The 8 Scariest Cyber Security Mistakes

Just in time for Halloween, comes our list of the scariest cyber security mistakes. It’s enough to give any business owner nightmares!

Making cyber security mistakes can have serious consequences for businesses of any size. Data breaches can bring large fines from ICO, then there’s the time and money lost in dealing with the results and aftermath of a cyber-attack, loss of highly sensitive company and client data, and potentially, damage to the company’s reputation. Some companies have even gone out of business directly as a consequence of suffering a cyber-attack, because they just didn’t have the right recovery plan in place.

Unfortunately, computer users make security mistakes all the time and hackers are poised, ready to take advantage of that.

The 8 scariest cyber security mistakes we see are:

1. Not updating your software

Software manufacturers put out updates and patches regularly to fix bugs, add new features and functions and, of course, to close security vulnerabilities that hackers can exploit.

If companies don’t have an up-to-date IT policy and systems in place for automatic software updates and patches, these vulnerabilities can be left unpatched, leaving the software open to known exploits and other vulnerabilities. Hackers can use these areas of weakness in the software to break into an IT system and perform any number of malicious actions, including causing damage just for fun, getting into sensitive company data, locking or corrupting files, and searching further into the system for other vulnerabilities to exploit.

 

2. Weak and easily guessable passwords

In 2023, the most used password is still “password,” according to NordPass’s list of 200 common passwords, as covered by TechRadar.

So many people still use easy-to-guess passwords, such as “password123” or “12345678”. We get it. Passwords are needed for so many different things and people want to be able to easily remember them. But this just makes it easy for cyber criminals to break into business IT systems and wreak havoc that, as we’ve seen above, can have expensive and devastating consequences.

It’s important for every company to have an established passwords policy and to ensure that only strong passwords can be used on their systems. In addition, make sure you have multiple passwords for your various accounts and change them or at least try out new variations every six months or so.

3. Falling for phishing scams

Luckily, most of us know better now than to give our money away to a Nigerian prince online, but that doesn’t mean that phishing scams have gone away. Cyber criminals still try to send emails that look like suppliers, clients, or banks that businesses use.

There are scams with fake invoices in them that look like they are from real suppliers and so many businesses don’t check and just pay the invoice. Whaling is another version of phishing where cyber criminals will specifically target just one high up member of a company, do deep research on them to learn enough about them, and then send them a carefully targeted email that they think will work. And if the “whale” falls for it, they’ve just let cyber criminals into their business systems.

Most email systems have spam filters to catch phishing emails, but even so, look out for obvious fakes, check logos, look at grammar, and always check the sender’s actual email address, not just what’s displayed. Always make sure it’s a trusted contact before clicking on any link you receive over email.

4. Not using two-factor authentication

Two-factor authentication adds another layer of protection when logging in to sensitive sites, software, and systems. Banks are increasingly adding ways to double and even triple verify that we are who we say we are before we can get into our online banking, and this kind of protection can work for your business too. But not if you don’t use it!

5. Clicking on questionable links

As well as suspicious links in emails, it’sa good idea to watch what you’re clicking on online. Click on the wrong link, and you might be taken to what looks like a reputable site. But, make a payment on that and yourmoney’s gone.

Sometimes even just clicking on a link is enough to download malware or spyware onto your business systems, giving away all sorts of sensitive client and financial information.

Double-check every link you are sent, watch where you’re going online, and for preference, directly type in the genuine URL of the site you want.

6. Not backing up data

Anybody can make a mistake and accidentally delete a file, and while there are sometimes things IT can do to recover it, it’s far better if your company has a regular, quality backup system in place. This ensures all your data is protected, both from the occasional accidental deletion, but also from any damage done by cyber attackers.

Without backups, it may be impossible to recover lost data, and this also increases the risk of data breaches.

7. Not training employees on cyber security best practices

Your employees are often considered the weakest link in an organisation’s cybersecurity defences, as cyber criminals can easily trick or manipulate them using phishing or social engineering tactics.

However, that’s only the case if they haven’t completed cyber security training. Employees need to know why security measures are so important, and how they can recognise phishing and scam emails. And they need to know what they should do immediately if they think they’ve been hacked or phished.

Without this knowledge, it’s far more likely that your own employees could be the ones to put your company’s data and systems at risk.

8. Not monitoring for security breaches regularly

Professional cyber security systems can regularly monitor for cyber-attacks and attempted security breaches and stop them before they start. Phishing emails and spam can be filtered out before they reach employees’ inboxes. There are so many preventative measures that can be taken to help keep your company safe.

Regular monitoring allows you to identify potential threats and attacks as soon as possible, so you can either prevent an attack or at least minimise the damage.

If our dark tale of cyber horrors really has given you a case of the heebie-jeebies, get in touch with us today to discuss how we can help protect your company from cyber-attacks and keep your data safe.

Then you can relax with a hot cup of tea and a nice slice of parkin. Don’t have nightmares, do sleep well.

Mira Valjakka

About the author

Mira is the Head of Marketing at Forge Technologies, with over 15 years of experience in the tech industry. She is dedicated to writing insightful articles and creating content that demystifies the complexities of managed services. Mira thrives on crafting marketing strategies that inspire connections between people and the tech that shapes their world.

Related Articles

Building Resilience Across the UK Financial System: The Rise of Critical Third-Party Oversight

From 13 July 2026, UK financial regulators have taken a significant step to strengthen the resilience...

Community Innovation Becomes Industry Standard: The Next Chapter for Azure Landing Zones

Microsoft has announced that Azure Landing Zones (ALZ) will move from a community-led initiative into...

Elevating Endpoint Management with Microsoft Intune

From 1 July 2026, Microsoft has expanded Intune capabilities within Microsoft 365 E3 and E5 licences....

How can we help?

Considering a particular technology?
Got a question for our team?
Please get in touch, we’re here to help.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.