Network users often expose themselves to cybercriminal attacks, for example by using the same password across many different websites. In such a case, when one account is breached, all the rest are at risk. To prevent this, it is crucial to adopt appropriate practices and precautions, known as cyber hygiene. Tools such as password managers or multi-factor authentication mechanisms can help here. Aamir Lakhani and Jonas Walker – experts from FortiGuard Labs at Fortinet – discuss the best practices.
Why does using a single password pose a threat to cybersecurity?
Jonas Walker: This is a very important issue, because many people still use one password, or slightly varied versions of it, for different accounts. If, for example, we put a "2" instead of a "1" at the end because of an update requirement, the password essentially stays the same. It is not unique, and in my opinion this is a big problem, because reused passwords make things easier for cybercriminals. The keyboard layout also gives them hints. If a site requires a password with a special character or a number, the special character will most likely be an exclamation mark, because it sits on the key with the number 1. That is the logic users typically follow, and cybercriminals know this perfectly well. The popularity of password patterns and machine learning (ML) mechanisms make it easier for them to determine which structures are used most often.
Aamir Lakhani: There are millions of old passwords that have leaked but are still used by users. Sometimes they merely change a digit, add or remove a letter. Cybercriminals have programs that look for these typical substitutions. They create password lists from which they can generate millions of new ones, with various combinations. Then they test them automatically until they hit the right one. That is why I always encourage using unique usernames on every website. Some of them require it to be an email address, but it is best to create a new one each time for that purpose.
How can passwords and usernames be secured in a hybrid work environment?
How to take care of cyber hygiene in hybrid work?
Jonas Walker: I recommend using password managers. This tool makes data protection much easier. Every time we register on a different platform, it automatically generates a new, unique password and stores it in its forms.
Aamir Lakhani: It should also be remembered that multi-factor authentication can give a false sense of security. Many people use text or SMS verification, but this solution has weak points. This is precisely where cyber hygiene is particularly important. Often, when pop-ups appear on mobile operating systems asking "Do you want to share SMS data with this app" or "Are these the permissions you want to grant to the app," not everyone reads their content. Typically, people carelessly click "yes," which means apps receive more data than the user would like. These permissions are used, for example, for advertising purposes. Malicious apps, on the other hand, force access to SMS messages this way in order to steal codes sent during the multi-factor authentication process. That is why it is important to be aware of what permissions you grant to apps.
How can a company best take care of cyber hygiene in the era of hybrid work?
Jonas Walker: Connecting devices used for remote work to the corporate network should be done with great caution. It should be remembered that in recent months home networks have often been attacked due to remote work. If the security of software installed on mobile equipment has been breached, connecting it later to the corporate network can bring serious risk. Cybercriminals anticipate such scenarios in advance, so I am convinced they are prepared for this type of attack. Meanwhile, more and more private devices are gaining access to the corporate network, so educating employees and providing them with training is essential.
Aamir Lakhani: I agree that training employees and raising awareness about digital threats is crucial for corporate cybersecurity. Knowing how to filter incoming emails can be a really simple way to avoid phishing attacks, which still happen often. I also recommend having two email inboxes – one for internal messages and another for external ones. It is also worth using digital signatures to verify the digital credibility of correspondence.