Ending Soon! Save 33% on All Access

7 Simple Business Security Tips From Her Majesty's Secret Service What can businesses on both sides of the Atlantic learn from how British spymasters keep data safe?

By Luke Walling Edited by Dan Bova

Opinions expressed by Entrepreneur contributors are their own.

United Artist | Getty Images

The British Secret Service isn't quite so secret any more.

Spymasters in London are publishing regular advice about how to bolster security defenses against hackers and insider data breaches.

Recently, the Queen opened a new National Cyber Security Center in London, run by the Government Communications Headquarters (GCHQ).

Against the backdrop of international allegations of cyber-hacking and cyber-meddling in recent elections, the new center will oversee British efforts to prevent hackers from disrupting the national infrastructure, from hospitals to the electricity grid.

The GCHQ also gives businesses security advice ranging from tips on password policies to ways to ensure mobile workers don't compromise security while on the move. Here are (double-"O") seven lessons businesses on both sides of the Atlantic can learn from Her Majesty's Secret Service:

1. "Least privilege" protocol

Ensure that employees have only the system access they need to do their jobs -- don't open up access to sensitive systems for employees at all grades.

Related: Is My Data Really Safe? Your Questions About Cloud-Based Storage, Answered.

2. Control removable media

An external device plugged into a network is a main route for malware to disrupt systems. Limit the use of external devices like USB memory sticks, particularly those brought in from home by employees.

3. Secure the doors

Ensure that old systems, network devices and sites are removed and decommissioned. Don't allow hackers to access your network through a forgotten entry point.

Related: Cyber Security a Growing Issue for Small Business

4. Start-to-finish process

Have a clear process in place for deciding what network privileges and devices new employees can use, what happens when they change roles, and what happens when they leave. Revoke access and recover company devices and data as soon as workers depart. Note that this can be complex if they've used personal devices in the workplace.

5. Define "tolerable risk."

What risk is your organization willing to take to get the job done? Can you allow your staff to use their own devices or take data files and documents home? It might help productivity, but you need to understand all the risks involved: devices getting lost, stolen, hacked or contaminated with malware.

Related: The Risks of Business Travel in a Wired World (Infographic)

6. Train.

If your staff doesn't know the risks and legal requirements around data security, you're inviting vulnerabilities. Explain the issues and train best practices.

7. Observe and report.

Encourage staff to be vigilant and report suspicious activity such as suspicious emails or unexpected changes to the systems they use.

The truth is that much of the threat around data security starts inside a business rather than outside, with malicious, accidental or ill-considered actions by employees allowing confidential information to be compromised.

The best defense is deploying data loss prevention (DLP) technology, which prevents unauthorized saving, copying, printing or emailing of sensitive files, to prevent accidental or criminal actions by insiders.

So, how does your organization stack up against these seven simple tips? Do you follow the basic advice of Her Majesty's Secret Service?

Luke Walling

General Manager of Safetica North America

Want to be an Entrepreneur Leadership Network contributor? Apply now to join.

Business News

Now that OpenAI's Superalignment Team Has Been Disbanded, Who's Preventing AI from Going Rogue?

We spoke to an AI expert who says safety and innovation are not separate things that must be balanced; they go hand in hand.

Franchise

What Franchising Can Teach The NFL About The Impact of Private Equity

The NFL is smart to take a thoughtful approach before approving institutional capital's investment in teams.

Employee Experience & Recruiting

Beyond the Great Resignation — How to Attract Freelancers and Independent Talent Back to Traditional Work

Discussing the recent workplace exit of employees in search of more meaningful work and ways companies can attract that talent back.

Business News

Scarlett Johansson 'Shocked' That OpenAI Used a Voice 'So Eerily Similar' to Hers After Already Telling the Company 'No'

Johansson asked OpenAI how they created the AI voice that her "closest friends and news outlets could not tell the difference."

Business Ideas

Struggling to Balance Your Business and Your Relationship? This Company Says It Has a Solution.

Jessica Holton, co-founder and CEO of Ours, says her company is on a mission to destigmatize couples therapy so that people can be proactive about relationship health.

Marketing

Marketing Campaigns Must Do More than Drive Clicks — Here's How to Craft Landing Pages That Convert Clicks into Customers

Following fundamental design principles will ensure that your landing pages lead potential customers from clicking on an ad to completing a purchase.