We stand with Ukraine
Go Wombat logo

The Importance of Cybersecurity for SMEs

Article by

Updated on December 7, 2022

Read — 5 minutes

What makes SMEs targets and what are the risks from hackers?

News about data breaches usually features large companies, which can make small and medium-sized businesses (SMEs) feel safe because they hold less data. That is a mistake.

Verizon's Data Breach Investigations Report for 2019 found that 43% of breaches involved small business victims.

One reason hackers target SMEs is a lack of cybersecurity awareness. A tight security budget saves money in the short term, but a breach can cost far more.

A detailed assessment of your GDPR or security needs will be made evident through the Project Discovery Phase. A suitable risk assessment would highlight any potential weaknesses. If you have questions, Go Wombat can help you improve and maintain your cybersecurity.

What is the importance of cybersecurity?

Online shops and streaming services are not the only businesses that run on networks. Healthcare, government, oil and gas, and manufacturing do too, so a data breach in these sectors can affect the work and lives of thousands of people.

Governments have also moved many services online over the last decade, which makes cybersecurity as important for them as physical security. For US figures, see Statista's overview of the US government and cybercrime.

What makes SMEs a hacker’s target?

Valuable data

Depending on your industry, you may hold valuable data: client databases, research, bank account credentials or anything else you collect in your work.

Attackers often sell stolen data on the dark web.

 You may have unique and high-value data depending on your business's niche or industry, making you a possible target.

Hardware

Sometimes attackers do not want your data at all, only your hardware. Compromised computers join a botnet of other hijacked devices and are used for DDoS attacks, which flood a target with traffic.

Large companies are usually better protected, but a smaller partner can give attackers a way in, because the two businesses exchange data through shared connections.

Money

Attackers can also go straight for money: they encrypt data and demand a ransom, blackmail the company or sell stolen customer records.

Why cybersecurity presents unique risks for SMEs

Tight budget

Smaller companies have tighter budgets, and cybersecurity is often treated as a low priority.

Larger companies can afford cybersecurity experts and ethical hackers to find vulnerabilities, yet small and large businesses face similar IT security risks.

Complexity challenges

Supply chains are getting longer and more complex. Attackers often go after the weakest link, frequently an SME vendor, to get into a larger enterprise with stronger security.

Expertise challenges

SMEs can rarely afford an in-house security team. Many smaller teams lack the experience to set up and run security processes, and attackers exploit that gap.

Types of threats for small businesses

Malware attacks

Malware ("malicious software") is a file or code that the victim usually receives over the network through an unprotected channel.

Common types of malware include trojans, viruses and worms.

Malware can give attackers remote control of the infected device, steal unprotected sensitive data, send spam and map the infected user's local network.

There are five main types of threat for SME hackers. Discover if you are at risk from any of them.

Phishing

Phishing is a social engineering attack: unlike malware, it relies on people, so spotting it is mainly up to users. A phishing message tricks the recipient into clicking a link and sharing sensitive data.

It usually imitates a service people already get emails or texts from. Attackers use it to steal passwords, credit card details and other data.

Ransomware

Ransomware blocks access to data or devices until the victim pays. It hits both businesses and individual users.

CryptoLocker is an early example of sophisticated ransomware. It used a 2,048-bit RSA key pair to encrypt the infected system, all connected drives and synced cloud services.

Weak password

Passwords written on sticky notes next to a PC are a common security gap. If the password is also short or easy to guess, the risk is higher still.

A weak password is short, common or left at the system default. Typical examples are birthdays, other important dates, common words and simple number sequences.

Having a weak password policy, or even no policy at all, could lead to major issues in the future. It is best to have a strong password policy for all employees.

Insider threats

Insiders, such as employees or contractors, sometimes gain unauthorised access to sensitive data. A zero-trust strategy helps: no user or device is trusted by default.

Since anyone connected to your company can become an insider threat, the same security rules should apply to everyone.

Best practices to reduce cyberattack risks

Security risk assessments process

A risk assessment shows your security from an attacker's point of view. Once you know how someone could get in, you can plan protection for each weak point.

It is, of course, recommended to follow best practices when tending to cybersecurity issues. A plan and an assessment are the least you can do.

Have a data security plan

A data security plan tells the team how to prevent and recognise data breaches.

Train your employees to prevent insider threats

Everyone with access to company data should know what to look out for and how to keep sensitive data safe. Regular security awareness training covers this.

Insider threats are growing: according to the Ponemon Institute's 2022 Cost of Insider Threats Global Report, commissioned by Proofpoint, insider threat incidents rose by 44% over the previous two years.

Implement a strong password policy

Set clear password rules for employees, use a password manager and generate long, unique passwords. Weak passwords are easy to crack with brute-force attacks.

Install firewalls

A firewall is a network security monitoring system that controls incoming and outgoing network traffic based on predetermined security rules. A firewall typically creates a barrier between a trusted and untrusted network, such as the internet.

Antivirus software is meant to protect your file system from unwanted programs, and a firewall helps keep intruders or external threats from accessing your system.

Firewalls are your immediate protection from the outside world. Using them as part of your cybersecurity plan will go a long way in protecting your systems.

Contact Go Wombat

Our team can help you assess and reduce your information security risks.

Conclusion

You would not leave the office door unlocked. Every unprotected way into your data or devices is the same kind of open door.

Investing in cybersecurity for SMEs saves money in the long term, reduces legal risk and protects your partners' and clients' sensitive data.

Talk to our team at Go Wombat about your organisation's cybersecurity.

How can we help you ?

How can we help youHow can we help youHow can we help you