Categories: Workspace

How SMEs Can Enhance Their Cyber Resilience

While it is true that small-medium sized enterprises (SMEs) do not need to worry about some of the issues that are of concern to large organisations, such as shareholder demands, cyber resilience is one that SMEs do need to pay attention to just as much as their larger counterparts.

Almost three-quarters (74 percent) of SMEs experienced a cyber-attack last year and the average cost of these attacks was between £75k and £311k, according to PriceWaterhouseCoopers 2015 Information Security Breaches survey.

No choice

It is clear that SMEs no longer have a choice on whether they need to invest in cyber resilience. The fact that they don’t get as much publicity when attacked does not mean that these incidents don’t impact on an SME’s operations, reputation and ability to survive in a fiercely competitive market. In fact, SMEs may not be able to recover from a cyber-attack as quickly and smoothly as large organisations due to a lack of resources and availability of appropriately trained staff to help them respond and recover in the aftermath of an attack.

Customer data is of particular interest to criminals and if this data falls into the hands of attackers, SMEs risk being fined up to £500k by the regulator, i.e. the Information Commissioners Office. Sanctions of this magnitude can be enough to put SMEs out of business and the reputational damage alone may be enough to destroy the company.

Regardless of resource availability, there is a lot that SMEs can do to defend themselves against a cyber-attack, including:

Employees are often the easiest route for attackers to gain the access they require to mount a cyber-attack. A large proportion of all incidents begin with a phishing and/or a social engineering attack. The good news is that preventing these types of attacks is fairly inexpensive and straightforward – the solution being to empower employees through cyber awareness training. Education and learning awareness programmes must move beyond a compliance ‘tick-box exercise’, towards truly engaging and informing employees in a relevant way can mitigate against these common occurrences.

With these type of attacks, no one in an organisation is safe from being an unwitting victim, so an education and awareness initiative must involve everyone within the organisation regardless of their role or seniority.

Once this training has been developed, the organisation is by no means fully protected. Vigilance must be adhered to on all cyber matters, which means that any new practices or methods for protecting against attacks will need to be integrated via refresher training for all employees. It is also important for organisations to ensure that new hires are properly informed on cyber resilience via their induction packs and compulsory new starter training.

SMEs can also find advice on cyber resilience from sources such as the UK government’s Cyber Essentials Scheme which outlines the basic steps all organisations should take to protect themselves against the threat of attack.

Similarly The UK Government’s National Technical Authority for Information Assurance (CESG), which advises how organisations can protect their information and systems against threats, has developed 10 steps to cyber security. SANs, a cooperative research and education organization, has also produced a top 20 critical security controls list for organisations to adopt. These sources can be useful for SMEs in understanding what they should be doing at a minimum to protect against risk of a cyber-attack.

Finally, cyber risk insurance can be a useful way of mitigating the consequences of a successful cyber-attack. However, it is difficult to price and coverage is often very limited.

These top tips identify where SMEs can enhance their cyber resilience. Education is cost effective and crucial in ensuring employees do not unwittingly allow their organisation to become a victim of an attack. SMEs cannot afford to adopt the view that they are too small to be targeted – often they are a small piece in a wider chain of activity by cyber attackers, providing a way into a much larger, more lucrative target.

Duncan Macrae

Duncan MacRae is former editor and now a contributor to TechWeekEurope. He previously edited Computer Business Review's print/digital magazines and CBR Online, as well as Arabian Computer News in the UAE.

Recent Posts

Apple Sales Rise 6 Percent After Early iPhone 16 Demand

Fourth quarter results beat Wall Street expectations, as overall sales rise 6 percent, but EU…

23 hours ago

X’s Community Notes Fails To Stem US Election Misinformation – Report

Hate speech non-profit that defeated Elon Musk's lawsuit, warns X's Community Notes is failing to…

1 day ago

Google Fined More Than World’s GDP By Russia

Good luck. Russia demands Google pay a fine worth more than the world's total GDP,…

1 day ago

Spotify, Paramount Sign Up To Use Google Cloud ARM Chips

Google Cloud signs up Spotify, Paramount Global as early customers of its first ARM-based cloud…

2 days ago

Meta Warns Of Accelerating AI Infrastructure Costs

Facebook parent Meta warns of 'significant acceleration' in expenditures on AI infrastructure as revenue, profits…

2 days ago

AI Helps Boost Microsoft Cloud Revenues By 33 Percent

Microsoft says Azure cloud revenues up 33 percent for September quarter as capital expenditures surge…

2 days ago