Cyber Threats

What are the 9 greatest cyber threats to a small business?

Introduction

The number of internet users has increased drastically in the last five years and is set to increase threefold in the coming few years, resulting in more innovative and practical services being provided over the internet – from ordering coffee, requesting ride sharing to an exact location, streaming live videos, and even banking online. In the period of the pandemic, SMBs have been completely transforming their operations by shifting online, however they are unaware of the new threats it brings to their business environment.

According to the US Government, the average amount stolen from a small business has risen from $7,000 to $20,000 in just two years. As 43% of cyber-attacks are on small businesses, small business owners need to understand the types of cyber threats that their business might face. Below, we have listed the most relevant cyber threats to small and medium enterprises with some tips on how to protect your business.

Phishing

Created by freepik

Phishing.org defines it as “a cybercrime technique in which a target is contacted by email, telephone or text message by a hacker posing as a legitimate person/institute to lure individuals into leaking sensitive data such as personally identifiable information, banking and credit card details, and passwords”. While the objective of this cyber threat is usually monetary, they can be used to install malicious software to gain access to your network, database or servers.

Specialist phishing attacks like Business Email Compromise (BEC) count for over $12 billion in business loss and have grown 65% over the last year. In fact, 90% of all breaches start with a phishing attempt. As small businesses do not get reimbursed for any amount scammed out of their accounts, phishing poses the biggest threat to their operations. Losing working capital due to such scams has closed down many businesses.

The best solution to tackle this cyber threat is to increase cybersecurity awareness amongst your staff through regular and frequently updated training. Phishing relies on human error to become successful, educating employees will prevent them from clicking suspicious links or attachments in such emails.

Malware

A malware is a malicious software developed by hackers to do various kinds of damage to data and systems or gain unauthorized access to a network. This cyber threat comes in various forms, each with a different objective - ransomware, online banking malware, trojans, spyware, adware, crypto malware, etc. Malwares have the potential of stealing your bank login credentials, providing backdoor access to your network, and many other functionalities to the hackers. Malware can sometimes take months to find and remediate and can have a severe effect on your business.

Small businesses are a prime target for malware as they’re not as secure as large organizations, allowing hackers to infect multiple computers with the same malware campaign. They are largely delivered through an email or malicious website and can be avoided by maintaining vigilance and having an effective Anti-Virus product.

Ransomware

Snapshot of WannaCry Ransomware 2017. Source: Cisco Talos

Ransomware is a type of malware that when downloaded on a victim’s computer, encrypts the entire hard drive, and demands a ransom, typically in the range of $500-$5000 per computer, to decrypt the file. Since this threat is so prevalent in small businesses, we have dedicated a separate section to it.

As most businesses succumb to the pressure and pay the ransom, it is not surprising that ransomware is regarded as the most important cyber threat for the year 2020. However, it is not recommended to pay the ransom, as there is no guarantee that you will get your data back. Also, paying a ransom will not prevent future attacks and will only strengthen the hacker’s resolve.

Petya and WannaCry are some of the recent examples of Ransomware that infected thousands of computers across the world. To protect against this cyber threat, small businesses can implement the inexpensive practice of backing up their critical data and have a dedicated response plan for such situations.

Insider Threats

Insider threat is a security risk that originates from within the targeted organization and can come in two forms - accidental or malicious. Accidental insider threats are due to a lack of cyber hygiene. This is displayed through clicking on malicious links, using weak passwords, leaving a device open or using public Wi-Fi for confidential work, etc.

People are considered the weakest link in cybersecurity. No matter how sophisticated and expensive your security solutions are, they will all fail if your staff is not aware and sensitized to the need for cybersecurity. This is the most common type of cyber threat and can be tackled only through regular security awareness training that is personal and engaging.

Source: Ilantus

On the other hand, a malicious insider can be a current or former employee that has access to sensitive information or privileged accounts, and intend to misuse this access for either personal financial gain or cause damage to the business to exact revenge. 

There are many indicators of an insider threat including disgruntlement, unusual enthusiasm, downloading huge amount of data, request for access to sensitive data not related to their job function, frequent vacations or absence, and sudden change in financial circumstances.

Cyber Threats from Unpatched Software

Source: ManageEngine

When a computer or software prompts users to update, it is our natural tendency to postpone it. However, these updates and patches are critical because it relates to bugs or critical vulnerabilities in the software. It can be hard for a small business with limited resources to be able to manually patch all the various kinds of devices regularly.

An easy method is to employ a “push” methodology for security updates to various devices at a particular time of the day or before connecting to the network. Employing this simple tactic, can help you protect against the latest discovered threats.

Man-In-The-Middle Attack (MITM)

Man In the Middle Atta.ck (MITM) Source: Imperva

MITM occurs when the hacker attacks your communication and network services. It is an extremely efficient attack where the hacker sits between you and a website, making you believe that you are communicating with the website, while he uses the information you provide to log in and transfer money to his account (in case of a banking website).  MITM occurs due to ineffective security protocols used for communication.

Potential targets of this cyber threat are financial enterprises, SaaS businesses, and e-commerce sites. Always ensure communication is over HTTPS rather than HTTP especially during login and money transfer activities. 

Weak Network Configuration

As remote work becomes a norm, network devices are becoming increasingly complex and large in numbers. For a small business, there is usually only one singular admin responsible for all configurations - LAN, WAN, Servers, Workstations. It can be quite difficult for one person to handle so many devices and can result in adopting practices that are inherently insecure.

Depiction of a Firewall. Source: BackBox

Small businesses can face cyber threats if they have misconfigured equipment. This is primarily due to a lack of knowledge, attention, or time to properly configure it for relevant operations. For example, Firewalls, if misconfigured, can bring security vulnerabilities that hackers can exploit.

Further, using default passwords, or short and easy to guess passwords can make it easy for a hacker to get access to your equipment. Majority of small businesses keep either the default or an easy to guess password for their routers. As a good practice, change the default admin passwords on the router, provide a different SSID for customers with their devices isolated from the rest of the network, and use the EPA2+AES password encryption for your Wi-Fi. 

Misconfigured internet services like Java applets, Java Script, FTP security settings, and IP can also bring in cyber threats. As a business owners, you will need to understand these technical terms, at least, at the surface level to configure them properly and prevent hacks.

Distributed Denial of Service (DDoS)

In this attack, a hacker, that has control over a botnet army spread across the world, directs all its traffic to your web servers which is incapable of handling such loads. What’s more concerning is that DDoS is now available as a service on hacker marketplaces. Anyone with access to a credit card and the internet can overload your servers and prevent your site from functioning. This has huge repercussions for small businesses that can lose not only revenue but also reputation.

Source: Avinetworks

One of the most famous examples of DDoS is the hack of the Estonian Government and Banking website that left the internet dependent country struggling for days.

Best way to defend from this cyber threat is to always be ready. Having and incident response plan for DDoS, with a strong and redundant network architecture will help you prepare for the worst case scenario. Further, SMBs can leverage cloud based DDoS solutions that are on per pay basis to keep the cost low.

Bring-Your-Own-Device (BYOD) and Remote Work

Did you know that 40% of the large data breaches were caused by stolen or lost devices and that 60% of companies do not remove business data from their ex-employees’ devices? Today, all employees need access to digital devices to do their work. Some businesses, to keep the cost low, allow their staff to bring their own device to work. This is a serious security risk and becomes more concerning with remote work. Generally, employees take a lax approach to security and it can have devastating effects for a small business.

Therefore, it is important to develop strong policies surrounding BYOD and remote work to educate your staff. The BYOD policy should include topics such as ,communicating over a secure VPN, preventing access to ‘rooted’ devices and reporting stolen devices to the IT team.

Conclusion

As high speed internet and digital services have grown in the past few years, so have cyber-attacks. Small businesses are primary targets for such attacks as they hold sensitive information but low level security when compared to large organizations. It’s imperative that small businesses understand this dynamic threat and adopt a culture of security at their organization. While cybersecurity can seem daunting at first, learning about the threats is the first step to securing your business from cyber-attacks.

We hope you found this post useful and easy to understand the cyber threats pertaining to small businesses. Remember, you can never make your business a 100% attack proof, but can raise your guard enough to make it unworthy of a hacker’s time.