Home / ITRM Insights / Blog / How Many IT Security Best Practices Do You Know?
23 Oct 2022
Whether you’re an employee or a business owner, it pays to be familiar with the best practices for cyber security. Now more than ever, businesses are regarding cyber threats as a problem for the entire organisation — not just the IT department.
In fact, Gartner’s 2022 Cyber Security Report states that 88% of boards now regard cybersecurity as a business risk rather than solely a technical IT problem. This statistic speaks to the ever-pressing need for all team members to be well acquainted with IT security best practices, regardless of their level in an organisation.
Read on and see how many IT security best practices you know.
Up first are a handful of simple practices that all staff members should be aware of (and actioning) on a daily basis to keep their organisation safe from threats such as data loss, phishing, cyber attacks, and social engineering.
Bluetooth is an excellent tool but should be disabled when it is not in use. This is because it is possible to hack some devices through Bluetooth, making private information vulnerable.
Increasingly, simple passwords are being replaced by more sophisticated methods of approval, such as two-factor authentication — and there’s good reason for this,
Over 15 years ago, Bill Gates proclaimed ‘the death of the password’ by pointing out its limitations in keeping data secure. And Gates was right. All of the following factors threaten the security of the humble password daily:
It is essential to conform to the increasingly-complex password requirements, change your password regularly, never use the same password twice, and never share it with anyone. Reviewing the strength of your passwords using a strength checker tool is also good practice.
Passwords, if done right, are one of the most cost-effective and straightforward defences against cyberattacks. The National Cyber Security Centre has a comprehensive list of guidance on password safety that you can find here.

This is quite a well-known point, but it is worth stating the obvious. It is never a wise idea to connect to a public network, as any information you retrieve or transfer is vulnerable. However, if you absolutely have to connect to a public network (let’s say you’re on the go), use a VPN or ‘Virtual Private Network’ to encrypt your connection.
Another core IT security best practice comes in the form of employee training. While we’ve dedicated another of our blogs to this topic entirely, we’ll give you the rundown here. When it comes to cybersecurity, your employees really could be our weakest link. So, it is crucial to invest time, money, and resources into bolstering your IT security processes from the inside out to avoid human error.
Still not convinced? According to the World Economic Forum’s 2022 Global Risk Report, over 95% of cybersecurity issues can be traced back to human error alone. So what should you be teaching your employees?
All employees should be familiar with the common social engineering and phishing scams, from suspicious emails to fraudulent links. Social engineering refers to the wide range of malicious activities that occur as a result of human interaction. This can take the form of:
If employees are educated on these common cyberattack methods, they are far less likely to fall victim to them, reducing the risk to themselves and their organisation’s data. Your staff should be receiving adequate, regular training that advises them to:
Regular IT security training for employees will eventually develop a culture of security within an organisation that sees employees independently exercise these best practices without even being told to. Read our blog for more information on the importance of educating your staff on cybersecurity.
Speaking of clicking links, HTTPS form a crucial part of any cybersecurity strategy. Before visiting and utilising a site, check its security status. If a site uses only ‘HTTP’, it is not guaranteed that the transfer of information between you and the server is 100% secure. Additionally, if you run a business, ensure an SSL certificate and HTTPS are installed on your own site.
As an organisation, it is essential to keep on top of software (and hardware) updates. Software updates aren’t just arbitrary, nor should they be treated as such. Software companies roll out these updates to add new features, fix any bugs, and — most importantly — improve security. If you are operating with older versions of certain software, there may be vulnerabilities that, unbeknownst to you, are risking your data.
Hand in hand with software updates comes (you guessed it) hardware updates! The reason why maintaining your hardware is equally important can be broken down into two things: a) Responsivity and b) Compatibility. Older hardware is likely to be running at a much slower rate, making it much more challenging to respond to cyber-attacks should they happen. What’s more, downloading the latest software is not possible if your outdated hardware is not compatible with it.

On this point, it is worth noting the importance of anti-virus and anti-malware software. All the while you are connected to the internet, it is impossible to be completely protected from cyber threats. However, you can significantly reduce your susceptibility by installing these things. It is essential to use both of them, mind, as they target different cybersecurity elements.
These defence mechanisms work in conjunction with one another to keep your systems safe.
Similarly, it is also a great idea to install a firewall. This acts as a digital defence between your data and cybercriminal activity.
Another critical cybersecurity best practice is the safe storing and sharing of data. This topic is exceptionally multifaceted, but pay close attention as there are plenty of easily-actionable insights here.
While this point sounds obvious, you’d be surprised how often it is overlooked by employees and organisations alike. If information of any nature is stored online, it should be in a location that is inaccessible to unauthorised users.
Your data can be vulnerable if you do not store information online and rely on external storage devices. In addition, if a device infected with malware is connected to your computer, this malware can spread. This is why it is wise always to scan these devices first.
This point we cannot emphasise enough. Data loss can devastate a company, especially if the information cannot be retrieved due to a lack of historical backups. You can back data up on the cloud or a local storage device.
How many cybersecurity practices did you know in the end? If you’re concerned about the security of your data or systems, get in touch with the experts at ITRM today. Or, browse the rest of our blog for more strategic insights into business IT security.