Skip to main content
  • Personal
  • Business
  • Foundation
    Close
  • Select Region
    • Global
    • India
    • MENA
  • mySHRM Login
  • MySHRM
    • Dashboard
    • Account
    • Logout
SHRM
  • Membership
    • Membership

      As a SHRM Member®, you’ll pave the path of your success with invaluable resources, world-class educational opportunities and premier events.

      Membership Tiers
      • Professional
      • Student
      • Global
      • Executive
      • Business
      Membership Benefits
  • Learning
    • Learning

      Build capability, credibility, and confidence to influence strategy, shape culture, and drive measurable business impact.

      SHRM Certification

      Demonstrate your ability to apply HR principles to real-life situations.

      • Choosing Your Certification
      • SHRM-CP
      • SHRM-SCP
      • How to Get Certified
      • Prepare for the Exam
      • Recertification
      Seminars

      Stand out from among your HR peers with the skills obtained from a SHRM Seminar.

      Specialty Credentials

      Demonstrate targeted competence and enhance your HR credibility.

      Educational Programs

      Designed and delivered by HR experts to empower you with the knowledge and tools you need to drive lasting change in the workplace.

      • Essentials of HR
      • eLearning
      Qualifications

      Gain a deeper understanding and develop critical skills.

  • Attend
    • Events

      Demonstrate your ability to apply HR principles to real-life situations.

      • SHRM26 Annual Conference & Expo
      • The AI+HI Project 2026
      • Talent 2026
      • Linkage Institute 2026
      • BLUEPRINT 2025
      State Conferences

      Attend a SHRM state event to network with other HR professionals and learn more about the future of work.

      Seminars

      Stand out from among your HR peers with the skills obtained from a SHRM Seminar.

      Webinars

      Learn live and on demand. Earn PDCs and gain immediate insights into the latest HR trends.

  • Resources
    • Resources

      Stay up to date with news and leverage our vast library of resources.

      • Flagships
      • HR Research
      • Legal & Compliance
      • Latest News & Trends
      • Tools & Guides
      • Webinars
      HR Topics
      • AI in the Workplace
      • Civility at Work
      • Compensation & Benefits
      • Inclusion & Diversity
      • Talent Acquisition
      • HR Technology
      • Workplace Violence Prevention
      Educational Programs

      Designed and delivered by HR experts to empower you with the knowledge and tools you need to drive lasting change in the workplace.

  • Community
    • Find a SHRM Chapter

      Easily find a local professional or student chapter in your area.

      • SHRM Northern California
      SHRM Connect

      Post polls, get crowdsourced answers to your questions and network with other HR professionals online.

      Membership Councils

      Learn about SHRM's five regional councils and the Membership Advisory Council (MAC).

      Volunteers

      Learn about volunteer opportunities with SHRM.

  • Shop
    • SHRM Store

      Shop for HR certifications, credentials, learning, events, merchandise and more.

      Workplace Essentials
      • SHRM Memberships
      • SHRM Certification
      • Specialty Credentials
      • HR Tools & Tech
      Education
      • Seminars
      • eLearning
      • Books
      Merchandise
      • Accessories
      • Apparel
      • Office & Home
Become a Member
Renew
Rejoin Now
Renew
Ask an HR Advisor
Close
  • Personal
  • Business
  • Foundation
  • Membership
    back
    Membership
    • Membership

      As a SHRM Member®, you’ll pave the path of your success with invaluable resources, world-class educational opportunities and premier events.

      Membership Tiers
      • Professional
      • Student
      • Global
      • Executive
      • Business
      Membership Benefits
  • Learning
    back
    Learning
    • Learning

      Build capability, credibility, and confidence to influence strategy, shape culture, and drive measurable business impact.

      SHRM Certification

      Demonstrate your ability to apply HR principles to real-life situations.

      • Choosing Your Certification
      • SHRM-CP
      • SHRM-SCP
      • How to Get Certified
      • Prepare for the Exam
      • Recertification
      Seminars

      Stand out from among your HR peers with the skills obtained from a SHRM Seminar.

      Specialty Credentials

      Demonstrate targeted competence and enhance your HR credibility.

      Educational Programs

      Designed and delivered by HR experts to empower you with the knowledge and tools you need to drive lasting change in the workplace.

      • Essentials of HR
      • eLearning
      Qualifications

      Gain a deeper understanding and develop critical skills.

  • Attend
    back
    Attend
    • Events

      Demonstrate your ability to apply HR principles to real-life situations.

      • SHRM26 Annual Conference & Expo
      • The AI+HI Project 2026
      • Talent 2026
      • Linkage Institute 2026
      • BLUEPRINT 2025
      State Conferences

      Attend a SHRM state event to network with other HR professionals and learn more about the future of work.

      Seminars

      Stand out from among your HR peers with the skills obtained from a SHRM Seminar.

      Webinars

      Learn live and on demand. Earn PDCs and gain immediate insights into the latest HR trends.

  • Resources
    back
    Resources
    • Resources

      Stay up to date with news and leverage our vast library of resources.

      • Flagships
      • HR Research
      • Legal & Compliance
      • Latest News & Trends
      • Tools & Guides
      • Webinars
      HR Topics
      • AI in the Workplace
      • Civility at Work
      • Compensation & Benefits
      • Inclusion & Diversity
      • Talent Acquisition
      • HR Technology
      • Workplace Violence Prevention
      Educational Programs

      Designed and delivered by HR experts to empower you with the knowledge and tools you need to drive lasting change in the workplace.

  • Community
    back
    Community
    • Find a SHRM Chapter

      Easily find a local professional or student chapter in your area.

      • SHRM Northern California
      SHRM Connect

      Post polls, get crowdsourced answers to your questions and network with other HR professionals online.

      Membership Councils

      Learn about SHRM's five regional councils and the Membership Advisory Council (MAC).

      Volunteers

      Learn about volunteer opportunities with SHRM.

  • Shop
    back
    Shop
    • SHRM Store

      Shop for HR certifications, credentials, learning, events, merchandise and more.

      Workplace Essentials
      • SHRM Memberships
      • SHRM Certification
      • Specialty Credentials
      • HR Tools & Tech
      Education
      • Seminars
      • eLearning
      • Books
      Merchandise
      • Accessories
      • Apparel
      • Office & Home
Become a Member
Renew
Rejoin Now
Renew
Ask an HR Advisor
  • Select Region
    • Global
    • India
    • MENA
SHRM
mySHRM Login
  • MySHRM
    • Dashboard
    • Account
    • Logout
Close

  1. Topics & Tools
  2. Workplace News & Trends
  3. 13 Ways to Reduce Cyberattack Vulnerability
Share
  • Linked In
  • Facebook
  • Twitter
  • Email

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Vivamus convallis sem tellus, vitae egestas felis vestibule ut.


Error message details.

Copy button
Reuse Permissions

Request permission to republish or redistribute SHRM content and materials.


Learn More
News

13 Ways to Reduce Cyberattack Vulnerability

July 10, 2018 | Dinah Wisenberg Brin

Two people working on computers in an office.


​Cybercriminals consider small businesses a "target of choice," and a vast number of owners may be leaving their websites and companies unnecessarily vulnerable to attack, a new report suggests. Training employees on sound cybersecurity practices is an integral part of protecting a business, experts note.

In a recent survey of 250 website owners, cloud-based security firm SiteLock found that 59 percent are responsible for their own website upkeep but only 41 percent update website applications at least once a month. Experts consider software updates vital to protecting computer systems.

Among other survey findings: Of owners who had experienced a security incident, 24 percent reported that it damaged their business reputation while more than 35 percent reported that it endangered their bottom line.

"This may leave businesses with websites vulnerable to a variety of cyberattacks. It also begs the question, what other cybersecurity vulnerabilities are being left exposed? All too often, one of the weak links in the cybersecurity chain for corporations is employee awareness," said SiteLock product marketing specialist Jessica Ortega.

[SHRM members-only online discussion platform: SHRM Connect]

Even though Millennials represent one-third of small-business owners, that generation's digital nimbleness doesn't make their websites more secure, according to SiteLock.

Ortega and other experts offered suggestions for making employees more aware and companies more cybersecure:

  1. Make sure remote workers use a virtual private network, or VPN, rather than public Wi-Fi. "Many employees and contractors work from coffee shops and libraries as needed, to make use of their public Wi-Fi. However, public Wi-Fi can put internal company data at higher risk," Ortega said. A VPN connection ensures that communications are encrypted, preventing cybercriminals from intercepting them.
  2. Require strong passwords and good password habits. "A strong password is your first line of defense against attackers attempting to gain unauthorized access to your data," Ortega said. Passwords should be at least eight to 12 characters long, include letters and numbers, and should not contain commonly used words such as "admin" or your username, she said. She also recommended using a password manager to store randomly generated passwords, never reusing a password and choosing a unique password for each account to prevent hackers from using one password to breach more than one account.
  3. Urge caution before clicking. Most data breaches arise from social engineering and phishing malware attacks, Ortega noted. Phishing files disguised as shopping or banking apps, deployed to steal login or credit card credentials, represented 11 percent of malicious files cleaned from infected sites in the first quarter of 2018, according to SiteLock, which studied more than 10 million websites. "When entering your password for an account, always verify in your browser that the website you're visiting is indeed the site you intended to enter this information on," Ortega said, noting that experts also warn against clicking links in e-mails to authenticate any account. Instead, enter the URL for the company that holds your account directly into your browser, she advised. National Cyber Security Alliance Executive Director Russ Schrader similarly said workers should be trained to recognize spam and taught that opening links from unsafe sites can expose the whole company to a virus. Make sure e-mails can't be used for sending spam and consider blacklisting and whitelisting websites, Schrader said. "There are third-party providers who can help companies implement these security measures."
  4. Warn employees about the dangers of oversharing. SiteLock cautions against sharing too much information through social media, steering clear of surveys that ask for "seemingly innocuous" information, like a pet's name or a first concert, that cybercriminals can use to access accounts.
  5. Limit employee access to company data. "It starts with access—knowing who can have access to which of the company's data, e-mail, websites, et cetera," Schrader said. "When onboarding, HR should collect the profile of an employee, including what that person's job description is and what they will have access to. You need to ensure that your systems are safe and secure and that an employee who is not authorized to access the company's financial data can't take that data and send it elsewhere."
  6. Track all devices. HR needs to log each device that every employee has and be able to map each one to a person, Schrader said. "It should also be clear who in management can log in remotely to turn off any device they think is being misused."
  7. Limit personal use of work devices. Workers must know that a work device is meant for work and that they shouldn't store personal passwords or photos on the devices, as that information can be viewed by an employer or lost if the device goes missing, Schrader said.
  8. Encourage employees to quickly report their cybermistakes. "Thank an employee who admits she clicked a bad link or opened an attachment she shouldn't have. IT needs to know about these things as soon as possible," said employment attorney and HR consultant Kate Bischoff, SHRM-SCP, of tHRive Law & Consulting LLC. "If you punish her, no employee is going to come forward when they do the same thing. This allows the issue to grow and possibly affect the whole organization."
  9. Require two-factor authentication to log in to company systems.
  10. Train employees regularly. Training should be part of onboarding and should take place annually or semiannually, Schrader said. Guidelines should be readily accessible on the company's internal website, he said.
  11. Make cybersecurity part of offboarding. "If you're going to do a layoff or a planned termination, have the tech people lined up and ready to go immediately after termination should a disgruntled employee try to retaliate through a cyberbreach," Schrader advised.
  12. Use artificial intelligence-based security monitoring to find irregularities. "These systems can identify weaknesses, even down to unusual activity of a single employee," Bischoff said.
  13. Consider cyberinsurance. Small businesses should have it, but even if they don't, many policy applications have a checklist of what you need to do to secure data, Schrader said.

The National Cyber Security Alliance's CyberSecure My Business program includes resources to help small businesses better protect data.

Dinah Wisenberg Brin is a freelance writer in Philadelphia, covering workplace issues, entrepreneurship and small business, health care, logistics, and personal finance.

HR Technology
Privacy & Security Compliance
Risk Management

Was this resource helpful?

Leave Feedback

SHRM-CP Promo Image
Validate your HR expertise

Earning your SHRM-CP credential makes you a recognized expert and leader in the HR field.

Get Certified


Related Content

(opens in a new tab)
News
How One Company Uses Digital Tools to Boost Employee Well-Being

Learn how Marsh McLennan successfully boosts staff well-being with digital tools, improving productivity and work satisfaction for more than 20,000 employees.

(opens in a new tab)
News
A 4-Day Workweek? AI-Fueled Efficiencies Could Make It Happen

The proliferation of artificial intelligence in the workplace, and the ensuing expected increase in productivity and efficiency, could help usher in the four-day workweek, some experts predict.

(opens in a new tab)
News
Rising Demand for Workforce AI Skills Leads to Calls for Upskilling

As artificial intelligence technology continues to develop, the demand for workers with the ability to work alongside and manage AI systems will increase. This means that workers who are not able to adapt and learn these new skills will be left behind in the job market.

HR Daily Newsletter

Stay up to date with the latest HR news, trends, and expert advice each business day.

Success title

Success caption

Manage Subscriptions
Our Brands

SHRM Foundation Logo
SHRM Executive Network Logo
CEO Circle Logo
SHRM Business Logo
SHRM Linkage Logo
SHRM Labs
Overview

  • About SHRM
  • Careers at SHRM
  • Press Room
  • Contact SHRM
  • Post an HR Job
SHRM Named to Newsweek's 2026 America's Top Online Learning Provider List
Advocacy

  • SHRM Advocacy
  • Federal Policies
  • State Affairs
  • Global Policy
  • Take Action
  • SHRM E2 Initiative
Brand Partnership

  • Partnership Opportunities
  • Advertise with Us
  • Exhibit & Sponsorship
  • Recertification Providers
  • Book a Speaker
Member Resources

  • Ask an HR Advisor
  • SHRM Newsletters
  • SHRM Flagships
  • Topics & Tools
  • Find an HR Job
  • Vendor Directory

© 2026 SHRM. All Rights Reserved
SHRM provides content as a service to its readers and members. It does not offer legal advice, and cannot guarantee the accuracy or suitability of its content for a particular purpose. Disclaimer

Follow Us

  • LinkedIn
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Feedback

  1. Your Privacy Choices

  2. Terms of Use

  3. Accessibility

Join SHRM for Exclusive Access to Professional Content

SHRM Members enjoy unlimited access to articles and exclusive professional content resources.

Already a member? Login
Free Article

Login to unlock unlimited access or join SHRM today to get unlimited access to articles and member-exclusive resources.

Already a member? Login
Limit Reached

You've reached the limit of 1 free article this month. Join to access unlimited articles and member-only resources.

Already a member? Login
Free Article

Login to unlock unlimited access or join SHRM today to get unlimited access articles and member-exclusive resources.

Already a member? Login
Limit Reached

You've reached the limit of 1 free article this month. Join the Executive Network and enjoy unlimited content.

Already a member? Login
Unlock Your Career with SHRM Membership

Please enjoy this free resource! Join SHRM for unlimited access to exclusive articles and tools.

Already a member? Login
Join SHRM for Exclusive Access to Professional Premium Content

SHRM Members enjoy unlimited access to articles and exclusive professional premium resources.

Already a member? Login
Join SHRM for Exclusive Access to Student Content

SHRM Members enjoy unlimited access to articles and exclusive member resources.

Already a member? Login
Join SHRM for Exclusive Access to Executive Network Content

SHRM member enjoys unlimited access to articles and exclusive executive member resources.

Already a member? Login

Your membership is almost expired! Renew today for unlimited access to member content.

Renew now

Your membership has expired. Renew today for unlimited access to member content.

Renew Now

Your Executive Network membership is nearing its expiration. Renew now to maintain access.

Renew Now

Your membership has expired. Renew your Executive Network benefits today.

Renew Now