a breach can be greatly reduced.<\/p>\n<p><strong>Step 8: \u2018It Can&#8217;t Happen To Me\u2019 Mentality <\/strong><\/p>\n<p>Whether it\u2019s thinking they are too small or in the wrong industry to be a target or that multi-factor authentication (MFA) and off-the-shelf antivirus software is enough, many companies think they aren\u2019t at risk or that they\u2019ve mitigated all the risks. To a cyber criminal, the industry, size of the business, or tools employed don\u2019t matter. All organizations are a target.<\/p>\n<p>No matter if your company has 20 or 20,000 employees, a proactive approach to security is imperative. That\u2019s not to say that MFA and software tools aren\u2019t important. They just aren\u2019t enough. And an \u201cI\u2019m totally safe\u201d mentality isn\u2019t helpful because it can breed apathy. (See #7.)<\/p>\n<p>Today\u2019s information security threats demand constant vigilance. Hackers, misinformed employees, and lax security \u2013 any of these can put your critical business operations, profits, and reputation at risk. In essence, organizations must conduct regular security risk assessments, awareness education, pen testing, and red teaming to ensure both networks and staff are secure.<\/p>\n<p><strong>Step 9: Weak Supply Chain Security <\/strong><\/p>\n<p>Many organizations do background checks on employees but fail to do a comprehensive review of third-party organizations that have the potential for significant harm. Risks associated with vendors vary but all have the potential to bring about financial and reputational harm through error, data loss, breach of contract or confidentiality, and more. The same can be said of data partners. Basically, anyone who has access to your systems could cause problems.<\/p>\n<p>Proper vetting can go a long way to alleviate this risk. Business leaders should perform due diligence on potential vendors to better understand backgrounds, performance history, and risk management practices. Supply chain security should not be limited to an annual audit. Organizations that hope to mitigate risk should conduct ongoing background checks on vendors and partners, especially as their personnel change.<\/p>\n<p>In addition to proper screening, organizations should ensure that their supplier contracts include the appropriate control language requiring suppliers to institute regular security testing and an ongoing commitment to keeping sensitive data protected. If you can\u2019t trust the participants in your supply chain to do their best to protect your assets, it\u2019s not worth doing business with them.<\/p>\n<p><strong>Step 10: Poor Physical Security <\/strong><\/p>\n<p>Physical security is the protection of personnel, hardware programs, networks, and data from physical circumstances and events that could cause serious losses or damage to an enterprise. This includes protection from fire, natural disasters, burglary, theft, vandalism, and terrorism. Having strong physical security does not require a great deal of technical knowledge and can be one of the most impactful areas within an organization\u2019s security strategy.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-baa05e5 e-flex e-con-boxed e-con e-parent\" data-id=\"baa05e5\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4dd2c99 elementor-widget elementor-widget-text-editor\" data-id=\"4dd2c99\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>Your Site Could be a Security Risk<\/strong><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f44f0b7 elementor-align-start elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"f44f0b7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"fas fa-arrow-circle-right\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Do windows have glass break sensors?<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"fas fa-arrow-circle-right\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Are physical network access points\/jacks secured to prevent an intruder from simply connecting their own device to the network?<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"fas fa-arrow-circle-right\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Is a valid proof of identification, such as a driver\u2019s license, required when a guest signs in?<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"fas fa-arrow-circle-right\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Is there camera coverage of facility dumpster\/waste bins?<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"fas fa-arrow-circle-right\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Can badges easily be counterfeited by a social engineer?<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"fas fa-arrow-circle-right\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Are your employees friendly and helpful if someone without a badge wants access to the building?<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-d2ca56a e-flex e-con-boxed e-con e-parent\" data-id=\"d2ca56a\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-43915a5 elementor-widget elementor-widget-text-editor\" data-id=\"43915a5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Virtual pen testing is a great security practice for your digital assets and physical pen testing can protect your physical assets. Train employees on the proper actions to take if they find a USB drive on company grounds, notice someone without a badge loitering inside, see someone trying to follow them or another employee in through a secure door, or anything else suspicious. Cover the ways a clever criminal could use social engineering to gain entry. Once everyone is trained, conduct a social engineering pen test to be sure your physical security is as good as your cybersecurity. Address any issues and test again. It\u2019s an ongoing process.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Cyber threats are all around and increasing every day. But there\u2019s no need to let fear overwhelm you. Staying ahead of the would-be attackers doesn\u2019t have to be a constant game of whack-a-mole or something that keeps you up at night. You can protect your company\u2019s assets and enjoy some peace of mind. Being aware&#8230;<\/p>\n","protected":false},"author":1,"featured_media":8436,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"footnotes":""},"categories":[16],"tags":[],"class_list":["post-987655","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity"],"jetpack_featured_media_url":"https:\/\/petrasoftsolutions.com\/ps\/wp-content\/uploads\/2023\/04\/pexels-thisisengineering-3861969.jpg","_links":{"self":[{"href":"https:\/\/petrasoftsolutions.com\/ps\/wp-json\/wp\/v2\/posts\/987655","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/petrasoftsolutions.com\/ps\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/petrasoftsolutions.com\/ps\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/petrasoftsolutions.com\/ps\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/petrasoftsolutions.com\/ps\/wp-json\/wp\/v2\/comments?post=987655"}],"version-history":[{"count":5,"href":"https:\/\/petrasoftsolutions.com\/ps\/wp-json\/wp\/v2\/posts\/987655\/revisions"}],"predecessor-version":[{"id":987983,"href":"https:\/\/petrasoftsolutions.com\/ps\/wp-json\/wp\/v2\/posts\/987655\/revisions\/987983"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/petrasoftsolutions.com\/ps\/wp-json\/wp\/v2\/media\/8436"}],"wp:attachment":[{"href":"https:\/\/petrasoftsolutions.com\/ps\/wp-json\/wp\/v2\/media?parent=987655"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/petrasoftsolutions.com\/ps\/wp-json\/wp\/v2\/categories?post=987655"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/petrasoftsolutions.com\/ps\/wp-json\/wp\/v2\/tags?post=987655"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}