---
description: Read our survey analysis to understand how businesses in Canada are managing cybersecurity risks and what security challenges they face.
image: https://gdm-localsites-assets-gfprod.imgix.net/images/getapp/og_logo-94fd2a03a6c7a0e54fc0c9e21a1c0ce9.png
title: How do Canadian firms bolster their cybersecurity measures?
---

# Managing cybersecurity risks: 49% of Canadian companies report careless employees as a common security vulnerability

Canonical: https://www.getapp.ca/blog/4504/managing-cybersecurity-risks

Published on 2024-01-30 | Written by Smriti Arya.

![Managing cybersecurity risks: 49% of Canadian companies report careless employees as a common security vulnerability](https://images.ctfassets.net/63bmaubptoky/4cVhHc2UJ7iGAshX30Zk22/4f0af76b0ac5077fb688271dde0ea268/Managing-cybersecurity-risks-CA-GetApp-Header.jpg)

> Are employees in Canada aware of cybersecurity risks? Do they have adequate data security strategies in place to prevent cyberattacks? What actions are being taken by their organizations to safeguard their businesses? Read our survey analysis to discover how Canadian firms are dealing with cybersecurity risks. 

-----

## Article Content

Are employees in Canada aware of cybersecurity risks? Do they have adequate data security strategies in place to prevent cyberattacks? What actions are being taken by their organizations to safeguard their businesses? Read our survey analysis to discover how Canadian firms are dealing with cybersecurity risks. In this articleNearly half of companies cite careless employees as a common security vulnerabilityAdvanced email phishing attacks are the top concern for 46% of respondents5 in 10 respondents deploy formal cybersecurity risk assessments to protect their dataOvercoming cybersecurity risksAccording to the Royal Canadian Mounted Police (RCMP), more than $530 million in financial losses were reported to the Canadian Anti-Fraud Centre in 2022. This equals a nearly 40% increase when compared with losses in 2021. Moreover, The Canadian Centre for Cyber Security also released a report in which they predicted that ‘financially motivated cybercriminals will almost certainly continue to target high-value organizations in critical infrastructure sectors in Canada and around the world over the next two years.’ Therefore, cybersecurity is essential in today’s digital era and every organization should prepare themselves to have strong security protocols in place. Considering all this —to understand how Canadian companies combat such increasingly prevalent risks— we surveyed 1,557 full-time employees who use some sort of cybersecurity tools in their organizations. Out of 1,557 total respondents, 1,119 respondents are either responsible for implementing cybersecurity measures, have participated in cybersecurity initiatives, or are fully aware of cybersecurity measures in their companies. We will refer to this group of survey participants as fully aware respondents.  On the other hand, 438 respondents are not fully aware of such measures, whom we will refer to as less aware respondents. Scroll down to the bottom of this article for the full methodology. Nearly half of companies cite careless employees as a common security vulnerability When it comes to breaches, what might come as a surprise is that hackers are not only the ones who are responsible for data breaches: negligent employees could also cause security violations. In particular, our study revealed that nearly half of fully aware respondents (49%) report that careless employees are a common security vulnerability that they are struggling with the most. This is followed by weak passwords/authentication methods (32%), and susceptibility to phishing schemes/social engineering schemes (32%). Other commonly cited vulnerabilities are listed below:The reason why employee negligence could be a top-most security vulnerability might be a lack of awareness of cybersecurity knowledge. Workers may not have the ability to identify suspicious/malicious messages, because of which they could fall prey to such forms of cyberattacks. Therefore, organizations should offer company-wide cybersecurity training programs that not only educate employees but also assess their knowledge levels regarding cybersecurity threats. This additional step can help businesses create more effective training programs. Setting weak passwords is another big challenge that companies usually have to struggle with. In this context, it is essential for companies to implement password policies that require employees to create strong passwords that cannot be easily hacked. In addition, using multi-factor authentication tech can add another layer of security.Another security measure that companies can take is to execute phishing simulations. A phishing simulation is typically part of a cybersecurity awareness program where an imitation of a real-world phishing email is sent to employees to test and monitor how they respond to such emails. Conducting regular phishing simulations may help your employees recognize malicious emails and avoid falling victim to such attacks. Advanced email phishing attacks are the top concern for 46% of respondents There are over 4.3 billion email users worldwide and around 347.3 billion emails are exchanged every day. Consequently, we can say that emails are among the foremost mediums of communication. This could be the reason why emails have increasingly become a common target for hackers. In fact, in one of our surveys on phishing attacks on GetApp, we found that nearly 9 in 10 respondents have received phishing attacks via email. Also, when we asked our fully aware respondents about threats that they were most concerned about for the next 12 months, they cited advanced email phishing attacks as a top concern (46%). In order to combat such issues, employees should be trained on how to spot such emails to safeguard their organization against cyberattacks. Here are some tips on how to spot a phishing email:Emails requiring quick action:Employees might receive an email that requires them to take action urgently, likely threatening a loss of opportunity. In such cases, people may take hasty actions without even reading the email completely.Emails with grammatical errors:Phishing emails may have some sort of grammatical and spelling errors and this is one of the common ways to spot spammy emails. Emails sent from a public or unknown domain:Typically,no business organization will send emails from public domains. Most companies will have their own email domains, which is why it is quite important to look at the domain name of an email before clicking any link or responding to the email.  Emails including suspicious attachments:Employees may receive an email containing infected attachments that can corrupt the system or hack sensitive information. Work-related file sharing in companies nowadays usually takes place using collaboration tools such as OneDrive, Google Drive, or SharePoint. So, workers should ideally treat attachments received with external emails suspiciously before downloading them into their system.   As a matter of precaution, organizations can additionally use email security software that can help them protect email accounts from phishing attacks by identifying emails received from bad IP addresses or dodgy domains. 5 in 10 respondents deploy formal cybersecurity risk assessments to protect their data On the risks of ransomware attacks in Canada, Sami Khoury, the head of the Centre for Cyber Security, said, ‘The threat is real, the threat is growing and we can’t talk enough about it.’ He further urged Canadians to report such incidents so that the Centre could gather more information about who might be behind such attacks. In this sense, it is crucial for companies to take appropriate measures on time so they don’t become a victim of major data breaches. To understand how survey-takers deal with such issues, we asked our fully aware respondents what measures they deploy to protect their company’s data and this is what they reported:54% of the respondents deploy formal cybersecurity risk assessments to protect their data38% of them use a data classification approach to safeguard sensitive data31% of them leverage privileged access management solutions to monitor, detect, and prevent unauthorized privileged access to essential resources Another 31% use zero-trust network security to enable strict access controls for additional securityOnly 7% of them do not implement any security measuresFormal cybersecurity risk assessments can be the first step to combating cyberattack risks for companies because they allow them to find security vulnerabilities in their systems. This can be followed by evaluating the right approach and creating a comprehensive action report. Key steps to performing formal cybersecurity assessmentsAudit your data and its infrastructureFirst, it is important to understand the type of data a business collects, how, and where it is stored, who has access to which data, and if the place where data is being stored is secure.Define the parameters of the assessmentOnce the data audit is done, the next step could be to identify the purpose of the assessment and if there are any priorities that need to be defined. Identify the value of dataGauge the importance of information to be secured and protected from cyberattacks. In particular, determine if there are any legal penalties or if any day-to-day business operations would be affected in case such data is exposed to cybercrime. Prioritize assetsBased on the information inferred from the above step, businesses should potentially prioritize which data assets to assess. Identify threats to the assetsOnce businesses prioritize assets based on their informational value, the next step could be identifying the possible cyber threats to the assets. Some of the common threats that may affect companies are unauthorized access, insider threats, loss of data, service disruption, or data leaks. Implement security controlsDepending on the potential threats a business might have, companies can make decisions on which security controls to implement to safeguard their data against cyberattacks.  Overcoming cybersecurity risksTo keep cybersecurity threats and attacks at bay, it is important for organizations to adopt strategies to overcome and mitigate such risks to create a safe and secure environment. In fact, when it comes to investing in cybersecurity solutions, we found that 49% of fully aware respondents said that spending on security has increased, while 40% of them said that the spending is about the same and only 2% reported that it has decreased. Considering this, we can safely assume that companies are aware of the risks associated with cyberattacks and are actively investing to protect their businesses. While companies are investing in cybersecurity solutions, it is also important for employees to have knowledge of relevant cybersecurity policies and risks. When we asked all our respondents if they had ever raised cybersecurity concerns with their IT departments, what came as a surprise was that only 33% of survey-takers have ever raised a cybersecurity concern with their IT department. Clearly, it’s imperative for companies to fully educate employees on both the risks and the appropriate forums to address such cybersecurity violations. Looking for cybersecurity software? Check out our catalogue\!

## Disclaimer

> MethodologyTo collect the data for this report, GetApp conducted an online survey in November 2023 among 1,557 Canadian employees. Of these, 1,119 are either responsible for, actively participate in, or are fully informed about their company's IT security policies. A group of 438 respondents were not fully aware of their company's cybersecurity policies and answered specific questions.All respondents were selected according to the following criteria:Residing in CanadaAged between 18 to 65 yearsFull-time employeesWorks with a company with some sort of a security system

## About the author

### Smriti Arya

Smriti is a Content Analyst for GetApp, helping SMBs deliver key insights into software, business and tech trends.

## Related Categories

- [Cloud Security Software](https://www.getapp.ca/directory/291/cloud-security/software)
- [Cybersecurity Software](https://www.getapp.ca/directory/1035/cybersecurity/software)
- [IT, Server & Network Monitoring Software](https://www.getapp.ca/directory/652/it-server-network-monitoring/software)
- [Network Monitoring Software](https://www.getapp.ca/directory/480/network-monitoring/software)
- [Network Security Software](https://www.getapp.ca/directory/1443/network-security/software)

## Related Articles

- [Modernizing libraries: Areas of library automation](https://www.getapp.ca/blog/3499/areas-of-library-automation)
- [AI-enhanced malware and phishing worry Canadian IT pros most for 2025, learn four ways to get secure](https://www.getapp.ca/blog/7229/canada-data-security-worries-it-professionals)
- [Building consumer trust online: Human-based elements are the most important to internet users](https://www.getapp.ca/blog/3620/building-consumer-trust-online)
- [Green marketing: 5 sustainable trends for your SME](https://www.getapp.ca/blog/2154/green-marketing-strategy-ideas)
- [Cyber privacy: Does consumer behaviour match consumer attitudes?](https://www.getapp.ca/blog/3098/consumer-cyber-privacy)

## Links

- [View on GetApp](https://www.getapp.ca/blog/4504/managing-cybersecurity-risks)
- [Blog](https://www.getapp.ca/blog)
- [Home](https://www.getapp.ca/)

-----

## Structured Data

<script type="application/ld+json">
  {"@context":"https://schema.org","@graph":[{"name":"GetApp Canada","address":{"@type":"PostalAddress","addressLocality":"Toronto","addressRegion":"ON","postalCode":"M2N 7E9","streetAddress":"5000 Yonge Street 14th Floor, Suite 1402 Toronto ON M2N 7E9"},"description":"Review, Compare and Evaluate small business software. GetApp Canada has software offers, SaaS and Cloud Apps, independent evaluations and reviews.","email":"info@getapp.ca","url":"https://www.getapp.ca/","logo":"https://dm-localsites-assets-prod.imgix.net/images/getapp/getapp-logo-light-mode-5f7ee07199c9b3b045bc654a55a2b9fa.svg","@type":"Organization","@id":"https://www.getapp.ca/#organization","parentOrganization":"G2.com, Inc.","sameAs":["https://twitter.com/getapp","https://www.facebook.com/GetAppcom","https://www.instagram.com/getappcom/","https://www.youtube.com/c/GetAppCom"]},{"name":"GetApp Canada","url":"https://www.getapp.ca/","@type":"WebSite","@id":"https://www.getapp.ca/#website","publisher":{"@id":"https://www.getapp.ca/#organization"},"potentialAction":{"query":"required","target":"https://www.getapp.ca/search/?q={search_term_string}","@type":"SearchAction","query-input":"required name=search_term_string"}},{"name":"How do Canadian firms bolster their cybersecurity measures?","description":"Read our survey analysis to understand how businesses in Canada are managing cybersecurity risks and what security challenges they face.","url":"https://www.getapp.ca/blog/4504/managing-cybersecurity-risks","about":{"@id":"https://www.getapp.ca/#organization"},"@type":"WebPage","@id":"https://www.getapp.ca/blog/4504/managing-cybersecurity-risks#webpage","isPartOf":{"@id":"https://www.getapp.ca/#website"}},{"description":"Are employees in Canada aware of cybersecurity risks? Do they have adequate data security strategies in place to prevent cyberattacks? What actions are being taken by their organizations to safeguard their businesses? Read our survey analysis to discover how Canadian firms are dealing with cybersecurity risks. ","author":[{"name":"Smriti Arya","@type":"Person"}],"image":{"url":"https://images.ctfassets.net/63bmaubptoky/4cVhHc2UJ7iGAshX30Zk22/4f0af76b0ac5077fb688271dde0ea268/Managing-cybersecurity-risks-CA-GetApp-Header.jpg","@type":"ImageObject","@id":"https://www.getapp.ca/blog/4504/managing-cybersecurity-risks#primaryimage"},"headline":"Managing cybersecurity risks: 49% of Canadian companies report careless employees as a common security vulnerability","@type":"BlogPosting","publisher":{"@id":"https://www.getapp.ca/#organization"},"inLanguage":"en-CA","articleBody":"&lt;p&gt;&lt;b&gt;Are employees in Canada aware of cybersecurity risks? Do they have adequate data security strategies in place to prevent cyberattacks? What actions are being taken by their organizations to safeguard their businesses? Read our survey analysis to discover how Canadian firms are dealing with cybersecurity risks. &lt;/b&gt;&lt;/p&gt;&lt;img title=&quot;Managing-cybersecurity-risks-CA-GetApp-Header&quot; alt=&quot;Managing cybersecurity risks&quot; class=&quot;aligncenter&quot; fetchpriority=&quot;high&quot; src=&quot;https://images.ctfassets.net/63bmaubptoky/4cVhHc2UJ7iGAshX30Zk22/4f0af76b0ac5077fb688271dde0ea268/Managing-cybersecurity-risks-CA-GetApp-Header.jpg&quot; srcset=&quot;https://images.ctfassets.net/63bmaubptoky/4cVhHc2UJ7iGAshX30Zk22/4f0af76b0ac5077fb688271dde0ea268/Managing-cybersecurity-risks-CA-GetApp-Header.jpg?w=400 400w, https://images.ctfassets.net/63bmaubptoky/4cVhHc2UJ7iGAshX30Zk22/4f0af76b0ac5077fb688271dde0ea268/Managing-cybersecurity-risks-CA-GetApp-Header.jpg?w=700 700w, https://images.ctfassets.net/63bmaubptoky/4cVhHc2UJ7iGAshX30Zk22/4f0af76b0ac5077fb688271dde0ea268/Managing-cybersecurity-risks-CA-GetApp-Header.jpg?w=1000 1000w, https://images.ctfassets.net/63bmaubptoky/4cVhHc2UJ7iGAshX30Zk22/4f0af76b0ac5077fb688271dde0ea268/Managing-cybersecurity-risks-CA-GetApp-Header.jpg?w=1500 1500w, https://images.ctfassets.net/63bmaubptoky/4cVhHc2UJ7iGAshX30Zk22/4f0af76b0ac5077fb688271dde0ea268/Managing-cybersecurity-risks-CA-GetApp-Header.jpg?w=2200 2200w&quot; sizes=&quot;(min-resolution: 2x) 2200px, (min-width: 992px) 1000px, 95vw&quot;/&gt;&lt;div class=&quot;table-of-contents&quot;&gt;&lt;h2 class=&quot;h3&quot;&gt;In this article&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;#Nearly-half-of-companies-cite-careless-employees-as-a-common-security-vulnerability&quot;&gt;Nearly half of companies cite careless employees as a common security vulnerability&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;#Advanced-email-phishing-attacks-are-the-top-concern-for-46-of-respondents&quot;&gt;Advanced email phishing attacks are the top concern for 46% of respondents&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;#5-in-10-respondents-deploy-formal-cybersecurity-risk-assessments-to-protect-their-data&quot;&gt;5 in 10 respondents deploy formal cybersecurity risk assessments to protect their data&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;#Overcoming-cybersecurity-risks&quot;&gt;Overcoming cybersecurity risks&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;According to the Royal Canadian Mounted Police (RCMP), &lt;a href=&quot;https://www.rcmp-grc.gc.ca/en/news/2023/fraud-prevention-month-2023-fraud-losses-canada-reach-historic-level&quot; rel=&quot;nofollow noopener noreferrer&quot; target=&quot;_blank&quot;&gt;more than $530 million in financial losses&lt;/a&gt; were reported to the Canadian Anti-Fraud Centre in 2022. This equals a nearly 40% increase when compared with losses in 2021. Moreover, The Canadian Centre for Cyber Security also released a report in which they predicted that ‘&lt;a href=&quot;https://www.canada.ca/en/communications-security/news/2023/08/cyber-centre-releases-baseline-cyber-threat-assessment-on-cybercrime-with-support-from-rcmp.html&quot; rel=&quot;nofollow noopener noreferrer&quot; target=&quot;_blank&quot;&gt;financially motivated cybercriminals will almost certainly&lt;/a&gt; continue to target high-value organizations in critical infrastructure sectors in Canada and around the world over the next two years.’ &lt;/p&gt;&lt;p&gt;Therefore, cybersecurity is essential in today’s digital era and every organization should prepare themselves to have strong security protocols in place. &lt;/p&gt;&lt;p&gt;Considering all this —to understand how Canadian companies combat such increasingly prevalent risks— we surveyed 1,557 full-time employees who use some sort of &lt;a href=&quot;/directory/1035/cybersecurity/software&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;cybersecurity tools&lt;/a&gt; in their organizations. Out of 1,557 total respondents, 1,119 respondents are either responsible for implementing cybersecurity measures, have participated in cybersecurity initiatives, or are fully aware of cybersecurity measures in their companies. We will refer to this group of survey participants as fully aware respondents.  On the other hand, 438 respondents are not fully aware of such measures, whom we will refer to as less aware respondents. Scroll down to the bottom of this article for the full methodology. &lt;/p&gt;&lt;h2 id=&quot;Nearly-half-of-companies-cite-careless-employees-as-a-common-security-vulnerability&quot;&gt;Nearly half of companies cite careless employees as a common security vulnerability &lt;/h2&gt;&lt;p&gt;When it comes to breaches, what might come as a surprise is that hackers are not only the ones who are responsible for data breaches: negligent employees could also cause security violations. &lt;/p&gt;&lt;p&gt;In particular, our study revealed that nearly half of fully aware respondents (49%) report that careless employees are a common security vulnerability that they are struggling with the most. This is followed by weak passwords/authentication methods (32%), and susceptibility to phishing schemes/social engineering schemes (32%). Other commonly cited vulnerabilities are listed below:&lt;/p&gt;&lt;img title=&quot;Security-vulnerabilities-faced-by-companies-CA-GetApp-Infographic-1&quot; alt=&quot;Security vulnerabilities that companies face&quot; class=&quot;aligncenter&quot; loading=&quot;lazy&quot; src=&quot;https://images.ctfassets.net/63bmaubptoky/ZmU8CC7FFx9PkPSiOMG1j/5f11e12912371aeaef08fdcf372a316a/Security-vulnerabilities-faced-by-companies-CA-GetApp-Infographic-1__1_.png&quot; srcset=&quot;https://images.ctfassets.net/63bmaubptoky/ZmU8CC7FFx9PkPSiOMG1j/5f11e12912371aeaef08fdcf372a316a/Security-vulnerabilities-faced-by-companies-CA-GetApp-Infographic-1__1_.png?w=400 400w, https://images.ctfassets.net/63bmaubptoky/ZmU8CC7FFx9PkPSiOMG1j/5f11e12912371aeaef08fdcf372a316a/Security-vulnerabilities-faced-by-companies-CA-GetApp-Infographic-1__1_.png?w=700 700w, https://images.ctfassets.net/63bmaubptoky/ZmU8CC7FFx9PkPSiOMG1j/5f11e12912371aeaef08fdcf372a316a/Security-vulnerabilities-faced-by-companies-CA-GetApp-Infographic-1__1_.png?w=1000 1000w, https://images.ctfassets.net/63bmaubptoky/ZmU8CC7FFx9PkPSiOMG1j/5f11e12912371aeaef08fdcf372a316a/Security-vulnerabilities-faced-by-companies-CA-GetApp-Infographic-1__1_.png?w=1500 1500w, https://images.ctfassets.net/63bmaubptoky/ZmU8CC7FFx9PkPSiOMG1j/5f11e12912371aeaef08fdcf372a316a/Security-vulnerabilities-faced-by-companies-CA-GetApp-Infographic-1__1_.png?w=2200 2200w&quot; sizes=&quot;(min-resolution: 2x) 2200px, (min-width: 992px) 1000px, 95vw&quot;/&gt;&lt;p&gt;The reason why employee negligence could be a top-most security vulnerability might be a lack of awareness of cybersecurity knowledge. Workers may not have the ability to identify suspicious/malicious messages, because of which they could fall prey to such forms of cyberattacks. Therefore, organizations should offer company-wide &lt;a href=&quot;/directory/3809/security-awareness-training/software&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;cybersecurity training programs&lt;/a&gt; that not only educate employees but also assess their knowledge levels regarding cybersecurity threats. This additional step can help businesses create more effective training programs. &lt;/p&gt;&lt;p&gt;Setting weak passwords is another big challenge that companies usually have to struggle with. In this context, it is essential for companies to implement password policies that require employees to &lt;a href=&quot;/directory/677/password-manager/software&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;create strong passwords&lt;/a&gt; that cannot be easily hacked. In addition, using &lt;a href=&quot;/directory/3814/multi-factor-authentication/software&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;multi-factor authentication&lt;/a&gt; tech can add another layer of security.&lt;/p&gt;&lt;p&gt;Another security measure that companies can take is to execute phishing simulations. A phishing simulation is typically part of a cybersecurity awareness program where an imitation of a real-world phishing email is sent to employees to test and monitor how they respond to such emails. Conducting regular phishing simulations may help your employees recognize malicious emails and avoid falling victim to such attacks. &lt;/p&gt;&lt;h2 id=&quot;Advanced-email-phishing-attacks-are-the-top-concern-for-46-of-respondents&quot;&gt;Advanced email phishing attacks are the top concern for 46% of respondents &lt;/h2&gt;&lt;p&gt;There are over &lt;a href=&quot;https://www.demandsage.com/how-many-emails-are-sent-per-day/&quot; rel=&quot;nofollow noopener noreferrer&quot; target=&quot;_blank&quot;&gt;4.3 billion email users worldwide&lt;/a&gt; and around 347.3 billion emails are exchanged every day. Consequently, we can say that emails are among the foremost mediums of communication. This could be the reason why emails have increasingly become a common target for hackers. In fact, in one of our surveys on phishing attacks on GetApp, we found that &lt;a href=&quot;/blog/4206/phishing-attacks-in-canada&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;nearly 9 in 10 respondents have received phishing attacks via email&lt;/a&gt;. &lt;/p&gt;&lt;p&gt;Also, when we asked our fully aware respondents about threats that they were most concerned about for the next 12 months, they cited advanced email phishing attacks as a top concern (46%). In order to combat such issues, employees should be trained on how to spot such emails to safeguard their organization against cyberattacks. &lt;/p&gt;&lt;div class=&quot;box-hint&quot;&gt;&lt;div class=&quot;box-header fw-700 mb-4&quot;&gt;Here are some tips on how to spot a phishing email:&lt;/div&gt;&lt;ol&gt;&lt;li&gt;&lt;b&gt;Emails requiring quick action:&lt;br/&gt;&lt;/b&gt;&lt;a href=&quot;https://www.getcybersafe.gc.ca/en/resources/7-red-flags-phishing&quot; rel=&quot;nofollow noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Employees might receive an email&lt;/a&gt; that requires them to take action urgently, likely threatening a loss of opportunity. In such cases, people may take hasty actions without even reading the email completely.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Emails with grammatical errors:&lt;br/&gt;&lt;/b&gt;Phishing emails may have some sort of grammatical and spelling errors and this is one of the common ways to spot spammy emails. &lt;/li&gt;&lt;li&gt;&lt;b&gt;Emails sent from a public or unknown domain:&lt;br/&gt;&lt;/b&gt;Typically,&lt;b&gt;&lt;/b&gt;no business organization will send emails from public domains. Most companies will have their own &lt;a href=&quot;https://www.mail.com/blog/posts/what-is-email-domain/44/&quot; rel=&quot;nofollow noopener noreferrer&quot; target=&quot;_blank&quot;&gt;email domains&lt;/a&gt;, which is why it is quite important to look at the domain name of an email before clicking any link or responding to the email.  &lt;/li&gt;&lt;li&gt;&lt;b&gt;Emails including suspicious attachments:&lt;br/&gt;&lt;/b&gt;Employees may receive an email containing infected attachments that can corrupt the system or hack sensitive information. Work-related file sharing in companies nowadays usually takes place using &lt;a href=&quot;/directory/335/web-collaboration/software&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;collaboration tools&lt;/a&gt; such as OneDrive, Google Drive, or SharePoint. So, workers should ideally treat attachments received with external emails suspiciously before downloading them into their system.   &lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt;&lt;p&gt;As a matter of precaution, organizations can additionally use &lt;a href=&quot;/directory/475/email-security/software&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;email security software&lt;/a&gt; that can help them protect email accounts from phishing attacks by identifying emails received from bad &lt;a href=&quot;https://www.fortinet.com/resources/cyberglossary/what-is-ip-address#:~:text=An%20Internet%20Protocol%20(IP)%20address,use%20the%20internet%20to%20communicate.&quot; rel=&quot;nofollow noopener noreferrer&quot; target=&quot;_blank&quot;&gt;IP addresses&lt;/a&gt; or dodgy domains. &lt;/p&gt;&lt;h2 id=&quot;5-in-10-respondents-deploy-formal-cybersecurity-risk-assessments-to-protect-their-data&quot;&gt;5 in 10 respondents deploy formal cybersecurity risk assessments to protect their data &lt;/h2&gt;&lt;p&gt;On the risks of ransomware attacks in Canada, Sami Khoury, the head of the Centre for Cyber Security, said, ‘The &lt;a href=&quot;https://globalnews.ca/news/9842276/ransomware-attacks-canada/&quot; rel=&quot;nofollow noopener noreferrer&quot; target=&quot;_blank&quot;&gt;threat is real, the threat is growing&lt;/a&gt; and we can’t talk enough about it.’ He further urged Canadians to report such incidents so that the Centre could gather more information about who might be behind such attacks. &lt;/p&gt;&lt;p&gt;In this sense, it is crucial for companies to take appropriate measures on time so they don’t become a victim of major data breaches. &lt;/p&gt;&lt;p&gt;To understand how survey-takers deal with such issues, we asked our fully aware respondents what measures they deploy to protect their company’s data and this is what they reported:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;54% of the respondents deploy formal cybersecurity risk assessments to protect their data&lt;/li&gt;&lt;li&gt;38% of them use a data classification approach to safeguard sensitive data&lt;/li&gt;&lt;li&gt;31% of them leverage privileged access management solutions to monitor, detect, and prevent unauthorized privileged access to essential resources &lt;/li&gt;&lt;li&gt;Another 31% use&lt;a href=&quot;https://www.cyber.gc.ca/en/guidance/zero-trust-security-model-itsap10008&quot; rel=&quot;nofollow noopener noreferrer&quot; target=&quot;_blank&quot;&gt; zero-trust network security&lt;/a&gt; to enable strict access controls for additional security&lt;/li&gt;&lt;li&gt;Only 7% of them do not implement any security measures&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Formal cybersecurity risk assessments can be the first step to combating cyberattack risks for companies because they allow them to find security vulnerabilities in their systems. This can be followed by evaluating the right approach and creating a comprehensive action report. &lt;/p&gt;&lt;div class=&quot;box-hint&quot;&gt;&lt;div class=&quot;box-header fw-700 mb-4&quot;&gt;Key steps to performing formal cybersecurity assessments&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Audit your data and its infrastructure&lt;br/&gt;&lt;/b&gt;First, it is important to understand the type of data a business collects, how, and where it is stored, who has access to which data, and if the place where data is being stored is secure.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Define the parameters of the assessment&lt;br/&gt;&lt;/b&gt;Once the data audit is done, the next step could be to identify the purpose of the assessment and if there are any priorities that need to be defined. &lt;/li&gt;&lt;li&gt;&lt;b&gt;Identify the value of data&lt;br/&gt;&lt;/b&gt;Gauge the importance of information to be secured and protected from cyberattacks. In particular, determine if there are any legal penalties or if any day-to-day business operations would be affected in case such data is exposed to cybercrime. &lt;/li&gt;&lt;li&gt;&lt;b&gt;Prioritize assets&lt;br/&gt;&lt;/b&gt;Based on the information inferred from the above step, businesses should potentially prioritize which data assets to assess. &lt;/li&gt;&lt;li&gt;&lt;b&gt;Identify threats to the assets&lt;br/&gt;&lt;/b&gt;Once businesses prioritize assets based on their informational value, the next step could be identifying the possible cyber threats to the assets. Some of the common threats that may affect companies are unauthorized access, insider threats, loss of data, service disruption, or data leaks. &lt;/li&gt;&lt;li&gt;&lt;b&gt;Implement security controls&lt;br/&gt;&lt;/b&gt;Depending on the potential threats a business might have, companies can make decisions on which security controls to implement to safeguard their data against cyberattacks.  &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt;&lt;h2 id=&quot;Overcoming-cybersecurity-risks&quot;&gt;Overcoming cybersecurity risks&lt;/h2&gt;&lt;p&gt;To keep cybersecurity threats and attacks at bay, it is important for organizations to adopt strategies to overcome and mitigate such risks to create a safe and secure environment. &lt;/p&gt;&lt;p&gt;In fact, when it comes to investing in cybersecurity solutions, we found that 49% of fully aware respondents said that spending on security has increased, while 40% of them said that the spending is about the same and only 2% reported that it has decreased. Considering this, we can safely assume that companies are aware of the risks associated with cyberattacks and are actively investing to protect their businesses. &lt;/p&gt;&lt;p&gt;While companies are investing in cybersecurity solutions, it is also important for employees to have knowledge of relevant cybersecurity policies and risks. When we asked all our respondents if they had ever raised cybersecurity concerns with their IT departments, what came as a surprise was that only 33% of survey-takers have ever raised a cybersecurity concern with their IT department. Clearly, it’s imperative for companies to fully educate employees on both the risks and the appropriate forums to address such cybersecurity violations. &lt;/p&gt;&lt;div class=&quot;box-idea&quot;&gt;Looking for &lt;a href=&quot;/directory/1035/cybersecurity/software&quot; rel=&quot;noopener noreferrer&quot; class=&quot;evnt&quot; data-evac=&quot;ua_click&quot; data-evca=&quot;Blog_idea&quot; data-evna=&quot;engagement_blog_product_category_click&quot; target=&quot;_blank&quot;&gt;cybersecurity software&lt;/a&gt;? Check out our catalogue!&lt;/div&gt;&lt;p&gt;&lt;/p&gt;","dateModified":"2024-02-07T08:36:21.000000Z","datePublished":"2024-01-30T00:00:00.000000Z","mainEntityOfPage":"https://www.getapp.ca/blog/4504/managing-cybersecurity-risks#webpage"}]}
</script>
