Paul Kelly: Basic cybersecurity protects against 98% of attacks

-

Paul Kelly explores the growing importance of basic cybersecurity training for staff. Given the rising amount of cyberattacks targeting enterprises and new research revealing employees are unable to detect phishing emails, it seems more prominent an issue than ever before.

Offering Hybrid working can liberate employees, help attract top talent and enable teams to do their best work from the location that works best for them. While the benefits for employers and employees are many, cybercriminals are also on the look out for opportunities this presents.

As organisations shifted to hybrid working, the attack surfaces for cybercriminals to exploit have grown exponentially. This evolving threat landscape has taught us all some tough lessons over the past eighteen months, a key takeaway being that security awareness and doing the basics matter. 

While there have been a growing number of sophisticated cyberattacks, data shows that many cybercriminals still favour tried and tested methods. In fact, Microsoft research shows that phishing – or email scams – is responsible for almost 70 percent of data breaches. ​

HRreview Logo

Get our essential weekday HR news and updates.

This field is for validation purposes and should be left unchanged.
Keep up with the latest in HR...
This field is hidden when viewing the form
This field is hidden when viewing the form
Optin_date
This field is hidden when viewing the form

 

A primary way criminals get in is through an unlocked door, so leaders need to ensure their employees are equipped with tools and knowledge to recognise and flag potential incidents. And, with Microsoft research revealing that basic security hygiene protects against 98 percent of cybersecurity attacks, nailing the basics is critical.

 

Attacks against enterprises are increasing, and so is the cost

In the last year alone, 4 in 10 UK businesses (39%) reported some kind of cybersecurity breach and this number has the potential to increase if businesses do not adequately secure their digital transformation efforts. The figure is even worse for small businesses, with one small business in the UK hacked successfully every 19 seconds, according to Hiscox.

The cost of a successful breach can also be extremely damaging, both to finances and reputation. The UK government estimated that cyberattacks cost businesses over £21bn a year, while Forrester revealed that 38 percent of businesses have lost customers due to security issues – with 44 percent of UK consumers claiming they will stop spending with a business temporarily after a data breach.

Certainly, there’s a lot on the line when it comes to ensuring that organisations are properly protected. Leaders need to implement practical security measures and create a strong security culture, so employees have a clear understanding of the dangers posed by poor cybersecurity hygiene.

 

Basic threat protection and mitigating risk

As organisations connect more and more systems together, security can become more complex, but organisations need to ensure that the diversity of skills, areas of expertise, work and learning style, and background, among other things are respected.

 The simple, practical steps any organisation can take to reduce their risk include making sure that they:

  • Get the Basics Right – In our personal lives, we’re all well used to a text message code from our Bank, Healthcare provider or Online Store to double check we are who we say we are. In a work context, this is an example of multi-factor authentication, a first key step to protecting against cyber threat. There are many ways this can be achieved – text message, mobile app, phone call etc. Biometric solutions such as facial recognition (e.g. Windows Hello for Business) are great for providing a slick, modern logon experience while also offering enhanced security without having to remember a password.
  • Apply least privilege access to prevent attackers spreading across a system. In the same way as you would determine HR access to sensitive information based on role and level, this this method works by setting rules on employee accounts that make sure they can only access the information they need to do their job, rather than the entire system.
  • Ensure devices, infrastructure and applications are up-to-date and correctly configured. Attackers look for easy targets, organisations who have not kept their systems up to date with the latest security updates. This potentially presents an open door for them. However, there are a range of tools that can help to keep an organisation up to date, such as Microsoft Endpoint Manager, which can secure each touchpoint in an organisation’s IT infrastructure.
  • Utilise cloud-connected anti-malware to protect against the most current attack methods and accurate detection capabilities, as well as implementing basic information protection best practices – such as sensitivity labels – and data loss prevention policies.
  • Democratise security awareness – educate your employees on what to look out for, help your leadership team understand the importance of security, and build diverse cyber security teams. The National Cyber Security Centre provide ‘Exercise in a Box’ – a great online tool which helps organisations find out how resilient they are to cyber attacks and practise their response in a safe environment Exercise in a Box – NCSC.GOV.UK

 

Put your people first

Building a people-first security culture is just as important as practical methods to protect your organisation. Training should be ongoing, designed to increase awareness and engagement. User training is not just a compliance activity but an essential part of the early detection and response to an attack.

Security training must also explain the risks in the context of the employees’ area of work, and provide the context and tools they need to recognise attacks, understand the appropriate behaviour and report unusual activity. A culture of enablement, trust, and engagement will significantly improve reporting and provide earlier warning of attacks.

By creating a people-first security culture, organisations will be able to ensure their users and data stays safe in a hybrid environment, while ensuring their employees stay productive and collaborative.

While cyberattacks are increasing and becoming more sophisticated, good cyber hygiene and security awareness is the best way to disrupt, prevent and detect such attacks. Do the basics well and organisations can set themselves up to ensure the businesses and their employees are protected.

_

Paul Kelly is theDirector of the Security Business Group at Microsoft UK.

 

Paul Kelly is UK Country Co-leader at AlixPartners, a global management consulting firm. He specializes in organizational transformation, finance, and the impact of emerging technologies on workforce dynamics. Kelly has contributed thought leadership to HRreview on topics including AI's impact on entry-level finance roles and broader workplace changes. His expertise spans strategy, digital transformation, and human capital implications of technological change in financial services and professional services sectors.

Latest news

Curtis Holmes: Payroll is the driver for employee engagement

Payroll has long been treated as a back-office necessity: essential, but not something that shapes culture or drives engagement. This no longer stands.

Labour market yet to show major AI impact on jobs, govt adviser says

A government economic adviser has challenged predictions of widespread AI-driven unemployment, arguing labour market data has yet to show disruption.

Young workers ‘pressured into signing NDAs after workplace injuries’

Workers say injuries are being hidden behind confidentiality agreements while financial pressures leave many afraid to challenge unsafe conditions.

CIPD recognises 30 HR leaders driving change across UK workplaces

The CIPD has unveiled its HR30 list for 2026, recognising senior people leaders whose work has delivered measurable impact across organisations and workforces.
- Advertisement -

Brits dream of being their own boss, but still cling to the monthly pay cheque, survey reveals

Britons say they like the idea of self-employment, but most still value the security and stability of traditional jobs.

AI Coaching Won’t Replace Managers. It Will Expose Coaching Debt.

As AI coaching expands, employers may gain a clearer view of where manager support is falling short.

Must read

Gail Cohen: Making the most of gift cards as an employee reward

The gift card market has grown by more than 20 per cent.

Nichola Hay: Spring Budget 2024: The UK’s skills shortage remains unaddressed

"Building a comprehensive national skills framework linked to industrial strategy will take time", says Nichola Hay.
- Advertisement -

You might also likeRELATED
Recommended to you