It's a common misconception that only larger companies are targeted
Sigurmundur Páll Jónsson, a consultant at Origo, is here for an informative chat about corporate cybersecurity. He says it's a common misconception that hackers only attack large companies and, in this context, gives an example of a small tourism company that lost its booking system due to an attack. "And then buses just started streaming in, full of tourists," he says.
He also points out that industrial companies can have various vulnerabilities in their computer systems. Various machines are often connected to computers and a shared drive, and these machines can stop working if the computer system is attacked.
Sigurmundur specifically points out that it's necessary to make sure to change passwords regularly and to have them be long and complex. This makes them harder to guess. Software needs to be updated regularly, and two-factor authentication is essential, where actions must be confirmed via a phone.
He believes it's important to educate staff rather than impose bans and, in this context, points out that many companies establish a security policy.
Sigurmundur also discusses security assessments, which provide an overview of cybersecurity and where potential security breaches lie. According to him, hackers are not thinking about the size or scope of the company, but simply where it's easiest to break in. You can learn more about security assessments here.