Table of Contents
Introduction:
A chain is only as strong as its weakest link and in the economic chain today SMBs are the weakest links. Therefore, understanding cybersecurity acts that are in place to protect them is of utmost importance. They run on a shoestring budget and have limited resources therefore they are unable to invest in high tech security, increasing risk exposure hence cybersecurity acts are most important to understand.
As we are transforming digitally, the fastest growing form of criminal activity is cybercrime. In the Hiscox Cybercrime Readiness Report 2021, on average an attack cost to a small business over 12 months stands at a whopping $ 25,612. They have also found that the pandemic has created cyber-stress for SMBs all over the US. About 63% of their workforce is remote and about 53% of the businesses assume themselves to be susceptible to cyber-attacks.
In an attempt to protect both the business and the consumer, governments have included them under their ambit. Various cybersecurity acts and regulations have been enacted over the past few years. This has been done to prevent unauthorised access, theft of information that is sensitive such as health and financial data - many of these are in the form of compulsory compliance mandates.
Various CyberSecurity Acts To Protect Small Businesses:
While many SMBS are following expert advice which is ensuring the basics such as updating software, password management, employee education etc., however, no one can be made to believe that these measures would protect their businesses to a large extent albeit their importance should not be underscored. Therefore, read more about how you can protect your business in small, easy ways.
Alongside following various practices to reduce cyberattacks, it’s also imperative for SMBs to understand and implement the various acts, regulations and compliances that have been set in place.
As a response to the various cybersecurity breaches cybersecurity acts, regulations and compliances have been promulgated, below are a few that SMB owners should keep in mind and should understand while setting up their systems:
- The National Institute of Standards and Technology (NIST):
The NIST passed the NIST small and medium business cybersecurity act in 2018. Earlier SMBs were excluded from the ambit of this cybersecurity law and hence did not receive their support. It is obligated to supply businesses with a framework that would comply with industry regulations.
They give SMBs frameworks that upon implementation with sufficient controls are of utmost importance in protecting their networks and systems from fraudsters and are industry compliant. However, they only suggest methods and standards and don’t enforce them. It’s burdensome to introduce standards that serve as defence and are industry compliant while being cost compliant as well. However, this is where the NIST framework comes into play to reduce the burden.
- The Health Insurance Portability and Accountability Act (HIPAA):
The information privacy requirements of the Health Health Insurance Portability and Accountability Act (HIPAA) affects almost all companies irrespective of their size. No small business exemption exists, any SMB that although may not offer health care services but offers to their employees’ benefits such as health insurance, a Flexible Spending Account plan, a wellness plan must comply with the security and privacy regulations laid down by HIPPA.
Many people link such privacy laws with clinics, and most SMBs are unaware of the fact that HIPPA regulations apply to all such entities that in some way handle any flow of patient information.
- The Gramm Leach Biley Act (GLBA):
This cybersecurity act requires financial institutions to set out methods that protect the sensitive data of their customers and these methods should be conveyed to their customers as well. Ensuring compliance with the regulations put forth by the GLBA allows financial institutions to enjoy a lower risk of penalties and the damage that they may face if their consumer data is shared or lost. Even customers enjoy many benefits under the GLBA as there are many safeguarding rules in place.
If compliance is met it will protect consumer and customer records, allowing the business to gain customer reliability and even trust. The compliance ensures customers that their information will be secured by the institution further increasing loyalty towards the said business.
- The European General Data Protection Regulation (GDPR):
The GDPR was put into place to give citizens and residents more control over their personal data. This may apply to all and any businesses that process the personal data of European Union citizens, this rule also applies to businesses the host less than 250 employees. Under the GDP, the business has to uphold the eight basic rights of the citizens. If a business fails to notify the authorities in charge about a breach or have failed to adhere to any part of the GDPR then they are subject to fines which amount to 4% of the business’s total revenue or 20 million Euros, whichever is greater.
- California Consumer Privacy Act (CCPA):
This is the first US law that resembles the GDPR, it aims to provide California residents with the right to have access to their personal data, say no to the sale of their personal data and know what is being collected about them. This law applies to any business that earns $25 million in revenue per year, sells 50,000 consumer records per year, or derives 50% of its annual revenue from selling personal information. The location of the company does not matter if the business collects or sells information from residents of California.
This provides SMB with an incentive to start pondering over the personal data collected by them and how it is protected within their network. While SMBs are in a crunch for resources and security takes a back seat, this act will push their system’s readiness in the right direction.
- The Children’s Online Privacy Protection Act (COPPA):
This cybersecurity act was implemented to protect the privacy of children under the age of 13. According to this act, websites that collect information of users that are below the age of 13 require parental consent. They are also required to state how the data will be collected and its usage. They are also expected to give access to data collected to parents.
- The New York State Department of Financial Services Cybersecurity Regulations (23 NYCRR 500)
Given the rise of cybersecurity threats, legislation was promulgated by the state of New York. This defines methods for a financial company to protect sensitive consumer information.
They are supposed to define their cybersecurity policies and regulations, a response plan for incidences etc… This law applies to both small businesses and startups, the exceptions being business with fewer than 10 employees, lesser than $ 5 million in gross annual revenue or less $ 10 million in assets.
- Fair Credit Reporting Act (FCRA):
This is heralded as one of the most important consumer protection acts, this limits information usage of various features of personal information, which can be credit standing or rating, the standard of living and other factors that qualify individuals for employment or insurance. The FCRA governs how the employers will be able to access data of potential employees to conduct a background check. Therefore, when companies or businesses use third party sources to access data about their employees FCRA should be complied with.
- Family Educational Rights and Privacy Act (FERPA):
This act is centred on protecting the privacy rights of students. It safeguards the privacy of the educational records of students. This act allows them the right to review or amend laws when they find discrepancies. This compliance affects institutions and relevant vendors, i.e. it applies to a business that sells textbooks, food or any other goods within the purview of a school.
- Payment Card Industry Data Security Standard (PCI-DSS):
A business that accepts either a credit or a debit card as a mode of payment, become responsible for not securing but also for processing and transmitting cardholder data. Therefore, they must be PCI compliant, and while it is maybe confusing or expensive to do so, not following them can cost a business dearly.
- FERC/NERC CIP:
The Federal Energy Regulatory Commission (FERC), certified the North American Electric Reliability Corporation (NERC), developed Critical Infrastructure Protection (CIP) which are cybersecurity reliability standards. For a business, it is imperative to ensure to make certain that all its crucial assets and cyber assets are both identified and securely protected.
- DOD-CMMC:
The United States Department of Defense (DOD), promulgated the Cybersecurity Maturity Model Certification (CMMC). This was done to normalise and regulate cybersecurity development throughout the federal government’s defence industrial base. Therefore all DOD contractors would not only have to apprise themselves with the technical know-how of the certification but also ensure long-term cybersecurity. This has been done because of the leakage of sensitive information from the contractor’s systems.
- DFAR:
All those companies that serve as DOD contractors and process, store and transmit, Controlled Unclassified Information (CUI) are mandated to meet DFARs set minimum security standards. If they fail to do so they would risk their contracts. The purpose of these standards is to safeguard the systems wherein the data of the contractor lies.
- SEC Regulation S-P:
As a member of FINRA, there is an obligation to protect the financial and personal information of a customer. As per the SEC Regulation S-P, they are obligated to have policies and procedures set in place that protect the customer’s information and records. Protection needs to be provided against any threats and hazards to the security of the information. They are also required to provide the customer with annual privacy noted detailing their sharing policies and customer rights.
- CFTC:
The Commodity Futures Trading Commission (CFTC), sanctioned a set of protective rules. These rules were set in place to safeguard contract markets, swap executions facilities, swap data repositories, derivatives clearing organisations. These were to have in place cybersecurity schemes of risk and oversight. Under the ambit of this program is to ensure that they conduct tests and review their systems to make sure that their automated networks and systems are not only reasonable but also secure.
Conclusion:
It is necessary to always understand regulations, compliances and acts about cybersecurity. It is not necessarily onerous, overwhelming, neither is it intimidating. Understanding these may not take much time but may take your business a long way. When technology is progressing with leaps and bounds it’s necessary to protect your small business with one more layer of the guard. A lack of awareness may not only lead to a lack of compliance but may also lead to significant financial penalties. We at Security Pilgrim are there to smoothen your journey in protecting your small business, one regulation at a time. To know more about the risks of your small business read here.
