Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Why Small Businesses Need Enterprise-Grade Security Just As Much As Large Corporations
Articles

Why Small Businesses Need Enterprise-Grade Security Just As Much As Large Corporations

ISBuzz TeamBy ISBuzz TeamFebruary 20, 2018Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In 2017, Verizon’s Data Breach Investigation Report revealed 61 percent of all cyberattacks target small businesses. And according to the U.S. Cyber Security Alliance, 60 percent of small business that suffer a cyberattack go out of business within six months.

Bad actors are using phishing and ransomware attacks to steal information to empty bank accounts via wire transfers, steal customers’ private information, commit health insurance fraud and file false tax refunds. All in all, the Ponemon Institute found the average price for small businesses to recover after being hacked stands at $690,000, and for middle market companies it’s over $1 million.

All too often, small business owners underestimate the need to invest in enterprise-grade authentication solutions, such as SSL certificates, believing their small operations are less attractive to hackers than their larger, highly-profitable competitors — when in reality, vulnerable systems make SMBs the more attractive targets.

Here are a few ways small businesses can amp up cybersecurity practices:

SSL/TLS certificates 

First impressions are important. That’s why business owners need to ensure there’s nothing affecting customers visiting their website. Browsers help protect Internet users by alerting them when a domain isn’t using encryption certificates to secure sensitive customer information like passwords, email addresses and credit card numbers. Small business owners need to make sure they’re using SSL/TLS certificates to avoid greeting customers with unsettling security alerts.

It is important to note that on March 1, 2018, new security protocols for SSL/TLS certificates are set to take effect. These new protocols mandate that DV, OV and EV validity periods be reduced from the previous 27-39 months maximum to a new maximum of 825 days. Moreover, in April 2018, Google Chrome will require all SSL/TLS certificates to be CT-logged in order to be trusted.

Failing to comply with these new protocols will prompt security warnings that may ultimately result in lost website traffic, reduced online sales and a diminished digital reputation.

Employee education 

Cybersecurity is like oxygen: everyone needs it, but it’s something that’s hard to explain. Most employees don’t fully understand how cybersecurity works, but they want it and expect it to be there. So, while it’s top of mind for everyone, there’s minimal understanding of how it’s actually delivered. As a result, it’s often written off as an infrastructure issue. Organizations need to change this mindset through actual investment in cybersecurity infrastructure and by building programs that educate people on why this infrastructure is important. Cybersecurity education programs, for both employees and consumers, will transform the enterprise, as well as small-to-medium sized businesses. Companies of all sizes could benefit from formalized approaches to cybersecurity education, as well as additional investment to build network security alliances between industry players.

Securing a connected workplace

While the rise of connected things in the workplace presents new opportunities for growth, it also introduces a high level of risk for organizations if not executed correctly. Many business owners today are focused on digital strategies and are pushing this forward at a rapid pace. But cloud access and connected devices can lead to IT headaches and leave unsecure entry points exposed to malicious individuals. The first step for businesses is to understand the need for IoT security, as well as the actual number of connected devices hiding in plain sight. Every wireless sensor, laptop, alarm system and automated office device can be hacked to crash an organization’s servers and gain access to the network. Despite having impressive Internet access and connectivity, most of these devices were not built with security being top of mind. With this said, there are simple things business owners can do to help prevent an IoT breach. Update all software, back up your data, and physically secure your office so only authorized employees have access to these devices.

Remote workforces and B.Y.O.D. policies

According to FlexJobs and Global Workplace Analytics’ ‘2017 State of Telecommuting in the U.S. Employee Workforce’ report, the number of people telecommuting in the U.S. increased 115 percent between 2005 and 2015. This is not only changing how businesses operate and manage their employees, but also how they approach cybersecurity and the risks involved with having their networks accessed around the globe. Today, remote workers authenticate themselves through a VPN, which gets them behind the company’s firewall. Mobile access, however, does not sit behind the firewall and creates a world without boundaries, which presents a huge identity problem for IT given the rise in BYOD (bring your own device) policies. Employees are using unauthorized applications to access sensitive work and personal info on their mobile devices. Ultimately, businesses want to enable access for employees in order to increase productivity, so the challenge is to control and protect that access. The key is to implement security solutions that go beyond the traditional username/password combination to authenticate employees in a more advanced capacity. For example, requiring two-factor authentication when logging into a secure network or installing mobile credentials on work phones.

As the number of cyberattacks continue to rise, it’s crucial that small business owners understand enterprise-grade security practices are necessary for more than just large corporations and take action to protect their companies, their customers and themselves.

[su_box title=”About Jay Schiavo” style=”noise” box_color=”#336588″][short_info id=’104457′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}