In-depth

Securing small businesses from cyber attacks

Why are SMBs increasingly coming under attack from cyber criminals, and how can they stay safe? Davey Winder investigates...

Research suggests the SMB sector is coming under increasing pressure from hackers and cyber criminals.

A recent report by security vendor Symantec revealed that the number of businesses with fewer than 250 staff subjected to attacks doubled between during the six months to the end of June 2012.

Rival security firm AVG reported that 3.37 million of damage was inflicted on UK SMBs by cyber criminals last year, and predicts this figure will rise.

Advertisement - Article continues below

Meanwhile, the majority of the 855 data breaches analysed in the 2012 Verizon Data Breach Investigations Report (DBIR) were perpetrated against smaller firms.

Casting an eye over the Verizon statistics, Kurt Hangerman, director of global compliance at FireHost, told IT Pro: "Seventy-nine per cent of breaches were against targets of opportunity, and 96 per cent were not difficult to conduct, meaning that cybercriminals are discerning when it comes to who they ultimately attack."

Shifting focus of cybercrime

Not everyone in the security business thinks the focus of cybercrime has shifted from large enterprise to small business, though.

Rik Ferguson, director of security research at Trend Micro, says the types of attacks inflicted on the enterprise and SMB market have "diverged and evolved", with firms at the larger end of the scale falling victim to "more sophisticated and finely targeted" onslaughts.

Advertisement
Advertisement - Article continues below

"[SMBs are] receiving the dubious attentions of the sophisticated, commoditised toolkits which have been years in development," he added.

Advertisement - Article continues below

The latter point is something Corey Nachreiner, director of security strategy at WatchGuard, agrees with.

"Attackers cast a wide net, using mass emails, automated SQL injection, or automated network attacks to opportunistically gain any victim," Nachreiner says. "Everyone is the target of this attack, whether they know it or not."

However, he also claims to have seen a marked rise in targeted spear-phishing attacks against SMBs. "One recent email appeared to come from ADP, a company that helps SMBs manage payroll (among other things)," Nachreiner recounts.

"This spear-phishing email seems to target accounting and HR folks at SMBs, in [the] hope of gaining access to their payroll systems."

There's no doubt smaller firms often make very attractive targets, not just because they tend to employ lower levels of security, but because of who they do business with.

Richard Wilding, cyber security director at BAE Systems Detica, explains: "Infiltrate [a] small company with a less secure network and a cyber criminal can use the information gathered to target [a] larger firm where the larger prize lies or to steal information the supplier has about the true target."

Advertisement - Article continues below

The attack surface

So just what kind of attacks and threats are SMBs most at risk from? Jacques Erasmus, Webroot's chief information security officer, claims smaller firms need to be on their guard against targeted, information stealing Trojans.

"They are proving to be very successful and result in significant losses in many cases," he adds.

Meanwhile, Check Point's UK managing director, Terry Greer-King, says "blended attacks" using social media profiling to trick employees are most likely to succeed, simply because SMBs tend to have fewer layers of security.

Or, as Nick Connor, managing director and co-founder of Assuria, puts it: the biggest security threat to a small business is its staff.

"I suspect social engineering will continue to grow and small businesses in particular will be key targets as they fail to recognise the value of the data in the business or how to properly protect it," he adds.

Featured Resources

Top 5 challenges of migrating applications to the cloud

Explore how VMware Cloud on AWS helps to address common cloud migration challenges

Download now

3 reasons why now is the time to rethink your network

Changing requirements call for new solutions

Download now

All-flash buyer’s guide

Tips for evaluating Solid-State Arrays

Download now

Enabling enterprise machine and deep learning with intelligent storage

The power of AI can only be realised through efficient and performant delivery of data

Download now
Advertisement
Advertisement

Most Popular

Visit/mobile/mobile-phones/355088/apple-lifts-iphone-purchase-restrictions
Mobile Phones

Apple lifts iPhone purchase restrictions

23 Mar 2020
Visit/software/operating-systems/355080/internal-docs-show-apple-is-aware-of-ios-13-hotspot-disconnect
operating systems

Report: Apple is aware of iOS 13 hotspot disconnect issue

23 Mar 2020
Visit/security/data-breaches/355097/ge-employees-hit-by-canon-data-breach
data breaches

General Electric employees hit by Canon data breach

24 Mar 2020
Visit/operating-systems/microsoft-windows/355105/microsoft-puts-windows-development-on-lockdown
Microsoft Windows

Microsoft puts Windows development on lockdown

25 Mar 2020