It’s easy to think because you have a small to medium-size business (SMB), cybercriminals will pass over attacking your company. The “we don't have much to steal” mindset is common with SMB owners when it comes to cyber security, but think again.
In reality, a number of studies have found that more than 50% of cyber-attacks happened at businesses with less than 100 employees. Even more concerning, the Ponemon Institute, the State of SMB Cybersecurity Report involved more than 1,000 IT professionals and found that 54% of respondents said negligent employees were the root cause of a data breach. The same survey found that Ransomware is hitting SMBs hard with more than 50% experiencing an attack with attacks becoming costlier to businesses with damage now over €1M.
But why are SMB attacked more often than larger businesses? Almost all cyber-attacks are to obtain personal data to use in credit card or identify theft. While larger enterprises typically have more data to steal, small businesses have less secure networks, making it easier to breach the network. CSO.com by IDG’s article “Why criminals pick on small businesses” says that by using automated attacks, cybercriminals can breach thousands or more small businesses, making the size less of an issue than the network security.
With the introduction of the GDPR forcing small business to focus more on Cyber Security. How does your business avoid being a victim of a cyber-attack? Here are 8 best practices for SMB cyber security:
1. Use a firewall
One of the first lines of defense in a cyber-attack is a firewall. We recommend that all SMBs set up a firewall to provide a barrier between your data and cybercriminals. In addition to the standard external firewall, many companies are starting to install internal firewalls to provide additional protection. It’s also important that employees working from home install a firewall on their home network as well. Consider providing firewall software and support for home networks to ensure compliance.
2. Document your cybersecurity policies
While small businesses often operate by word of mouth and intuitional knowledge, cyber security is one area where it is essential to document your protocols. The National Cyber Security Centre (GCHQ) portal provides more information specifically to protect online businesses.
3. Plan for mobile devices
With studies reporting more than 60% percent of businesses currently allowing BYOD, it is essential that companies have a documented BYOD policy that focuses on security precautions. With increasing popularity of wearables, such as smart watches and fitness trackers with wireless capability, it is essential to include these devices in a policy. Norton by Symantec also recommends that small businesses require employees to set up automatic security updates and require that the company’s password policy apply to all mobile devices accessing the network.
4. Educate all employees
Employees often wear many hats at SMBs, making it essential that all employees accessing the network be trained on your company’s network security policies.
Since the policies are evolving as cybercriminals become savvier, it’s essential to have regular updates on new protocols. To hold employees accountable, have each employee sign a document stating that they have been informed of the policies and understand that actions may be taken if they do not follow security policies.
5, Enforce safe password practices
Yes, employees find changing passwords to be a pain. However, the Verizon 2017 Data Breach Investigations Report found that 63 percent of data breaches happened due to lost, stolen or weak passwords. In today’s BYOD world, it’s essential that all employee devices accessing the company network be password protected.
6. Regularly back up all data
While it’s important to prevent as many attacks as possible, it is still possible to be breached regardless of your precautions. We recommend backing up word processing documents, electronic spreadsheets, databases, financial files, human resources files, and accounts receivable/payable files. Be sure to also back up all data stored on the cloud. Make sure that backups are stored in a separate location in case of fire or flood. To ensure that you will have the latest backup if you ever need it, check your backup regularly to ensure that it is functioning correctly.
7. Install anti-malware software
It’s easy to assume that your employees know to never open phishing emails. However, the Verizon Data Breach Investigations Report found that 30 percent of employees opened phishing emails. Since phishing attacks involve installing malware on the employee’s computer when the link is clicked, it’s essential to have anti-malware software installed on all devices and the network. Since phishing attacks often target specific SMB employee roles, use the position-specific tactics outlined in the Entreprenuer.com article “5 Types of Employees Often Targeted by Phishing Attacks” as part of your training.
8. Use multifactor identification
Regardless of your preparation, an employee will likely make a security mistake that can compromise your data. In the PC Week article “10 Cyber Security Steps Your Small Business Should Take Right Now,” Darren Craig CEO of RiskXchange says using the multi-factor identification settings on most major network and email products is simple to do and provides an extra layer of protection. He recommends using employees’ cell numbers as a second form, since it is unlikely a thief will have both the PIN and the password.
Security is a moving target. The cyber criminals get more advanced every day. In order to protect your data as much as possible, it’s essential that each and every employee make cyber security a top priority. And most importantly, that you stay on top of the latest trends for attacks and newest prevention technology. Your business depends on it. See our other post Must have Security Blogs to add to your List.