Cyber threat alerts often come with a list of recommended actions, but they don't always explain what those actions involve. This guide breaks down common cyber security recommendations, explaining what they mean, why they're important and how businesses can put them into practice.
-
Enable multi-factor authentication (MFA)
What it means
Protecting accounts with an extra layer of security, requiring a code from an authenticator app, a biometric check or a security key on top of the password.Why it matters
Passwords can be guessed, reused or stolen. MFA reduces this risk, blocking the vast majority of account compromise attempts even if a password is compromised.How to apply it
Use MFA across all critical accounts, especially email, remote access tools and administrator logins.
Prioritize admin accounts and users with sensitive access.
Use app-based authentication or security keys wherever available.
-
Stay vigilant against phishing
What it means
Equipping employees to recognize and avoid phishing attacks – this includes suspicious emails, links and messages.Why it matters
Phishing remains one of the most common entry points for cyber attacks, deceiving users into revealing credentials or downloading malware.How to apply it
Train employees to question urgent or unusual requests and check sender email addresses and links before clicking or replying.
Make it easy for employees to report suspicious emails.
Use the phishing simulation tool in the CFC Response app to help employees recognize phishing attempts.
-
Monitor systems for unusual activity
What it means
Monitoring networks, systems and user activity for unusual behavior that could indicate a cyber attack or security breach.Why it matters
Attackers often operate unnoticed before launching an attack. Early detection can help stop threats before they cause significant disruption or damage.How to apply it
Use monitoring tools or managed detection and response services.
Set alerts for unusual login activity or data movement.
Regularly review logs and alerts, even at a basic level, to spot unusual activity early.
-
Reset passwords on key accounts
What it means
Changing passwords on employee and admin accounts, particularly after a known threat or potential compromise has been released.Why it matters
Stolen credentials are a leading cause of breaches. Once exposed, passwords can be used to access multiple accounts.How to apply it
Ask employees to reset passwords following any suspected incident.
Prioritize critical systems first, such as IT admins accounts.
Encourage long, unique passphrases that are memorable but difficult to guess
-
Review your data and backups
What it means
Understanding what data you hold, where it’s stored and how it can be recovered if systems become unavailable.Why it matters
Backups can be the quickest way to restore systems and recover data after an incident or ransomware attack. And if they’re unavailable, recovery becomes much harder.How to apply it
Identify critical business data and where it’s held.
Ensure backups are automated and stored separately from your usual systems, ideally offline or in a protected cloud environment.
Regularly test backups to confirm data and systems can be restored successfully.
-
Patch and update software
What it means
Installing software updates to fix bugs and security vulnerabilities.Why it matters
Cybercriminals frequently exploit known vulnerabilities in outdated systems to gain access to business systems. Regular patching closes these gaps and reduces exposure.How to apply it
Enable automatic updates where possible to reduce the risk of missing critical patches.
Prioritize critical systems and internet-facing software.
Apply patches promptly when software vendors disclose critical vulnerabilities.
-
Audit VPNs and RDP (Remote Desktop Protocol)
What it means
Reviewing and securing tools employees use to access systems remotely, including VPNs and remote desktop protocols (RDP).Why it matters
Remote access tools are a common target for cybercriminals, especially if poorly configured or left exposed.How to apply it
Disable unused remote access services.
Restrict access by IP address, user role or business need.
Protect remote access with MFA and strong passwords.
Regularly review who has remote access and remove when it’s no longer required.
Strong cyber security starts with the basics
Cyber security doesn't have to be complicated. Many of the most effective ways to reduce cyber risk come down to a handful of practical measures, from strengthening access controls and keeping software up to date to monitoring for unusual activity and maintaining reliable backups. By putting these foundations in place, businesses can reduce their risk and be better prepared when new threats emerge.
For brokers wanting to learn more, module four of Cyber Masterclass provides a simple guide to the cyber security controls that help protect businesses. Explore it here.