How is your cyber hygiene?
13 May 2025Every company strives for cyber resilience against threats and invests in good security. After all, the continuity of the organization must not be endangered by system failures or data breaches.
Cyberattacks and data leaks occur daily. Although systems are often well secured, users of devices can (accidentally) cause damage. Learning good habits in the field of cybersecurity is called cyber hygiene.
Safe behavior
Safe behavior is necessary. It regularly happens that computers are left on while employees are not at their desks and computers are left unattended and not locked. This can unintentionally or even intentionally cause major damage. Are employees aware of this?
Criminals are good at provoking
Employees can be provoked by increasingly smarter criminals. We all know the Phishing emails, but also infected USB sticks, passwords that are easy to guess, strangers on the train looking over your shoulder when you type a password, company waste being obtained (a phone list, a job description, or even a hard drive), someone pretending to be the external IT party, a technician pretending to be a supplier and gaining access to the server room, or simply walking into the office and seeing which computers are left unattended and unlocked.
Make employees resilient and ensure secure systems
Ensure cyber-aware employees and make agreements regarding cyber hygiene. Provide security rules and awareness training. Tell employees what to do and who to contact when a cyber incident does occur.
Below are some cyber hygiene tips:
- Ensure a screen policy (such as always locking when someone walks away from a computer)
- Password policy (for example a capital letter, a special character, at least 8 characters, a number, in short not too easy!)
- Log in with multi-factor authentication (logging in with your phone, a fingerprint, facial recognition, an authenticator etc. + always an extra password)
- Teach employees to recognize Phishing, provide examples and training.
- Install and manage antivirus software on all devices.
- Where possible, set up a good update policy and ensure your systems remain up-to-date.
- Implement a good backup policy and schedule periodic tests.
- Provide a (printed) list of important contact details needed in the event of a cyberattack.
Do you want us to help your organization get its cyber hygiene in order? Then contact us!
Implementing cyber hygiene is one of the NIS2 guidelines. Earlier we told about the access policy and the duty of care, two other important components that you as a company must have in order. Especially in preparation for the new Cybersecurity Act.