English

Open Circle AG – Zurich
Freilagerstrasse 32
8047 Zürich

Open Circle AG – Bern
Lagerhausweg 30
3018 Bern

A look back at our most recent event shows that cybersecurity is not a one-off measure, but an ongoing process. Proactive preparation is the key to fending off attacks and remaining capable of acting in an emergency. ‘It can happen to anyone – the best defence is proactive preparation,’ says Alex Hediger, CISO as a Service at Camarque Switzerland.

Important recommendations for preventing cyber attacks

The experts presented five crucial protective measures for companies:

1. Technical measures

Protection against cyber attacks begins with technology. Critical security updates must be installed immediately to quickly close potential security gaps. Regular, ransomware-proof backups that cannot be encrypted in the event of an attack, for example on an offline storage medium such as a tape, are also essential. Using a password manager also makes it possible to use complex passwords that no longer have to be memorised individually. Two-factor authentication (MFA) can also be easily managed in this way, providing additional access protection.

2. Partnerships for emergencies

Cooperation with experienced partners (such as Redguard), who specialise in the management and investigation of cyber attacks, can be crucial in an emergency. These professionals deal with the analysis and defence against threats on a daily basis and bring valuable experience to crisis management. Crisis communication is equally important: it must always be formulated carefully and truthfully in order to maintain trust and minimise possible reputational damage. Specialised crisis communication agencies can provide valuable support here.

3. Back up important data on a stick in case of an emergency

In an emergency – such as a ransomware attack – fast and structured access to important data is essential. It must be possible to inform customers immediately and call on specialised partners for defence and recovery quickly. Furthermore, it is essential to promptly change the passwords for all systems, including external platforms such as online shops. It is also necessary to quickly check whether sensitive personal data may have been compromised. To ensure this, all critical information – from customer lists and partner contacts to network plans – should be securely stored on physical data carriers and available offline.

4. Business continuity planning

A clearly defined emergency plan is essential to maintain business operations during and after a cyber attack. Of course, a plan will never be implemented exactly as intended, as every crisis brings with it its own unique challenges. But a carefully prepared emergency plan, created in calm times, serves as a valuable tool in an emergency. In the usually stressful situation of an attack, a well-developed plan provides a structure that everyone involved can use for orientation.

5. Employee training

‘Awareness is essential,‘ says Alex Hediger. Regular training, such as phishing simulations, can be used to raise employees’ awareness and increase their vigilance. This makes it easier to recognise well-disguised ‘CEO fraud’ emails, in which a supposed managing director or senior executive asks employees to make expensive transfers. Such training helps to minimise risks and protect the company from costly attacks.

EDUCATION

IT Security Awareness Webinar

We have developed an IT Security Awareness Webinar to sensitise our customers’ employees. We provide basic knowledge about cybersecurity, correct behaviour in the event of incidents, secure use of IT systems and many other exciting insights.

More information

Crisis Management in an Emergency – Fast and Structured Action

In the event of an attack, it is essential to immediately establish a clear management rhythm, according to Dominik Nufer, Redguard’s Lead Incident Responder. This includes a precise damage analysis, the identification of necessary measures, and the decision as to which internal and external partners – for example, management, the IT department or external specialists such as Redguard – are to be involved. The importance of transparent and timely communication to keep all parties involved informed was also emphasised.

Dominik Nufer pointed out crucial questions in an emergency: Can we identify the attacker? What is their standard operating procedure? Which playbooks can be applied? The importance of rest periods and meals was also pointed out to strengthen the resilience of the teams involved in crisis situations.

 

Conclusion – cybersecurity is an ongoing process

The event at the ComedyHaus made it clear that cybersecurity is not a one-off task, but an ongoing process that must be strengthened through preventive measures and regular training. Companies are called upon to face up to this challenge and to continuously optimise their measures for defending against and dealing with cyberattacks. The event provided valuable impetus and a platform for exchange and networking – the organisers thanked all the participants and experts for making it such a successful evening.

Presentations of the keynote speakers

Get advice