Labor Day traditionally marks the unofficial end of summer. For many of us, it means a long weekend, a little time away from work, perhaps a cookout, a trip, or simply an opportunity to slow down for a few days.
Unfortunately, cybercriminals don’t observe the holiday.
In fact, long weekends can create exactly the kind of opportunity attackers are looking for. Offices may be lightly staffed. Employees may be traveling. IT personnel may be unavailable. And people who are trying to finish something before leaving for the weekend may be more likely to click on an email or approve a request without giving it the attention they normally would.
That makes Labor Day a good opportunity to talk about something every organization should periodically consider:
How secure is your business when no one is watching?
Cybersecurity Is No Longer Just an IT Problem
There was a time when computer security primarily meant installing antivirus software, putting a firewall at the edge of the network, and making sure someone performed backups.
Those things are still important, but today’s threat environment is considerably more complicated.
Most businesses now depend on a collection of interconnected systems: Microsoft 365, cloud applications, remote access, mobile devices, online banking, electronic records, vendor portals, and dozens of other services.
Every one of those systems represents both a business tool and a potential point of attack.
The attackers know this.
More importantly, they know that attacking the technology directly isn’t always the easiest way into your organization.
Sometimes it’s much easier to attack the person using it.
Your Employees Are Constantly Being Tested
One of the most common attacks we see doesn’t involve sophisticated computer hacking at all.
It starts with an email.
Perhaps the message appears to come from Microsoft and tells an employee that their password is about to expire. Maybe it looks like a DocuSign document waiting for a signature. It could even appear to come from the owner of the company asking someone to pay an invoice or change banking information.
The employee clicks the link, enters a password, and goes back to work.
From their perspective, nothing happened.
From the attacker’s perspective, quite a lot may have happened.
They may now have the username and password necessary to access the employee’s email account.
And email access can be extraordinarily valuable.
An attacker who gains access to a mailbox may spend days or even weeks quietly watching conversations. They learn who handles accounting, who approves payments, which vendors the company uses, and how employees communicate with one another.
Then they wait for the right opportunity.
An invoice arrives.
The attacker intercepts the conversation, changes the banking instructions, and sends the message along.
Everything looks legitimate because much of the email actually is legitimate.
That is one reason Business Email Compromise continues to be such an effective form of cybercrime.
Passwords Aren’t Enough Anymore
If your organization still relies primarily on passwords to protect important systems, it is time to reconsider that strategy.
Passwords get reused. They get stolen. They appear in data breaches. And increasingly sophisticated phishing attacks are specifically designed to capture them.
Multi-factor authentication, or MFA, provides an additional layer of protection by requiring something beyond the password.
But even MFA isn’t something we should simply enable and forget about.
Attackers have adapted.
Employees may receive repeated authentication requests hoping they’ll eventually approve one just to make the notifications stop. Fake login pages may attempt to capture authentication information in real time.
The lesson isn’t that MFA doesn’t work.
It absolutely should be part of your security strategy.
The lesson is that no single security product solves the cybersecurity problem.
Effective security comes from layers.
What Happens If Something Gets Through?
This may be one of the most important questions a business owner can ask.
We spend a lot of time trying to prevent cyberattacks, and rightly so. But every organization should also assume that eventually something may get through.
What happens then?
If ransomware encrypts your server tonight, can you restore it?
When was the last time someone actually tested that restore?
If an administrator account is compromised, will someone be alerted?
If a computer suddenly begins communicating with a known malicious website, will anyone notice?
If an employee accidentally downloads malware at 2:00 Saturday morning during a holiday weekend, does your security system simply record the event—or does someone actually respond to it?
These questions reveal an important distinction between having security products and having a security strategy.
Buying a firewall does not make a network secure.
Installing antivirus software does not make computers secure.
Having backups does not guarantee that your business can recover.
Each of these is simply one component of a larger security system.
Don’t Forget the Information You’re Protecting
Cybersecurity conversations frequently focus on technology, but technology isn’t ultimately what we’re trying to protect.
We’re protecting information.
That may include financial records, employee information, customer information, personally identifiable information, protected health information, intellectual property, banking information, passwords, contracts, and confidential communications.
For some organizations, losing access to that information for even a few hours can significantly disrupt operations.
For others, unauthorized disclosure could create regulatory, contractual, financial, and reputational consequences.
That is why security decisions should begin with a relatively simple question:
What information do we have that someone else would want?
The answer is rarely “nothing.”
Small and midsized businesses sometimes assume they are too small to interest cybercriminals.
Unfortunately, attackers don’t necessarily see it that way.
Automated systems can scan thousands of organizations looking for vulnerable computers, exposed remote-access systems, weak passwords, and compromised accounts. The attacker doesn’t necessarily have to know your company’s name before attacking you.
Sometimes you simply happen to have the door they discovered was unlocked.
Use the Holiday as an Opportunity
Labor Day is supposed to give us a break from work, so I’m certainly not suggesting you spend the weekend worrying about cybersecurity.
But when everyone returns to work, it might be worth taking a few minutes to ask some questions.
Are we using multi-factor authentication everywhere we reasonably can?
Are our computers and servers being patched?
Are our backups protected, monitored, and regularly tested?
Do employees know how to recognize suspicious emails?
Do we have appropriate protection for Microsoft 365 and other cloud services?
Is someone actively monitoring our security systems?
And perhaps most importantly:
If something happened tonight, would we know about it—and would we know what to do next?
You don’t need to become a cybersecurity expert to protect your organization.
But someone needs to be paying attention.
Cybersecurity isn’t something we install once and check off a list. It is an ongoing process of identifying risk, putting appropriate protections in place, monitoring those protections, and adjusting them as both your business and the threats against it change.
Enjoy the Labor Day holiday.
Turn off the computer for a while. Spend some time with family and friends. Fire up the grill.
Just make sure your cybersecurity doesn’t take the weekend off with you.
How secure is your network?
If you’re not sure how your organization would respond to a cyberattack—or simply want an independent look at your current security posture—we’d be happy to help.
NetSystems can evaluate your network, identify potential areas of risk, and help you understand where your security protections are strong and where improvements may be appropriate.
Sometimes the most important step in cybersecurity is simply knowing where you stand.
