Leveraging Technology to Succeed in Business View web version

Hackers don't care whether your annual revenue is in five figures or nine. They will target you. Indeed, if you're on the smaller size, you're more likely to be vulnerable because, chances are, you're an easier target. After all, as BullGuard CEO Paul Lipman said: "Small businesses are not immune to cyberattacks and data breaches and are often targeted specifically because they often fail to prioritize security."

A 2020 study by BullGuard, a cybersecurity company focused on the consumer and small business markets, found a third of companies with 50 or fewer employees report using free, consumer-grade cybersecurity. That's okay as far it goes. For example, Microsoft Defender Antivirus, formerly Windows Defender, is, by the AV-TEST Institute's tests, a reasonably good anti-virus and malware-detection program. And, of course, it comes baked in and free in any still supported version of Windows. (Though if you're still running Windows 7 or XP, you've got more security problems than any anti-virus program can help you with.)

But — and this is a killer — BullGuard also found one in five companies use no endpoint security whatsoever. I repeat no endpoint security. Tell me: Do you like playing Russian roulette with your company's security?

Worse still, BullGuard also discovered that 43% of SMB owners have no cybersecurity defense plan in place at all. They're relying on each user to do their best — like activating Microsoft Defender — to protect their PCs. These, mind you, are often the same people who use "password" for their password.

It gets better (or worse). While nearly 60% of SMB owners believe their business is unlikely to be targeted by cybercrooks, about 18.5% of SMB owners have suffered from a cyberattack or data breach within the past year. That tallies with my own experience.

For example, I've never been cracked, knock on wood, but then I do lock down my systems like they're Fort Knox. I assume that I'm constantly under attack. I am. Every. Single. Day. For example, my website, Practical Technology, is a simple WordPress site I run off one of my own servers. All it does is contain an archive of my older stories. That's it. I don't update its content anywhere often enough and you can't even post comments to it.

Care to guess how many times in the last week someone tried to hack in?

Go ahead, guess.

According to Wordfence, an excellent WordPress all-in-one security program that I highly recommend, I've had 1,551 attacks this week. So far.

Why would anyone do this? Because no one has to actually "target" me. Botnet networks do nothing all day but automatically scan the Internet looking for vulnerable targets. Have a popular network socket open on your firewall? Run WordPress, which now powers almost 40% of the web? Or, just run Windows? Whether you know it or not, you're being attacked every day.

That's not even counting all the malware hiding in the erectile dysfunction and other spam emails hitting your mailbox over and over. That's not even counting spear-phishing, where someone has bothered to target individuals in your company. That, too, is easier to do than you might think.

Are you on Facebook? LinkedIn? If you are — and who isn't on one social network or the other? — there's enough information online for someone to whip up a message tempting you to download a malicious file or go to a poisoned web page that looks like a message from someone you might know or want to do business with.

So, what can you do about this? A lot. I'll be going into some details in the weeks ahead. But, for now, let's just go over the bare bones of defending yourself.

First, someone needs to keep an eye on security. You may not need a full-time security person on staff, but someone has to make sure that everyone's using an updated anti-virus program. That same tech-support person must also make sure backups are being made — and that they actually are backing up your valuable files. Ransomware, where someone encrypts your data and demands you pay up for your customer data, doesn't hurt as much when you can just restore your files.

There's a lot more of course. There's a reason why computer security is an industry in itself. But, if you just do that much, you'll still be ahead of the game.

5 simple steps for SMBs to ensure cyber resiliency

While these tips are by no means a complete guide for how SMBs can be resilient, they can be the start of a continuous process small and mid-sized business should implement to be better prepared. Read more.

 

The password hall of shame (and 10 tips for better password security)

Banish these common passwords now and employ these tips for better password security. Read more.

 

14 real-world phishing examples — and how to recognize them

Even though computer users are getting smarter, and the anti-phishing tools they use as protection are more accurate than ever, the scammers are still succeeding. Read more.

 

15 signs you've been hacked—and how to fight back

In today's threatscape, antimalware software provides little peace of mind. In fact, antimalware scanners are horrifically inaccurate, especially with exploits less than 24 hours old. Read more.

 

Social engineering explained: How criminals exploit human behavior

Social engineering is the art of exploiting human psychology, rather than technical hacking techniques, to gain access to buildings, systems or data. Train yourself to spot the signs. Read more.

 
 

About the Author
Steven J. Vaughan-Nichols, aka sjvn, has been writing about the intersection of business and technology for over 30 years. He continues to scoop up awards for his valuable insights and practical guidance in highly technical publications, business & technology magazines, and mainstream newspapers.
 

Linkedin Facebook Twitter YouTube
Privacy Policy | Manage Your Subscriptions | Unsubscribe
Advertise with us | More Newsletters | Our Brands
©2021 IDG Communications, Inc.
140 Kendrick Street
Building B
Needham, MA 02494