Hackers who target businesses and other organizations are constantly finding new ways to try and steal information. Some of the stolen information is used for other criminal activities such as identity theft, online banking fraud and social networking scams.
With more and more data breaches happening every day, it’s likely that your employees’ information is being sold on the dark web, aka the darknet. This information is used by other criminals to gain access to accounts or to conduct illegal activities.
Why do I need a dark web scan?
You probably don’t know how many of your employee accounts can be found on the dark web. A dark web scan reviews lists of stolen identity data found on the dark web (emails, passwords and personal information) to identify accounts associated with your email domain that have been compromised by an external data breach.
An external data breach is a breach that has happened outside your company or organization. Some notable breaches include the LinkedIn breach that compromised over 160 million accounts, the DropBox breach, that compromised close to 70 million accounts, and most recently, the Marriott breach that affected up to 500 million accounts.
The dark web scan will identify which of your accounts were exposed, which breaches they were involved with, and what passwords were hacked.
What is the risk?
While these data breaches are no fault of your own or your employees, they could potentially have damaging consequences. Many times, hackers and cybercriminals will use the credentials of one breach, say, the LinkedIn breach, and try them on other websites. If your employees use the same email and password across multiple websites, they could be at risk of compromising their accounts, including their business accounts.
Having compromised business information on the dark web thereby significantly increases the risk of receiving a phishing email at your organization, which can be a vector for serious malware or ransomware to enter your organization. The more external data breaches your organization has been involved with, the higher your risk.
How do I protect my company?
If you discover that your email address has been associated with one or more external data breaches, you and your employees should take immediate action to minimize the risk of a breach by immediately changing all passwords associated with the compromised accounts to unique, strong passwords.
One of the most important preventative steps you can take is to conduct an employee vulnerability assessment. Using simulated phishing techniques, the assessment will identify what employees would do when they are sent real phishing emails, thereby uncovering risky behaviors and vulnerabilities.
After identifying these human vulnerabilities, remediate with education, ensuring that your employees are properly trained on cybersecurity. Training should include:
• How to spot phishing and phone scams
• The dangers of social media scams
• How to create strong unique passwords for each account
• When to avoid using biz emails for personal activities
• How to protect portable devices such as smartphones, laptops and USB drives
• Help employees keep the door locked!
Your employees are the weakest link in your security plan. Over half of all data breaches are caused by human mistakes, but properly trained employees can be your first line of defense. They can act as human firewalls and protect your organization and minimize the chance of data breaches.
Scott Schulze is the founder and director of operations of Fusion Technology Solutions (fusiontechnologysolutions.com, 888-380-3580) in Healdsburg.