The Cyber Delusion Challenge For Small & Medium Businesses

Growing dangers around cyber threats in the current disruptive landscape are a real concern for SMBs. Cyber attacks against businesses doubled in 2021 compared to the previous year according to SiteLock, yet nearly half (48%) of SMB website owners still think they’re not big enough to be troubled by cyber threats.  
 
With mounting risks, education and training need to be properly explored in organisations. The right knowledge can help employees use IT efficiently and safely, and block threats at the door.

Creating A Solid Cyber Defence Strategy With The Right Training

Cybersecurity training allows SMBs to approach their security strategy cost effectively. Employees will have the knowledge they need to spot attempted cyber attacks and ensure they're using defensive actions when accessing a business' systems.  

Prevention is at the centre of cyber awareness programmes. According to the Cyber Security Breaches Survey 2022 produced by the UK Government, nearly four in ten (39%) UK businesses identifying a cyber attack over the last 12 months, but only 8% of organisations have set up multifactor authentication and forced employees to change passwords since their most disruptive breach or attack of the last 12 months, in cases where breaches had material outcomes.

Taking steps towards preventative measures is vital, as it helps stop cyber attacks dead in their tracks.

When it comes to educating staff, and ensuring that the expertise to defend against bad actors is  shared within teams, the advantages of cybersecurity training are endless. However, knowing how to implement it or where to start can be a challenge for SMBs. 

What Main Areas Does Cybersecurity Awareness Training Need To Address?

Cybersecurity is no longer just about technology, it's also about people. In today's hybrid work landscape, SMBs need to empower employees to aid in reducing a business' attack surface for cybercriminals, this can be quickly achieved by implementing a cyber awareness programme. Implementing a cyber awareness programme into your business can provide a structured approach to managing human risk. 

The first step to developing a mature cyber awareness programme is to evaluate human risks and employee behaviour on how they are using business systems. Once businesses understand their employees' cybersecurity behaviours, and the mounting ransomware threat, business leaders can better assess what systems to focus on to improve security and overall cyber resilience. 

The second phase to implementing a mature cyber awareness programme is invoking change. SMBs must provide employees with the right know-how to identify and deal with cyberattacks or risk becoming the victim of what could be a crippling attack. 

While there's no one-stop-shop to achieving an educated workforce, it is a good idea to start with some of the basics, which includes educating employees on phishing, the need for strong passwords, and encouraging software patching: 

1.    Phishing – phishing is where a cybercriminal pretends to be someone else in an email to steal credentials and information from the organisation. To mitigate this risk, SMBs should educate employees on what to look for in an email, such as identifying the sender, reading the email thoroughly, and observing the link or attachment in the email before clicking or opening it. Whenever in doubt, employees should be encouraged to contact the email sending through another means, other than email.

2.    Passwords – it's good practice for employees to use strong passwords, however, this is no longer sufficient to protect against modern cybercriminals. SMBs should be implementing multi-factor authentication, which improves security by combining employee passwords with one-time passcodes, biometrics or more. The vast majority of SaaS platforms (i.e. Microsoft 365, Google Workspace, Salesforce, etc.) offer this for free.

3.    Patching – software updates often address vulnerabilities in software. If left unpatched, organisations risk having attackers exploit these vulnerabilities to wreak havoc. Conducting patching regularly is a simple yet effective way to improve security.

With increased sophiscation of cybercrime tools, plus the worrying backdrop of cyber warfare in the current climate, SMBs need to consider their own cyber defence strategies keenly.

Unfortunately, there’s a reticence to invest in training, as it necessitates the setting aside of budget, but by keeping on top of it now and regularly checking online resources, alongside investing in training programmes, businesses can save a lot of money down the line.  

John Davis is Director UK & Ireland of  SANS Institute EMEA

You Might Also Read:  

Most SMEs Do Not Provide Cyber Security Training

 

« Identity & Authentication For Mobile Users
Half Of Phishing Emails Target LinkedIn Accounts »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Resecurity, Inc.

Resecurity, Inc.

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

USNA Center for Cyber Security Studies

USNA Center for Cyber Security Studies

The mission of the Center for Cyber Security Studies is to enhance the education of midshipmen in all areas of cyber warfare.

ManTech International

ManTech International

ManTech provides comprehensive, integrated cyber security support, which includes computer and network design, implementation, and operations.

Securepoint

Securepoint

Securepoint is the market leader in the development of professional “Unified Threat Management” solutions in Germany.

Magtech Solutions

Magtech Solutions

Magtech Solutions is a one-stop IT Solutions provider offering Cloud Computing, IT Security, Unified Email Solutions and ERP systems.

Aporeto

Aporeto

The Aporeto platform protects cloud applications from attack by authenticating and authorizing all communications with a cryptographically signed identity assigned to every workload.

Zeguro

Zeguro

Zeguro provides complete cybersecurity risk assessment, mitigation and insurance, allowing you to easily manage your cyber risk.

CONCORDIA

CONCORDIA

Concordia is a Cybersecurity Competence Network with leading research, technology, and competences to build the European Secure, Resilient and Trusted Ecosystem.

Griffeshield

Griffeshield

Griffeshield is a company specialised in new information technologies used to protect Intellectual Property.

Cyber Pop-Up

Cyber Pop-Up

Cyber Pop-Up provide on-demand access to top security experts. No recruiting. No onboarding. No overhead costs.

Quantinuum

Quantinuum

Quantinuum is the combination of Cambridge Quantum with Honeywell Quantum Solutions, structured to drive the future of quantum computing.

SecurityGen

SecurityGen

SecurityGen is a global cybersecurity start-up focused on telecom security, with a focus on 5G networks.

Avint

Avint

Avint delivers transformational cybersecurity solutions that help both commercial and government entities achieve mission success.

Primary Guard

Primary Guard

Primary Guard provides IT solutions and computing technologies that help minimize impact from cyber threats, improve business efficiency and maintain essential functions during or after a disaster.

Gotham Security

Gotham Security

Gotham Security delivers high-quality penetration testing, malicious adversary simulation, compliance program development, and threat intelligence services.

AHAD

AHAD

AHAD provides cybersecurity, digital transformation, and risk management services and solutions to Government, Fortune 500, And Start-Up Companies in the Middle East region.

RB42

RB42

RB42 (formerly Nexa Technologies) provide cyber defense solutions (ComUnity, secure and encrypted messaging, detection of interception tools, etc) and cyber defense consultancy service.