6 Best Practices for Data Protection Awareness | Total security

6 data privacy awareness tips for your users:

Data Protection, Total security


1. Know what is considered personal information

Personal information can be used alone or in conjunction with other information to identify an individual. Here are some examples :

  • Name, address and date of birth.
  • Passport or driver's license number
  • Medical, criminal or financial history
  • Ethnic or racial origins
  • IP address, if it can be assigned to an individual
  • DNA, fingerprints and voiceprints

2. Beware of phishing attempts

Remind your users of these best practices:

  • If you don't know who sent the email, don't open it. If you know where it's coming from, but it looks a bit strange, be careful. Ask yourself a few questions: Do I usually communicate with this person by email? If so, would she write to me at this time of day? And if you still have doubts, call her!
  • Do not click on links in unsolicited emails.
  • Never divulge confidential information in an email.
  • If an offer sounds too good to be true, it probably is.

3. Don't be fooled by the cousins ​​of phishing: vishing and Smising

Other social engineering methods such as calls, text messages, or even social media communications can trick you into passing on personal information. These fraudulent communications appear to come from the government (IRS, Census Bureau, or law enforcement), or from someone you know whose account has been compromised. For example, a successful vishing campaign targets seniors who believe they receive a phone call from a grandchild asking for money.

4. Report a Fraudulent Email

Whether it's your IT department, your email provider, or a government body, be sure to report the fraudulent email. Activate the phishing report button and be proactive (even in your personal inbox).

Most email providers have built-in mechanisms that make it easy to report an email scam. The phishing report button can be activated in Outlook, Gmail, Yahoo! and other email providers.

You should also know that most countries have a government body that deals with phishing scams. In the United States, the email can be sent to the Cyber ​​Security and Infrastructure Agency. In Canada, report the email to the Canadian Anti-Fraud Center. In the UK, fraud can be reported to the National Fraud and Cyber ​​Crime Reporting Center.

5. Remember These Tips When Shopping Online

  • Make sure the site is legitimate. If you are shopping on a new site that you don't know, it's worth checking out its legitimacy. You can do it using this method:
    • Check the URL, paying close attention to domains and subdomains and making sure it begins with "https: //". The "s" indicates encrypted communication between you (your browser) and the website. A closed padlock also indicates a secure transaction.
    • Dig to find the details of the certificate.
    • Watch for seals of approval from third parties such as total security providers.
  • Identity theft is on the rise. Identity thieves stole $ 16.8 billion from U.S. consumers in 2017, according to a study published by Javelin Strategy and Research.
  • Use multi-factor authentication wherever you can while shopping online. Many online stores will require you to create an account with them when ordering. If you do (rather than paying as a guest), make sure the password you create is strong. Better yet, use multi-factor authentication if it is offered. And while you are encouraged to save your payment information on the site, the convenience of doing so might not be worth the risk if you are not a frequent buyer of the site.

6. Don't use public Wi-Fi

You might be tempted to use open Wi-Fi networks to shop online. Whether it's impulse shopping online or just using in-store Wi-Fi to save time, don't trust public Wi-Fi when it comes to your address, contact details. credit card and any other personal item.

Create a cybersecurity corporate culture

Every business, regardless of industry, size, and location, is a target for cybercriminals. Therefore, special attention should be paid to creating a culture of cybersecurity within companies. January 28 is the perfect day to start an annual campaign on data protection and security awareness. Take advantage of the Personal Data Protection Toolkit  to launch your own data privacy awareness program. This kit includes a free interactive course and various communication and good practice reinforcement tools. It will help you train cyber heroes whose role will be to lead by example and fuel conversation throughout the year.

While January 28 is the perfect day to deal with data protection, the discussion shouldn't end on January 29. To maintain interest throughout the year, rely on interesting and stimulating training, simulations and communications.

Take advantage of these resources offered by NCSA on Data Privacy Day to stimulate thinking and discussion about data privacy.

* Available in English:

  • Get Involved in Data Privacy Day 
  • Update Your Privacy Settings 
  • Become A Data Privacy Day Chamion 

Learn about data protection

Measures such as the GDPR and the California Consumer Privacy Act (CCPA) help to raise awareness about data privacy. More and more people are realizing how their digital footprint is being used by large companies.

Even though the GDPR and CCPA have created a lot of buzz online, many people just don't understand the impact these policies can have on them.

GDPR

This European Union (EU) policy grants EU citizens the right to protect their data. This is a set of regulations that allows them to control how their personal data is used by companies operating within the EU. GDPR applies to any business operating within the EU or offering products and services to its citizens. However, GDPR is far from straightforward. Try our GDPR online learning modules for free  to improve your employees' knowledge.

CCPA

This policy lets California consumers know how their data is used and shared by businesses. They can also choose to have their data not shared with other organizations. The CCPA applies to any business operating in California with revenue of $ 25 million or more, that has data for at least 50,000 users, or has more than 50% of revenue from data. users. This policy was developed around two fundamental consumer rights, namely the “right to know” and the “right to say no”. Share these two links with your employees to learn more about the CCPA: California's data protection law takes effect today. And then after? and CCACFact Sheet.

It is important to broach the subject of data protection when trying to build a corporate culture focused on cybersecurity. Once your employees understand how their data is used by websites and businesses, they're more likely to think twice before sharing their personal information and IDs online.

When data protection is a priority, it is much easier to engage employees in the importance of cybersecurity awareness. There is a spillover effect that leads to increased awareness of the importance of not sharing personal data mindlessly.

 How to maintain interest in data protection

Data Privacy Day is a perfect opportunity to educate your employees and start the conversation about data privacy. However, to develop a real culture of data protection, interest must be maintained throughout the year.

You'll achieve this by using the tools in the Data Protection Toolkit and focusing on Cybersecurity awareness. These two elements go hand in hand in building a safe organization.

When people know the risks associated with sharing their data, they think twice before revealing their personal information.

Comments

Popular posts from this blog

Why Not to Restart Your Computer if It Is Infected With the Ransomware | Total Security

What Is a Ransomware Virus and How Do You Protect Your Computer From It | Total Security

What is a zero-day threat? Free Antivirus Software