Key takeaways

Prioritize business resiliency planning

Create or strengthen your organization’s incident response and data recovery plan.

Manage vulnerabilities

Routinely assess, identify, and promptly address vulnerabilities in your IT environment.

Implement security measures

Use MFA, role-based access control, and other safeguards to protect against common threats.

Develop and deepen a strong security culture

Educate employees about cybersecurity best practices and reinforce the importance of vigilance.

Cyber threats aren't slowing down, and AI is reshaping the threat landscape at an accelerating speed and scale. By using AI tools to craft convincing messages, spoof websites, and inject malicious prompts or code, cybercriminals can evade traditional detection mechanisms, leading to businesses being targeted more than ever.

A report on data breaches last year found that third-party involvement in breaches doubled to 30%, while vulnerability exploitation as an initial attack vector rose 34%1. Costs climbed too. The average U.S. data breach hit a record $10.22 million, and ransomware appeared in 44% of breaches, up from 32% in the prior year2.

Strong cybersecurity starts with a robust, layered defense strategy, which most importantly includes informed, vigilant employees. This practical checklist can help your organization build a strong security-first culture and stay ahead of emerging threats.

Prioritize business resiliency planning that includes incident response and data recovery

  • Create or strengthen an incident response and data recovery plan. Kick off the year by developing or bolstering your organization’s strategy for responding to cyber threats or natural disasters.
    • Designate those who will execute the incident and crisis response plan.
    • Identify key stakeholders and decision-makers.
    • Prioritize the critical data needed to maintain operations.
    • Use tabletop exercises to test the response plan and continually refine it.
  • Maintain an accurate inventory of your organization’s assets (IT equipment, data, and systems). In the event of an attack or disaster, this information supports insurance claims and guides data recovery after the incident. Set a policy to maintain the inventory on a regular schedule for updating and verifying accuracy.
  • Perform automatic, continual backups of business data and information. Prioritize critical data, such as databases, financial files, spreadsheets, human resource files, accounts receivable/payable files, and core IT configurations.
    • Recovery Point Objective (RPO) and Recovery Time Objective (RTO) are two aspects of a data recovery and backup plan. Add these requirements to your plan.
    • Practice retrieving your backup files to make sure you can recover them in the event of a cyberattack.
  • Create and enforce corporate policies for systems or areas that hold personally identifiable information (PII) and other sensitive data. Because bad actors may target this information, help protect it with added security controls.
  • Add extra layers of protection for critical data. Implement physical security, download offline copies of backups, and enable encryption. In the event of a ransomware or destructive malware attack, these backups can help maintain business continuity.
  • Review and update your cyber liability insurance policy. In the event of a breach or attack, this policy can help cover financial losses. Assess whether your current policy provides the first- and third-party coverage your organization needs, based on your technology infrastructure and susceptibility to cyberattacks. If not, consider making it a priority to upgrade your policy.
  • Implement Shadow AI detection. Use a multi-layered approach that combines visibility, policy enforcement, and technical controls to manage unauthorized use of AI tools, or Shadow AI, in your organization.

Manage vulnerabilities

  • Conduct an annual assessment of vulnerabilities in your IT environment. Set a regular cadence to audit your security posture and implement standards to ensure vulnerabilities are addressed.
  • Enforce security controls for remote workers. Require employees working from home to use a virtual private network (VPN) and secured home router. Remind them to keep work and personal devices separate to help keep sensitive data and networks safe.
  • Keep all operating systems and applications updated with the latest security patches. Staying current on versions and patches can help prevent bad actors from exploiting vulnerabilities. Scanning tools can assist with identifying vulnerabilities and deploying patches across networks, endpoints, databases, and equipment.
  • Ensure your organization’s antivirus, malware protection, and email security software are active and up to date. These detective and preventative measures allow your organization to help prevent bad actors from exploiting vulnerabilities or gaining access to sensitive data or systems.
    • Use a firewall to protect the enterprise network.
    • Enable a security incident and event management (SIEM) system to collect data and help your team better detect and respond to incidents.
    • Consider investing in a managed security services provider (MSSP) for continuous monitoring.
  • Consider subscribing to CISA’s Known Exploited Vulnerabilities Catalog. The Cybersecurity & Infrastructure Security Agency (CISA) maintains an ongoing record of known vulnerabilities. Make sure your security team subscribes to this catalog and uses it to prioritize vulnerability management.

Implement measures to help protect against common cyber threats

  • Employ identity and access management (IAM) policies. Your organization’s policies should include multifactor authentication (MFA) for all users, privileged access management, and single sign-on capability. These precautions can help mitigate insider threat risks.
  • Implement role-based access control (RBAC) and restrict third-party access. Limit access to essential functions for employees and third-party entities to help protect your network, infrastructure, and data.
  • Reduce or eliminate vulnerable connection methods into your network. These vulnerabilities, including Server Message Block or Remote Desktop Protocol, can give bad actors an entry point to deploy ransomware.
  • Require permission for USB or remote drive access. This helps protect against insiders copying sensitive data onto a remote drive or device.
  • Control physical access to computers and network components. Technology devices, such as tablets or laptops, are common targets for theft. Review your corporate asset inventory and implement measures to prevent unauthorized access.
  • Train employees to look for BIMI in their email provider. Brand Indicators for Message Identification (BIMI) is an email specification that displays brand-controlled logos next to emails as an added defense against business email compromise. For example, a validated email from Huntington appears with a honeycomb icon to verify it’s from a trusted source.
  • Add an external email banner. This banner, which appears at the top of emails from an external sender, helps draw attention to the fact that it isn’t from someone within the company. Seeing the banner alerts employees to stay vigilant against an email phishing scam.
  • Assess your website and social media to determine whether they share too much information. Bad actors can use this public information to gain knowledge about a company and wield it through a social engineering attack to con employees into giving away access to secure data.

Develop and deepen a strong security culture

  • Implement a year-round cybersecurity education program for employees. Your organization’s security program should include awareness, training, and outreach. Every member of your company should know their role in cybersecurity, regardless of their position.
  • Regularly communicate about common threats and how to guard against them. Examples include how to identify and report a suspicious email, or when to verify an email sender’s identity via phone or another communication method.
  • Educate employees about cybersecurity best practices. Employee education is one of the simplest ways to build a culture that prioritizes cybersecurity. Here are a few basic reminders to help keep employees vigilant:
    • Use strong passwords unique to each account. A password manager can help with this.
    • Never click suspicious links or open unknown attachments.
    • Lock devices when not in use.
    • Pay attention to email details, such as whether it is from an external source or includes brand indicators for message identification (BIMI).
  • Set up multiple channels for employees to report suspicious behavior or incidents. Your employees should feel safe reporting incidents, even if they caused them. Allowing employees to report anonymously might empower some to speak up when they otherwise wouldn’t.
  • Make it easy for employees to find your cybersecurity team’s contact information. Consider adding the security team’s email and phone number to your intranet home page, and encourage employees to reach out with questions or concerns.

Strengthen your organization’s cybersecurity defenses

Cyberattacks remain an ongoing threat to businesses across every industry, and a successful data breach or attack can carry far-reaching financial and reputational consequences. Preventative measures like those included in this checklist can help keep your organization safe and secure.

Download our business security checklist for a practical guide to staying ahead of fraud and enhancing payment security.

Huntington is committed to connecting you with the insights, resources, and expertise you need to grow and protect your organization. To learn more, start the conversation with your relationship manager.

Featured insights with industry expertise

Tap into insights designed to help you navigate today’s decisions and tomorrow’s opportunities.

Business Cyber Resilience

Midyear cybersecurity and fraud threat report

This year’s report highlights top trends threatening organizations and covers six key prevention strategies to help reduce risk.

Business Cyber Resilience

How to build a business resiliency plan for your company

Weather-related disasters and cybersecurity attacks can cause disastrous disruptions to your business. Learn the five-pillar framework for business continuity and resiliency.

Business Cyber Resilience

Understanding business email compromise (BEC): A guide to help protect your organization

Business Email Compromise (BEC) scams can be surprisingly convincing. A quick pause to verify unexpected requests can make a difference in preventing fraud.

The information provided in this document is intended solely for general informational purposes and is provided with the understanding that neither Huntington, its affiliates nor any other party is engaging in rendering financial, legal, technical or other professional advice or services, or endorsing any third-party product or service. Any use of this information should be done only in consultation with a qualified and licensed professional who can take into account all relevant factors and desired outcomes in the context of the facts surrounding your particular circumstances. The information in this document was developed with reasonable care and attention. However, it is possible that some of the information is incomplete, incorrect, or inapplicable to particular circumstances or conditions. NEITHER HUNTINGTON NOR ITS AFFILIATES SHALL HAVE LIABILITY FOR ANY DAMAGES, LOSSES, COSTS OR EXPENSES (DIRECT, CONSEQUENTIAL, SPECIAL, INDIRECT OR OTHERWISE) RESULTING FROM USING, RELYING ON OR ACTING UPON INFORMATION IN THIS DOCUMENT EVEN IF HUNTINGTON AND/OR ITS AFFILIATES HAVE BEEN ADVISED OF OR FORESEEN THE POSSIBILITY OF SUCH DAMAGES, LOSSES, COSTS OR EXPENSES.

Third-party product, service and business names are trademarks/service marks of their respective owners.