With the rapid rise of digital systems and cloud services, businesses have become more vulnerable to cyberattacks aimed at stealing data, disrupting services, or compromising accounts and internal systems.
In this context, the National Cybersecurity Agency indicated that the dark web had transformed into a true marketplace for trading stolen databases, passwords, personal information and sensitive documents, thus posing a direct threat to the reputation of companies and the continuity of their operations.
The agency published a series of recommendations and guidance aimed at strengthening the protection of businesses against cyberattacks and limiting the risks of data leakage.
Phishing Tops the Threats
Phishing is among the most commonly used methods by cybercriminals. It involves sending fake emails or messages to deceive employees and induce them to disclose sensitive information, including usernames, passwords, bank details or verification codes.
These messages often appear to come from reliable entities, such as banks, government administrations or service providers. Ongoing employee awareness is therefore a key preventive measure.
Malware includes viruses, spyware and keylogging programs, as well as tools designed to steal passwords stored in web browsers.
These programs can enable the compromise of devices, data theft or monitoring of user activities, but also cause interruptions to systems and services.
Exploitation of Unpatched Systems
Many cyberattacks rely on exploiting security flaws present in systems and applications that are not regularly updated.
These include operating systems used on servers and computers, web applications, as well as network equipment. Prompt installation of security updates is therefore essential to reduce intrusion risks.
The agency also stressed the importance of using a strong, unique password for each account to better protect users and prevent unauthorized access.
It is also recommended to enable multi-factor authentication, not to store sensitive passwords in browsers, and to change them regularly, especially in case of suspected hacking.
The “3-2-1” Rule for Protecting Backups
Backups are among the main means of protecting companies against data loss and ransomware attacks. The agency recommends applying the so‑called “3-2-1” rule, which consists of keeping three copies of data, on two different storage media, including one offline or immutable copy. This method allows data restoration when systems are compromised or damaged.
The agency also emphasized the need to regularly conduct security audits of systems and software. These should include vulnerability analysis, intrusion testing, and verification of server configurations and user access rights.
Backups should also be checked, while security risks should be periodically reevaluated. At the same time, employees should be regularly educated about cyber threats and how to prevent them.
Beyond preventive measures, every company should develop a comprehensive cyber incident response plan. This framework should provide mechanisms to detect incidents, assess their severity, isolate affected devices, eliminate the cause of the intrusion, and restore systems and data.
The incident should also be documented and analyzed to determine its causes and extract the necessary lessons. This approach helps prevent recurrence and strengthen the company’s ability to face future threats.
The recommendations of the National Cybersecurity Agency conclude that protecting businesses does not rely solely on technical solutions. It also requires a global security culture, continuous system updates, regular employee training, and an operational plan ready to be activated in the event of a cyber emergency.