Skip to main content
Pointless Compliance · Episode 3

Data protection - are we fighting a losing battle? With Nicholas Williams

LinkedIn
14 April 2025 1:09:53

Nick Williams, a GRC analyst, discusses the pervasive threat of human error in data breaches and shares practical steps individuals and organisations can take to reduce risk, from phishing awareness and strong passwords to training programs and security certifications.

Chapters
Transcript

So this week we find ourselves with Nicholas Williams from Boot Consulting. So Nick, you are officially titled as a GRC analyst. So I had to do a little bit of research and Googling to actually find out what that means. But do you want to tell us maybe?

Yeah. Well, I mean, I guess it's quite a broad title. GRC stands for Governance, Risk, and Compliance. With my role at the company that I'm with now, Boot Consulting, my role is helping to implement governance frameworks such as ISO 27001, or management frameworks, which is implementation of an information security management system. Bit of a mouthful. We also do ISO 14001, which is an environmental management system. ISO 9001, which is a quality management system. So that would be part of it. My main focus will probably be a lot of ISO work but also training. So before I came into this role, I've worked in health and social care for 12 years in a variety of roles, which I am finding are very transferable. There's a lot of transferable skills from that industry into cyber and IT.

Got any examples of what some of those might be?

Well, I guess the main one is that the last four years I spent working in health and social care. Two of them I spent during COVID. I worked as a suicide support worker, which was as intense as it sounds. It was quite a job. And then the last two years I spent working for a small care provider who focus their efforts on helping children who have quite severe behavioral difficulties through learning disabilities and trauma that they've gone through as young people.

The commonality with a lot of suicide work and also behavior management is behavior change. And actually that has a lot to do with governance, risk, and compliance. Especially compliance. One of your biggest assets when you're looking at implementing governance and management frameworks is your training and awareness. A lot about training and awareness is trying to help people, or trying to change people's habits to support the business security culture. So whilst a lot of my work was about changing people's behaviors, changing people's habits and mindsets within health and social care, I've taken that or a lot of that is then transferable into this industry, trying to change behaviors.

Yeah. And I mean, how do you approach that then? I assume you've already been into a few companies to look at implementation and changing behaviors. I mean, what's your approach?

Well, I guess where do you start? If we take, for example, ISO 27001 implementation, which is the information security management system, there's a whole process involved in that which lays out the pathway in which it's going to be implemented. When it comes to behavior change, we're looking predominantly at a clause which is people controls. So we're looking at what we can put in place to help staff, and any staff, anybody supporting the business, any human who's supporting the business, how we can change their behaviors to bolster the security culture.

Where you start, I guess, well, having been fairly new to the industry and learning from my colleagues and our manager Lynn, my expertise comes in in training and awareness. In my previous roles, I ran training programs for staff to help them deal with challenging behaviors. I'm just trying to think how to best explain it.

So one thing I was wondering about is that when Lynn mentioned you, one of the things she talked about was human risk.

Yeah. So, coming into a company to look at any compliance standards you're going to satisfy, it always involves people, isn't it? People are core to your workforce, to what you do, to what you make, and whatever service you provide. So from a human risk element, what would you say are the risks preventing companies from complying?

Well, if we sort of move away from compliance, because whilst that is an important part of it, it suggests that there is a box ticking exercise. If we shift away from that and look at it more as we're implementing this framework because we want to be a more secure company, we want our clients to trust that we are going to be looking after their data. We don't want to be spending our profit margins on paying fines because our security wasn't robust enough to be resilient to a cyber attack.

When we were talking about human risk, the human risk is a broad term. A definition could be it's the potential that human behaviors could result in a cyber incident. We can break that down further. Well, firstly, that covers everybody from your supply chain to your employees to your C-suite to the cleaners, to anybody who has involvement within your company, anybody who supports your company.

You can sort of break that down further into insider risk and then also insider threat. An insider risk is a broad category that describes anybody in the company and any human behavior that could potentially cause harm. Usually, it's not thought of as a malicious act. It's not someone trying to damage a company. Whereas an insider threat is generally described as something that is purposely malicious.

When we're looking at reducing insider risk or human risk, what we're looking at is we're trying to minimize the potential that a person in your business may fall for a phishing attack. The sort of category of attacks that affects humans the most within a company are social engineering. That is phishing. So that's when an attacker sends a crafted email to a target. Within that email, there could be malicious links or downloads that the target is encouraged to click, and that can result in various problems. So credential theft, or they click on the link and then it says you need to sign in to Microsoft again to use this link, and then they put their details in, and then the attacker has their details, which gives them access.

Other social engineering attacks may also include things that don't have a direct attacker or employee link. So USB drop attack is quite common.

What's that?

So that's when a threat actor will leave somewhere around the target company a USB, and on that USB will be preloaded with malware. The USB may have something on it like a sticker that says "payrise documents" or "pay documents", or "Who's next to be fired?", you know, something that if an employee sees it, might go, "Oh, actually, I would quite like to know that. I'll have a look at that." Or "Property of the CEO", something like that. And then they'll go and plug it into their computer, and then boom, you've got malware on your computer, which the attackers have installed.

And I mean, is that quite prevalent? You know, a lot of effort.

So when you're looking at why an attacker might attack a business or an organization, they're looking for a return on investment. So the investment is a USB, but actually what they get from that is credentials into a massive organization, and from that they have access to business emails, they have access to potential shared files. If the security within the company isn't robust enough, they can make their way through, and what's called privilege escalation, so they can give themselves more privilege within the company to be able to get data that isn't available to everybody. Then actually it's a very small investment.

You know, nowadays, well, there was a study done by Cyber Safe, and they found that 80% of data breaches that were reported to the Information Commissioner's Office, the ICO, were due to human error. That was in 2021, which is actually an improvement compared to 2019, in which case it was 90% of data breaches reported to the ICO due to human error.

Now, whenever it's quoted, obviously these statistics are from different sources and they have different sources from which they collect their data. So you can take everything with a pinch of salt. But your staff have got a huge role to play in improving your company's resilience. I guess the probably most common attack vector when it comes to social engineering is phishing. I'm sure you have received phishing emails. I received quite a lot of phishing emails as soon as I started working here. I guess if you put cyber security or information security on your LinkedIn profile, it's people who scrape social media profiles to get information about companies, and then they have all that information.

The first one I got was from Lynn, asking me to contact her immediately about something very important via WhatsApp. Lynn was sat next to me at that time when I received this email. So we knew it was a phishing attempt. But you know, it's a type of attack that is becoming more and more readily available to people who have very little to no technical skill at all to be able to implement.

So what would be some actions to take? I know it was quite a broad question earlier about this whole compliance process and so forth, but what would you think then is the first port of call to prevent the human risk in that area?

Well, I guess in terms of phishing, your biggest asset is going to be awareness and training. Phishing emails are becoming more sophisticated through the use of AI, but also through cybercrime as a service. We know about software as a service, platforms as a service, sort of legal legitimate services that people offer, IT services that people offer. Well, cybercrime has now taken on that role. Certain criminal organizations are taking on that role to offer malware as a service, ransomware as a service. All of these attacks can now be bought by anybody who can then use them on pretty much any organization that they want.

I guess one of the most profitable areas of organized cybercrime is the initial access broker. An initial access broker is someone who is paid to gain access to an organization and then that's it. They will obtain credentials of a member of staff, potentially through phishing, through other forms of social engineering, or finding disgruntled employees and paying them for their credentials.

So when it comes to that kind of attack, your best method of mitigation is going to be through training and awareness. With disgruntled employees, you're looking at making sure that your employees are happy, and if they aren't, finding out why and what you can do to help them not want to sell their credentials to people.

Yeah. And I suppose it's also having processes in place to absolutely get information back in the right method. Especially maybe if you have processes where somebody goes, it's kind of being aware of the potential if you haven't managed certain assets before that decision's made.

Yeah. Absolutely. Having a move, second to training and awareness is having a really solid policy and process suite. Making sure that employees know exactly what they need to do and when they need to do it when it comes to security. But yeah, like looking at, I mean, maybe I am biased because my background is training and awareness. Well, it was in a different industry, it was still training and awareness, so training and awareness often gets used interchangeably.

So awareness is your staff and the people that support your business's ability to spot threats and attacks before they happen. And then the training is there to help them to know what to do when that happens. So you can make people aware of phishing, but when a phishing email comes through, they need the training to know what to do with it.

So there's a lot you can pay for with simulated phishing attacks, whereby an external company, a trading company, will send fake phishing emails to your employees, and it collects data as to how far in the process that employee then takes it. So whether they opened the email, whether they clicked a link, whether they filled in their credentials, or whether they just reported the email and got rid of it.

And who would you say this is best for? Because I mean there's probably people listening who will think, well, I don't think we need to do that because we do X, Y, and Z, and it's not really an issue to us.

Yeah. So security works best in layers. There's a quite common saying which I'm hearing more and more whenever I'm at a networking event or at a conference or anything to do with security and IT security, which is there's two types of companies. There's those who have been hacked and had a data breach, and those who are about to be hacked or have a data breach.

You know, especially with the changing landscape where cybercrime is becoming readily available to anybody. Whereas before you needed to know programming, you needed to know how to write a script, how to create malware, or definitely be in the right circles to be able to get it and implement it. Now, in a landscape where you have ChatGPT and you have all these LLMs and AI software that can create these very convincing emails, this is becoming accessible and available to everyone.

For people who don't think that they, because they have other things in place, means that they won't need to have this in place. You can't really be too secure. I'm sure there'll be people who argue with me about that. The thing is, I mean, the whole scam thing applies the same way. There's ones who have been scammed and there's ones who are about to be scammed. Because even I, I thought that I was pretty scam safe to a degree, but I found myself losing out on a 600-pound camera because I sent it to the buyer through a reputable service that I thought it was, but they had just mimicked the whole service all the way through.

Really?

Yeah. Yeah. Or there's those people who have been hacked but don't know it and don't think they have been, and actually slowly but surely there's a lot of data that has been used.

Whenever it comes to any kind of social engineering, attackers need to do an amount of research and reconnaissance. If they have a target company that they want to look at, they're going to be trying to find their best way in, and they want it to be the easiest, most cost-effective way with the biggest amount of breach. So yeah, you're going to be looking for your disgruntled employees.

And I'm not saying that employees are the only way that an attack is going to get in. Arctic Wolf recently released their 2025 threats report. According to their 2025 threat report, the root causes they found of ransomware and data extortion were found to be external exposure. So that is very little of it has anything to do with humans, using known vulnerabilities through computer systems, which they would have found out through reconnaissance by scanning networks and looking at that kind of stuff.

So that kind of attack, you're not really looking too much into some of it would have been done through phishing. You click on a link, you give someone access to your network, you put in some credential.

Is there any advice that you might be able to give? So, and we've been talking a lot about companies, but even on a one-to-one personal level, something that I could change tomorrow to be more safe or to be more aware, and then something that a company might be able to change tomorrow.

Well, I actually did a talk about this recently at a tech showcase. I'll just find my notes from that, and that will help me give a bit better flow for things.

Okay. And I definitely want to talk about some of the suicide discussion as well, the similarities or read across there.

Yeah, of course. Yeah. So on a personal level, if you're looking to improve your security posture, I mean, the basics that everybody always talks about: you need to have good, strong passwords. You know, attackers, if they're looking to get into your personal account that you use, and if you use the same password for everything, it's not going to be difficult for them. If once they've found that password, to be able to...

There's a website called "Have I Been Pwned", P-W-N, so it's Have I Been Pwned dot com. On that website, you click into it, and it gives you a box to put your email address in. So you can put in your email address, give it a search, and it will tell you what information from that email address is for sale and whether there is a password that has been compromised.

So I've just put in what I call my throwaway email address, which is one that I use to sign up to various newsletters or if a company wants me to put in my email address. This is one that I put in. It's a Yahoo email, and it says that this email address has been featured in nine data breaches through various different service providers.

I've got on here Last.fm, which was quite a big data breach back in 2016, I think. It says that they breached 37 million email addresses, usernames, and passwords. So there is somewhere out there 37 million usernames, emails, and passwords that are all linked to these accounts, which someone could get them and try on various different sites.

If you have the same email address and password for your Last.fm account that was breached, and you have the same one for your bank, it's not going to be too difficult for them to get into it.

Something that you can do from that point is you enable multi-factor authentication. That's your something you know, so like a password, something you have, such as a phone. So that's when you put in your email address, and it says "We've sent you a one-time password to this number", and then you've got that, you click that, or you put that into there, and then that allows you into your account. Or something you are, so biometrics, fingerprints. I spend quite a lot of time in the sea and around rocks, so my fingerprints don't tend to work anymore. But I find facial recognition is good. And iris recognition, that kind of stuff is all good.

So these are all things that whilst they are something that a person can implement, these are also things that it's really important for companies to implement as well. Phishing awareness, being able to recognize these emails and then what to do about them.

I did recently do my tax return, as most people did in January. I sent that off, and within maybe three or four hours, I had a phishing email which was very convincing from HMRC, asking me, saying thank you for filling out your tax return, your self-assessment, click that, you have a message, or there has been a problem, click this link, and it will take you to the website.

And I thought, "Oh, that's weird. I've been doing this for 12 years. I've never got one of those." I looked at it, sort of accidentally hovered over the sender's address, which was masked as an HMRC address, and it came up with a totally different email address.

You know, and I know I've had that one recently. I know a couple of family members have had one similar to that as well. Whenever you come across anything that you think, "Oh, that's a bit weird", you know, especially no one likes to call HMRC because it can take a while to get through to places. But putting that extra effort in to verify these things, whether it's from a government department or your phone provider, you know. A lot of banks say, "We will never ask you to put your details in through email. We will never ask you to give your details over the phone. We will never do this."

You know, if you think, "Oh, that's a bit weird", taking those extra steps just to verify that it is an email or a message from them. We saw a huge rise in it when it was when people were working from home during COVID. Yeah, trying to...

So I mean you talked about AI, and obviously now things are more within people's hands than they ever were. What about the possibility of deepfake phishing, you know? Is that becoming... I mean, are you aware of any examples of that?

Yeah, I mean, it's now huge. You go on any kind of internet IT security, cyber security news forum like the Hacker News, or whoever else it is, and nine times out of ten there's an article on there about some form of deepfake. Yeah, deepfake video that has, sorry, deepfake sort of Teams, suppose someone's been made to do something they don't do.

Most recently, the one that comes to mind was a Chinese firm. I can't remember the absolute details, and I can't remember the absolute amount of money, but it was well within the millions. Someone from accounting was invited into a Teams meeting, and within that Teams meeting, there was the CEO, there were other colleagues, there were other C-suite members, and they basically said we need you to transfer a vast amount of money from one account to another. And he did it because he was asked to. Everyone was in there. Everybody in there was fake. Nobody was real. And the company lost a huge amount of money. They transferred huge amounts of money out.

You know, what website was that on? Is that some hacker website?

Well, the Hacker News is just a news website. It's an internet security news website. Really, really good. I mean, there's plenty out there. Some of the other sort of resources which I've been pointed to use are cyber security news, information security magazine, the Register, cyber magazine. But also other resources such as the NCSC, National Cyber Security Center, so that's our government's cyber security department. They put out loads of really useful stuff. The ICO puts out lots of useful resources as well. National Institute of Standards and Technology. So that's the United States cyber security department, I guess. They've got lots of useful information.

Yeah. Yeah. I'm sure that'd be really useful for people to have a little bit of a look at because you know, the more you are aware, then the better prepared you can be.

The thing I was thinking of is also, coming back to a company's efforts to make their staff aware and train them, you know, that Teams example, there's so many things which are just part of our everyday life that you don't even think could be a question for concern. You know, Teams absolutely.

And so I suppose, because I saw an example before of a daughter and her father, and the messages that even when asking for money, there were three phases of questions that they go through to just verify that it's the real person.

Absolutely. I have this with my family as well.

Yeah. Absolutely. So we ask each other questions that only we know that the other person has the answer to, and they are set questions that we always ask, which change on a semi-regular basis. So verification is going to be really important.

You know, I'm not a threat analyst. But it's going to be interesting to see how far this is taken when it comes to deepfakes and voice recognition and stuff. I even heard someone on a forum saying that even with facial recognition, you are able to falsify someone's face well enough that it will let you into their computer through facial recognition, which is where your multi-factor authentication comes in, and it's really important.

Oh sorry. Yeah. No, yeah. Sorry. I was just going to think of more things for people to do that they can do. But yeah, carry on, please.

No, no. I guess, and you see it then makes you understand why certain things like the banks, for example, you know, if everybody's logging into their bank app, I know mine, after maybe three or four facial ID ones, it then forces you to put the passcode in.

Yeah. So I mean they're doing it because they're already, and it's more critical obviously when you're a banking organization, but I suppose the same applies to you as a business and you as an individual. What safeguards have you got in place to protect yourself? Because, you know, and actually that is a method that attackers rely on. They're relying on people to get sort of authentication fatigue and just be sick of it.

So an approach that some attackers may take is that they will continue to send fake authentication notifications until the person just goes, "Oh, for goodness sake, fine, I'll accept that." You know, it just happens so often. If things like that are happening, then you need to get hold of whoever it is that is saying that they're sending these, because either it's going to be a mistake or it's going to be someone who is trying to access your account, and they're banking on the fact that you are getting sick of these notifications coming through.

Hmm. But yeah, so for individuals, strong passwords, not even passwords, use passphrases. Three random words with numbers and stuff. Password managers are the way forward. Having hundreds and hundreds of different character passwords, none of which I could remember off the top of my head anyway, I use a password manager, which I find incredibly useful. So strong passphrases, multi-factor authentication, taking your time to verify whether things are real or not.

I saw something actually during my lunch saying that fake adverts are on the rise again. Fake advertisements put onto various pages, and the person clicks on it, and it's a great deal, and then you, it's another form of phishing but through advertising phishing, rather than through email phishing.

This is it. Phishing comes in in so many different forms. There's vishing, V phishing, which is voice phishing. Someone may phone up the customer service line, pretending to be someone who is one of their customers. They have very small amounts of information, and they're trying to get more information to be able to get into that customer's account. They will use that as a method of trying to get into the account, getting more data, getting more information.

Yeah. Yeah. It makes you it makes you a bit worried, you know? It makes you start to think about, well, how am I going to ever be able to trust anything in the near future?

I mean, I guess, yeah. I mean, we're at that point. For sure. I don't, I mean, it's a worrying topic, but there's some pretty strong steps that you can take so that you shouldn't really be worried. You know, things just like having those protections I spoke about before. Making sure that your laptop, your computers, and your phones are updated. Okay, there are, you know, every time there's an update, there is some form of exploit or vulnerability that someone will find, which will result in something. But for the most part, making sure that when those security updates come through on your phone, you are doing them when they're coming up. On your laptop, you are doing them. They're patching all the little holes in the software and operating systems that are going to give attackers a way in.

Verify, verify, verify, verify. Make sure that who you're talking to is the right person.

And you know, all of these steps, again, there's another quite common saying where there is no such thing as 100% security. You know, the technological landscape is changing so quickly, it's impossible to plug all the holes that are appearing. But you know, these steps can make you a harder target.

What you're trying to do is you're not trying to make it worth the attacker's time. They're looking for a return on investment. They're looking for easy access. Unless you're a massive big corporation like the company recently that lost 1.5 billion in Ethereum, you know, that would have required a huge amount of resources and money and is sort of suggested that it was a state-sponsored attack.

But for your average person, for a lot of people, they're just looking to make easy, hassle-free money. And you are easy, hassle-free potential money if you haven't got passwords and you're not looking after them.

Other things about having a VPN, Virtual Private Network, which masks your IP address. Easy. There's lots of free options out there. Proton has a free version. I'm sure there's lots more. That's what I use. I actually use the paid version of Proton for a lot of my stuff.

And what does that do for people? Essentially, that gives every time they access the internet they've got their IP masked.

Yeah. So you, through technology that I'm not going to be able to explain very well, it's you are, it masks your IP by connecting you to a server that is, um, a virtual server that is in another place than where you are. So in London or something like that.

That sounds fine. That sounds fine.

Yeah. So I mean there's definitely some quick wins, isn't there? And I mean, even the example you gave before, which you're doing, is having an email address you use for X and an email address you use for Y. You know, I think some people are still, especially the buying process now is that a lot of companies will send you a receipt by email. So you're putting your email in, and it's kind of, well, maybe you have one for that, work email or your...

Absolutely. And you're relying on them to be looking after your data as well. You know, something that I was told recently, I think it was maybe like a Money Supermarket thing, was if you have a credit card, I'm not suggesting people go out and take credit cards because they can be pretty nasty things. But whenever you're doing any internet-facing purchases, use a credit card, because if you have money taken off you, it's a lot easier to get it back.

So my debit card is used strictly for my mortgage and bills. Whereas anything that I purchase on the internet is going on my credit card. You know, that's again something quite easy that you can implement to sort of protect yourself just that little bit more.

Yeah. So I mean, in terms of businesses and companies looking to reduce human risk, again I will always say training and awareness. Make sure that your team or anybody does... Oh, we were talking about supply chains. That was it. We were talking about looking at suppliers as well. But yeah, making sure that your team knows what they're doing.

Whenever you're getting a supplier, when you're looking at taking on a supplier, and you're buying a service from them, doing good due diligence on them will save you in the long run.

And what kind of due diligence would that be?

So, primarily, first off, you're looking at their certifications, whether they hold any security certifications or assurances. So whether they have ISO 27001, whether they have Cyber Essentials, and whether they have SOC 2 reports.

Yeah, you can get a lot of information from that. So big companies such as Google and Apple, they have all their ISO certifications. They've got fairly robust, you can hope that they would have fairly robust services. But for smaller firms, smaller companies, you know, having showing that you do look after people's data and that you will look after it can be a real good, that can set you aside from competitors potentially. You know, showing that companies and other people can trust you.

I know that a lot of if you want a government contract, if you want to work with the government, you have to have ISO 27001 certifications. So any companies who are looking at getting government contracts, that is a necessity. That's where you guys would come to be able to support on that kind of...

Yeah. Yeah. Yeah. We do specialize in ISO 27001. You know, my colleagues and Lynn have got a huge amount of experience, as well as a really easy toolkit to use, and really spend the time to work with companies to help them achieve that.

Uh, so yeah, DJ doesn't, uh, security assurances is a good place to start. And just chatting to them. You know, if it's a smaller company and you can speak to someone, ask them what their security procedures are like. By law, you have to report breaches over a certain size. So you can do your own research to find out if they've had a breach within a certain period of time, or if they did, what it was, what caused it.

And where would that, is there a website you're aware of to do that?

So the ICO, Information Commissioner's Office, breaches of a certain size, and I can't actually remember the exact details, must be reported to them. And I'm sure there are other resources that I can't think of right now. The government... Yeah, I'm sure there are more. I couldn't, I can ask Lynn and see if she knows anything more. She might be a good person to talk to about that.

No, sure. But yeah, looking at that. Yeah. So due diligence, making sure that you know your suppliers are maintaining their security, and then that goes down the line because then hopefully they'll make sure that their suppliers are doing it, and then they'll make sure that their suppliers are doing it. Again, a really common articles that are being published at the moment on these various news websites and information websites is supply chain attacks.

Where attackers are looking to disrupt supply chains and therefore disrupt the people that they are supplying. Um okay. Unfortunately, a lot of the time there's a lot of sort of healthcare, health, hospitals that are targeted because of that.

You know, I talked before a little bit about your previous experiences with obviously suicide support. Are there any, I feel, yeah, I feel worried about saying like methods that you've learned, or ways of talking with. I mean, talking through the role. What did the role involve?

So I was a, I ran a, yeah, I worked on the phones predominantly. Yeah. So we had, I worked for a charity, a charitable organization who took phone calls from people who felt that they needed help. And I guess from a point of view... Yeah, it was a pretty crazy job doing a pretty crazy time.

I guess things that I've kind of learned that I've learned there, which have kind of come over to this bit, is being able to sort of listen to people. Listen to your colleagues, listen to your staff. And find out what their problems are. You know, a staff that feel supported and listened to within a company are far less likely to want to potentially sell their credentials. But also, I'm sure like I saw a statistic recently that's there, actually not a huge amount of people that do that.

A lot of the time it is people who are in the workplace who have problems outside of work. You know, everybody has life problems. They're coming to work. They're struggling to leave that at the door. And then you make mistakes. You know, if someone is having, is suffering from poor mental health or ill mental health because of something that's going on in their life, they are more likely to click on a phishing link because they're not thinking about it.

So looking after your staff is a hugely beneficial means of protecting your business, not just from the point of you will lose staff, but also from a security point of view as well.

Yeah. No, that's a good point in terms of the approach. So you know, how does that conversation go with a person who's rang up because they've got suicidal thoughts to bring them back down? And can we learn from that, the opposite, to bring someone else? I guess the thoughts, the thoughts are the part that is showing, you know, there's a root cause there somewhere.

If you can, you, yeah, it's about, I guess it's about being proactive rather than reactive as well. If someone is suffering in that way and they are having sort of those kind of thoughts, all you're doing there is you're looking to minimize harm reduction. Yeah. So if someone was to call the line who said that they were imminently going to do something, we would be looking at minimizing that.

Yeah. I want to be quite careful the way that I talk about this because I what I don't want to do is compare too much the horrible things that people go through to this, to a security conversation, just because I'm aware that it's a really hard... Yeah, absolutely. And there's so much more at play.

But I think maybe just to pick up on what you've just said there is that obviously in that scenario it's to reduce harm and minimize any impact. So I suppose if we, if we're just taking a learning, it's it's to reduce harm and minimize any impact. So I suppose if we're taking a learning, it's it's the opposite to get people to act more, to be more proactive. It's to maximize the protection from data protection.

You know, we need to understand well what's the worst that can go wrong, and let's track back from that, from how we implement data protection in our business or in my life. You know, I need to be thinking what's the worst so that I can put the appropriate controls in place, I suppose, is what we're saying.

Not to scaremonger people, but yeah.

Yeah. I guess maybe a better way might be saying instead of what's the worst thing that could happen, because there's always going to be something worse that could happen, what's the most realistic thing that could happen? And that's where the risk analysis side of stuff comes in. What's the most realistic thing that could happen? And then what are the effects of that that happens, what are the effects of that on my business?

So yeah, because I suppose you have to believe it. You have to believe that it is an actual risk to then be willing to go along with whatever you put in place, isn't it?

I suppose. And you know, and you know, you can't prepare for everything. Which is why things like threat analysis is really useful. If you can use some form of threat analysis provider, and I think Windows even do one now as part of their Defender suite. Looking at what is going to be most affecting your business is a really good way to prepare for it.

You know, if you have a company that operates in finance, healthcare targeting isn't going to be much of a problem for you. Attacking supply drug companies or whatever. And vice versa. So looking at being aware of what the sort of threat landscape is within your industry is a really good way of looking at what you should do to sort of prepare for those.

I guess there's a point, and I wish I could remember where or I wish someone else who would have better rehearsed it than I am could explain it, but there's a point where security systems, if you try and put too many in place, they start to counteract each other, cancel each other out. Which is where it's really useful to have something like an Information Security Management System, which uses a framework, because all these various controls that you have within the framework work cohesively to protect your company.

You know, like so for example, I'll just see if I can find... Yeah, I guess what you're saying is there is no silver bullet, but... No way. No. There's things that you can put in place to minimize it. There's controls that you can put in place to minimize certain areas of attack and to sort of shrink that attack surface. But ultimately, it comes down to a multitude of things.

So if you're looking at sort of an ISO 27001 framework, where you've got four clauses. So you've got organizational, which looks at sort of organizational controls that you can put in. So, for example, access rights, so making sure that people have the correct access for their job. Another one I can just pick out from here is segregation of duties. Ensuring that everybody knows what their responsibilities are within the company in terms of security.

You then have a second clause, which is people controls. So you're looking at good screening, terms and conditions of employment. And then there's physical controls. So this is sort of like physical security monitoring, checking at your entry. Ensuring that the security of assets that are taken off premises, so whether it's company phones, that kind of stuff.

And then you have your technological controls, which is your network security, your malware, the logging of activities, and being able to go through logs. You know, it takes, it takes a lot of different areas that need to be taken into consideration to build your company's resilience.

And that's where the beauty of ISO is. The thing is, like you can implement an ISO 27001 without going through the accreditation. So you could as a company put all the things in place to have an ISMS, but don't have to go through certification if you don't necessarily need it. But at least then you know that you have robust information security when it comes to that kind of stuff.

And I think that's what, you know, you hit the nail on the head in terms of what compliance is. You know, it's a best practice framework. You know, regardless of whether there's a mandatory element in that from customer orders or customer requirements, if you just look at it as a best practice methodology, then regardless of whether it's driven from the top down, it should be something that's on people's radar to want to think about implementing and doing.

I mean, one of the challenges having to, so we're currently sort of reviewing our training provisions, training products, and I've been speaking to some of our clients as well as speaking to people at networking events, and it's all that one of the hardest parts that comes with security is employee buy-in.

Well, and it's one of those things. It's like, well, actually, a lot of times, and I think about now when I look back into my previous work life, you know, why do we do it this way? Well, this is just the way we do it, and this is the way we've always done it. Stop asking questions.

A lot of people want to know how, like, why they're doing this training. Why am I taking eight hours of my day to do this training? Why is this kind of stuff? And you know, as per our sort of conversation we've had already, a lot of the things that you learn in your workplace you can then take out to your personal life. So it's not just about, you know, whilst you need to look after your company, if you want to continue having a job, and your company has a data breach, I think a statistic was something like 60% of companies, small to medium enterprises, who experience a data breach will close within 6 months.

You know, data breaches are very, they happen, and if it's big enough, you know, that could put people out of their job. So that's a reason why your employees, that's why people should be invested in the security of their company.

But then also, take what you learn out of these training days and apply it into your life. You know, you can protect your company, but you can also protect your family. You know, there's, you know, I've had some family members who've got children who are starting to access the internet, and you need to think about how protecting them is really important.

You know, we hear horrible stories all the time about online predators and things, and when you're not giving your children access to the internet, you are giving the internet access to your children. That's a very, very good way of saying it.

You know, and so many companies will have some form of IT training and awareness. Some of it will be better than others. But take what you learn, take what people learn, and take what you learn, and then you can implement that into your life. So ensuring that if they have a mobile device, you know, I used to work with a woman, and she had two children, and I remember talking to her, and we were talking about how they had just been given phones and things.

She was saying, you know, I can control their phones. Everything that happens from my phone. So I can see exactly what they're on. I can see what they've done. I can turn it off if I want. I could do this, that, and the other.

And at that time, before I was kind of in this industry, I was like, God, big brother vibes, you know? Like, yeah, give them a break. Let them, you know, kind of let them do this and stuff. And I guess because I've had, I mean, yeah, like I didn't have a mobile phone until I was 16. And, you know, I was kind of that, but now actually...

And I used to tell people that story, and I used to be like, can you imagine like how overbearing that must feel? But now I'm in this industry, I'm like, that was the right choice. You know, that was really, that was a really good choice. She knew what was going on.

And I know that she did a lot of work that did, um, where she was supposed to. I used to support young people who didn't have, who had severe learning disabilities. They were able to go about their days with very minimal support. They had some sort of emotional maybe emotional regulation issues and things, and maybe sort of didn't because of that, weren't able to go to school. They sort of lacked a bit of an education.

I would spend so much of my time trying to convey the message that the person that has messaged them on Instagram isn't the girl that they are, or the boy that they are putting themselves over to, and actually they don't want to be in a relationship with you, but they do want you to send them money.

It was a really difficult, I look back and I think that was, it was a really difficult conversation that we had to have, because we didn't know how to do it. I mean, there's lots of really good resources online now to help parents and carers to have that conversation with these young people. But you know, I mean, that is, that is, yeah, that is an unfortunate side effect of the care industry, is that of those children living in the circumstances that they did, in the sense that they may not have had an adult oversight on sort of technology from that point of view.

But you know, there are, yeah, it's getting better to that point, I guess. But yeah, it's like, it's a really, it's a thing that's changing. And if there's anything that...

Yeah. So I mean, going back to my original point, which is, you know, trying to get buy-in from employees to think about security, you know, you can take it from your workplace, you can take it into your own life, to sort of look after your family and friends. Even though I haven't been in this industry for that long already, my mom and dad message me fairly regularly asking whether this is a real thing or is it not, you know?

And yeah, probably not just mom and dad, but also friends, you know.

But yeah, so I can't remember what the original question was from that, but yeah.

Neither can I.

But no, it's a very, it's it was a very good explanation, though, and and I think that, you know, even the fact that you talked about kids these days, and that, you know, as I'm not a parent, you are, but that buy-in starts at home, isn't it? To get them to understand why those controls are in place, because I guess the danger with the younger generation coming into the workplace as well is that some of these things are so normal that maybe they don't think about it as much. But then also probably they understand some of these things more, because of how easy, you know, you talked about AI and what you can actually do with it.

I don't think half of us know what's really capable, but yet your 15-year-old probably does.

So maybe for companies, you know, using their younger resource to really understand the landscape more, get that buy-in from the older generation through getting that education across from the younger generation.

Yeah. Yeah. Absolutely. I mean, I guess, yeah, I mean, a lot of these, a lot of everybody born now is going to be growing up with this kind of technology.

I did hear, I think there is, I follow a few people on, um, I think it's LinkedIn. I actually recently got rid of all my social media because I just got the information overload. Maybe it's because I'm also studying at the moment, and it's taking a lot of brain power to study. Not the future getting older now. No, no, nothing to do with that.

I was about to drop my age into it then. But as an adult, you know, like and someone who has some life experience, and who's, you know, it is, it's overwhelming, this information that a lot of people are given, conflicting information as well, that you're given, or that people are exposed to at the moment. Even from not a security point of view, just that fatigue, what is a good thing to do, what's a bad thing to do, and that's the sort of misconceptions that come with it, is pretty big as well, I guess.

But yeah, I think there's, um, hopefully there's a big push. Well, there's a lot. I mean, there's some regulation coming through from the government. So in terms of age limits for social media, yeah. Yeah. Safe, is it called the safer technologies act or safer technologies bill? Something like that.

Yeah. Um, that would be pretty good. And I know the AI regulation has been debated a lot as well. I'm not really sure of the ins and outs of everything like that. But hopefully we do need more regulation when it comes to technology. I know that a lot of people think that regulation is bad and it stops progress and things, but actually, I think regulation in technology is pretty needed at the moment and will only become more needed as technology develops and becomes available to everybody, you know.

Yeah. No, good. So maybe just to finish off, yeah, if you were to give a sort of top hits, so Nick's top three tips when it comes to I guess minimizing human risk, what would your three ideas be?

So for organizations, I would say number one is training and awareness. Having a robust training and awareness program for your company is essential, because your employees are some of your most powerful assets when it comes to protecting your company. You need them. Almost every company needs a certain amount of employees. And whilst a lot of the time the focus is on they are also the biggest danger, but they are also your front line in stopping it.

So training and awareness covers so many bases. You know, you can cover lots of different attack vectors and things like that to be able to protect your business.

Number two, supply chain due diligence. I've touched on this a few times in this talk. Supply chain checking, your supply chain, making sure that they're doing everything that they need to do to maintain your company's safety, especially if they have access to your network. So if you have a managed IT provider, they have quite a lot of access to company sensitive data. So making sure that they have the correct security assurances in place is really important.

I would then say proactive strategies, or proactive security. So reviewing your policies and your security controls. I guess this is a bit of a cheat one because it also covers a few different other things within it. Ensuring that you're signing up to threat intelligence. So there's an organization called Alien Vault. They have a free threat intelligence subscription service, where you can, I mean, it goes, you can pay, there's a paid version of it as well, and you can sort of break it down even further to your industry. But that's a really good place. I know Microsoft also have one.

So things like threat intelligence as part of proactive security. Data loss prevention is really important. So making sure that when you're people are transferring data from one place to another, or if you're sending emails and so on, like that, making sure that you've invested in good data loss prevention. And then, like I say, simulated phishing exercises. Phishing, phishing, phishing, phishing, phishing.

You know, that's a really good, it's one of the most common ways. I think it was something like 80%, I've got the statistic here somewhere. It was, so 80% of reported breaches were caused by human errors. This is from 2023. Phishing accounted for 84% of those attacks in businesses, and 83% of those attacks in charities. So investing in phishing simulations in his own, but again, that's a really good thing for training and awareness.

Okay. And then if you really want to sort of show that you're taking it seriously, and if you really want to have it in a, investing in like an ISO 27001 certification, or just implementing an information security management system, and not even then going through with the certification, is a really good place as well.

I could keep them going on, but I think those are my three and a half.

No. Excellent. And and maybe one thing for you know, just Joe Blogs on the street.

Yeah. Let's go for, I think probably passphrases. Check what your security posture is first. So websites like Have I Been Pwned, P-W, have I Been Pwned dot com, in there you can check your whether your email address has been compromised, and you can check whether your password has been compromised.

And then ensuring that if you find that stuff out, so that will give you a good place to start. And then making sure that you have changed your passwords, and you change things to reflect that, is a really good one. And then multi-factor authentication. Making sure that if someone does get hold of your details, and they are sent, they can't get into it without knowing something else. If someone does find out your password, they also need another means of getting into your stuff. It's just making it harder. Make it not worth their time, you know.

Yeah. Yeah. Excellent. Excellent. No, thank you. Nick, I think that's been really really useful. Fair's fair. Lots of facts and figures in there, but lots of really practical advice that we can put in place, and hopefully companies and people find that beneficial. So, thank you for your time.

See Q-Hub in action

Book a personalised demo and we'll walk you through it on your own data.