Home
Blog

Cybersecurity and SMS Marketing: protect your data

Cybersecurity and SMS Marketing: protect your data

SMS Marketing
November 17, 2020

Table of Contents

Ready to send your first campaign?

Create your account in two minutes, no credit card required.

Create an account
Create an account
Create an account
Featured image blog 1

Once you have finished your membership form, you are ready to collect your customers' data. But wait, have you thought about where you are going to store all that data? What steps will you take to secure it?

As the GDPR states, data protection should be "by design and by default." "This is a GDPR principle indicating that all institutions must comply from the outset, as the foundation of their processes and mechanisms," explain our lawyers Sophie Soubelet-Caroit and Perrine Salagnac from SSC Avocats. This means that institutions must be built with the GDPR as an essential component of the business, rather than just something they "add on" at the end.

We consulted Hadi El-Khoury, CEO and founder of Sekimia Cybersecurity & Risk Management on how to meet this requirement and secure customer data.

Secure processes and connections are not just for payment pages, so let's look at what we can do to achieve this:

  • strengthen our information systems
  • prevent and recognize data breaches
  • handle an incident if we experience one

What are the most common cyberattacks?

"The biggest threats today are phishing and ransomware," he stated.

  • Phishing is a type of cybercrime where someone poses as a legitimate institution and lures individuals via email, phone, or text message into providing personal data, such as passwords and banking or credit card information. "This information is then used to access important accounts and can result in identity theft and financial loss," as noted by Phishing.org, a project dedicated to awareness, education, and information regarding this type of threat.
  • Ransomware is a type of malicious software (malware) designed to deny access to a computer system or data until a ransom is paid, and it can be the result of a phishing attack, according to the Cybersecurity and Infrastructure Security Agency (CISA).

However, these two are not the only ones you should be wary of.

"We have many examples of organizations discovering that their information systems were compromised by hackers two or three years ago. Why? Because those hackers were only interested in stealing or modifying information; they weren't interested in ransom demands or denial-of-service attacks," explains Hadi.

"You need indicators that can tell you when you've been compromised, otherwise, you might never notice," he adds.

How can cyberattacks be prevented?

There are multiple measures we can take to protect our systems and data from theft, modification, or infection, and they depend on a number of factors such as the size of the company, its model, the type of data it collects, and so on.

It is fair to say that there is a security model for every company, and the ideal way to determine it would be to **consult a specialist *beforehand***.

In the meantime, Hadi suggested some basic and more advanced preventive methods that can significantly reduce the likelihood of an incident.

Basic cybersecurity measures:

  • Continuously update your software and systems. Apply security patches as soon and as widely as possible, such as antivirus and malware detection software.
  • Back up your data and, just as importantly, disconnect your backup. There is no point in having an online backup because if you are attacked, it is highly likely that the hacker will also compromise your backup.
  • Use a password manager – such as LastPass or 1Password – and enable two-factor authentication whenever possible.

More advanced cybersecurity measures:

DNS monitoring tools. They detect and monitor whenever someone registers a domain name similar to yours to trick victims into thinking it is you. If this happens, it is a sign that the entity may be preparing for an attack. By detecting it with your DNS monitor, you can take action and alert the authorities.

Outbound traffic monitoring tools. They monitor the destination of URLs that you or an employee might click on by mistake and intercept the outbound traffic if it is identified as a malicious link.

What to do in the event of a hack or data breach?

Having a first-response plan to know exactly what to do in the event of a cyberattack should be like having a first-aid kit. "Every day, I meet clients who suffer a breach and don't know who to call. They spend countless hours looking for the right expert or forensic advisor," explains Hadi.

We asked him what we could do in the event of a hack or intrusion, and he suggested three basic steps, which we have outlined below.

In the event of a cyberattack:

  1. Disconnect your information system from the Internet. This will prevent intruders from advancing the attack.
  2. Identify the source of the breach. To do this, map out your information system in advance as comprehensively as possible.
  3. Know who to call. Keep a repository of contacts for law enforcement or private organizations that can help you respond to any incident.

Fighting cybercrime together

The more we unite, the better we can fight back. If you are a victim of spamming, phishing, ransomware, or any other cyberattack, report it, take action, and help make the internet safer for everyone.

The Cybermalveillance platform is a public resource that allows cyber-victims to seek help and request assistance from various private companies. You can also call the police to report it and pursue legal action," he adds. At the bottom of this article, you will find a more extensive list of sites to consult for reporting cybercrime and obtaining more information on how to combat it.

"The starting point would be to raise awareness and train your employees to follow the 'stop, think, connect' mantra. So, when in doubt, don't click. Ask someone around you. Double-check everything," explains Hadi.

Our commitment at Octopush

As a company that manages not only its own client data but also the data of its clients' clients, Octopush must be extremely cautious and methodical regarding its own cybersecurity.

We feel strongly committed to the fight against cybercrime and to raising awareness about cybersecurity, both for ourselves and for our clients. To align with this mission,

we have decided to create a GDPR and data security section that we will be publishing very soon.

Stay tuned!

FAQ

Frequently asked questions

Find answers to the most frequently asked questions about our platform, its features, and how to use it here.

Already used by over 4,000 users
No items found.
contact

Ready to send your first campaign?

Create your account in two minutes, no credit card required.
Get started for free
Get started for free
Get started for free
No commitment • no credit card required.