Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Cyber Criminals Are Turning To The Weakest Link: SMEs
Articles

Cyber Criminals Are Turning To The Weakest Link: SMEs

ISBuzz TeamBy ISBuzz TeamJuly 7, 2016Updated:July 5, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Chris Dye1Small to medium-sized companies now make up 99.3 per cent of the UK’s private sector business, contributing an astounding £1.6 trillion to the national economy every year.[1] With this in mind, it should come as no surprise that hackers are increasingly turning to SMEs to fuel their criminal operations.

This unwanted attention isn’t being attracted solely by profitability; SMEs are also considered much easier targets than their larger counterparts. Though 82 per cent of companies believe they are too small to be considered a worthwhile target for cyber criminals, this couldn’t be further from the truth.

In 2014 alone, 92 per cent of attacks were carried out against SMEs.[2]  The average year sees seven million attacks launched against smaller firms, costing the UK economy an average of £5.26 billion, according to the Federation of Small Businesses.[3] As attacks against SMEs become more common, they are also becoming more costly; a survey recently published by Digital Economy Minister Ed Vaizey found that the cost of a cyber attack in 2015 could be as high as £310,800, up from £115,000 in 2014.[4]

While some SMEs (approximately 23 per cent) have caught on to the potential risk posed by cybercrime, too many are still relying on outdated technology that only provides perimeter security, completely ignoring file-based threats. As these sorts of attacks make conventional security methods utterly useless, an increasing number of hackers are seeing them as their most valuable tool. According to a survey by the Institute of Directors, nine out of ten business leaders believe that cyber security is important whilst only half had a formal strategy in place to actually protect themselves from threats.[5]

File-based threats

File-based attacks involve the use of malicious code, hidden within common file types and launched via email messages. The potential of a file-based threat is only constrained by the ingenuity of the hacker, and history has shown, time and again, the catastrophic effect these corrupted files can bring when they gain access to an enterprise’s systems.

The few SMEs who have woken up to the threat of cybercrime still stand little chance against these file-based threats. Many companies are still relying on costly perimeter security solutions, such as firewalls and email scanning, which are only effective against widely-known threats. Furthermore, these defences rely on incremental updates to remain effective against attacks, though they are often one step behind the hackers.

File-based attacks are responsible for 94 per cent of breaches across all businesses, and this figure continues to grow each year [6]. As a result, many businesses are losing faith in their current security solutions, as well as supposed “new solutions” such as sandboxing, and moving towards more innovative approaches.

Social engineering

The most well-trodden route into a company’s systems is through their own employees. By using well-practiced social engineering methods, hackers can turn an organisation’s own staff into unwitting accomplices. Alarmingly, 88 per cent of breaches include the use of social engineering.

Ammunition for these types of operations is shockingly easy to acquire. Cyber criminals will typically find this information from a number of sources, such as files from the company’s official website that have not been cleaned or files that have been intercepted during exchange. This information can be used to identify user IDs, server paths, software versions and even employee reference data.

With this information on hand, it’s relatively simple for a hacker to forge a convincing email to an employee, posing as a trusted contact and duping the employee into opening a link designed to send a zero day exploit, to be activated at a later date, straight into the company’s system. With this in mind, it is vital that companies keep this information out of the wrong hands, ensuring any data leakage is prevented.

The urgency of cybersecurity

With the European General Data Protection Regulation (GDPR) set to come into effect next year, preventing file-based attacks is more urgent than ever for businesses with operations in the EU. The new law will impose increased penalties and fines to businesses which fail to protect data adequately, or are subject to a breach.

Minimum fines will be set at two per cent of global turnover, with maximum fines reaching four per cent. In addition to stiffer fines, the new regulation will also include a provision for disclosure, in the name of public interest, which will likely lead to many cybercrime victims losing additional revenue as their customers lose faith in their ability to protect their personal information.

Although the GDPR gives some leeway to SMEs deemed to pose a smaller risk to the privacy of citizens, even “one-man bands” will be expected to be fully compliant with the regulations. They must manage their data just as closely as their larger counterparts, avoid introducing unnecessary privacy risks and consider the risks their business practices pose to the privacy of their customers.

To ensure they can live up to the upcoming regulations, SMEs must turn towards a solution based on file-regeneration, one that guarantees total security and full protection against the most common form of cyber threat and can do so without compromising the speed and efficiency that businesses require in order to deliver their clients and customers a competitive service.

SMEs would be wise to adopt Managed Service Solutions; one which is adapted specifically for smaller businesses and takes into account the growing threat posed by file-based attacks. These solutions allow SMEs to achieve full protection from threats in a cost-effective manner, and place the burden of risk on the shoulders of a third-party.

With both the GDPR and cybercriminals casting their eyes on SMEs, it is more urgent than ever for these enterprises to look beyond conventional perimeter security measures and adopt a proven security solution that can protect them from the most common and volatile attacks.

[1]https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/467443/bpe_2015_statistical_release.pdf

[2] https://www.theguardian.com/small-business-network/2016/feb/08/huge-rise-hack-attacks-cyber-criminals-target-small-businesses

[3]

[4] Government urges business to take action as cost of cyber security breaches double

[5]

[6] http://www.professionalsecurity.co.uk/products/computer-systems-and-it-security-news/changing-face-of-cybercrime/

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}