The cyber security risk to SMEs

By StoneHouse Logic

09 Feb 2015

One of the topics I always raise when visiting potential clients is what measures they have in place to protect their IT network and business from internet borne threats.

By Andy Long, Stonehouse Logic.

Disappointingly, a lot of small business owners and directors will often either plead ignorance in this department or, more worryingly, not feel this is something that will effect an SME. A common response is that why would a cyber-criminal target my little business, surely they are after the big corporations? The fact is, most large corporations have extensive budgets for cyber security making them a very difficult nut to crack. This has resulted in hackers moving lower down the chain and specifically targeting smaller business with weaker systems.

It's important to understand that today's hackers are no longer the spotty 16 year old sat in his bedroom trying to cause a bit of havoc. Cyber-crime is big business and is carried out by advanced criminal organisations and even governments. So ask yourself, do you have anything that may be of interest to them? The simple answer is if you have money in the bank, have some intellectual property such as a blueprint or formula that is unique or even if you are in the supply chain to a larger organisation then then the answer is most definitely yes.

Here are some facts. In 2014, 60% of small business reported a security breach. The cost of the worst breaches on average ranged from £60k to £115k and this figure has increased year on year for the last three years. I personally helped a local business that had what the owner described as a "substantial amount of money" taken from their bank account due to a security breach.

Increasingly, security breaches are cleverly targeted at a specific company. It doesn't take much detective work to find the names of people within a business and at that point a criminal organisation can start to use a "social engineered" attack with personalised emails to an employee containing malware, quite often followed up by phone calls claiming to be from their bank. This was the method used against the company I mentioned earlier and within minutes two transactions had been taken from the account.

Another threat that businesses often forget about is that of employees. You trust your employees with access to sensitive data and systems, however a large proportion of security breaches are either maliciously or accidentally caused by staff members. This can be either stealing important data or information, sabotaging data or just plain and simple deleting data by accident.

So what basic steps can you take to help protect your business? Here is a checklist:-

Malware protection

Ensure up to date antivirus is installed on all systems and that Windows or Mac OS security patches are updated regularly. Running out of date operating systems (such as Windows XP) and internet browsers is an easy way to invite problems

Network security

Use an effective firewall to protect your network at the boundary and ensure your wireless network is secure

Secure configuration

Keep an inventory of your IT equipment and software and use policies to ensure users have effective and difficult to crack passwords

Manage user privileges

Keep access for staff and third-parties to the minimum. Over-privileging users is a common way for data to be compromised or stolen.

Home and mobile working

Where possible, encrypt sensitive data on mobile devices and ensure online transmission of data is via secure methods only.

Removable media

Restrict use of media such as USB drives and memory cards and ensure any sensitive data that needs to be stored on these is encrypted.

Train your staff

This is possibly the most important area. Ensure your staff are aware of the risks and their role in keeping the business secure. As you can see, some fairly basic steps will help protect your business and mitigate the risk posed by cyber threats. If you have concerns or would like some further advice then please contact StoneHouse Logic and we will happily discuss how you can improve your IT security.

Enjoyed this? Read more from StoneHouse Logic

Latest news

1

Fulfilmentcrowd makes double senior hires Katie Shepherd L And Rachel Miller R

Fulfilmentcrowd makes double senior hires

19 Apr 2024

2

Forbes makes Manchester move Forbes Manchester

Forbes makes Manchester move

15 Apr 2024

3

Blackpool approves plans for pair of apartment complexes New South Promenade Apartments Visuals

Blackpool approves plans for pair of apartment complexes

12 Apr 2024

4

Distinguished engineer takes senior role at Lancaster University Rebecca Lingwood

Distinguished engineer takes senior role at Lancaster University

11 Apr 2024

5

International building supplies firm to open new plant in Preston New Kerakoll Group Premises Visuals

International building supplies firm to open new plant in Preston

11 Apr 2024

Hwc 2024 Email Signature 980x120
Background image for hub sign up block

LBV Hub

Reach 50,000 members of the Lancashire business community

Post your news
Post your events
Post your offers
Company profile
Social reach
Magazine coverage
Sign-up
Events
Health and Wellbeing Conference 2024
Hwc 2024 Social Media 1200px 1
Networking
23 Apr 2024

Health and Wellbeing Conference 2024

Crow Wood Hotel, Burnley , BB12 0RT

08:30 - 13:00

Help to Grow Management Course
HTG2.png.png
LBV Hub Seminars
15 Apr 2024 - 17 Jul 2024

Help to Grow Management Course

Preston Campus , Preston , PR1 2HE

09:30 - 14:00

St Catherine’s Corporate Skydive
Corporate SkyDive.jpg.jpg
LBV Hub Fundraisers
21 Apr 2024

St Catherine’s Corporate Skydive

Black Knights Parachute Centre, Lancaster, LA2 0YD

12:00 - 16:30

HR Complete Training Programme: Equality and Diversity
Picture1.png.png
LBV Hub Webinar
23 Apr 2024

HR Complete Training Programme: Equality and Diversity

Online (Zoom)

09:30 - 11:00

Business Networking in Blackburn - BNI Vista
EVENT LISTING SIZING Vista.png.png
LBV Hub Networking
23 Apr 2024

Business Networking in Blackburn - BNI Vista

Hampton by Hilton, 2 Frontier Ave, Blackburn, BB1 3AL

06:45 - 08:30

Emergency First Aid at Work
Chamber Logo1.png.png
LBV Hub Seminars
23 Apr 2024

Emergency First Aid at Work

FGH Training, 3rd Floor, Storey House, White Cross Business Park, Lancaster, LA1 4XQ

09:00 - 16:00

Business Networking in Chorley - BNI Endeavour
EVENT LISTING SIZING Endeavour.png.png
LBV Hub Networking
23 Apr 2024

Business Networking in Chorley - BNI Endeavour

Oak Royal, Bury Lane, Chorley, PR6 8SW

06:30 - 08:30

Business Networking in Lancaster - Eden Business Network
EVENT LISTING Eden Business Network.png.png
LBV Hub Networking
24 Apr 2024

Business Networking in Lancaster - Eden Business Network

The Borough, 3 Dalton Square, Lancaster, LA1 1PP

18:30 - 20:30

Business Networking in Preston - BNI Diamond
EVENT LISTING BNI Diamond.png.png
LBV Hub Networking
24 Apr 2024

Business Networking in Preston - BNI Diamond

The Marriot Hotel, Garstang Road, Broughton, PR3 5JB

07:15 - 09:00

30 Minutes: Net Zero Introduction for Blackpool Businesses - Free online event
BU 2024 Events.jpg.jpg
LBV Hub Webinar
24 Apr 2024 - 24 Apr 2024

30 Minutes: Net Zero Introduction for Blackpool Businesses - Free online event

Online, Blackpool , FY4 1EW

10:00 - 10:30

Your Business Bootcamp Bitesize: "Roger That… The Importance of Asking Twice"
CBP-logo LBV.png.png
LBV Hub Webinar
24 Apr 2024 - 24 Apr 2024

Your Business Bootcamp Bitesize: "Roger That… The Importance of Asking Twice"

Online, Online, Online

08:00 - 09:30

Business Networking in Accrington - BNI Zeus
EVENT LISTING SIZING Zeus.png.png
LBV Hub Networking
24 Apr 2024

Business Networking in Accrington - BNI Zeus

The Mill House, Corn Mill Yard, Accrington, BB5 5HX

06:45 - 08:30

Advertise with us

Reaching 50,000 members, our print, digital and event platforms offer a fantastic way to raise your business profile and help you grow.

Find out more Lbv115 Online Graphic
Subscribe now

Weekly news bulletin