To ensure that craft businesses do not become victims themselves, a well-thought-out security management system is recommended.

To prevent craft businesses from becoming victims themselves, a well-thought-out security management system is recommended. (Photo: © aurielaki/123RF.com)

Read aloud:

Rules for greater data security

Industry 4.0: The increasing digitalization of the skilled trades brings many advantages – but also new risks such as data loss and data misuse. These risks can be minimized.


The numbers are striking: According to a representative Bitkom study from October 2016, almost every second internet user in Germany has been a victim of cybercrime. The reason: Criminals often have an easy time of it, as the study found that 20 percent of respondents don't use antivirus software. 33 percent also don't have a firewall to prevent hackers from accessing the internet. This is why crimes such as virus attacks, identity theft, or extortion are repeatedly successful. Popular targets are not only computers, but increasingly also mobile devices such as smartphones and tablets.

To prevent craft businesses from becoming victims themselves, a well-thought-out security management system is recommended. Essential basic protection includes antivirus programs on all computers and mobile devices. These programs find and destroy viruses, worms, or Trojan horses that attempt to manipulate, spy on, or transmit data independently. In addition, basic security for all devices should be provided by a firewall. The most cost-effective solution is a so-called personal firewall. This compensates for the typical security vulnerabilities of the operating system and protects the device from external attacks. There are also hardware firewalls, which are integrated into routers, for example, as well as firewalls for entire networks. These are called "gateways" and often consist of a PC with firewall software that is placed in front of all other computers in the network. The firewall PC then controls all access and fends off external attacks.

Protect yourself from spies

Another threat to data security is spyware (spy software), which is usually installed unnoticed to spy on users' data, passwords, or behavior and send it over the internet. To counter this, there are special programs that detect spyware and permanently delete it. Companies can also achieve increased security with encryption programs: This allows sensitive data such as trade secrets, customer databases, invoices, or tax returns to be securely stored and protected from unauthorized access.

Backup programs

Backup Maker
(free for private use, corporate license: 50 euros) ascomp.net

TrayBackup
(free for private use, corporate license: 15 euros) traybackup.de

Z-DBackup
(free for private use, corporate license: from 30 euros) z-dbackup.de

You might also be interested in:

Protecting computers and mobile devices doesn't have to be expensive: In addition to combined solutions that combine, for example, a virus scanner and firewall, there are also many free programs and apps that offer at least basic security. However, with all software solutions, you should be aware that they consume system resources, which may slow the device down somewhat depending on its performance. Another key aspect for increased data security is regular backups of all important data, which should be stored in a way that prevents them from being infected by viruses on the network. Technical devices such as uninterruptible power supplies on servers and PCs also prevent data loss: In the event of an unexpected power outage, there is still enough power available to save unsecured data.

Raise awareness among employees

But hackers and power outages aren't the only threats to digital data – customers and your own employees are also a potential risk. If customers are left alone on business premises, they could theoretically access data from unprotected devices or steal USB flash drives. However, your own employees can pose an even greater threat – for example, if they open virus-infected email attachments from unknown senders or click on links in phishing emails. It's also possible that disgruntled employees, after being fired, will copy entire customer databases and hand them over to their new boss. Raising employee awareness of data security is therefore an important step in developing a security concept for your company.

Text: Thomas Busch / Photo: © Aurielaki/123RF.com

table 12 17 bush copy

Important technical terms

Backup
Backup copies of data and storage media. These copies can be used to restore the original information in the event of data loss or destruction.

Chippers
A hacker exploits security vulnerabilities to gain unauthorized access to other people's PCs and mobile devices over the internet. His goal: to take control of a device or steal data.

Router
A router connects PCs and networks. It establishes and terminates connections and transfers data.

Spam
The American word for canned meat (abbreviation of "Spiced Pork And Meat") refers to unwanted, unsolicited mass advertising sent via email.

spyware
A software that is usually installed unnoticed to log a user's behavior and send the results to the programmer via the Internet.

Trojan horse, Trojan
A small program that gets onto computers unnoticed, installs itself there and spies on data.

Update
A software update that adds new features to a program or fixes existing bugs and security vulnerabilities.

Virus Scanner
A program that protects a device from viruses by regularly scanning files and safely removing them when necessary.

checklist

More security for digital data
The following points can be part of a general security concept to achieve greater data security within the company. To develop a customized concept, we recommend engaging an external service provider specializing in operational and data security.

1. Install and activate firewall, virus scanner, and phishing protection on all devices.

2. Always keep operating systems, firewalls, and virus protection up to date.

3. Create a separate password-protected access for each employee in the Windows user control panel.

4. Allow employees access only to hard drives or folders that are absolutely necessary for their work.

5. Store sensitive data in encrypted form and protect it from unauthorized copying.

6. Configure PC screen savers, smartphones, and tablets to go into sleep mode after at most one minute of inactivity. The devices should only be usable after entering a password.

7. Install spam filters and delete spam emails unread.

8. Never click on links in unsolicited emails.

9. Do not open or launch unknown email attachments with file extensions such as "bat", "com", "exe" or "vbs".

10. Instruct employees not to leave documents containing important information unattended at copiers or on desks.

11. Keep floppy disks and storage media containing important data in locked cabinets.

12. Use loan slips on which each employee confirms with their signature which storage media and devices they have just borrowed.

13. Position PC monitors and printers so that customers or unauthorized employees cannot see them.

14. Lock data drives unless doing so would interfere with workflow. This prevents unauthorized copying of data and the introduction of computer viruses.

15. Protect PCs and important documents with passwords. Recommended: a seemingly random combination of letters, numbers, and special characters.

16. Only company directors and system administrators should have the ability to modify operating or application programs or to install new ones.

17. Make regular backups of all important data and ensure that the backup copies cannot be infected by viruses over the network.

18. Install an uninterruptible power supply (UPS) so you can still back up unsaved data in the event of a power outage. These small boxes (starting at around €60) are connected between the mains and the PC and provide several minutes of battery power in an emergency.

19. Delete all data from devices that are being sold, disposed of, or repaired outside of your company. Ideally, do so using special programs that prevent data recovery.

20. Raise awareness among all employees about data security and data protection.

Text: / handwerksblatt.de

You might also be interested in: