What You Can Do NOW to Protect Your Houston Business Network
After you’ve read about everything you stand to lose to hackers and cybercriminals, and all the subversive ways they get into a network, you might wonder if you even have a chance. Absolutely you do. In my experience, the business owners who best avoid getting hacked are the ones who are most proactive. The more defenses you put between your network and the criminals right now, the more likely you’ll avoid becoming the next small-business statistic.
This post is adapted from Chapter 6 of my book, Protecting Your Business Against Hackers. If you’d rather read the whole thing, you can download the full book here.
Take Responsibility as the Owner
Nobody expects you to be the one scanning for viruses or installing optimization software. But as the owner, you should at least know how secure your network really is, or isn’t. After auditing most business networks, I’m usually appalled at what I find: faulty or nonexistent backups, security loopholes, shoddy reporting and flawed systems that cost more to maintain and don’t even fit how the business runs. In 98% of the networks we review, I find at least one of those problems.
Here’s the uncomfortable truth: if a hacker breaks in, your clients, partners and employees won’t blame your “computer guy.” They’ll blame you. It’s your business, so it’s your responsibility. The good news is that the rest of this post is a checklist of concrete steps you can start on today.
Keep Spyware, Malware and Viruses Off Your Network
In almost every attack we see, malware got in because of something a user did, usually downloading something enticing but unnecessary. Make it a rule that nobody in your office downloads:
- Screen savers and emoticons
- “Enhanced” web browsers
- Games and “for fun” surveys
- Peer-to-peer file-sharing software
- Music files
- Banners that tell you to “punch the monkey” or win a prize
- Sweepstakes and drawings
- Any software that makes you accept conditions in the fine print (that’s how third-party junk piggybacks in)
Watch the File Types Coming In by Email
Most attachments are legitimate, but it only takes one with a dangerous payload to bring your business to a halt. Train your team to be cautious with:
- Executable files (.exe, and HTML files). Never open an .exe attached to an email. These have carried some of the most destructive payloads ever. Most providers like Gmail and Outlook block them outright. Trojans and worms also hide easily inside HTML email.
- Documents and PDFs (.doc, .docx, .xls, .pptx, .pdf, .txt). These can carry macro viruses, and PDFs have security gaps criminals exploit. The ILOVEYOU worm in 2000 hid behind a fake “.txt” extension and did an estimated $10 billion in damage. Beware of links inside documents that send you to a remote site.
- Image files (.jpg). Most offices have little reason to receive them, and the extension is often used to camouflage an executable program.
- Audio and video files (.mp3, .wav, .mpg, .avi, .mov). Large, uncompressed files are excellent hiding places for malware. If staff are exchanging songs or videos by company email, ask why.
- Compressed files (.zip, .rar). These can contain viruses that activate the moment you extract them. Always trust the origin first.
The practical rule: if you weren’t expecting an attachment, confirm with the sender before opening it, and ask them to resend a risky .doc as a .pdf when you can.
Put a Strong Firewall in Front of Everything
Don’t scrimp on a good firewall. It’s your frontline defense, blocking everything you haven’t specifically allowed in or out of your network. Like every device, it needs ongoing monitoring and maintenance as part of your regular IT upkeep. A strong firewall lets you:
- Block unapproved websites, including social media, betting and sports sites, and other time-wasters.
- Stop malicious code by inspecting traffic in and out, blocking viruses, worms and spam while logging intrusion attempts.
- Control bandwidth by curtailing non-business traffic so essential applications get the room they need.
- Provide secure VPN access so remote, traveling and work-from-home staff can reach internal resources safely.
Train Your Employees: Your First Line of Defense
We tend to assume the best defense is electronic. But your first line of defense is the people in and around your office. Tucking security tips into the back of an employee manual isn’t enough, and neither is a one-time training that gets forgotten. Your team needs a working understanding of cybercrime tactics plus regular updates on the latest threats, covering passwords, a clean workspace, spotting malicious email, open communication and email encryption.
Create and Enforce an Acceptable Use Policy (AUP)
An AUP is a written document that spells out exactly what employees, subcontractors and end users can and can’t do with your internet, computers and email. Require everyone who touches your network to sign it before they get access. A good AUP:
- Protects users by deterring illegal or offensive behavior
- Shields your business from legal action by proving you took reasonable measures
- Safeguards your reputation
- Improves productivity by guiding people away from non-business sites
- Regulates personal devices, because an infected personal laptop is a gateway straight into your network
Your IT consultant can help you draft it and enforce it.
Add a Bring Your Own Device (BYOD) Policy
Letting employees use personal phones and laptops for work is convenient, but it opens new doors into your network. Ask yourself: are you permitted to erase company data from that personal device? If those devices fall into the wrong hands, hackers may have a direct line to your servers. Your policy must give you the right to remotely wipe any device. And if you handle highly sensitive data, such as patient records, credit card or financial information, you may not legally be allowed to let employees access it on unsecured personal devices at all.
Build Better Passwords
It’s easier to reuse the same password or one with your kid’s name in it, and yes, “password” is still one of the most common passwords out there. But strong credentials are worth the inconvenience:
- Longer is better. Include at least one special character, one number, and both uppercase and lowercase letters.
- Use a unique password for every application. Never reuse.
- Turn on two-factor authentication everywhere a password is required, so knowing the password alone isn’t enough to get in.
- Keep passwords to yourself, and deactivate them the moment an employee leaves.
- Use a reputable password manager instead of a spreadsheet or sticky note, and turn off browser auto-fill, which hackers treat as a gold mine.
Tighten Up Your Day-to-Day Habits
Keep a Clean Workspace
How you do anything is how you do everything. Both physical desks and computer desktops should be clean, with nothing on them that isn’t relevant to work, and absolutely no passwords or personal material left lying around.
Know How to Identify Malicious Email
When your team starts from the assumption that every email could contain malware, you’ve added a lot of defenders. Watch for these red flags:
- Unfamiliar domain names in the sender’s address
- Short, vague messages with links attached
- Unexpected links with no explanation
- Innocuous attachments on vague or unfamiliar emails
- Bad spelling or grammar
- Requests for personal information
- Threatening or panic-inducing messages
Be aware of man-in-the-middle attacks, too: you click a link and nothing seems to happen, but the hacker may have just gained remote access. If that ever happens, report it. Give each employee a tip sheet, and encourage them to call the sender when in doubt; emailing back isn’t enough if the sender’s account is already compromised.
Keep Communication Open
See something, say something. If an email, web page or attachment looks suspicious, assume it is, don’t click, and alert your IT consultant. Most criminals are trying to infiltrate the whole business, not just one person, so when one employee spots an attack, a quick heads-up protects everyone else. Nobody should hide a slip out of embarrassment; owning it and warning the team is what keeps the next person safe.
Destroy Old Data
Don’t just throw away old computers, printers or any device that stores data. Wipe them clean and physically destroy the hard drives before trashing or donating. You may see junk; a cybercriminal sees a treasure of passwords, customer files and financial data plucked straight from the recycle bin.
Protect Your WiFi Network
Customers expect free guest WiFi, but you don’t want to hand criminals another way in. A few rules:
- Never give guests access to your primary WiFi. Almost anyone with a little technical background can use it as an access point to your network. Devices on your network should run a full security stack.
- Create a separate guest network. Most office routers support a built-in guest WiFi feature that keeps visitors off your company network.
- Restrict bandwidth and range. Limit guest bandwidth so streaming visitors don’t choke your operations, and make sure people outside your building can’t reach the guest network at all.
Encrypt Sensitive Email
Email is one of the most common entry points for malware, and even amateur hackers can intercept what you send. Most messages don’t contain anything sensitive, but when you must send something that would expose your business, encrypt it. Encryption uses a public key (which you share) and a private key (known only to you); an intercepted message just looks like gibberish without the private key, which can also digitally sign messages so recipients know they came from you. The best advice is still to never send account information, passwords or credit card numbers by email at all. If there’s truly no other option, use encryption software.
Stay Current on Security Patches
Most hackers don’t discover loopholes on their own. They learn about them when a vendor like Microsoft announces a vulnerability and ships an update. That announcement is their cue: they analyze the patch and craft an exploit for every system that hasn’t applied it yet, and the gap between update and exploit gets shorter every year. When the Nimda worm hit in 2001, Microsoft had released the protective patch nearly a year earlier, yet so many administrators never applied it that the worm did widespread damage. This is exactly why small businesses without full-time IT staff should let a consultant monitor and maintain the network so critical updates land as soon as they’re announced.
Have an Excellent Backup
Ransomware locks up your files and holds them hostage until you pay. The moment that notice hits your screen is the moment you’ll regret not having a backup, because if your files are backed up, you don’t have to pay a crook to get them back. A good backup also protects against accidental deletions, hardware failures, fire, water damage and natural disasters. Your backups should be:
- Automated and monitored
- Tested every month (the worst time to find out your backup doesn’t work is when you desperately need it)
- Watched for usage fluctuations so your IT team catches oddities early
Check Before You Connect
Flash drives and thumb drives are everywhere, and we rarely remember who handed us which one. There are countless cases of an innocent-looking USB drive or CD uploading malware onto a network. Unless you know exactly what’s on the device and you trust the person who gave it to you, don’t let it onto your system.
Frequently Asked Questions
What’s the single most important thing I can do to protect my network?
Be proactive and layered. Don’t rely on one tool. A strong firewall and a solid backup are great, but they aren’t enough on their own. The businesses that avoid getting hacked combine employee training, patching, strong passwords, secure WiFi, backups and clear policies. Implement as many of these measures as you can.
Why does employee training matter if I have security software?
Because in almost every attack we investigate, malware got in through something a person did: clicking a link, opening an attachment or downloading something they shouldn’t. Software is critical, but your people are your first line of defense. A trained team that treats every email as a possible threat catches attacks before the software ever has to.
How often should I test my backups?
Every month, at minimum, and the process should be automated and monitored. A backup you’ve never tested isn’t really a backup, it’s a hope. The worst possible time to discover a backup failure is the moment ransomware has already locked your files.
Why are software updates such a big deal?
Because hackers often learn about vulnerabilities from the very updates meant to fix them, then race to exploit any system that hasn’t patched yet. The Nimda worm caused major damage even though the fix had been available for nearly a year. Applying critical updates promptly closes that window, which is why ongoing monitoring matters so much for businesses without full-time IT staff.
Ready to Close Your Gaps?
You now have a lot of ways to defend your network and protect your data, your finances and your business. Being proactive is the key, and you don’t have to do it alone.
Get a Free Cybersecurity Risk Assessment
We act as the IT team for Houston businesses with 10 to 200 employees, with fast response and after-hours support when you need it.
If you’re ready to find out exactly where your gaps are, book a free discovery call, request a cybersecurity risk assessment, explore our cybersecurity services, or call us in Houston at 281-367-8253.