SMBs Are Taking Cybersecurity More Seriously

Amongst a backdrop of mounting cybersecurity threats, small and medium-sized businesses (SMBs) have woken up to the risk that ransomware and malware pose for their organisation. Many are taking additional measures to protect themselves against attacks, according to a new survey by Datto, a Kaseya company.

In its annual State of Ransomware Report, nearly 3,000 IT professionals in SMBs across eight countries weighed in on the steps they are taking to protect themselves, from investing in more security products to utilising multiple security frameworks.

The key finding is that SMBs globally are actively investing in cyber protection. While on average, a fifth of the IT budget is dedicated to security, around 4 in 10 businesses (42%) are seeing their security budget increase and allocating additional resources.

The majority have implemented basic defences - anti-virus and email protection - and are now expanding their security strategy to other areas.

For example, nearly half (47%) of SMBs plan to invest in network security in the next 12 months, and 45% percent are looking to add cloud security. Further down the shopping list are security solutions for collaboration tools, endpoint security and Business Continuity and Disaster Recovery (BCDR).

While installing the right tools is important, SMBs also increasingly understand the need to proactively monitor their security posture. Nearly two thirds (62%) run vulnerability assessments at least twice a year, with more than a third (37%) scheduling them three or more times a year.

The CIS framework is the most used cybersecurity framework, with 34% of respondents utilising it. This is followed by CMMC (30%), COBIT (27%), and NIST (22%).

Investment In Cyber Insurance

Cyber insurance is a key consideration for SMBs as it can offset the repercussions of breaches. However, in the face of stricter regulations and growing threat volumes, cyber insurance is becoming harder to obtain, with some insurers stipulating that businesses need to have certain security controls in place in order to qualify. 

In the survey, over two thirds (69%) of respondents said they have cyber insurance in place, and 34% of those without insurance are likely to get it within a year. Fear of being hit by ransomware seems to be one of the drivers, as 42% of SMBs with cyber insurance believe it’s extremely likely that a ransomware attack will happen to them. Seven in 10 respondents admitted that a successful attack would seriously impact their organisation, with some saying it could be a fatal blow.

Overall, the survey found that organisations with cyber insurance tend to be more actively engaged in cybersecurity. They have more IT support, more frameworks (CSFs) and more security solutions. They’re also more likely to have experienced a security incident in the past.

Across the board, nearly a third of all respondents encountered computer viruses in the past year and 21% reported COVID-19 related scams or threats. As the main reason behind these security issues, 37% of SMBs cited phishing emails, followed by malicious websites and weak password and access management. However, around 42% feel they have had security issues due to lack of training and 24% said it was down to poor user practices and gullibility – indicating that there is room for improvement when it comes to building out their defence layers.

Lack Of Preparedness Is The Weak Spot

Despite the heightened awareness and increased investment in cyber protection, there is another area that could let SMBs down: planning for the worst-case scenario. Only 3 in 10 businesses have a best-in-class recovery plan in place. Around half (52%) rely on a standard plan and 16% admitted there is no formal recovery plan, leaving them wide open to complete data loss and major business interruption. Perhaps this explains why nearly half of respondents (47%) say their companies would find recovery from a cyberattack difficult – and 16% fear that their business would not recover at all.

In fact, downtime is an expensive problem that nearly half of survey respondents have encountered in the past year.

In 2022, the average cost of downtime was 126,000 USD, including lost revenue. An eyewatering figure, but many SMBs still don’t have the tools to minimise downtime, such as a unified BCDR solution, a managed security operations centre (SOC) or an incident response strategy.

Just under half (49%) of surveyed SMBs relied on manual backups to recover data during an incident, and one fifth were forced to reinstall and reconfigure all systems from scratch. With slow and cumbersome recovery processes, around 45% of businesses endured more than two days of downtime before their systems were back up and running.

It is clear that many SMBs will need additional help planning for, and dealing with, security incidents. The cybersecurity talent shortage is a contributing factor, as is lack of expertise.

A growing number outsource the job: Almost half (47%) of the IT professionals surveyed said their organisation relies on a managed service provider (MSP) or a managed security service provider (MSSP). With increasingly complex cyber threats, this percentage is likely to grow.

Chris Mckie is VP, Product Marketing Security & Networking Solutions at Datto

You Might Also Read: 

Cyber Security Tools For Your Small Business:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Human Error Is A Hacker's Dream
Creating Order Out Of WAF Management Chaos »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Omerta

Omerta

Omerta is a global security technology and services company. We advise, consult, design, build, mitigate, protect, manage, provide and train to protect from increasing cyber threats.

Global Station for Big Data & Cybersecurity (GSB)

Global Station for Big Data & Cybersecurity (GSB)

GSB is an interdisciplinary research hub to cover big data, information networks, and cybersecurity.

United Security Providers

United Security Providers

United Security Providers is a leading specialist in information security, protecting IT infrastructures and applications for companies with high demands on security.

Dice

Dice

Dice is a leading recruitment platform, helping technology professionals manage their careers and employers connect with highly skilled tech talent in specialist areas including cybersecurity.

Blockchain Research Institute (BRI)

Blockchain Research Institute (BRI)

Blockchain Research Institute (BRI) is an independent, global think-tank. We bring together the world’s top global researchers to undertake ground-breaking research on blockchain technology.

SecureStrux

SecureStrux

SecureStrux are a cybersecurity consulting firm providing specialized services in the areas of compliance, vulnerability assessment, computer network defense, and cybersecurity strategies.

riskmethods

riskmethods

riskmethods helps you proactively identify, assess and mitigate supply chain risk. You need to master supply chain risk management—we can help.

Securolytics

Securolytics

Securolytics offers the simplest, most complete and affordable IoT security for all organizations. Securolytics quickly identifies unmanaged devices to reduce security and compliance risks.

E2E Technologies

E2E Technologies

E2E Technologies are a proactive, SLA-beating, managed service provider that busts the common stereotypes surrounding IT.

Island

Island

Island puts the enterprise in complete control of the browser, delivering a level of governance, visibility, and productivity that simply weren’t possible before.

Kirk ISS

Kirk ISS

Kirk ISS are the leading provider of IT services in the Cayman Islands. We offer best-in class hardware, software, communications and cloud computing, all backed by professional services support.

StealthPath

StealthPath

StealthPath is focused on endpoint protection, securing the “implicit trust” vulnerabilities of current leading information security solutions.

NextGen Cyber Talent

NextGen Cyber Talent

NextGen Cyber Talent is a non-profit providing a platform to increase diversity and inclusion in the cybersecurity industry.

Boecore

Boecore

Boecore is an aerospace and defense engineering company that specializes in software solutions, systems engineering, cybersecurity, enterprise networks, and mission operations.

Apex

Apex

We aspire to make the AI revolution run faster, securely, for the benefit of all. We are purposely built for the new AI era and are creating capabilities to safely enable AI.

TeamSystem

TeamSystem

TeamSystem is a leading tech company in the market for digital business management solutions for companies and professionals.