top of page

Issue - May/June 2025

The Growing Threat of Cyber Intrusion in Our Industry—and How to Prevent It

By Philip Gordon, Director, Conroy Removals

Our industry is a prime target for cyber intrusion. The very nature of our business—where rapid access to data is essential—has made us particularly vulnerable to cybercriminals. These attackers understand that companies in our field are often more inclined to pay ransoms quickly rather than hold out and risk operational delays.


However, the biggest cyber threat does not always come from sophisticated hackers working in the shadows. Often, the greatest risk comes from within our own organizations. Employees, accustomed to quickly responding to emails from partners worldwide, can unknowingly become the entry point for a cyber-attack. When a seemingly legitimate email arrives from an overseas associate, the instinct is to trust it. Yet, if that sender’s system has been compromised or infected with malware, opening the email or clicking a link could jeopardize your entire environment.


The Importance of Proactive Cybersecurity Measures

Cybersecurity must be approached proactively rather than reactively. By the time an attack occurs, the damage is often already done. Organizations must implement multi-layered security measures to prevent threats before they infiltrate the system.


1. Strengthening Firewall and IT Security

An active and strong firewall is critical for filtering out malicious content before it reaches employees. Additionally, keeping all systems up-to-date is essential. Your IT department or provider should continuously apply patches, security updates, and firmware upgrades to safeguard against newly-emerging vulnerabilities.


2. Employee Training and Awareness

One of the most effective ways to mitigate internal risks is through continuous training and awareness programs. Employees should undergo regular phishing tests and spoofing simulations to assess their ability to recognize suspicious emails. Those who frequently fall for phishing attempts should receive additional targeted training.


3. Implementing Multi-Factor Authentication (MFA)

Controlling access points is fundamental to cybersecurity. Multi-Factor Authentication (MFA) should be mandatory for all logins, requiring employees to complete two-step verification before accessing systems. This reduces the likelihood of successful intrusions, even if a password is compromised.


Additionally, all company devices must be managed by IT. Employees logging in from personal devices outside the organization’s control pose a major security risk, as these devices may already be infected with malware or be used for unauthorized purposes.


Cybersecurity Is Not a ‘Set and Forget’ Strategy

Cybersecurity is an ongoing effort. Threat actors continuously evolve their tactics, meaning businesses must stay vigilant and adapt their strategies. Regular audits, security assessments, and penetration testing should be conducted to identify weaknesses before cybercriminals exploit them.


4. Managing Access Control for Users and IT Providers

Organizations must actively manage user lists to prevent unauthorized access. Former employees should immediately have their credentials revoked, ensuring no lingering access rights exist after their departure.


For third-party IT providers with deep access to critical systems, additional security measures are necessary. MFA should be mandatory, and in some cases, access should only be enabled when required rather than remaining permanently open.


5. Limiting the Exchange of Sensitive Data

Data sharing is an integral part of modern business operations, but companies must ask: “What data is actually necessary?” Too often, inventory or transactional documents contain excessive personal information when only basic identifiers, such as a customer name and reference number, are sufficient.


Privacy laws in many countries impose strict regulations around data protection, and businesses must adhere to them—not just for compliance but to safeguard customer trust.


6. Avoid Storing Payment Information

Under no circumstance should businesses store sensitive payment information such as credit card details on their internal systems. While it may seem convenient to retain this data for recurring transactions, it poses a serious security risk.


Instead, companies should work directly with financial institutions to handle secure transactions. Additionally, employees must be trained to avoid recording payment details manually—for instance, when processing payments over the phone, data should be entered directly into a secure banking portal without being written down.


Building a Robust Incident Response Plan

Despite taking preventive measures, businesses must be prepared for worst-case scenarios. A detailed incident response plan ensures swift action in the event of a breach.


7. Establishing an IT Continuity Plan

Cyberattacks often go unnoticed for days or even weeks before companies realize they’ve been compromised. The longer a breach remains undiscovered, the greater the damage. Clear protocols must be outlined regarding:

  • Who is responsible for taking immediate action,

  • How communications will be handled internally and externally, and

  • Steps to mitigate further damage and recover operations.


A well-prepared response plan ensures businesses do not scramble to react when an attack occurs.


The Risks of Paying Cyber Ransoms

Some industry professionals advocate for cyber ransom insurance as a safeguard against hacking incidents. However, paying a ransom can be more dangerous than refusing to do so. Many governments are moving toward making ransom payments illegal, as paying attackers often guarantees future attacks. Once a hacker successfully breaches a system and receives payment, they frequently implant backdoor access for repeat exploitation.


Final Thoughts: Strengthening Cyber Resilience

Many businesses in the mobility space are behind the curve on cybersecurity—but that must change. Cyber threats are not going away, and the best defense is prevention. By investing in robust security measures, continuously training employees, and implementing strict access controls, organizations can significantly reduce their vulnerability.


Cybersecurity is not a one-time effort—it is a continuous commitment to staying ahead of ever-evolving threats. Companies that recognize this will not only protect their own assets but also earn the trust of customers and business partners in an increasingly digital world.

Defending Your Data
bottom of page