The turn of the year doesn’t bring a halt to cybersecurity challenges. Common threats like phishing, ransomware, data breaches, and shadow IT remain prevalent. It’s an opportune moment to prioritize cybersecurity enhancements among your New Year resolutions, alongside personal goals like more exercise and healthy eating.

Enhance account security

The likelihood of a significant account breach occurring early in the year is high. It’s crucial to ensure that your team’s online accounts are secure. IBM’s report shows that the rate of system intrusions has seen a significant increase, escalating from 15% in 2019 to 30% in the current year. In terms of breaches caused by organized crime, there’s been a rise from 51% in 2020 to 82% as reported now. Comparatively, breaches impacting availability stood at just 7% in 2019, in contrast to the current rate of 13%. Notably, the method of discovering breaches through actor disclosure has surged from 6% in 2019 to 62% in the latest report. It’s important to highlight that these trends are largely attributed to ransomware attacks. Given its high profitability and low risk, ransomware remains a favored tactic among criminals. Additionally, it’s crucial to acknowledge the persistent issue of DoS attacks in this sector. Accounting for 58% of security incidents, these attacks are roughly double in frequency compared to other industries.

This means updating all critical passwords to be complex and unique, storing them in a password manager, and enabling robust Multi-Factor Authentication, preferably with an authenticator app or hardware token, for all vital business accounts.

Audit your online presence

Anything that’s online is vulnerable to attacks. Regular audits of your online assets, including websites, systems, and servers, are vital, especially for businesses with extensive technical infrastructure. Understanding your actual online footprint, as opposed to what you assume it to be, is key to maintaining security. Stay tuned for potential solutions to help with this task later in the year.

Review your email setup

Once your accounts are secure and you’ve assessed your online exposure, the next step is to examine your email configuration. Incorrect SPF, DKIM, and DMARC settings can lead to email spoofing or delivery issues. Tightening your email configuration is a significant step in protecting against phishing, a common component of ransomware attacks.

Assess your cybersecurity maturity

Investing in cybersecurity warrants visible progress. One way to track this is through a cybersecurity maturity assessment. These assessments can vary in complexity and resource requirements. For a DIY approach, consider the NIST framework, which evaluates the maturity of five cybersecurity activities (identify, protect, detect, respond, recover) across four levels (partial, risk-informed, repeatable, adaptive).

Evaluate cybersecurity spending

As the financial year end approaches, reassess your cybersecurity product investments. Consider the real business benefits, effectiveness, and impact measurement of these products. This review can inform budget planning for the upcoming financial year and any adjustments to your cybersecurity strategy.

Tackle overlooked security issues

Many established businesses have lingering cybersecurity or IT issues that have been overlooked. Whether it’s upgrading outdated systems, removing dormant accounts, or enforcing necessary but challenging policies, the new year is an ideal time to address these issues.

Embarking on these resolutions can significantly enhance your organization’s cybersecurity posture, ensuring a safer and more secure operational environment.


Remember that navigating the ever-evolving landscape of cybersecurity requires a proactive and comprehensive approach. The challenges of safeguarding your digital assets against threats like phishing, ransomware, and data breaches are ongoing and demand constant vigilance and adaptation. From strengthening account security to evaluating your cybersecurity spending and maturity, each resolution plays a pivotal role in fortifying your organization’s defenses against cyber threats.

