Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Study & Research - David vs Goliath – How Small Businesses Can Battle Cybercriminals
Study & Research

David vs Goliath – How Small Businesses Can Battle Cybercriminals

ISBuzz TeamBy ISBuzz TeamAugust 30, 2017Updated:July 4, 20248 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Small Businesses
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Small businesses come in all shapes and sizes, but in today’s world, no organisation, large or small, can afford to ignore online security. Whether you’re a team operating out of an office, or an individual working from home, cybersecurity is an issue that every business should prioritise.

Granted, cybercrime generally grabs the headlines when a huge multi-national or government agency is the victim, but the many unreported cases affecting small businesses are arguably the bigger story.

In Q2 2017, Kaspersky Lab solutions detected and repelled over 342 million malicious attacks from online resources located in 191 countries all over the world[1]. What’s more, the majority of these were directed against individuals and organisations who wouldn’t have regarded themselves as likely targets.

The truth is that any business is a potential target, but the good news is that there’s a huge difference between being a target and being a victim. It simply comes down to being prepared – and there are several steps that businesses should take to arm themselves against threats.

  1. Conduct a security audit – The starting point for any cybersecurity strategy is to assess the risks to the business. Identifying your business’s security strengths, weaknesses and opportunities for improvements will provide a good foundation for your future decision-making process on appropriate technology and other measures. Ask yourself the following questions to identify how you need to protect your business:
  • What do you have that’s valuable – intellectual property, customer data, money?
  • Who might want it?
  • How might they try to get it?
  • What methods of attack might they use – e-mail, social media, through your network?
  • What might they do with it – sell it, publish it, damage the company reputation?

Once you’ve established what you’re already doing to secure your assets, it will help you identify what else you need to do for adequate protection.

  1. Choose the right anti-malware protection – When it comes to cybersecurity, small businesses are in a unique position. They face many of the same threats as enterprise, while sharing many of the same vulnerabilities as individuals.

This unique position deserves its own approach to security. Simply repackaging a consumer product as a small business solution isn’t adequate. For instance, it might offer no protection for servers, but many small businesses either use one or soon will.

Unlike consumers, businesses need a way to protect multiple devices easily. However, simply taking functions away from a solution intended for a large enterprise doesn’t work either. Small businesses don’t have dedicated IT teams or the time to wrestle with complicated software built for specialists.

Choosing the right security software will allow you to feel relaxed and comfortable that your business is adequately protected, without the hassle of managing an expensive or overly elaborate security solution.

 

  1. Keep your software up to date – According to AV-test data, four new pieces of malware are now detected every second, so businesses need to stay ahead. This means applying updates to your operating systems and applications as soon as they become available (switch on automatic updates where this is available). Remember, programs that haven’t been updated are one of the key means that cybercriminals use to hack businesses:  this was underlined by the WannaCry epidemic earlier in the year.
  1. Manage your network to minimise threats – By managing your network, you can limit the scope of any potential attacks. This includes:
  • Not automatically assigning admin rights to all staff – only to those who need access.
  • Segmenting the network – this will prevent lateral movement of malware if an infection does occur.
  • Limiting write-access to only those who need it restricts the access of an attacker.
  1. Back up – Plan for the worst-case scenario: infection. It’s vital to back up your files – so that, if your documents are compromised, you can restore your files with minimal disruption. This is true for ransomware attacks.  It’s also true for attacks like ExPetr, that are wipers disguised as ransomware and which delete your files rather than holding them to ransom – which means that even if you pay the fee you won’t get your files back.
  1. Enforce a password policy – Ensure your employees use unique, complex passwords that mix symbols, numerals and letters of both cases. Everyday words can be cracked by programs that simply scan through dictionaries until they find the right one. Even if it’s strong, the same password used across multiple accounts increases the risk of a security breach – if it is compromised, attackers can try to reuse it to access other accounts.

Businesses should have a strong password policy in place and ensure that teams aren’t making any classic password errors. Follow the following guidelines:

  • Make every password at least 15 characters long – the longer the better.
  • Don’t make them easily guessable. There’s a good chance that personal details, such as your date of birth, place of birth, partner’s name, etc. can be found online – and maybe even on your Facebook wall.
  • Don’t use real words. They are open to ‘dictionary attacks’, where someone uses a program to quickly try a huge list of possible words until they find one that matches your password.
  • Combine letters (including uppercase letters), numbers and symbols.
  • Don’t ‘recycle’ them, e.g. ‘david1’, ‘david2’, ‘david3’, etc.
  • Use a password manager to help you store and remember your passwords securely.

In addition to this, make use of two-factor authentication to reduce the likelihood of an account being compromised and to limit the damage that can occur if an attacker manages to obtain the password.

  1. Educate your staff about browsing behaviours – From sophisticated targeted attack campaigns to random, speculative malware, the starting point for most attacks is tricking people into doing something that allows attackers to get a foothold. So proactively educating your staff about the impact their online activity can have on the business will help to reduce your exposure to online threats significantly. This includes the type of sites they visit at work, how they transact sensitive business online (using only secure websites, for example) as well as how they respond to attachments and links in unsolicited e-mails. Good habits include manually typing URLs, to avoid being redirected to fake sites, only entering confidential data on secure site (only those starting with ‘https’ and checking that the security certificate of the site is valid).

If they’re also using a mobile device such as a laptop, smartphone or tablet, either a personal or business device, they may become less security-conscious once they’ve left the building. Therefore, it is vital to secure all devices and the data stored on them.

Staff should also be encouraged to avoid using untrusted, public Wi-Fi networks for conducting sensitive business. Increasing general awareness of IT security threats will help employees stay safe in their personal life as well as reducing the risk of an attack on the company.

  1. Banking – From directing you to fake versions of trusted sites to using malware to spy on your activity and capture passwords, cybercriminals have a number of methods for obtaining your financial information. You need to take active measures to stop them.

Stay alert for ‘phishing’ attempts. Phishing is when cybercriminals impersonate a trusted institution, hoping to obtain information – such as passwords and credit card details – which they could use to defraud you. Often phishing scam artists send emails impersonating your bank, a trusted supplier or an official organisation (HMRC, for example), so always take a close look at the URL before inputting your details on any site to make sure it’s a genuine site, and ideally use a secure browser. It’s also best to avoid sharing sensitive in e-mails, using IM or in social networks – they may be seen by eyes they weren’t intended for.

  1. Mobile devices – As working on the move is now part of our everyday life, cybercrime is increasingly directed at mobile devices. In 2016, more than 8,500,000 new malicious mobile apps were detected[2].

Their portability and size means that mobile devices can be lost or stolen very easily, and if they’re inadequately protected, they provide an easy route for someone to gain access to the business. Remember that on a mobile device, a weak PIN or password becomes a single point of failure, allowing easy access to everything you do on your device.

Even though it’s just as important to protect phones and tablets as it is to protect PCs and Macs, only 32 per cent of small businesses currently recognise the risk mobile devices present.

  1. Encryption is key – If you have sensitive data stored on your computers, it should be encrypted, so that if it’s lost or stolen it won’t be accessible. It’s important to realise that as a business, the information you hold is a highly valuable asset that needs protecting.

The unfortunate truth is that cyberattacks and malicious malware are lurking around every corner and these threats continue to grow in scale and severity. Although businesses have no direct control over the growth of cybercrime, there are some simple steps they can take to secure their internal systems and processes and so reduce their exposure to attack.

[su_box title=”About David Emm” style=”noise” box_color=”#336588″][short_info id=’60695′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}