• LinkedIn
  • Twitter
  • Google+
.
|
TechRecs: Cool Tools & Hot Topics
|
Is Your Business Vulnerable to Cyberattack? Understanding Your Risks and Protecting Your Sensitive Data
Posted on February 27, 2019 by

Regardless of what size your business is, you shouldn’t ignore cybercrime. Everyone is a target. Too many small businesses believe they are too little for cybercriminals to target them, thinking their data has no value. According to the Ponemon Institute’s 2016 State of Cybersecurity in Small and Medium-Sized Business study, about 55% of small and medium businesses said they had suffered a cyberattack and 50% reported they had data breaches involving customer and employee information in the past 12 months. Yet only 14% rated their ability to mitigate cyber risks as “highly effective”.

While it’s true that cybercriminals aren’t necessarily interested in the small company’s data, they often use small businesses as unwitting pawns to breach larger organizations. In the 2013 Target cyberattack, it is believed the breach began with a phishing email sent to an HVAC company that had a data connection with Target for electronic billing, contract submission and project management.

What You Should Know About Phishing

There are three types of email phishing approaches. The first and most common casts a wide net, with cybercriminals sending emails to large groups in order to ensnare as many victims as possible. The second, spear phishing, is a more refined approach which targets specific groups or individuals. Spear phishing emails often appear to come from a familiar sender and include requests for sensitive information such as social security numbers, credit card numbers and financial account information. This technique is, by far, the most successful on the internet today, accounting for greater than 90% of attacks. Spear phishers gather personal information about victims from social media and other sources to use in bait emails to increase the chances users will believe them.

The third phishing technique is known as whaling. These are highly customized and personalized emails that often include the target’s name, title, and other personal information and are targeted towards C-level executives and other high level targets.

Knowing that the biggest security vulnerability within any organization is it’s employees, businesses need to train users to identify and avoid phishing emails. Additionally, email security should be enabled so incoming emails are evaluated to verify if they were sent by an authorized host, with auto-whitelisting and a regularly updated spam filter that identifies and filters potential phishing emails.

Web-Based Cyberattacks

Cybercriminals utilize web-based attacks to download malicious code designed to alter files, disrupt network operations, and steal sensitive information. Web-based threats includes clickjacking – when a legitimate website link is redirected to an infected website where users either share confidential information or trigger an intrusive action. Another example of a web-based threat is drive-by downloads. When a user visits an infected website, malware is downloaded, often hiding in the background until it activates to either steal sensitive information or turn the workstation into a bot, controlled remotely by hackers. Other commonly used web-based threats are watering hole attacks, web tools plug-in vulnerabilities, social engineering data theft, and malvertizing.

To protect against web-based threats, employees should be educated on safe web browsing practices that help prevent downloading malware. Security tools including a good anti-virus, firewalls, and web filters should be deployed with up to date patch management.

Too many small and medium businesses spend their limited funds on security products only to see their investment – and best intentions – wasted when they fail to implement the most basic security practices. Here are 10 security practices to protect your SMB from cyberattacks:

1. Install Antivirus
Your best defense against the vast majority of malware is your antivirus solution. Look for advanced features that protect against prevalent threats like ransomware, and choose an endpoint security solution that offers protection at
multiple attack points to defend against bad websites, phishing and spam, malicious URLs, Zero-days and other online threats.

2. Restrict Administrator Rights
Only authorized, knowledgeable IT admins should have administrator rights to your PCs.

3. Install and Update a Firewall
Firewalls monitor and control traffic in and out of your network. To protect against downloading malicious content or to stop communication to harmful IP addresses, a firewall is a critical line of defense.

4. Implement Patches
Cybercriminals exploit vulnerabilities to open a backdoor onto your systems to drop malware and infect your network. Implement an automated patch management solution to fix newly discovered security vulnerabilities.

5. Enforce Password Policies
Require strong passwords or passphrases to maximize effectiveness, implement regular updates and instruct users not to share them.

6. Lock Screens
Enforce a short lock-screen timeout as added protection, especially in environments where users can walk away from workstations without logging
off.

7. Secure Wi-Fi Routers
Wireless routers and networks are notoriously easy to break into, so take extra precautions in securing them. Use a separate Wi-Fi network for business guests.

8. Secure Your Browsers
Configure web browsers to avoid inadvertent malware downloads by users. Steps to take include disabling popup windows, which can contain malicious code, and using web filters that warn you of potential malware attacks and harmful sites.

9. Use encryption
Many machines come with built-in encryption, both at the disk and file levels. Take advantage of each device’s encryption capabilities to prevent data from getting into the wrong hands when laptops, external hard drives, USB drives and other mobile devices are lost or stolen.

10. Train and Recruit Your Users

Your users can be your biggest liability or your biggest asset. Engage your users and educate them on security best practices and why they are important.

For more information on solutions for running your businesses’ technology more efficiently, visit our website or contact Megan Meisner at mmeisner@launchpadonline.com or 813 448-7100 x210.

This was originally posted by Vipre. Image credit Secure Thoughts

Posted in TechRecs: Cool Tools & Hot Topics, Small Business IT Management, Small Business Web Strategies, IT Solutions - Cloud | Mobile, IT Solutions - Stay Secure
Two Quick Ways to Copy Data From One Excel Workbook to Another
20 Ways Google Assistant Can Make You More Efficient

Related Posts

  • What Is Patch Tuesday? Microsoft’s Monthly Update Explained

    On the second Tuesday of each month, Microsoft and other tech companies release patches for
    read more
  • 10 Ways to Save Time on Your Windows 11 PC

    Windows 11 packs many features that you can use to speed up your tasks and
    read more
  • How to Automatically Fix Column Width to Fit Your Data in Excel

    There are numerous ways to change column widths in Excel, but did you know you
    read more
  • Why I Use a Privacy Screen When Working in Public

    Privacy screens are an affordable way to protect yourself from nosy colleagues and strangers whilst
    read more
Logging In...

Profile cancel

Sign in with Twitter Sign in with Facebook
or

Not published

TO WEBSITE >>
launchpadonline.com

CATEGORIES

  • Launch Pad News
  • TechRecs: Cool Tools & Hot Topics
  • Small Business IT Management
  • Small Business Web Strategies
  • IT Solutions – Cloud | Mobile
  • IT Solutions – Stay Secure
  • ITs Easy Being Green
  • RevITup TechCare Client Forum
  • GreenBack Nonprofit Wish List
  • Launch Pad Franchise Forum
  • Launch Pad Partner News

Cloud Computing in Plain English

Copyright © 2026 | Privacy Policy
  • LinkedIn
  • Twitter
  • Google+

Archives

  • January 2025 (1)
  • December 2024 (3)
  • November 2024 (4)
  • October 2024 (2)
  • September 2024 (4)
  • August 2024 (3)
  • July 2024 (2)
  • June 2024 (1)
  • May 2024 (3)
  • April 2024 (4)
  • March 2024 (2)
  • February 2024 (3)
  • January 2024 (4)
  • December 2023 (3)
  • November 2023 (3)
  • October 2023 (3)
  • September 2023 (3)
  • August 2023 (5)
  • July 2023 (3)
  • June 2023 (5)
  • May 2023 (4)
  • April 2023 (3)
  • March 2023 (4)
  • February 2023 (3)
  • January 2023 (3)
  • December 2022 (2)
  • November 2022 (2)
  • October 2022 (2)
  • September 2022 (3)
  • August 2022 (3)
  • July 2022 (2)
  • June 2022 (3)
  • May 2022 (2)
  • April 2022 (2)
  • March 2022 (2)
  • February 2022 (3)
  • January 2022 (2)
  • December 2021 (2)
  • November 2021 (3)
  • October 2021 (3)
  • September 2021 (3)
  • August 2021 (3)
  • July 2021 (2)
  • June 2021 (4)
  • May 2021 (3)
  • April 2021 (2)
  • March 2021 (2)
  • February 2021 (3)
  • January 2021 (2)
  • December 2020 (2)
  • November 2020 (2)
  • October 2020 (4)
  • September 2020 (2)
  • August 2020 (3)
  • July 2020 (2)
  • June 2020 (3)
  • May 2020 (2)
  • April 2020 (3)
  • March 2020 (3)
  • February 2020 (3)
  • January 2020 (4)
  • December 2019 (3)
  • November 2019 (2)
  • October 2019 (4)
  • September 2019 (3)
  • August 2019 (4)
  • July 2019 (2)
  • June 2019 (3)
  • May 2019 (3)
  • April 2019 (3)
  • March 2019 (3)
  • February 2019 (3)
  • January 2019 (4)
  • December 2018 (3)
  • November 2018 (4)
  • October 2018 (3)
  • September 2018 (2)
  • August 2018 (3)
  • July 2018 (3)
  • June 2018 (3)
  • May 2018 (2)
  • April 2018 (3)
  • March 2018 (3)
  • February 2018 (3)
  • January 2018 (3)
  • December 2017 (3)
  • November 2017 (4)
  • October 2017 (3)
  • September 2017 (4)
  • August 2017 (4)
  • July 2017 (4)
  • June 2017 (3)
  • May 2017 (5)
  • April 2017 (4)
  • March 2017 (4)
  • February 2017 (5)
  • January 2017 (4)
  • December 2016 (3)
  • November 2016 (4)
  • October 2016 (4)
  • September 2016 (4)
  • August 2016 (5)
  • July 2016 (4)
  • June 2016 (5)
  • May 2016 (3)
  • April 2016 (4)
  • March 2016 (4)
  • February 2016 (3)
  • January 2016 (3)
  • December 2015 (4)
  • November 2015 (4)
  • October 2015 (3)
  • September 2015 (3)
  • August 2015 (3)
  • July 2015 (3)
  • June 2015 (5)
  • May 2015 (4)
  • April 2015 (6)
  • March 2015 (4)
  • February 2015 (2)
  • January 2015 (5)
  • December 2014 (4)
  • November 2014 (3)
  • October 2014 (8)
  • September 2014 (5)
  • August 2014 (2)
  • July 2014 (3)
  • June 2014 (6)
  • May 2014 (3)
  • April 2014 (6)
  • March 2014 (5)
  • February 2014 (3)
  • January 2014 (5)
  • December 2013 (4)
  • November 2013 (4)
  • October 2013 (6)
  • September 2013 (3)
  • August 2013 (5)
  • July 2013 (6)
  • June 2013 (4)
  • May 2013 (3)
  • April 2013 (4)
  • March 2013 (4)
  • February 2013 (3)
  • January 2013 (5)
  • December 2012 (4)
  • November 2012 (5)
  • October 2012 (5)
  • September 2012 (6)
  • August 2012 (6)
  • July 2012 (6)
  • June 2012 (3)
  • May 2012 (7)
  • April 2012 (6)
  • March 2012 (10)
  • February 2012 (6)
  • January 2012 (5)
  • December 2011 (7)
  • November 2011 (9)
  • October 2011 (4)
  • September 2011 (4)
  • August 2011 (11)
  • July 2011 (14)
  • June 2011 (4)
  • May 2011 (11)
  • April 2011 (8)
  • March 2011 (11)
  • February 2011 (11)
  • January 2011 (21)
  • December 2010 (10)
  • November 2010 (10)
  • October 2010 (8)
  • September 2010 (10)
  • August 2010 (12)
  • July 2010 (8)
  • June 2010 (9)
  • May 2010 (8)
  • April 2010 (7)
  • March 2010 (10)
  • February 2010 (8)
  • January 2010 (6)
  • December 2009 (7)
  • November 2009 (13)
  • October 2009 (11)
  • September 2009 (16)
  • August 2009 (13)
  • July 2009 (16)
  • June 2009 (18)
  • May 2009 (16)