As the current level of staff turnover remains high across most industries, we thought it would be a good idea to look at how you can continue to protect your clients and your business reputation by carrying out some basic steps. This is not about GDPR – by now most agents are fully aware of their responsibilities as far as Data Protection is concerned - this is about having some basic procedures in place to protect your business.
Therefore, in no particular order, here are 5 things you should have baked into your business:
As an owner, you need to set the right tone from the start.
It may seem over-the-top but, as tempting as it is to allow staff to use one of their colleagues’ usernames and passwords, it sets a very bad precedent. If it’s OK to use someone else’s credentials to edit a mobile number, maybe it’s OK to do the same for bank account details?
By letting staff share login details you immediately lose sight of who’s doing what on your systems and open the potential for landlord and tenant details to be copied or in the worst case used to carry out identity theft.
TIP
Regular password updating - Fix a regular date in the calendar (maybe the first day of every quarter) so people get into the habit of doing it cyclically.
Research shows* that at least 82% of cyber security attacks have been caused by human error, particularly through phishing scams. For example, cybercriminals pretending to be from a business’s IT department will get an employee to hand over all sorts of security information under the pretext of fixing an error on their pc. Another phishing method is to send an email from what looks like a reputable or recognised company to trick the recipient into installing malware by clicking on a malicious link or opening an unknown attachment. Examples include emails with quotes attached or with a link to an unknown website, etc.
Ultimately the most valuable defence against phishing and other cyber-attacks that prey on human error is training. Make sure your staff are aware of the dangers and who to contact if they have any doubts about a caller or an email.
Providing regular training opportunities in general is also a good way to show that you are interested in your employee's future, and therefore reduce the likelyhood of them wanting to leave.
Human error is unavoidable, but there’s no excuse for bad processes or a lack of contingency plans. No individual should have more control than they need over certain areas of your business records. Always have at least a basic backup plan in case someone is unavailable or decides to leave.
[* source: 2022 Verizon Data Breach Investigations Report]
* * *
Sign-up for our monthly Newsletter for helpful articles and regular industry updates. We promise not to spam you with hundreds of emails and you can unsubscribe at any time.