The Cyber Delusion Challenge For Small & Medium Businesses

Growing dangers around cyber threats in the current disruptive landscape are a real concern for SMBs. Cyber attacks against businesses doubled in 2021 compared to the previous year according to SiteLock, yet nearly half (48%) of SMB website owners still think they’re not big enough to be troubled by cyber threats.  
 
With mounting risks, education and training need to be properly explored in organisations. The right knowledge can help employees use IT efficiently and safely, and block threats at the door.

Creating A Solid Cyber Defence Strategy With The Right Training

Cybersecurity training allows SMBs to approach their security strategy cost effectively. Employees will have the knowledge they need to spot attempted cyber attacks and ensure they're using defensive actions when accessing a business' systems.  

Prevention is at the centre of cyber awareness programmes. According to the Cyber Security Breaches Survey 2022 produced by the UK Government, nearly four in ten (39%) UK businesses identifying a cyber attack over the last 12 months, but only 8% of organisations have set up multifactor authentication and forced employees to change passwords since their most disruptive breach or attack of the last 12 months, in cases where breaches had material outcomes.

Taking steps towards preventative measures is vital, as it helps stop cyber attacks dead in their tracks.

When it comes to educating staff, and ensuring that the expertise to defend against bad actors is  shared within teams, the advantages of cybersecurity training are endless. However, knowing how to implement it or where to start can be a challenge for SMBs. 

What Main Areas Does Cybersecurity Awareness Training Need To Address?

Cybersecurity is no longer just about technology, it's also about people. In today's hybrid work landscape, SMBs need to empower employees to aid in reducing a business' attack surface for cybercriminals, this can be quickly achieved by implementing a cyber awareness programme. Implementing a cyber awareness programme into your business can provide a structured approach to managing human risk. 

The first step to developing a mature cyber awareness programme is to evaluate human risks and employee behaviour on how they are using business systems. Once businesses understand their employees' cybersecurity behaviours, and the mounting ransomware threat, business leaders can better assess what systems to focus on to improve security and overall cyber resilience. 

The second phase to implementing a mature cyber awareness programme is invoking change. SMBs must provide employees with the right know-how to identify and deal with cyberattacks or risk becoming the victim of what could be a crippling attack. 

While there's no one-stop-shop to achieving an educated workforce, it is a good idea to start with some of the basics, which includes educating employees on phishing, the need for strong passwords, and encouraging software patching: 

1.    Phishing – phishing is where a cybercriminal pretends to be someone else in an email to steal credentials and information from the organisation. To mitigate this risk, SMBs should educate employees on what to look for in an email, such as identifying the sender, reading the email thoroughly, and observing the link or attachment in the email before clicking or opening it. Whenever in doubt, employees should be encouraged to contact the email sending through another means, other than email.

2.    Passwords – it's good practice for employees to use strong passwords, however, this is no longer sufficient to protect against modern cybercriminals. SMBs should be implementing multi-factor authentication, which improves security by combining employee passwords with one-time passcodes, biometrics or more. The vast majority of SaaS platforms (i.e. Microsoft 365, Google Workspace, Salesforce, etc.) offer this for free.

3.    Patching – software updates often address vulnerabilities in software. If left unpatched, organisations risk having attackers exploit these vulnerabilities to wreak havoc. Conducting patching regularly is a simple yet effective way to improve security.

With increased sophiscation of cybercrime tools, plus the worrying backdrop of cyber warfare in the current climate, SMBs need to consider their own cyber defence strategies keenly.

Unfortunately, there’s a reticence to invest in training, as it necessitates the setting aside of budget, but by keeping on top of it now and regularly checking online resources, alongside investing in training programmes, businesses can save a lot of money down the line.  

John Davis is Director UK & Ireland of  SANS Institute EMEA

You Might Also Read:  

Most SMEs Do Not Provide Cyber Security Training

 

« Identity & Authentication For Mobile Users
Half Of Phishing Emails Target LinkedIn Accounts »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

ZenGRC

ZenGRC

ZenGRC (formerly Reciprocity) is a leader in the GRC SaaS landscape, offering robust and intuitive products designed to make compliance straightforward and efficient.

Micro Systemation AB (MSAB)

Micro Systemation AB (MSAB)

MSAB is a leader in the provision of forensically secure tools for the extraction and analysis of data from mobile devices.

WhiteHat Security

WhiteHat Security

WhiteHat’s products enable customers to “Hack Yourself First” so that they gain a greater understanding of the actual risk to their business.

Nuvias Group

Nuvias Group

Nuvias Group is a specialist value-addedd IT distribution company offering a service-led and solution-rich proposition ready for the new world of technology supply.

Skurio

Skurio

Skurio create cost-effective, intuitive and powerful Cloud based solutions to identify threats, detect data breaches outside the network and automate the response.

SANS CyberStart

SANS CyberStart

SANS CyberStart is a unique and innovative suite of tools and games designed to introduce children and young adults to the field of cyber security.

DOS

DOS

DOS is an Ecuadorian company with 3 decades of presence in the market and extensive experience in the planning, management and execution of IT Service Integration Projects.

BoldCloud

BoldCloud

BoldCloud's award winning Cybersecurity Advisory services and Layered Security approach adds new critical layers of protection for your data and your business.

CyberKnight Technologies

CyberKnight Technologies

CyberKnight Technologies is a cybersecurity focused value-added-distributor (VAD) headquartered in Dubai and covering the Middle East.

Raonsecure

Raonsecure

Raonsecure is one of Korea’s leading ICT security software companies – providing a variety of PC and mobile security solutions to financial institutions, government, and enterprise.

SecSign Technologies

SecSign Technologies

SecSign Technologies delivers user authentication, messaging, file sharing, and file storage with next generation security for company networks, websites, platforms, and devices.

Anjuna Security

Anjuna Security

Software from Anjuna Security effortlessly enables enterprises to safely run even their most sensitive workloads in the public cloud.

Strategic Technology Solutions (STS)

Strategic Technology Solutions (STS)

Strategic Technology Solutions specialize in providing Cybersecurity and Managed IT Services to the legal industry.

Daisy Corporate Services

Daisy Corporate Services

Daisy is one of the largest providers of communications and IT solutions across the UK, with a portfolio spanning unified communications, cloud, cyber security and resilience.

Bulletproof Solutions

Bulletproof Solutions

Bulletproof provides IT expert support, services, and guidance to businesses small and large as they grow and adapt to today’s complex IT, cybersecurity, and compliance needs.

Oxygen Technologies

Oxygen Technologies

Oxygen Technologies is a business systems strategy and integration company offering a variety of solutions to give our clients ways to work smarter not harder.

National Protective Security Authority (NPSA) - UK

National Protective Security Authority (NPSA) - UK

NPSA is part of MI5 and is the National Technical Authority for physical and personnel protective security. By making the UK more resilient to national security threats, we help to make the UK safe.