sb-au logo
Story image

Seven things SMBs can do right now to prevent cyber attacks

04 Sep 2018

New research from Australian’s Deakin University has found that many small businesses are at risk of cyber attacks, but most are unaware of the risk and doing nothing to prevent it.

Professor Matthew Warren is the deputy director of Deakin’s Centre for Cyber Security Research and Innovation. He believes businesses are becoming more dependent on IT systems, which makes them vulnerable to emerging security risks.

“From hairdressers to builders, accountants to GPs, small businesses are using IT to improve, expand and market their services, and that includes things like booking services, online sales, social media promotion, websites and customer databases,” he explains.

However those businesses are using technology for convenience, without understanding privacy and security risks. In addition, they may not have the right skills, resources, or expertise to protect their systems and data.

“Many think security is not their responsibility but it’s a serious risk that can destroy their business,” Warren warns.

You don’t have to go far to find examples. In 2016, thieves targeted a small business that had a national security contract with the Australian federal government. The thieves stole large amounts of data.

“While not all breaches will impact on matters of national security, when you consider that the average time it takes to resolve a cyber-attack is 23 days, that can still have an enormous impact on a small business’ operations and ultimately on its bottom line,” Warren says.

He says there are several things SMBs can do to protect themselves.

  • Patch systems and enable automatic patching. All systems and packages are updated (called patching) and the patching can be done automatically rather than implemented individually by users.
  • Back up all important data.
  • Use a cloud based email and/or data storage.
  • Use strong authentication. Use passphrases instead of passwords and use two stage authentication where possible.
  • Set up different accounts. For example you can set up an administrator account, as well as user accounts.
  • Don’t use the same password across all accounts (Twitter, Facebook, LinkedIn, Gmail, Adobe, Apple, etc). When one is hacked, they all become vulnerable if you’re using the same password.
  • Don’t click on links, attachments or images from people not known to you. Criminals often hack one account and use that account to send malware to people in the contact list.

“SMBs need to ask themselves – if they were a victim of a cyber-attack how much immediate business would they lose, could they restore their system and data, and would their customers have confidence in their organisation in the future,” Warren concludes.

Story image
The cybersecurity risks that come with re-onshoring Australian manufacturing
As technology such as IoT, robotic process automation (RPA) and artificial intelligence (AI) reshapes the manufacturing landscape, organisations are simultaneously put at an increased risk of a cyberattack.More
Story image
Cybermerc launches AU cyber threat intelligence platform, AUSHIELD
So far Australian National University, Fortinet, Anomali, Elastic, Vault Cloud, and startups SecureStack and Countersight have joined the project.More
Story image
Frost & Sullivan: Firewalls to drive network security market
Enterprises’ heightened threats from criminal entities and state-sponsored actors are strongly encouraging them to adopt network security solutions.More
Story image
Forrester names Thycotic a Leader in privileged access management
Thycotic received the highest possible score in 11 of the 24 criteria in the study, including SaaS/cloud, innovation roadmap, and integrations, deployment, supporting products and services, commercial model, and PIM installed base.More
Story image
Rising threat of data breaches among enterprises drives growth in network security revenue
"Key factors leading to the growth of network security market revenue in the Asia Pacific region includes instances of ransomware attacks, targeted attacks and phishing."More
Story image
Ivanti extends ESM automation capabilities with latest additions
Ivanti has made additions to its Enterprise Service Management (ESM) portfolio, with greater automation capabilities between service management and SecOps. More