Table of Contents
Introduction
2020 was a challenging year for small businesses. With worldwide lockdown, many companies suffered huge losses as their business had come to a standstill. It was clear that complete digitization was the only way to survive this unforeseen challenge. While many people struggled with this drastic change, many were able to achieve it with some effort. However, this created a huge security challenge and brought a surge in cyberattacks such as phishing and ransomware.
2021 seems to be moving further in this direction. Not only will small businesses witness more cyberattacks, but the sophistication of the attacks will increase. While many companies worldwide will focus on surviving the post-COVID world, they also need to be aware of the evolution of cyber threats in 2021 and how best to protect against them.
Below, we discuss five technological changes we expect in the year 2021 and how it will impact your company’s online security. By the end of this article, you will realize that comprehensive cybersecurity has never been more critical for small businesses.
Digitization of business will accelerate
Imagine the digital part of your business as a walled city. As more of your business becomes digital, the city’s size increases and, therefore, the wall that needs to protect it. Depending on your resources, time, and skills, the wall can be a wooden fence or a rock-solid wall to protect your city from being attacked by enemies.
Most small businesses either have no wall or a flimsy wooden fence - broken at multiple places. Like everything, one must continuously maintain and upgrade this wall. Therefore, with accelerating digitization, small businesses must keep and improve their defenses.
Protecting your digital business can seem daunting, but simple measures can instantly enhance your online security. First, understand and document your digital assets, including devices and online accounts. Then prioritize which assets are most important for your business continuity. Ensure you have high security for at least these devices and implement robust password controls with MFA and regularly update each asset’s software.
However, some digitization efforts will require a whole new perspective on securing your online business. This is most evident in cloud migration, as explained below.
Cloud Misconfiguration Vulnerabilities
Continuing with the previous analogy of your data being within a walled city, implementing cloud technology in your business will bring your data from within the walled city to a major city (Cloud Company). Comparatively, this major city has more resources and is much more advanced than your city, and allows storage and access to your data in them for a regular fee.
Cloud technology sounds like an ideal solution for a business owner where heavy lifting and responsibility lies with the cloud provider, allowing small business owners to focus on other parts of the business! However, cloud services also introduce several vulnerabilities. As customers of cloud technologies, small businesses must understand the contract terms that delineate and isolate vendor’s responsibilities from that of the customers.
While the cloud companies have much better technology to protect your data, how you configure that relationship ensures security from all sorts of cyberattacks. apart from ensuring the service availability levels, capabilities, and utility of the cloud services, all other responsibilities fall on the cloud customers.
Many companies are victims of cyberattacks for precisely this reason. As the company, you need to ensure that you have configured the cloud technology to provide the highest security possible. Failure to do so or misconfiguring it will increase your chances of getting attacked. Misconfigurations are easy to target for hackers and can be quite dire and expensive for any business, as is evident with Capital One’s example.
How does an organization prevent misconfigurations? The NSA has been kind enough to provide guidelines on the cloud architecture components that can prevent misconfigurations. These include Identity and Access Management (IdAM), Cloud Network segmentation, Computing virtualization and containerization, and storage segmentation.
Furthermore, it might not be possible to identify all misconfigurations, so it is best to work with the cloud-managed service team to help you implement tools to identify and fix vulnerabilities and improve your overall cloud security posture.
Impact of Remote working on cybersecurity
After the worldwide lockdown, many companies had to implement Work From Home (WFH) to continue operations in a world that required social distancing. While there has been some relaxation in the lockdowns over the past year, many workplaces will implement have part of their staff working remotely.
Unfortunately, securing a remote working environment can be quite challenging. Before the lockdown, all the employees were within the “walls” of the company network, and it was easy to implement security controls. Now that employees work from their home, with their network and devices often shared with other family members and not implementing the same security level as that of an enterprise environment, security becomes a lot more challenging. Malware developers have rushed to weaponize popular applications such as Zoom, often packing RAT (Remote Access Trojan), Ransomware, Banking Trojan, and even highly aggressive adware!
Best practices to reduce your business threat exposure include using a dedicated router or Internet connection for working, preventing family members from using your devices, using a VPN to connect to the company network, mandatory implementation of Multi Factor Authentication, and segregating (and encrypting) company data from personal data on the devices.
Increase use of IoT devices
There has been widespread adoption of IoT devices in the past few years, at home and at work. Cisco reports that 27.1 billion devices will be connected to the Internet of Things (IoT) in the year 2021. However, the IoT developers don’t have security and privacy in mind when developing these products. We are still a few years away from setting a security standard for the IoT industry. Till then, we should be mindful of how we install and use them in our homes and offices.
Suppose your business has internet-connected security cameras, mobile card readers (mPOS), Barcodes & RFID tags for inventory, temperature & climate monitoring, or supply chain data monitoring. In that case, your business needs to consider these devices for your security! Bitdefender has found an increase of 46% in reported suspicious events on IoT devices from January 2020.
We expect exponential growth in the IoT and 5G technologies and suggest small businesses to ramp up their cloud security! We recommend that you segregate such devices over the internet via an IoT gateway and implement automatic to keep the software updated. Where possible, you must limit the functionality of such devices to mitigate any hack that might occur.
Ransomware Attacks
Ransomware has always been a top threat for small businesses. However, ever since the start of the lockdown, ransomware attacks have tremendously increased. According to Bitdefender’s report, there has been a 715% increase (year-on-year) in detected and blocked ransomware.
Phishing is the preferred method through which hackers deliver ransomware to their victims. They take advantage of times of uncertainty (like during the coronavirus) and create massive email phishing campaigns that prey on the public’s fear. Many businesses have been the victim of a ransomware attack in 2020. According to a recent survey, 2021 ransomware attacks will further increase, with 50% of companies expecting an attack!
The majority of the ransomware victims choose to pay the ransom instead of losing their valuable data and prevent any further disruption to their businesses. However, we advise you never to pay the ransom, as it only encourages the hackers to continue with such attacks.
The best strategy against a ransomware attack is to back up your data regularly. The frequency depends on the type of business you operate, but we recommend a frequency of at least twice a week. Further, have a detailed plan to bring back your business to the pre-attack day by restoring the back up as swiftly as possible.
Conclusion
The coronavirus pandemic has changed our lives forever. Small business owners have struggled to keep their business running in the past year. It has forced many of them to digitize their business by adopting technologies like cloud, online payments, and others at an unprecedented rate. We expect small businesses to integrate more technologies in 2021. Every small business must become tech-savvy to survive the new world. These changes will bring a new threat to business – cyber attacks and company data loss resulting in potentially huge financial losses. While people are unprepared for handling them, small businesses can have the upper hand in such circumstances through active learning and practice.
In 2021, a small business owner must ensure that they improve the company’s cyber hygiene, increase security awareness amongst its employees and adopt safe technology practices such as regular backup of crucial data, implementing Multi-Factor Authentication (MFA), and changing the default passwords of all accounts. Furthermore, Small businesses must ensure they actively maintain a list of their IT assets (both physical and digital) and ensure that their software is always up to date.
The year 2021 will see a further rise in ransomware, phishing and cloud attacks. Ensuring proper configuration of cloud services will protect your small business from majority of the cyberattacks. This year will be challenging for business owners, who will need to expand their security knowledge and balance it efficiently with all digital services’ usability. At Security Pilgrim, we will support you in this transition and help you efficiently secure your business from cyberattacks.
