{"id":117033,"date":"2017-04-22T15:00:16","date_gmt":"2017-04-22T13:00:16","guid":{"rendered":"https:\/\/mygaming.co.za\/news\/?p=117033"},"modified":"2017-04-21T15:08:28","modified_gmt":"2017-04-21T13:08:28","slug":"cybersecurity-tips-for-small-businesses","status":"publish","type":"post","link":"https:\/\/mygaming.co.za\/news\/business\/117033-cybersecurity-tips-for-small-businesses","title":{"rendered":"Cybersecurity tips for small businesses"},"content":{"rendered":"<p>Large-scale cyberattacks with eye-watering statistics, like the <a href=\"https:\/\/techcrunch.com\/2016\/12\/14\/yahoo-discloses-hack-of-1-billion-accounts\/\">breach of a billion Yahoo accounts<\/a> in 2016, <a href=\"https:\/\/theconversation.com\/overcoming-cyber-fatigue-requires-users-to-step-up-for-security-70621\">grab most of the headlines<\/a>. But what often gets lost in the noise is how often small and medium-sized organizations find themselves under attack.<\/p>\n<p>In the last year, <a href=\"http:\/\/www.cnbc.com\/2017\/04\/05\/congress-addresses-cyberwar-on-small-business-14-million-hacked.html\">half of American small businesses<\/a> have been breached by hackers. That includes Meridian Health in Muncie, Indiana, <a href=\"http:\/\/fox59.com\/2017\/02\/22\/meridian-health-services-in-muncie-latest-company-to-fall-victim-to-data-breach\/\">where 1,200 workers\u2019 W-2 forms were stolen<\/a> when an employee was duped by an email purporting to come from a top company executive. Many small companies are just one <a href=\"http:\/\/www.reuters.com\/article\/us-cyber-fraud-email-idUSKCN0Z023W\">fraudulent wire transfer<\/a> away from going out of business.<\/p>\n<p>There\u2019s lots of <a href=\"https:\/\/illinoislawreview.org\/print\/volume-2016-issue-5\/sustainable-cybersecurity-applying-lessons-from-the-green-movement-to-managing-cyber-attacks\/\">advice available<\/a> about how to <a href=\"http:\/\/www.fbiic.govpublic2011mar2010_Annual_Study_Data_Breach.pdf\">fight cybercrime<\/a>, but it\u2019s hard to tell what\u2019s best. I am a scholar of <a href=\"https:\/\/theconversation.com\/how-companies-can-stay-ahead-of-the-cybersecurity-curve-74414\">how businesses can more effectively mitigate cyber risk<\/a>, and my advice is to know the three \u201cB\u2019s\u201d of cybersecurity: Be aware, be organized and be proactive.<\/p>\n<p>Here\u2019s how more companies can <a href=\"http:\/\/www.americanbar.org\/publications\/tyl\/topics\/cybersecurity\/how-to-protect-small-businesses-and-law-firms-cyber-attacks\">boost their cybersecurity preparedness<\/a> without breaking the bank.<\/p>\n<h3 class=\"my-4\">Be aware<\/h3>\n<p>Almost <a href=\"https:\/\/theconversation.com\/before-decrying-the-latest-cyberbreach-consider-your-own-cyberhygiene-37834\">any company can be vulnerable<\/a> to a range of cyberattacks. A company manager or network security professional needs to <a href=\"http:\/\/www.csoonline.com\/article\/2942083\/big-data-security\/cybersecurity-is-the-killer-app-for-big-data-analytics.html\">know about<\/a> the <a href=\"http:\/\/www.sans.edu\/cyber-research\/security-laboratory\/article\/traffic-analysis\">various types<\/a> of <a href=\"http:\/\/www.wired.co.uk\/article\/how-deep-packet-inspection-works\">digital threats<\/a> and how to limit vulnerability.<\/p>\n<p>There are some attacks that every employee should know about. The most common attacks use a method called \u201cphishing,\u201d or a variant that specifically targets one potential victim, called \u201c<a href=\"https:\/\/theconversation.com\/spearphishing-roiled-the-presidential-campaign-heres-how-to-protect-yourself-68274\">spearphishing<\/a>.\u201d These typically take the form of email messages that appear to be sent by coworkers or supervisors asking for sensitive information. That\u2019s what happened to the health care company in Muncie. These messages can contain instructions that a victim might follow, believing them legitimate \u2013 such as clicking a link that installs malware or captures login information, or even making a <a href=\"https:\/\/www.jpmorgan.com\/global\/cb\/wire-transfer-fraud\">wire transfer<\/a> to another business\u2019s account.<\/p>\n<p>The <a href=\"http:\/\/www.pbs.org\/wgbh\/nova\/labs\/lab\/cyber\/\">best defenses against these types of attacks<\/a> involve skepticism and <a href=\"https:\/\/www.forbes.com\/sites\/kpmg\/2017\/02\/22\/5-ways-to-combat-cyber-fatigue\/\">vigilance<\/a>. Attackers can be very clever and persistent: If just one person has one weak moment and clicks on one malicious link, an entire network can be compromised.<\/p>\n<h3 class=\"my-4\">Be organized<\/h3>\n<p>Most companies go to great lengths to protect their <a href=\"http:\/\/www.techrepublic.com\/blog\/10-things\/10-physical-security-measures-every-organization-should-take\/\">physical assets<\/a> and personnel. But many do not <a href=\"http:\/\/www.computerweekly.com\/opinion\/Security-Zone-Do-You-Need-a-CISO\">take similar precautions<\/a> with their digital information. A key computer may be kept disconnected from the internet, but if it accepts flash drives or rewriteable CDs, or if its <a href=\"http:\/\/www.huffingtonpost.com\/entry\/2016-most-common-passwords_us_587f9663e4b0c147f0bc299d\">password is easy to guess<\/a>, the information is just as vulnerable.<\/p>\n<p>Small business owners need to prioritize cybersecurity. Without proper preparation, even large companies can find themselves unprepared for cyberattacks. When <a href=\"http:\/\/fortune.com\/2014\/12\/24\/why-sony-didnt-learn-from-its-2011-hack\/\">Sony was hacked in 2011<\/a>, it did not have an executive focused solely on information security. But hiring someone did not prevent <a href=\"https:\/\/www.washingtonpost.com\/news\/the-switch\/wp\/2014\/12\/18\/the-sony-pictures-hack-explained\/\">another hack in 2014<\/a>.<\/p>\n<h3 class=\"my-4\">Be proactive<\/h3>\n<p>Planning ahead is vital, instead of just <a href=\"https:\/\/www.cerias.purdue.edu\/assets\/pdf\/mfe_unsec_econ_pr_rpt_fnl_online_012109.pdf\">being reactive<\/a>. The <a href=\"https:\/\/www.nist.gov\/cyberframework\">National Institute for Standards and Technology Cybersecurity Framework<\/a> lists <a href=\"https:\/\/www.nist.gov\/sites\/default\/files\/documents\/cyberframework\/cybersecurity-framework-021214.pdf#page=9\">five main functions<\/a> of cybersecurity efforts: Identify vulnerabilities, protect against attacks, detect anyone who gets through, respond to the attack quickly and recover after the attack has been stopped.<\/p>\n<p>Some companies are already <a href=\"http:\/\/www.pivotpointsecurity.com\/risky-business\/nist-cybersecurity-framework\">receiving advice<\/a> that following the NIST guidelines can reduce legal liability if cybersecurity problems arise or are discovered. Companies can also work with colleges and universities to create <a href=\"https:\/\/cybersecurityprograms.indiana.edu\/\">cybersecurity clinics<\/a>, or even consider buying <a href=\"http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0007681312000377\">cyber risk insurance<\/a>.<\/p>\n<p>There\u2019s no way to avoid being the target of a cyberattack, but that doesn\u2019t mean <a href=\"https:\/\/www.amazon.com\/Managing-Attacks-International-Business-Relations\/dp\/1316600122\">becoming a victim<\/a>. Simple steps can have huge results: The Australian government reported <a href=\"http:\/\/csis.org\/files\/publication\/130212_Lewis_RaisingBarCybersecurity.pdf\">resisting 85 percent of cyberattacks<\/a> by taking three basic steps: restricting which programs can run on government computers, keeping software updated regularly and minimizing the number of people who have administrative control over networks and key machines.<\/p>\n<p>Cybersecurity doesn\u2019t have to be rocket science; it\u2019s just computer science.<\/p>\n<p><a href=\"https:\/\/theconversation.com\/profiles\/scott-shackelford-335009\">Scott Shackelford<\/a>, Associate Professor of Business Law and Ethics; Director, Ostrom Workshop Program on Cybersecurity and Internet Governance; Cybersecurity Program Chair, IU-Bloomington, <em><a href=\"http:\/\/theconversation.com\/institutions\/indiana-university-1368\">Indiana University<\/a><\/em><\/p>\n<p>This article was originally published on <a href=\"http:\/\/theconversation.com\">The Conversation<\/a>. Read the <a href=\"https:\/\/theconversation.com\/the-three-bs-of-cybersecurity-for-small-businesses-76259\">original article<\/a>.<\/p>\n<h4><strong>Now read:\u00a0<\/strong><a title=\"Permalink to Microsoft announces new update schedule for Windows 10\" href=\"https:\/\/mygaming.co.za\/news\/pc\/117017-microsoft-announces-new-update-schedule-for-windows-10.html\" rel=\"bookmark\">Microsoft announces new update schedule for Windows 10<\/a><\/h4>\n","protected":false},"excerpt":{"rendered":"<p>Here\u2019s how more companies can boost their cybersecurity preparedness without breaking the bank.<\/p>\n","protected":false},"author":220,"featured_media":29051,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_enabled":true,"_sma_x_custom_text":"","_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[2],"tags":[18685,1461],"class_list":["post-117033","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business","tag-cyber","tag-security"],"_links":{"self":[{"href":"https:\/\/mygaming.co.za\/news\/wp-json\/wp\/v2\/posts\/117033","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mygaming.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mygaming.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mygaming.co.za\/news\/wp-json\/wp\/v2\/users\/220"}],"replies":[{"embeddable":true,"href":"https:\/\/mygaming.co.za\/news\/wp-json\/wp\/v2\/comments?post=117033"}],"version-history":[{"count":0,"href":"https:\/\/mygaming.co.za\/news\/wp-json\/wp\/v2\/posts\/117033\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mygaming.co.za\/news\/wp-json\/wp\/v2\/media\/29051"}],"wp:attachment":[{"href":"https:\/\/mygaming.co.za\/news\/wp-json\/wp\/v2\/media?parent=117033"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mygaming.co.za\/news\/wp-json\/wp\/v2\/categories?post=117033"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mygaming.co.za\/news\/wp-json\/wp\/v2\/tags?post=117033"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}