Welcome!

@CloudExpo Authors: Flint Brenton, Elizabeth White, Pat Romanski, Liz McMillan, Dean Madison

Related Topics: @CloudExpo, Agile Computing, Cloud Security

@CloudExpo: Blog Post

Why Small Businesses Still Don't Take Cyber Security Seriously By @NateMVickery | @CloudExpo #Cloud

Statistics say that more than half of all small businesses in the US don't provide security training for their employees

Although corporate giants realized the danger of cyber attacks and cyber crime in general, especially after attacks on Sony and Zappos, as well as the very sensitive data breach that struck Ashley Madison website, small businesses still don't do much for making their networks more secure.

Statistics say that more than half of all small businesses in the US don't provide security training for their employees, only one quarter conduct outside party security tests, and more than 40% don't produce backup copies of their most important business files, in case something goes wrong.

Why Small Businesses Don't Invest in Cyber Security?
Most small entrepreneurs think that their businesses are immune to cyber attacks due to false belief that cyber criminals only attack corporative and government websites. Annual research conducted by Symantec, for their 2015 Internet Security Threat Report determined that more than 40% of businesses that became victims of cyber crime have 500 or less employees.

These attacks create huge losses, and close thousands of small businesses every year. Small companies are much less likely to stand back on their feet and become competitive again after a disastrous data breach. Same research done by Symantec also determined that more than 60% of attacked companies had to be permanently closed afterwards.

How to Prevent Cyber Attacks?
No website can be 100% secure from cyber attacks, but by introducing new security protocols and providing proper training for employees, entrepreneurs can reduce the risk of cyber attacks to minimum. These are some of the things that can be done:

  • Physical Access Control- Only authorized personnel should have the access to company computers and gadgets.
  • Employee's training- All company employees' should understand cyber security principles and know how to securely use common services that can be found online. This includes: social networks, web browsing, e mail correspondence, and SMS and text messaging, since these are some of the most frequent channels through which cyber criminals slip in malware files into company computers. Security training for employees is especially important for companies that use BYOD work model.
  • Regular System Updates- Most cyber attacks are based on exploits which are continuously scanned by automated tools. Each one of these exploits comes with a patch that is quickly released, and that can protect system from outside attacks.
  • Backup- Having few backup locations is necessary, especially for businesses that deal with sensitive information.
  • Firewall- Firewalls are the basis of almost every network security strategy. They prevent the entrance of malicious files by checking all passing data that that enters and exits the network.
  • Regular Antivirus Updates- Outdated antivirus programs are mostly useless. These programs need to be regularly updated in order to recognize and deal with the latest bugs and other malicious software.
  • Secure Wi Fi networks- Only secure Wi-Fi networks should be used, both at company premises and at home, for employees who access company networks after work. One part of employee's security training should inform employees about the dangers of non-secure Wi-Fi networks.
  • Strong and Frequently Updated Passwords- Companies should use pass phrases instead of regular passwords, and should constantly update them.
  • Remote Support- Remote support software enables security technicians and engineers to access other computers in the network and act fast in case of security breach.
  • Limiting Access to Installation Software- Only few key technician and engineers should have access to installation software, because over-exposure of these sensitive files can have disastrous consequences on company's security.
  • Emergency Protocols- Companies need to have elaborate plans that determine specific tasks that should be done in case of emergency. These protocols should define the role of every employee and minimize the consequences of cyber attacks.
  • Hire Professionals- Many small businesses decide to hire cyber security agencies for developing security strategies. Although this can be costly at first, on the long run it is much more affordable and reliable option than hiring whole team of security experts in a regular way.

Although the facts acquired by independent researchers that deal with cyber security for small businesses still sound grim, a positive trend can be observed where entrepreneurs are becoming more aware of this problem. This comes as a result of media coverage of cyber attacks on big corporate entities, as well as many informative articles and guidelines published online.

More Stories By Nate Vickery

Nate M. Vickery is a business consultant from Sydney, Australia. He has a degree in marketing and almost a decade of experience in company management through latest technology trends. Nate is also the editor-in-chief at bizzmarkblog.com.

@CloudExpo Stories
Automation is enabling enterprises to design, deploy, and manage more complex, hybrid cloud environments. Yet the people who manage these environments must be trained in and understanding these environments better than ever before. A new era of analytics and cognitive computing is adding intelligence, but also more complexity, to these cloud environments. How smart is your cloud? How smart should it be? In this power panel at 20th Cloud Expo, moderated by Conference Chair Roger Strukhoff, paneli...
SYS-CON Events announced today that NetApp has been named “Bronze Sponsor” of SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. NetApp is the data authority for hybrid cloud. NetApp provides a full range of hybrid cloud data services that simplify management of applications and data across cloud and on-premises environments to accelerate digital transformation. Together with their partners, NetApp em...
Most of the time there is a lot of work involved to move to the cloud, and most of that isn't really related to AWS or Azure or Google Cloud. Before we talk about public cloud vendors and DevOps tools, there are usually several technical and non-technical challenges that are connected to it and that every company needs to solve to move to the cloud. In his session at 21st Cloud Expo, Stefano Bellasio, CEO and founder of Cloud Academy Inc., will discuss what the tools, disciplines, and cultural...
What is the best strategy for selecting the right offshore company for your business? In his session at 21st Cloud Expo, Alan Winters, U.S. Head of Business Development at MobiDev, will discuss the things to look for - positive and negative - in evaluating your options. He will also discuss how to maximize productivity with your offshore developers. Before you start your search, clearly understand your business needs and how that impacts software choices.
SYS-CON Events announced today that Interface Corporation will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Interface Corporation is a company developing, manufacturing and marketing high quality and wide variety of industrial computers and interface modules such as PCIs and PCI express. For more information, visit http://www.i...
SYS-CON Events announced today that Keisoku Research Consultant Co. will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Keisoku Research Consultant, Co. offers research and consulting in a wide range of civil engineering-related fields from information construction to preservation of cultural properties. For more information, vi...
SYS-CON Events announced today that MIRAI Inc. will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. MIRAI Inc. are IT consultants from the public sector whose mission is to solve social issues by technology and innovation and to create a meaningful future for people.
SYS-CON Events announced today that Fusic will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Fusic Co. provides mocks as virtual IoT devices. You can customize mocks, and get any amount of data at any time in your test. For more information, visit https://fusic.co.jp/english/.
SYS-CON Events announced today that N3N will exhibit at SYS-CON's @ThingsExpo, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. N3N’s solutions increase the effectiveness of operations and control centers, increase the value of IoT investments, and facilitate real-time operational decision making. N3N enables operations teams with a four dimensional digital “big board” that consolidates real-time live video feeds alongside IoT sensor data a...
Mobile device usage has increased exponentially during the past several years, as consumers rely on handhelds for everything from news and weather to banking and purchases. What can we expect in the next few years? The way in which we interact with our devices will fundamentally change, as businesses leverage Artificial Intelligence. We already see this taking shape as businesses leverage AI for cost savings and customer responsiveness. This trend will continue, as AI is used for more sophistica...
Today most companies are adopting or evaluating container technology - Docker in particular - to speed up application deployment, drive down cost, ease management and make application delivery more flexible overall. As with most new architectures, this dream takes significant work to become a reality. Even when you do get your application componentized enough and packaged properly, there are still challenges for DevOps teams to making the shift to continuous delivery and achieving that reducti...
Enterprises are moving to the cloud faster than most of us in security expected. CIOs are going from 0 to 100 in cloud adoption and leaving security teams in the dust. Once cloud is part of an enterprise stack, it’s unclear who has responsibility for the protection of applications, services, and data. When cloud breaches occur, whether active compromise or a publicly accessible database, the blame must fall on both service providers and users. In his session at 21st Cloud Expo, Ben Johnson, C...
SYS-CON Events announced today that Massive Networks, that helps your business operate seamlessly with fast, reliable, and secure internet and network solutions, has been named "Exhibitor" of SYS-CON's 21st International Cloud Expo ®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. As a premier telecommunications provider, Massive Networks is headquartered out of Louisville, Colorado. With years of experience under their belt, their team of...
21st International Cloud Expo, taking place October 31 - November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA, will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy. Me...
SYS-CON Events announced today that Enroute Lab will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Enroute Lab is an industrial design, research and development company of unmanned robotic vehicle system. For more information, please visit http://elab.co.jp/.
IBM helps FinTechs and financial services companies build and monetize cognitive-enabled financial services apps quickly and at scale. Hosted on IBM Bluemix, IBM’s platform builds in customer insights, regulatory compliance analytics and security to help reduce development time and testing. In his session at 21st Cloud Expo, Lennart Frantzell, a Developer Advocate with IBM, will discuss how these tools simplify the time-consuming tasks of selection, mapping and data integration, allowing devel...
SYS-CON Events announced today that Mobile Create USA will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Mobile Create USA Inc. is an MVNO-based business model that uses portable communication devices and cellular-based infrastructure in the development, sales, operation and mobile communications systems incorporating GPS capabi...
Today traditional IT approaches leverage well-architected compute/networking domains to control what applications can access what data, and how. DevOps includes rapid application development/deployment leveraging concepts like containerization, third-party sourced applications and databases. Such applications need access to production data for its test and iteration cycles. Data Security? That sounds like a roadblock to DevOps vs. protecting the crown jewels to those in IT.
SYS-CON Events announced today that SIGMA Corporation will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. uLaser flow inspection device from the Japanese top share to Global Standard! Then, make the best use of data to flip to next page. For more information, visit http://www.sigma-k.co.jp/en/.
SYS-CON Events announced today that B2Cloud will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. B2Cloud specializes in IoT devices for preventive and predictive maintenance in any kind of equipment retrieving data like Energy consumption, working time, temperature, humidity, pressure, etc.