The UK Government is Offering £5000 Cyber Secure Vouchers to SMEs

solent-cyber-security-cluster-2-bis-presentation-8-638.jpg?cb=1421748751Under the UK The UK Government’s new £1m cybersecurity innovation vouchers scheme, micro-, small- and medium-sized businesses will be offered up to £5000 worth of vouchers for advice on how to boost their cybersecurity and protect their valuable intellectual property from prying eyes.

Given the major headlines over the past year, whether it is Sony or JP Morgan, it would be easy to assume that cyber-criminals only prioritize big multinational organizations over the likes of smaller businesses. Whilst these larger corporations are undeniably under constant threat from attack, headlines tend to distract from the threats facing the growing businesses who characteristically have more vulnerable systems and highly prized intellectual property.
This is reflected in the level of confidence many small businesses have assumed when it comes to cybersecurity. According to a survey by Zurich Insurance Group, this constant threat is seen as less of a danger than a natural disaster or fire damage, with only 6.9% of small- to medium-sized businesses in Europe citing cybercrime as the biggest risk to their company. 

A 2014 survey by the Federation of Small Businesses proved that over half of SMBs in the UK have been victimized by cyber-attack. It is these businesses the government is looking to aid with the free provision of cybersecurity advice.
A lack of visibility constitutes a large part of what makes SMBs such prime targets. Attempting to hack large businesses quickly grabs the attention of law enforcement and government agencies and is often well documented by the media. Attacking smaller businesses, on the other hand, allows hackers to operate largely under the radar whilst still wreaking enormous damage.

But it’s not just the assets held by SMBs that are attracting malicious actors. These new vouchers must also address a growing supply-chain risk. For the ambitious hacker, successfully breaching the defenses of a high street shop isn’t necessarily an end goal; it could simply provide a route to much bigger rewards. By infiltrating the network of a smaller supply-chain partner, experienced cyber-criminals can gain back-door access to the larger company’s systems, bypassing the robust defenses they have elsewhere in the network. 
 
Despite hacks like the Target breach demonstrating the effectiveness of this strategy, small firms actually cut their security spending by 20% in 2014, compared to a 5% increase in security investments by larger companies. It’s clear then that the news stories alone aren’t enough to adjust the course many small businesses are firmly set on when it comes to cybersecurity.

Offering financial incentives to promote security amongst small businesses is certainly the right strategy for the government to have adopted. The smaller budget of SMBs greatly limits their security spending when compared to larger enterprises, resulting in more vulnerabilities. In addition to this, internal security expertise is quite expensive, meaning these susceptible companies often aren’t able to seek the guidance needed to safeguard themselves from enterprise-scale attacks.
In this way, the £5000 grant for consultation will offer SMBs the opportunity to hire an external security consultant, which goes some way towards addressing ongoing problems in their security system. However, the grant will not cover the cost of implementing all the security controls and changes that consultant recommends.

Looking more towards the future of this scheme and others with similar goals of improving the resilience of corporate networks, it will be important for public bodies to realize funding also needs to deliver on a more direct level. Offering advice on the Cyber Kill Chain is all well and good but it still cannot offer the defense-in-depth that will ultimately give them the chance to defend their network right until the very last stage of an attack.

Pairing a campaign to improve understanding and cyber-strategy among small business leaders with a financial incentive scheme for adopting the right controls and solutions will give both small businesses and, through their supply-chain, big businesses, a better chance at avoiding the headlines.
InfoSecurity:  http://bit.ly/1Ke01Ew

« Interpol is Training Police to Fight DarkNet Crime
Will Robots Eliminate Many Humans From the Workplace? »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

UpGuard

UpGuard

UpGuard's discovery engine brings visibility to complex IT environments, enabling teams to identify risk, confirm compliance and make business safer.

DataLocker

DataLocker

DataLocker offers both hardware based external storage and software based cloud storage encryption solutions.

Apricorn

Apricorn

Apricorn provides hardware-based 256-bit encrypted external storage products to companies and organizations that require high-level protection for their data at rest.

Data Shepherd

Data Shepherd

Data Shepherds primary focus is to protect your business. We achieve this by offering extensive and unique expertise in innovative IT and Cyber security solutions.

NPCore

NPCore

NPCore is specialized in defense solution against unknown APT and Ransomware and provides two-level defense on network and endpoint based on behavior.

VU Security

VU Security

VU is a specialist in Cybersecurity software development with a focus on the prevention of fraud and identity theft.

IDnow

IDnow

IDnow is the world’s fastest, most flexible and most secure identity verification platform, delivering instant verification of the identity documents used by 7 billion people.

i-Sprint Innovations

i-Sprint Innovations

i-Sprint is a leader in Securing Identity and Transactions in the Cyber World for industries that are security sensitive.

Infosistem

Infosistem

Infosistem is a Croatian ICT company with extensive expertise and experience in enterprise and SMB ICT projects and solutions.

Cybertron

Cybertron

Cybertron services include real-time monitoring and incident response and a cyber range for competency development.

Splone

Splone

Splone is a Berlin-based IT security research team and consultancy. We help improve IT-security by offering red team assements, penetration tests, audits and customized consulting.

Kontex

Kontex

Kontex is a Cyber Security consultancy creating resilient solutions. From Strategy, Advisory and Implementation to Management and everything in between.

Vala Secure

Vala Secure

Vala Secure is a cybersecurity and compliance consultancy that always stays ahead of regulations, future threats and ever-changing security environments.

Novacoast

Novacoast

Novacoast helps organizations find, create & implement solutions for a powerful security posture through advisory, engineering, development & managed services.

Nortal

Nortal

Nortal is a strategic digital transformation partner for leading companies and governments around the world.

Effectiv

Effectiv

Effectiv is a real-time fraud & risk management platform for Financial Institutions and Fintechs.