Keeping your employees educated on identifying malicious behavior and Indicators of Compromise is essential to mitigating cyber threats from the get-go. You don't have to force your employees to become certified IT experts, but you should keep them well versed in what to be on the lookout for. Most people today have at least some understanding of what a cyber threat is. You will often hear terms like virus, hacker, and scam thrown around. A good cybersecurity program should elaborate on what these terms mean and how to identify them.
For example, you could make printouts of guides for identifying various cyber threats and post them around the facility. They could be taped to desks, posted in server rooms, and even uploaded to employee portals.
Phishing Indicators
- Emails from individuals with invalid addresses.
- Inspection of the email header reveals a suspicious-looking email address different from the one displayed in the email body.
- Overly urgent subject lines and email bodies.
- Explicit requests for money.
- Pretexting involving crimes, unpaid bills, and account compromises.
- Links to strange websites with suspicious domains.
- Typos and grammatical errors.
- Email attachments with strange file extensions.
Malware Infection Indicators
- Slow device performance.
- High utilization of network bandwidth.
- Heavy use of memory, disk, and/or CPU.
- Antivirus programs are suddenly disabled.
- Missing files.
- Task Manager reveals suspicious-looking or unknown processes with high resource utilization.
Account Compromise
- Account is locked despite entering the correct password.
- Strange account behavior soon after interacting with a strange email or pop-up, or providing your credentials to a third party.
- Logs reveal strange login times and login locations.
- New devices connected to your account.
- Strange messages sent from your account.
- Unrecognized purchases through your account.
When educating your employees, make sure to provide them with contact information to escalate incidents to. The Stage 2 documentation on Emergency Hotlines is useful information to post around your facilities.
