As we enter week 2 of this special month, it’s important to remember that cybersecurity isn’t just a tech issue; it’s everyone’s responsibility, whether you are a student, a CEO, a board member, or someone just scrolling through social media.

Cyber threats are growing more sophisticated and intense every day. This month serves as a reminder to stay vigilant, informed, and proactive about protecting ourselves, our families, and our businesses. In this issue, we share practical tips and recommendations tailored for everyone, from the general public to top executives and board members.

For the general public

  1. Use strong, unique passwords

Using “password123” or your birthday as your password is like leaving your door closed but not unlocked.  Here is the password strength meter, https://www.passwordmonster.com/. Some passwords like password124 can be cracked within just 0.05 seconds!

Figure 1: Weak passwords are easily hacked

However, another password of 11 words with special and mixed characters, would take 93 years to crack! So, mixing the characters of the password is critical.  

Figure 2: Mixed-character passwords are ideal to tighten your online activity

Make sure to use complex passwords (think random words, numbers, and symbols) and avoid reusing them across different accounts. A password manager can help you generate and store strong passwords without having to remember them all.

Tip: Think of a password like a toothbrush. You wouldn’t share it with others, and you should change it regularly!

  1. Beware of phishing scams

Have you ever received an email or SMS claiming you’ve won a prize or your account has been compromised? Pause before you click. Phishing scams trick you into giving up personal info.

Always verify directly with the company through their official website or phone number instead of clicking on the link. For example, if you receive an email that appears to come from say MTN Uganda. Instead of clicking on the links in the email, go directly to the MTN Uganda website or contact MTN Uganda via its social networks. Avoid clicking on the links in the email.

Recommendation: When in doubt, throw it out! If a message feels fishy, don’t engage.

  1. Update your software regularly

Those constant software update notifications might seem annoying, but they are essential for keeping your devices secure. Hackers exploit outdated software, so make sure to update your phone, apps, and computer regularly.

Fun fact: Software updates are like getting a free service on your boda boda, it keeps it running smoothly and safely.

  1. Be cautious with public Wi-Fi

Free Wi-Fi is convenient, but it’s a goldmine for hackers. Avoid accessing sensitive accounts (like banking or email) on public Wi-Fi without a VPN (Virtual Private Network). Otherwise, you are broadcasting your personal info to anyone in the same coffee shop!

Tip: Treat public Wi-Fi like an open market - be mindful of what you reveal in public!

  1. Enable multi-factor authentication (MFA)

Adding a second layer of security (like a code sent to your phone) can keep your accounts secure, even if someone guesses your password. It’s like adding a second lock to your front door!

Recommendation: Activate MFA on all your critical accounts, like email, social media, and banking. It’s quick, easy, and makes a huge difference.

For Executives and Board Directors

  1. Lead by example

Cybersecurity hygiene starts from the top. As leaders, set the standard for your employees by following best practices to increase digital trust. Use secure passwords, stay updated on cybersecurity trends, and encourage open dialogue about digital safety within your organization.

Recommendation: Conduct regular cybersecurity training for your staff. Make sure everyone understands that good security hygiene isn’t optional, it’s a must. Undertake ongoing threat intelligence for a practical-led cybersecurity management strategy.

  1. Create a culture of cybersecurity awareness

One of the biggest risks to an organization is human error. Employees might fall for phishing scams or use weak passwords, leaving the company vulnerable. Regular awareness programs can significantly reduce these risks.

Tip for Boards: Introduce annual cybersecurity awareness months in your organization to keep the momentum going beyond just October. Get the board involved in cybersecurity awareness initiatives including all customers and all staff, just as you have a CSR day or week.

  1. Understand your risk landscape

Cyber risks vary from industry to industry. As an executive or board member, it’s crucial to understand the specific threats that your organization faces, whether it’s ransomware, insider threats, or phishing. Have regular discussions with your Chief Information Security Officer (CISO) and make sure there’s a clear risk mitigation plan in place.

Recommendation: Incorporate cybersecurity into boardroom conversations regularly. Cybersecurity is not just an IT issue; it’s a business risk. Have cybersecurity reporting as an agenda item on all board meetings and exco meetings to create a more cybersecurity-conscious organisation.

  1. Invest in cybersecurity tools

While cybersecurity awareness is key, investing in robust security tools like firewalls, encryption, and security monitoring solutions is essential. These tools act as your company’s digital fence-keeping the bad guys out.

Tip: Allocate the budget towards cybersecurity-consider it a crucial investment, not just an expense. How much money has your company allocated to physical security? How many of the resources are at risk? Now, how much do you allocate to cybersecurity to protect your crown jewels, the heart of your business?

  1. Regularly review cybersecurity policies

Cyber threats evolve quickly. Ensure that your company’s cybersecurity policies are reviewed regularly and adapted to the latest threats. From password management to data access controls, policies should be clear, regularly updated, and communicated effectively to all levels of the organization.

Recommendation: Consider quarterly cybersecurity audits to stay on top of any weaknesses in your defenses. It’s always better to be proactive than reactive.

Special cybersecurity tips for family use

  1. Monitor children’s online activity

Children are curious, and the internet is vast. Use parental controls to limit what they can access and make sure they know not to talk to strangers online, just as they wouldn’t in real life.

Tip: Teach your children about cyberbullying and online safety from an early age. The internet is like a big playground-make sure they know the safe zones.

  1. Back up important data

Whether it’s family photos or school projects, regularly backing up important files ensures that if something happens (like your device gets hacked or lost), you won’t lose everything.

Fun Fact: Think of backups like photocopies of precious documents-you’d never keep just one version of something important, right?

Final thoughts: Let’s all do our part

Cybersecurity Awareness Month is a time for all of us to reflect on the importance of staying secure online. Whether you’re checking your emails at work, watching Netflix at home, or managing company finances, cybersecurity is your responsibility. By staying vigilant, informed, and proactive, we can all reduce the risk of cyber threats.

Remember: It only takes one click to compromise your data, but it also takes just one good decision to protect it.

Thank you for being part of this movement to create a safer online world. Let’s all take steps - big or small - to stay protected. If you have any questions or need further cybersecurity guidance, don’t hesitate to reach out.

Stay safe, secure, and cyber-aware! For a free cybersecurity talk to your team, contact us.