Whilst 2020 has been the year of furloughing and lockdowns, hackers certainly haven’t been furloughed and they certainly haven’t stopped their activities…in fact they have increased!
Cyber attacks are on the increase and it is small and medium-sized businesses that are the victims, largely because remote working is making things easier for them. But why are these businesses targeted?
-
Small businesses are low-hanging fruit
While the headlines focus on major security breaches at major companies, small and medium sized businesses are actually the more common victims of cyber-attacks. In fact, the Federation for Small Businesses (FSB) estimates that small firms are being hit with upwards of 10,000 attacks daily. Even though the rewards may be less, cybercriminals see smaller organizations as low-hanging fruit because – due to lack of education and resources – they usually invest less in IT security and don’t often train their staff on cybersecurity risks.
-
Small businesses are more vulnerable to social engineering
Social engineering is an act of manipulating people into doing things like sharing confidential information or transferring money. Small businesses tend to be more exposed to this risk for a number of reasons: they have less basic security in place, like two-factor authentication; they don’t often know the risk or train employees; they usually work with a variety of third-party partners to run their business which is the root cause of 41% of data breaches; and they almost always makes and receive payments using bank transfers.
-
Small businesses often feel they must pay ransoms
Faced with choosing between paying a ransomware demand that may get them back online faster or enduring a long period of potentially business-crippling downtime, small businesses often feel that they have no choice but to pay these demands in the event of an attack. Without anyone to turn to for help, this is particularly true of those without access to the cyber incident specialists that cyber insurance can provide.
-
Small businesses are the ‘gateway’ to larger organisations
Many SMEs are connected electronically to the IT systems of a range of larger, partner organisations. So when cybercriminals are looking to infiltrate these larger and more cybersecure organisations, they are increasingly targeting their humble downstream suppliers to see if these small businesses offer a less-secure way in. What’s more, many of these IT relationships are visible through publicly available data.
-
Small businesses are sometimes just simply collateral damage
From the WannaCry attack of 2017 to the Blackbaud attack more recently (where over 125 UK organisations have already reported to the ICO that they’ve had a potential data breach), SMEs are often collateral damage in large-scale cyber-attacks that have nothing to do with them. Small businesses might think they are safe because they outsource their IT and their data is stored in the cloud, but if a cyber-attack is launched against one of these technology providers, it’s the businesses that rely on it that are often left footing the bill, whether paying for the business interruption costs involved, privacy notifications to customers, or reputational harm.
For more information about the risks your buisness might face and to find out how cyber insurance can help, please get in touch by phone (01527 306041) or complete your details below.
Information courtesy of CFC Underwriting