Final paper

profileRas423
cyber_security_improvement_areas.docx

Running Head: CYBER SECURITY IMPROVEMENT AREAS

CYBER SECURITY

Cyber Security Improvement Areas

Pureland Wastewater Treatment is a company that provides all aspects of waste water treatment especially in the areas of both biological fermentation industries as well as chemical manufacturing. However, due to the toxic nature of the chemicals this company uses, it has quite some special security concerns. However, it is good to note that this company has only put all its efforts on physical security and completely ignoring on the cyber security. The Department of Homeland Security however recently contacted both the organization’s operation folks as well as the executives in regard to the chemical they use in their operations terming it as very toxic. As much as the company knew that this chemical, ( Chlorine Dioxide) is very harmful, little did it not know that it is prone to risks such as cyber terrorism. DHS therefore needs the company to comply with not only the physical but also cyber security regulations that are related to the use of this chemical failure to which they will be subjected to heavy fines and penalties or even the closure of the company.

Personally, there are a number of ways that I would recommend the company to follow so as to ensure not only the improvement of the company’s security, but also so as to ensure compliance. To begin with, the company needs to create an internal policy. This is because one of the greatest cyber security risks in any company is usually the employees. For example, there are quite a lot of cases where criminals get through a company’s network either because an employee used a poor password or he/she clicked on a line in an email which led to the installation of a malware. Therefore, as much as the employees should be educated or rather informed of the latest scams that are going around, it is always good to check with the personnel who put the server so as to ensure that all the company’s protection rights are in place. Secondly, the company needs to ensure that all its computers are up to date. This basically means that the personnel behind the computers have to ensure that all the notifications regarding firewall, operating system or even antivirus are all up to date failure to which they may lead to the creation of cracks within the defense system.

Thirdly, the company can consider using cloud services so as to store their data as well as when it comes to handling their application needs. This is because, with the cloud services, the companies crucial information remains safe even when let’s say a malware destroys some files since the cloud services can provide backup at any time. However, the company should remember to only stick on reputable companies. Fourthly, increasing the employees’ awareness is also very necessary. Actually, it is one of the most cost effective methods of curbing cyber-attacks. Awareness can only be achieved through training. The company needs to train its employees about cyber-attacks, how they occur, how to curb them as well as other issues. For example, the company can introduce privacy training which will help their employees to know the need of maintaining privacy especially when it comes to their devices. This is because there are malicious people who can take their devices and use them in acquiring crucial information about the company.

The company also needs to ensure that their passwords are very strong as well as that they change them frequently. Strong passwords have to be long enough and should also combine symbols, letters, numbers as well as other factors. They also have to be changed regularly so as to prevent security issues, for example, with a poor password; one can easily guess it and hack the company’s accounts as well as get some very crucial and confidential files. Lastly, the company will have to hire a few competent security consultants. They will in turn help in identifying any holes in the company’s infrastructure as well as provide the right remedy.

References

Katrina Manning, (2015). 8 Ways Businesses Can Avoid Cyber Attacks. Business 2 Community.

Craig Scotts, (2015). How to Stop Cyber Attacks on Your Organization. The Guardian.

Bertrand Liard, (2015). Cyber risk: Why cyber security is important. White & Case.