First Published: 04/10/2022, updated 6/10/2025
Overview
With the recent high profile cyber-security breaches at Marks & Spencer, Jaguar Land Rover and Harrods to name a few, it may be a good time to review your own cyber-security and make sure you are doing enough to protect your data…
October is Cyber Security Awareness Month, a campaign to raise awareness of cyber resilience and how individuals and businesses can protect themselves against cyber-crime.
Cyber-crime can cost organisations time, money, reputation, and customers. According to the Governments 2025 Cyber Security Breaches Survey 43% of UK businesses and 30% of charities reported having experienced any kind of cyber security breach or attack in the last 12 months. Of the 50% of UK businesses who identified an attack, the most common threat vector was phishing attempts (85% of businesses and 86% of charities). This is followed by others impersonating organisations in emails or online (34% of businesses and 35% of charities) and then viruses or other malware (18% of businesses and 14% of charities).
Among those identifying any breaches or attacks in the previous 12 months, around half of businesses (47%) and around two in five charities (39%) say this happens once a month or more often, one in three businesses (29%) and a fifth of charities (20%) said it happened at least once a week.
The average cost of the most disruptive breach was £3,550 for businesses and £8,690 for charities. The costs reported here are self-reported estimates, which may represent an underestimation of full financial impact.
Cyber Security Awareness is important for any organisation, however small. With the evolution of remote and hybrid working which has accelerated since the pandemic, Cyber Security is more important than ever as cyber criminals are continually improving their attack methods and techniques.
Traditionally where workers were mainly office based, it might have been considered adequate to have a perimeter firewall for the office and anti-virus software on user computers. Today that is not adequate, and organisations should take a Zero Trust approach – verify and authenticate everything.
A Layered Approach
At Engage IT we take a layered approach to Cyber Security, although I may describe various security concepts in isolation, they should be used in combination to enable a robust cyber security strategy to enhance Prevention, Detection and Response.
During this month I will be looking at the following:
- User Account Security
- User Awareness & Security Culture
- Endpoint Security
- Advanced Threat Protection
- Advanced Phishing & Malware Protection
- Patching and Updates
- Backup
- Email Authentication & Security
User Account Security
In this article I am going to focus on how you can improve User Account Security.
The principle of least privilege
Small businesses often think it is easier to give everyone access to all organisational data.
Although this may be easier to manage, it is not best practice and businesses should operate on the principle of least privilege – each staff member should only have access to the data they require to perform their role.
This helps reduce the attack surface area should a user account get breached.
Device Security
All staff members should have their own login and should not use shared login accounts to access their PC/devices or online accounts.
Any PC or devices accessing organisational data should lock after a certain amount of idle time and require a password/pin/fingerprint/face ID to unlock them.
All PCs and devices should be encrypted.
Use a Password Manager
The password is still your front line of defence, but unfortunately it is often the weakest. According to Microsoft they receive 921 password attacks every second—nearly doubling in frequency over the past 12 months.
Password Problems
Firstly, for a password to be as secure as possible it should be complex, which means at least 12 characters long and ideally be a set of random characters including upper and lower case, numbers, and special characters. A password such as !fcTXi4@i-bc although very secure is also very difficult to remember.
Secondly, each system accessed should use different passwords. Otherwise, if a user account is breached, other related accounts are often easily breached as well.
Thirdly, because of the multitude of passwords users have to remember, they are often stored insecurely in unprotected documents or notebooks, or worse still, written down on post-it notes and stuck to the screen!
Unfortunately, the reality is passwords are hard to remember and keep track of, so users often choose weak passwords; combinations of dictionary words and numbers that are easy to remember but also easily breached. And due to the multitude of services a user may be accessing, passwords are often re-used.
A Password Manager can resolve these issues, my previous article Why you should be using a Password Manager explains what a Password Manager is and why you should be using one.
Three Random Words
If you cannot or will not use a password manager, consider using a passphrase of at least three random words e.g: briefly hereby angrily
Add some upper and lower case, special characters and some numbers and you have a very secure password that is easy to remember: brieflY-Hereby-angrily27
Multi-Factor Authentication (MFA)
Traditionally a username and password were considered enough to verify your identity, but today with the steady rise in cyber-crime, they are often too easily breached.
Most online services offer an additional way of verifying your identity and financial services will enforce it; if like most people you are using online banking, you are already using a form of MFA without necessarily knowing it.
As most modern smartphones use fingerprint or facial recognition, users are already familiar with this concept. Using your smartphone as an additional level of authentication means that if your account password is breached the account still cannot be accessed without your smartphone.
My previous article What is Multi-Factor Authentication (MFA)? explains this in detail.
Look out for further articles this month focusing on Cyber Security.
If you need any help with your Cyber Security requirements Contact Us

