What Does a Cybersecurity Consultant Do? with Martin Cadwallader

What Do You Do? podcast

Martin Cadwallader | Cybersecurity Consultant | LawFinity

The thing that I find about any kind of IT support, is that when everything is working correctly, you don’t notice it’s there. You start to think that you don’t need it. Cybersecurity is similar. It may not look like it’s doing anything, but it’s the only thing standing between losing confidential customer data, and ultimately money.

As we discover in this episode, being complacent about cybersecurity can be catastrophic for your business.

youtube placeholder image

Key Takeaways

  • Nowadays, a cyber attack is very unlikely to be caused by a virus. It’s far more likely to be caused by a phishing scam.
  • With cybersecurity, your people are your greatest strength and greatest weakness. Keeping them educated is key to safety.
  • Reusing your password across multiple accounts can make it far more easier to get hacked, as if any of those accounts become vulnerable, they all do.

The Role of a Cybersecurity Consultant

The Road to Good Cybersecurity

When asked about what his job entails, my guest Martin describes it as finding out where an organisation is with their cybersecurity, and finding out where they want to go. This looks different for every organisation, as they all have different needs. For example, a bakery shouldn’t need as much security as a legal firm.

To do this, he starts with a cybersecurity audit. One thing that Martin emphasises in this episode is that a lot of cybersecurity companies offer free audits, so the barrier to understanding your organisation’s security is low. He suggests getting multiple audits from different companies to get a complete picture.

During the episode, Martin revealed the results of my cybersecurity mini-audit, and for an organisation this size, we did really well. What he revealed that was more shocking was that he’d worked with organisations far larger, and holding far more sensitive data than me, who’d performed far worse.

Imagine having a user account with that company. One company with poor cybersecurity could threaten every one of your other accounts.

Complacency is the Enemy of Good Cybersecurity

As we discuss in the episode, the biggest hurdle to being secure is user complacency. “I’m too small an organisation, I won’t be targeted.” “I don’t need to train my staff to watch out for phishing scams.” “I’ll use the same password over and over again.” And I can go on.

The size of the organisation doesn’t matter – criminals target the vulnerable, and whoever they can get the most money from for the least risk and effort.

Training staff is vital. One click of the wrong link can bring an entire organisation down, regardless of the size.

Reusing a password greatly increases your risk of exposure. If just one of your online accounts is hacked, it leaves all of the other vulnerable.

Every day, cybersecurity threats become a little bit more advanced and dangerous. As Martin describes in the podcast, it’s difficult to not feel ‘doom and gloom’ about it, and it can seem daunting to know what to do. Getting good cybersecurity isn’t difficult though – it’s just appreciating that you need it and taking the right actions.