# The three “must haves” of cyber security that you need to stay cyber safe
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2022-05-31
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: Three Must-Haves for Cyber Security: People, Processes,
Meta Description: Discover the essential &#039;must haves&#039; - People, Processes, and Technology - to safeguard your business from cyber threats. Learn how to empower your
URL: https://financedigest.com/the-three-must-haves-of-cyber-security-that-you-need-to-stay-cyber-safehtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/istock-1011996682-1736815675576-compressed.jpg)

![](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/untitle-1736815675556-compressed.jpg)

_By_ **_Mark Brown,_** _Founder of_ [_Psybersafe_](https://psybersafe.com/)

I worked in cybersecurity in the finance sector for many years, and I know from experience that there are three “must haves” that all businesses should have in place in order to keep their online systems safe from hackers. Without  these three pillars – People, Processes and Technology   all being present, the cybersecurity job becomes much harder.

- **People**

Of these three, my view is that ‘People’ must be at the [top of this list](https://www.financedigest.com/the-secret-to-academic-success-colouring-in-oxford-and-cambridge-residents-top-the-list-of-crayon-wielding-adults.html "The secret to academic success? Colouring in! Oxford and Cambridge residents top the list of crayon wielding adults"). Of course, many companies take this to mean hiring specialist [cyber security](https://www.financedigest.com/how-to-handle-cyber-security-during-mergers-and-acquisitions.html "How to Handle Cyber Security during Mergers and Acquisitions") staff. But actually, everyone in your business is part of this pillar. Every single one. And that’s because statistics show that 90% of [cyber security](https://www.financedigest.com/the-future-of-cyber-security.html "THE FUTURE OF CYBER SECURITY") breaches are down to human error.

And, regardless of how experienced they are, it could as easily be your CIO or someone in your IT [team as the customer service rep who opened an email that looked like it was from the client](https://www.financedigest.com/brand-metrics-bolsters-client-services-team-as-brand-lift-measurement-booms.html "Brand Metrics bolsters client services team as brand lift measurement booms"). It could equally easily be the accountant who thought she was clicking on an invoice, or the HR Director who followed a link to an updated CV.

That’s how [cyber criminals get into your business](https://www.financedigest.com/over-50-of-businesses-increased-their-cyber-security-budget-last-year-amid-attacks.html "Over 50% of businesses increased their cyber security budget last year amid attacks"). They tend to use people. That makes your people your first line of [defence against cyber](https://www.financedigest.com/shoring-up-cyber-defences-in-the-remote-working-era.html "Shoring up cyber defences in the remote working era") criminals.  Everyone in your [business needs to know](https://www.financedigest.com/setting-up-a-business-in-the-uk-heres-what-you-need-to-know.html "Setting up a business in the UK? Here’s what you need to know.") not just what to look out for, but how to change the way they behave to stop inadvertently opening the door to data loss and all the serious financial and reputational damage that inevitably comes with it.

All the [data in your business](https://www.financedigest.com/from-sec-edgar-to-business-applications-exploring-an-alternative-to-manual-data-extraction.html "From SEC EDGAR to Business Applications: Exploring an Alternative to Manual Data Extraction") is sensitive – it’s your data. And the [data of your clients](https://www.financedigest.com/dimension-data-introduces-next-generation-managed-services-offering-accelerate-client-innovation.html "Dimension Data introduces next-generation managed services offering to accelerate client innovation"), suppliers, and shareholders. Importantly, a criminal doesn’t [need highly personal details to do real damage](https://www.financedigest.com/uk-businesses-need-to-embrace-payment-technologies-to-reduce-financial-damage-risk.html "UK businesses need to embrace payment technologies to reduce financial damage risk") – names and email addresses may be enough. So anyone [working in your business with access to any information could put your business at risk](https://www.financedigest.com/combating-the-security-risk-of-remote-working.html "Combating the security risk of remote working "). To support your people, you need three things: good quality, behaviour changing [cyber security](https://www.financedigest.com/why-preparation-for-new-swift-cyber-security-standards-needs-to-start-now.html "‘Why preparation for new SWIFT cyber security standards needs to start now’") training, backed by the other two pillars of effective cyber security.

- **Processes**

Every organisation – no matter how big or small and no matter what type – should have processes in place that help manage [cyber security](https://www.financedigest.com/5-ways-to-protect-your-company-from-cyber-security-threats.html "5 Ways to Protect Your Company From Cyber Security Threats") issues. Who has access to what data? How do people log on? Do you use two-factor authentication? What happens if your [security is breached](https://www.financedigest.com/financial-services-risk-data-security-breaches-insecure-instant-messaging.html "Financial services risk data security breaches with insecure instant messaging")? How do you tell your customers you’ve lost their [private data](https://www.financedigest.com/2023-fintech-prediction-secure-and-private-data-usage-is-key.html "2023 FinTech Prediction: Secure and Private Data Usage is Key")? How do you manage the damage to your reputation? You really [don’t want to be doing all of this when you’ve](https://www.financedigest.com/dont-let-compliance-trip-you-up-how-tech-can-ensure-youve-tied-up-your-contracts-2.html "Don’t let compliance trip you up: how tech can ensure you’ve tied up your contracts ") fallen victim to an attack. Develop clear, robust policies and [share them with your teams so they know you are taking this significant risk](https://www.financedigest.com/asia-shares-weigh-china-risks-yen-hits-6-month-high.html "Asia shares weigh China risks, yen hits 6-month high") seriously.

- **Technology**

[Technology plays a critical role in protecting your business](https://www.financedigest.com/how-an-advanced-manufacturing-technology-can-make-your-business-more-3-dimensional.html "How an advanced manufacturing technology can make your business more 3-dimensional") against attack.  But where to start?   Whilst ISO 27001 is the strongest standard, smaller companies can start with adopting the [Cyber Essentials certification – a government-backed scheme that is managed by the National Cyber Security](https://www.financedigest.com/uks-morgan-advanced-materials-reports-cyber-security-incident-on-its-network.html "UK’s Morgan Advanced Materials reports cyber security incident on its network") Centre. This certification covers a wide technical scope and [gives your customers](https://www.financedigest.com/businesses-are-investing-in-technology-to-improve-customer-experience-but-many-are-still-falling-short-of-giving-customers-what-they-want.html "Businesses Are Investing in Technology to Improve Customer Experience, but Many Are Still Falling Short of Giving Customers What They Want"), suppliers and investors confidence in the general standards of your technology and systems.

At the moment, Cyber Essentials includes a range of requirements for IT infrastructure – hardware, [software and devices](https://www.financedigest.com/does-device-entitlement-software-in-smartphones-signal-new-growth-for-volte.html "Does Device Entitlement Software in Smartphones Signal New Growth For VoLTE?") – including:

- Wireless devices
- Bring Your Own devices
- Externally managed, or cloud devices
- Other externally [managed services](https://www.financedigest.com/managing-the-hidden-security-gap-in-financial-services-the-office-printer.html "MANAGING THE HIDDEN SECURITY GAP IN FINANCIAL SERVICES: THE OFFICE PRINTER")
- Web applications
- Firewalls
- Routers
- Desktop devices

In addition, the certification looks at other issues, including password-based authentication and administration of accounts..

Your [internal or external IT support should be constantly assessing the potential risks to your business and putting mitigation in place to keep systems secure](https://www.financedigest.com/the-financial-sector-must-act-to-tackle-internal-data-security.html "THE FINANCIAL SECTOR MUST ACT TO TACKLE INTERNAL DATA SECURITY").

Together, these three pillars form the basis of a strong and secure approach to the risks that [cyber crime](https://www.financedigest.com/london-the-capital-of-cyber-crime-in-the-uk.html "London: the capital of cyber crime in the UK") presents. But you [need to have all three in place](https://www.financedigest.com/fintech-needs-women-5-reasons-why-this-is-the-place-to-be.html "Fintech needs women – 5 reasons why this is the place to be") to be truly effective. Many [companies focus on the tech](https://www.financedigest.com/uk-to-fine-tech-companies-that-fail-to-remove-self-harm-material.html "UK to fine tech companies that fail to remove self-harm material") and forget the people – and that’s a mistake. Your people are the heart of your business, and they are the [hacker’s easiest way to your data](https://www.financedigest.com/frances-thales-says-hackers-claim-to-have-stolen-data.html "France’s Thales says hackers claim to have stolen data").

I am a great believer in getting the right technology in place to support good [cyber security](https://www.financedigest.com/the-financial-services-industry-needs-to-get-serious-about-cyber-security-in-the-covid-19-era.html "The financial services industry needs to get serious about cyber security in the Covid-19 era") practice.  But technology alone is not going to protect you.  Make sure you put your [people at the heart of your cyber security](https://www.financedigest.com/31972social-engineering-in-the-financial-services-people-are-the-weakest-link-in-the-security-chain.html "Social engineering in the Financial Services : People Are The  Weakest Link in the Security Chain") defences.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

